CVE-2026-5704
MediumAdvisory
Published 6 Apr 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.004
- 34th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,264
- of 17,792 indexed, latest versions
- Container images
- 2,232
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Security update for tar
Carried by container images the latest versions of 2,264 of 17,792 indexed charts deploy, on 2,232 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| tardeb | 1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+28 more | 1.27.1-1ubuntu0.1+esm7, 1.28-2.1ubuntu0.2+esm6, 1.29b-2ubuntu0.4+esm4, 1.30+dfsg-7ubuntu0.20.04.4+esm3+4 more | 2,226 |
| tarrpm | 1.34-150000.3.34.1, 1.34-150000.3.37.1 | 1.34-150000.3.42.1 | 6 |
- OSV records
- DEBIAN-CVE-2026-5704UBUNTU-CVE-2026-5704ECHO-6544-7e09-569cSUSE-SU-2026:2714-1
- Also known as
- USN-8477-1, USN-8477-2, USN-8477-3
Charts affected
2,264 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| wordpress-alpinewordpress-alpine | 1.5.18 | 2 of 6See more | 4,080 |
| Wordpresswordpress-mariadb | 1.0.2 | 1 of 2See more | 5,713 |
| playwright-synthetic-monitoringwork-adventure | 1.0.1 | 1 of 1See more | 14,218 |
| workshop-pipelinesworkshop-pipelines | 0.1.6 | 1 of 2See more | 11,622 |
| tabbyxdVerified publisher | 1.0.6 | 1 of 2See more | 7,714 |
| xkopsxkops | 0.1.0 | 3 of 5See more | 13,813 |
| xlinexline | 0.0.1 | 1 of 1See more | 2,152 |
| nginx-chartxxoznge-nginx | 0.1.0 | 1 of 1See more | 1,861 |
| helm-demoyahoon-helm-demoVerified publisher | 1.0.0 | 1 of 1See more | 1,311 |
| my-nginx-appyasser-nginx-app | 0.1.0 | 1 of 1See more | 1,861 |
| api-snapyoukadevVerified publisher | 0.1.1 | 1 of 1See more | 2,692 |
| changedetection-iozekker6Verified publisher | 1.99.0 | 1 of 1See more | 2,630 |
| NEW_APPzekker6Verified publisher | 0.0.0 | 1 of 1See more | 1,861 |
| clickhousezloi-space | 1.2.0 | 2 of 3See more | 9,272 |
Container images carrying it
2,232 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| cloudve/ | d79c1c5881c0 | tar | 1.29b-2ubuntu0.4+esm4 | 1 |
| clowder/ | 11f3d844e4c0 | tar | no fix listed | 1 |
| clowder/ | 14155326c7b9 | tar | no fix listed | 1 |
| clowder/ | bf146f1ca24f | tar | no fix listed | 1 |
| cm2network/ | 8cba47f53df5 | tar | no fix listed | 1 |
| codedesignplus/ | e336012bc781 | tar | no fix listed | 1 |
| codedesignplus/ | ac84661c605e | tar | no fix listed | 1 |
| codedesignplus/ | 360144457f4d | tar | no fix listed | 1 |
| codedesignplus/ | 3f6aaa32d526 | tar | no fix listed | 1 |
| collabora/ | 01dc4ab83977 | tar | no fix listed | 1 |
| collabora/ | 05299b452f7f | tar | no fix listed | 1 |
| conductoross/ | 9fba127693e6 | tar | no fix listed | 1 |
| consensys/ | bf6ecd2ea716 | tar | 1.35+dfsg-3ubuntu0.4 | 1 |
| contentsquareplatform/ | 24555f22d4be | tar | no fix listed | 1 |
| continuoussecuritytooling/ | f04ecefab64e | tar | no fix listed | 1 |
| cortezaproject/ | 0bcdcbcd3c63 | tar | 1.34+dfsg-1ubuntu0.1.22.04.6 | 1 |
| cortezaproject/ | 8eb7a26605c9 | tar | 1.30+dfsg-7ubuntu0.20.04.4+esm3 | 1 |
| cortezaproject/ | cb9f200de5d2 | tar | 1.34+dfsg-1ubuntu0.1.22.04.6 | 1 |
| cortezaproject/ | 4ea78dfe5364 | tar | no fix listed | 1 |
| coturn/ | f4c2af06c3c5 | tar | no fix listed | 1 |
| countly/ | e3c238248f99 | tar | 1.30+dfsg-7ubuntu0.20.04.4+esm3 | 1 |
| cradlepoint/ | 8f5720b0cd03 | tar | 1.29b-2ubuntu0.4+esm4 | 1 |
| cribl/ | 762747cb6796 | tar | 1.29b-2ubuntu0.4+esm4 | 1 |
| csiplugin/ | 1fa83d45417f | tar | 1.28-2.1ubuntu0.2+esm6 | 1 |
| cspconsole/ | 5524a26a6c23 | tar | no fix listed | 1 |
| cspconsole/ | 46dda4a31bd6 | tar | no fix listed | 1 |
| cspconsole/ | 39750248193b | tar | no fix listed | 1 |
| cspconsole/ | 9a2d8840bfdf | tar | no fix listed | 1 |
| cubejs/ | 34ac523a9bab | tar | no fix listed | 1 |
| cybrarist/ | e9e2447ac666 | tar | no fix listed | 1 |
| cyfershepard/ | c4e2dfa8bddf | tar | no fix listed | 1 |
| cznic/ | fe71c5214fdc | tar | no fix listed | 1 |
| dachichang/ | 7ccac90a935e | tar | no fix listed | 1 |
| daedalusproject/ | 6f72b5119eda | tar | 1.30+dfsg-7ubuntu0.20.04.4+esm3 | 1 |
| dagster/ | 0505973033e1 | tar | no fix listed | 1 |
| dagster/ | 22036fc83927 | tar | no fix listed | 1 |
| danialnabiyan1382/ | f96a7ebf1f42 | tar | no fix listed | 1 |
| dannielkil/ | 937993927694 | tar | no fix listed | 1 |
| darthsim/ | 3b709e4a0e5e | tar | 1.35+dfsg-3ubuntu0.4 | 1 |
| darthsim/ | 476cb08c816a | tar | 1.35+dfsg-3ubuntu0.4 | 1 |
| darthsim/ | 7d12c7c8fc66 | tar | 1.35+dfsg-3ubuntu0.4 | 1 |
| daskdev/ | 052630f5ca04 | tar | 1.29b-2ubuntu0.4+esm4 | 1 |
| dasmeta/ | fa657960dfec | tar | 1.29b-2ubuntu0.4+esm4 | 1 |
| datadog/ | aad9994de6a7 | tar | 1.35+dfsg-3ubuntu0.4 | 1 |
| datafuselabs/ | ba877ee6cb4d | tar | no fix listed | 1 |
| datafuselabs/ | a936843b85b4 | tar | no fix listed | 1 |
| datalayers/ | 17b292079239 | tar | 1.34+dfsg-1ubuntu0.1.22.04.6 | 1 |
| datalust/ | 9c731bb207a6 | tar | 1.28-2.1ubuntu0.2+esm6 | 1 |
| datalust/ | 3de34aed5642 | tar | 1.30+dfsg-7ubuntu0.20.04.4+esm3 | 1 |
| datamate/ | 2dd66b722464 | tar | 1.34+dfsg-1ubuntu0.1.22.04.6 | 1 |