StackRadar

CVE-2026-5704

Medium

Advisory

Published 6 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,259
of 17,781 indexed, latest versions
Container images
2,226
deployed by those charts
Fix available
2 of 2
affected packages

Security update for tar

Carried by container images the latest versions of 2,259 of 17,781 indexed charts deploy, on 2,226 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+28 more1.27.1-1ubuntu0.1+esm7, 1.28-2.1ubuntu0.2+esm6, 1.29b-2ubuntu0.4+esm4, 1.30+dfsg-7ubuntu0.20.04.4+esm3+4 more2,220
tarrpm1.34-150000.3.34.1, 1.34-150000.3.37.11.34-150000.3.42.16
OSV records
DEBIAN-CVE-2026-5704UBUNTU-CVE-2026-5704ECHO-6544-7e09-569cSUSE-SU-2026:2714-1
Also known as
USN-8477-1, USN-8477-2, USN-8477-3

Charts affected

2,259 by stars
ChartLatestAffected imagesRadar Score
technitium-dnsserverobeoneVerified publisher1.13.01 of 1See more

technitium-dnsserver obeone 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
technitium/dns-server:15.4.0df7d90ef0f7b
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

1,187
passboltpassbolt2.1.15 of 6See more

passbolt passbolt 2.1.1

5 of the 6 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/redis-sentinel:8.2.1-debian-12-r00ca3ea1d2f82
tar@1.34+dfsg-1.2+deb12u1
no fix listed
library/haproxy:3.4.10f597665a2a6
tar@1.35+dfsg-3.1
no fix listed
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

13,350
mssqlserver-2022simcube1.2.31 of 1See more

mssqlserver-2022 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
tar@1.34+dfsg-1ubuntu0.1.22.04.4
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

2,878
swo-k8s-collectorsolarwindsOfficialVerified publisher5.3.01 of 3See more

swo-k8s-collector solarwinds 5.3.0

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
solarwinds/solarwinds-otel-collector:0.152.3-k8s3c1110e8bdfb
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,335
thehivestrangebee-helmOfficialVerified publisher1.0.64 of 7See more

thehive strangebee-helm 1.0.6

4 of the 7 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
strangebee/thehive:5.7.6-1e77b713124dd
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

16,210
uffizzi-controlleruffizzi-controller2.4.61 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

1 of the 11 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

14,240
minecraft-overvieweralphani-helm-chartsVerified publisher0.1.01 of 3See more

minecraft-overviewer alphani-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,380
openvpn-asas-helm-chartOfficialVerified publisher0.2.11 of 1See more

openvpn-as as-helm-chart 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
openvpn/openvpn-as:latest2253c10ec652
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

2,668
baserowbaserow-chartVerified publisher1.0.565 of 6See more

baserow baserow-chart 1.0.56

5 of the 6 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
baserow/backend:2.3.37c00549b3a6f
tar@1.35+dfsg-3.1
no fix listed
baserow/web-frontend:2.3.3566d24c7d9f5
tar@1.35+dfsg-3.1
no fix listed
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/redis:7.2.5-debian-12-r05261cae9e407
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

17,263
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
tar@1.30+dfsg-7
1.30+dfsg-7ubuntu0.20.04.4+esm3
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
tar@1.30+dfsg-7
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

52,919
headwind-mdmchristianhuthVerified publisher5.10.11 of 2See more

headwind-mdm christianhuth 5.10.1

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

5,870
dolibarrcowboysysopVerified publisher9.0.32 of 3See more

dolibarr cowboysysop 9.0.3

2 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
tar@1.34+dfsg-1.2+deb12u1
no fix listed
dolibarr/dolibarr:22.0.47ad88fc9b13c
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

9,106
dagster-user-deploymentsdagsterVerified publisher1.13.221 of 1See more

dagster-user-deployments dagster 1.13.22

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
dagster/user-code-example:1.13.225947f9ae481c
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

928
daskhubdask2024.1.11 of 9See more

daskhub dask 2024.1.1

1 of the 9 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
pangeo/base-notebook:2024.01.155fbe688a4f80
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

14,094
seafiledatamateVerified publisher0.6.04 of 6See more

seafile datamate 0.6.0

4 of the 6 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb-galera:11.4.3-debian-12-r0cb8beb6dbb58
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/memcached:1.6.29-debian-12-r4ff0e7239c17c
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
datamate/seafile-professional:11.0.202dd66b722464
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

27,267
dialdialOfficialVerified publisher7.2.01 of 4See more

dial dial 7.2.0

1 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,163
jellyfindjjudas21Verified publisher4.0.81 of 1See more

jellyfin djjudas21 4.0.8

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,604
plexgabe565Verified publisher0.5.11 of 1See more

plex gabe565 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:version-1.41.4.9463-630c9f557e6d2775e77ec
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

2,539
geonode-k8sgeonode-k8sVerified publisher2.0.04 of 10See more

geonode-k8s geonode-k8s 2.0.0

4 of the 10 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
geopython/pycsw:3.0.0-beta284662ea6b78b
tar@1.34+dfsg-1.2+deb12u1
no fix listed
library/memcached:1.6.40cc523a19da58
tar@1.35+dfsg-3.1
no fix listed
library/redis:8.4.03906b477e4b6
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

13,953
gitops-promotergitops-promoterOfficialVerified publisher0.17.01 of 2See more

gitops-promoter gitops-promoter 0.17.0

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,814
glpiglpi-conteiner0.1.02 of 3See more

glpi glpi-conteiner 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
tar@1.35+dfsg-3.1
no fix listed
vdiogov/glpi-conteiner:latest6945f84f0058
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

12,170
grafana-mcpgrafana-communityVerified publisher0.23.11 of 1See more

grafana-mcp grafana-community 0.23.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
grafana/mcp-grafana:1.4.1cfcf06863c23
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,073
dolibarrhelmforgeVerified publisher1.2.181 of 3See more

dolibarr helmforge 1.2.18

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
dolibarr/dolibarr:24.0.069ec52e3b7ef
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

4,109
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

9,460
openhabhelmforgeVerified publisher1.2.01 of 1See more

openhab helmforge 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
openhab/openhab:5.2.1bfd4a60e90da
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,641
postgresqlhelmforgeVerified publisher2.0.51 of 1See more

postgresql helmforge 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,626
umamihelmforgeVerified publisher2.3.31 of 3See more

umami helmforge 2.3.3

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,027
openctihelm-openctiVerified publisher3.0.91 of 8See more

opencti helm-opencti 3.0.9

1 of the 8 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,383
hertzbeathertzbeatOfficialVerified publisher1.8.13 of 4See more

hertzbeat hertzbeat 1.8.1

3 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
apache/hertzbeat-collector:1.8.0a2bab1be574c
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
library/postgres:159b1d34adbce1
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

14,000
infrahubinfrahubVerified publisher4.33.24 of 5See more

infrahub infrahub 4.33.2

4 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
library/neo4j:2026.05.06c162e2432f8
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

10,428
plexk8s-home-lab-repo7.3.11 of 1See more

plex k8s-home-lab-repo 7.3.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

1,685
kamu-api-serverkamuVerified publisher0.89.01 of 1See more

kamu-api-server kamu 0.89.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
tar@1.30+dfsg-7ubuntu0.20.04.4
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

6,307
kubeflowkubeflow1.6.25 of 45See more

kubeflow kubeflow 1.6.2

5 of the 45 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
tar@1.29b-2ubuntu0.2
1.29b-2ubuntu0.4+esm4
istio/proxyv2:1.14.1df69c1a7af7c
tar@1.30+dfsg-7ubuntu0.20.04.2
1.30+dfsg-7ubuntu0.20.04.4+esm3
library/python:3.7eedf63967cdb
tar@1.34+dfsg-1.2
no fix listed
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
tar@1.28-2.1ubuntu0.1
1.28-2.1ubuntu0.2+esm6
gcr.io/tfx-oss-public/ml_metadata_store_server:1.5.0db8691752b4c
tar@1.29b-2ubuntu0.2
1.29b-2ubuntu0.4+esm4

Open the chart page →

96,941
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

10,530
librechatlibrechat-openshiftVerified publisher1.9.02 of 3See more

librechat librechat-openshift 1.9.0

2 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

5,779
libredb-studiolibredb-studioVerified publisher0.1.631 of 1See more

libredb-studio libredb-studio 0.1.63

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.15.04b696f960ac1
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,222
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

7,949
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
gradiant/open5gs-dbctl:0.10.3332031245fce
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

9,261
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
tar@1.34+dfsg-1ubuntu0.1.22.04.1
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

8,722
unifi-controllerqonstruktVerified publisher2.6.11 of 1See more

unifi-controller qonstrukt 2.6.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:8.0.240ae315a3a456
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

10,469
steampipe-powerpipe-kubernetessteampipe-powerpipe-kubernetesVerified publisher0.13.12 of 2See more

steampipe-powerpipe-kubernetes steampipe-powerpipe-kubernetes 0.13.1

2 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

5,468
uffizzi-appuffizzi-app1.3.01 of 14See more

uffizzi-app uffizzi-app 1.3.0

1 of the 14 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

19,337
reposilitevolker-raschekVerified publisher1.0.01 of 1See more

reposilite volker-raschek 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
dzikoysk/reposilite:3.5.264128c2d7a6ba
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

2,957
dexwiremindVerified publisher2.15.71 of 2See more

dex wiremind 2.15.7

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
gcr.io/google_containers/kubernetes-dashboard-init-amd64:v1.0.0fbe12aa24de6
tar@1.28-2.1ubuntu0.1
1.28-2.1ubuntu0.2+esm6

Open the chart page →

13,562
grafana-pdf-exporterwiremindVerified publisher2.1.11 of 1See more

grafana-pdf-exporter wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

9,746
matrixzekker6Verified publisher3.30.01 of 4See more

matrix zekker6 3.30.0

1 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.160.078de1d10bef0
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

5,557
zenmlzenml0.96.41 of 1See more

zenml zenml 0.96.4

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
zenmldocker/zenml-server:0.96.409027a6312ee
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,272
eshoponabpabp-charts1.0.01 of 15See more

eshoponabp abp-charts 1.0.0

1 of the 15 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/mongo:4.2699d652ed674
tar@1.29b-2ubuntu0.4
1.29b-2ubuntu0.4+esm4

Open the chart page →

19,799
changedetectionalekcVerified publisher0.14.21 of 1See more

changedetection alekc 0.14.2

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.47bb6963b730d
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,595
code-serveralekcVerified publisher0.1.11 of 1See more

code-server alekc 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
linuxserver/code-server:4.10.1a5e43a05ae79
tar@1.34+dfsg-1ubuntu0.1.22.04.1
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

8,212

Container images carrying it

2,226 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
tar@1.30+dfsg-7ubuntu0.20.04.2
1.30+dfsg-7ubuntu0.20.04.4+esm3
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
tar@1.28-2.1ubuntu0.2
1.28-2.1ubuntu0.2+esm6
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
tar@1.34+dfsg-1ubuntu0.1.22.04.1
1.34+dfsg-1ubuntu0.1.22.04.6
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
tar@1.34+dfsg-1.2+deb12u1
no fix listed
3
actualbudget/actual-server:26.9.0552beab3dec8
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
alazidis/kube-netlag:1.1.00e8c84152201
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
2
apache/nifi-registry:1.26.07cdfd8deec92
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
2
apache/rocketmq:5.4.0319cd8a81ed1
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnamilegacy/etcd:latest99b408c15272
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnamilegacy/redis:latest5927ff3702df
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnami/minideb:latestab4d5b45116e
tar@1.35+dfsg-3.1
no fix listed
2
blockstack/stacks-core:3.2.0.0.0f79944317326
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
tar@1.35+dfsg-3.1
no fix listed
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
tar@1.34+dfsg-1.2
no fix listed
2
chromedp/headless-shell:148.0.7778.97313ed7255ae1
tar@1.35+dfsg-3.1
no fix listed
2
clickhouse/clickhouse-server:24.2ed9640bfff07
tar@1.30+dfsg-7ubuntu0.20.04.4
1.30+dfsg-7ubuntu0.20.04.4+esm3
2
dagster/user-code-example:1.13.225947f9ae481c
tar@1.35+dfsg-3.1
no fix listed
2
eqalpha/keydb:latest6537505c4235
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
tar@1.35+dfsg-3.1
no fix listed
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
tar@1.35+dfsg-3.1
no fix listed
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
tar@1.29b-2ubuntu0.1
1.29b-2ubuntu0.4+esm4
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
tar@1.34+dfsg-1.2
no fix listed
2
gotenberg/gotenberg:8.36.087c16b9f3642
tar@1.35+dfsg-3.1
no fix listed
2
gotenberg/gotenberg:8:8.37.0f29984bd1e22
tar@1.35+dfsg-3.1
no fix listed
2
gradiant/ueransim:3.2.6015b30d5fa0f
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
2
grafana/alloy:v1.8.17790f6f7fbd8
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
2
grafana/alloy:v1.12.2f94b1c82957a
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
2
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
tar@1.35+dfsg-3.1
no fix listed
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
tar@1.35+dfsg-3.1
no fix listed
2
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
tar@1.34+dfsg-1.2
no fix listed
2
honestica/kube-iptables-tailer:master-91a393242fb939
tar@1.30+dfsg-7ubuntu0.20.04.2
1.30+dfsg-7ubuntu0.20.04.4+esm3
2
hookiesolutions/webhookie:latest0629694246ba
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.