StackRadar

CVE-2026-5704

Medium

Advisory

Published 6 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,298
of 17,821 indexed, latest versions
Container images
2,273
deployed by those charts
Fix available
2 of 2
affected packages

tar-1.35-8.1 on GA media

Carried by container images the latest versions of 2,298 of 17,821 indexed charts deploy, on 2,273 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+28 more1.27.1-1ubuntu0.1+esm7, 1.28-2.1ubuntu0.2+esm6, 1.29b-2ubuntu0.4+esm4, 1.30+dfsg-7ubuntu0.20.04.4+esm3+4 more2,266
tarrpm1.30-lp152.3.6, 1.34-150000.3.34.1, 1.34-150000.3.37.11.34-150000.3.42.1, 1.35-8.17
OSV records
DEBIAN-CVE-2026-5704UBUNTU-CVE-2026-5704ECHO-6544-7e09-569copenSUSE-SU-2026:11125-1SUSE-SU-2026:2714-1
Also known as
USN-8477-1, USN-8477-2, USN-8477-3

Charts affected

2,298 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,273 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
tar@1.35+dfsg-3.1
no fix listed
1
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
tar@1.35+dfsg-3.1
no fix listed
1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
tar@1.35+dfsg-3.1
no fix listed
1
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
tar@1.35+dfsg-3.1
no fix listed
1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
tar@1.35+dfsg-3.1
no fix listed
1
stackstorm/st2actionrunner:3.888235ba70cad
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
stackstorm/st2api:3.86f56d239d280
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
stackstorm/st2auth:3.833ecfda16608
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
stackstorm/st2notifier:3.8f190a6212195
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
stackstorm/st2rulesengine:3.8259503496ff9
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
stackstorm/st2scheduler:3.8b1de2055c362
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
stackstorm/st2stream:3.81c8904a3bf67
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
stackstorm/st2timersengine:3.81bf35bfaf00c
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
stackstorm/st2web:3.809989a26c8b7
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
stackstorm/st2workflowengine:3.819fdfffdbba8
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
stalwartlabs/stalwart:v0.16.1425001929f36a
tar@1.35+dfsg-3.1
no fix listed
1
stalwartlabs/stalwart:v0.16.22388dcb75a707
tar@1.35+dfsg-3.1
no fix listed
1
stalwartlabs/stalwart:v0.16.2074ca4f7f6885
tar@1.35+dfsg-3.1
no fix listed
1
stalwartlabs/stalwart:v0.15.5dcf575db2d53
tar@1.35+dfsg-3.1
no fix listed
1
stashapp/stash:latest24dbd7607174
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
stashapp/stash-box:latesta534c8afdf39
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
statcan/ckan:2.93921305425b8
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
statusim/nimbus-eth2:multiarch-latest6ccd9d382885
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
strangebee/thehive:5.8.0-1a7f7b05fba24
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
structurizr/onpremises:2025.11.094b5ffb5119c8
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
substratusai/verba:v0.4.0-baseURL261695be635eb
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
supabase/edge-runtime:v1.74.02781daf92394
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
supabase/edge-runtime:v1.59.0eff9c554d649
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
supabase/logflare:latest49bfe526f1b4
tar@1.35+dfsg-3.1
no fix listed
1
supabase/postgres-meta:v0.96.6a84cc713585e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
supabase/postgres-meta:v0.84.2d0a96973e9f1
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
supabase/realtime:v2.102.3aa1c92c0cf32
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
supabase/realtime:v2.33.8d207e6e23ad3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
supabase/realtime:latestd3aa0c86c7b3
tar@1.35+dfsg-3.1
no fix listed
1
supabase/studio:20241021-9f9b08326d8070c55e9
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
supabase/studio:latest94a2a9d2906e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
tar@1.34+dfsg-1ubuntu0.1.22.04.1
1.34+dfsg-1ubuntu0.1.22.04.6
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
swimmwatch/cloakbrowser-mcp:1.13.0d48c705a58c8
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
sysnet4admin/colosseum-agg:logbc25b152d88e
tar@1.34+dfsg-1ubuntu0.1.22.04.4
1.34+dfsg-1ubuntu0.1.22.04.6
1
sysnet4admin/colosseum-cms:loge74b43c7f492
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
sysnet4admin/colosseum-rwd:log74ded2d92f07
tar@1.35+dfsg-3.1
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.