StackRadar

CVE-2026-5704

Medium

Advisory

Published 6 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,264
of 17,792 indexed, latest versions
Container images
2,232
deployed by those charts
Fix available
2 of 2
affected packages

Security update for tar

Carried by container images the latest versions of 2,264 of 17,792 indexed charts deploy, on 2,232 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+28 more1.27.1-1ubuntu0.1+esm7, 1.28-2.1ubuntu0.2+esm6, 1.29b-2ubuntu0.4+esm4, 1.30+dfsg-7ubuntu0.20.04.4+esm3+4 more2,226
tarrpm1.34-150000.3.34.1, 1.34-150000.3.37.11.34-150000.3.42.16
OSV records
DEBIAN-CVE-2026-5704UBUNTU-CVE-2026-5704ECHO-6544-7e09-569cSUSE-SU-2026:2714-1
Also known as
USN-8477-1, USN-8477-2, USN-8477-3

Charts affected

2,264 by stars
ChartLatestAffected imagesRadar Score
wordpress-alpinewordpress-alpine1.5.182 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

2 of the 6 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/mariadb:12.3.2628f228f0fd5
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
library/memcached:1.6.45dc561d52bb8a
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

4,080
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

5,713
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

14,218
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

11,622
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

7,714
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
hamzaarshad10/querypodpy:1.7154f38e8668e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
murtazashah46/helmfile:latest4d11726cf803
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

13,813
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

2,152
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,861
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,311
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,861
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,692
changedetection-iozekker6Verified publisher1.99.01 of 1See more

changedetection-io zekker6 1.99.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.47bb6963b730d
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,630
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,861
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
tar@1.29b-2ubuntu0.2
1.29b-2ubuntu0.4+esm4
yandex/clickhouse-server:21.3.204eccfffb01d7
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

9,272

Container images carrying it

2,232 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
cloudve/ttyd:latestd79c1c5881c0
tar@1.29b-2ubuntu0.1
1.29b-2ubuntu0.4+esm4
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
cm2network/squad:latest8cba47f53df5
tar@1.35+dfsg-3.1
no fix listed
1
codedesignplus/ms-emails-grpc:lateste336012bc781
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
codedesignplus/ms-emails-rest:latestac84661c605e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
codedesignplus/ms-licenses-grpc:latest360144457f4d
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
codedesignplus/ms-modules-grpc:latest3f6aaa32d526
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
collabora/code:24.04.13.2.101dc4ab83977
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
collabora/code:23.05.10.1.105299b452f7f
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
conductoross/conductor:3.31.09fba127693e6
tar@1.35+dfsg-3.1
no fix listed
1
consensys/teku:25.4.1bf6ecd2ea716
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
1
cortezaproject/corteza:2024.9.08eb7a26605c9
tar@1.30+dfsg-7ubuntu0.20.04.4
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
coturn/coturn:4.10.0-r1f4c2af06c3c5
tar@1.35+dfsg-3.1
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
tar@1.30+dfsg-7ubuntu0.20.04.2
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
cradlepoint/pgbouncer:1.0.18f5720b0cd03
tar@1.29b-2
1.29b-2ubuntu0.4+esm4
1
cribl/cribl:3.0.2762747cb6796
tar@1.29b-2ubuntu0.2
1.29b-2ubuntu0.4+esm4
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
tar@1.28-2.1ubuntu0.2
1.28-2.1ubuntu0.2+esm6
1
cspconsole/config-provider:1.0.365524a26a6c23
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
cspconsole/report-collector:1.0.15839750248193b
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
cspconsole/report-processor:1.0.279a2d8840bfdf
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
cubejs/cubestore:v1.5.334ac523a9bab
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
tar@1.35+dfsg-3.1
no fix listed
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
cznic/knot-resolver:v6.4.2fe71c5214fdc
tar@1.35+dfsg-3.1
no fix listed
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
tar@1.34+dfsg-1.2
no fix listed
1
daedalusproject/base_kubectl:latest6f72b5119eda
tar@1.30+dfsg-7
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
dagster/dagster-celery-k8s:1.13.230505973033e1
tar@1.35+dfsg-3.1
no fix listed
1
dagster/dagster-cloud-agent:1.13.2322036fc83927
tar@1.35+dfsg-3.1
no fix listed
1
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
dannielkil/book-frontend:latest937993927694
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
darthsim/imgproxy:v3.30.13b709e4a0e5e
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
darthsim/imgproxy:v3.26476cb08c816a
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
darthsim/imgproxy:v3.29.17d12c7c8fc66
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
daskdev/dask-notebook:1.1.0052630f5ca04
tar@1.29b-2
1.29b-2ubuntu0.4+esm4
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
tar@1.29b-2ubuntu0.3
1.29b-2ubuntu0.4+esm4
1
datadog/agent:6aad9994de6a7
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
datafuselabs/databend-meta:v1.2.279ba877ee6cb4d
tar@1.34+dfsg-1.2
no fix listed
1
datafuselabs/databend-query:v1.2.279a936843b85b4
tar@1.34+dfsg-1.2
no fix listed
1
datalayers/datalayers:v2.2.1017b292079239
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
1
datalust/seq:5.0.832-pre9c731bb207a6
tar@1.28-2.1ubuntu0.1
1.28-2.1ubuntu0.2+esm6
1
datalust/seq-input-gelf:3.0.441-x643de34aed5642
tar@1.30+dfsg-7ubuntu0.20.04.2
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
datamate/seafile-professional:11.0.202dd66b722464
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.