StackRadar

CVE-2026-5704

Medium

Advisory

Published 6 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,264
of 17,790 indexed, latest versions
Container images
2,237
deployed by those charts
Fix available
2 of 2
affected packages

Security update for tar

Carried by container images the latest versions of 2,264 of 17,790 indexed charts deploy, on 2,237 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+28 more1.27.1-1ubuntu0.1+esm7, 1.28-2.1ubuntu0.2+esm6, 1.29b-2ubuntu0.4+esm4, 1.30+dfsg-7ubuntu0.20.04.4+esm3+4 more2,231
tarrpm1.34-150000.3.34.1, 1.34-150000.3.37.11.34-150000.3.42.16
OSV records
DEBIAN-CVE-2026-5704UBUNTU-CVE-2026-5704ECHO-6544-7e09-569cSUSE-SU-2026:2714-1
Also known as
USN-8477-1, USN-8477-2, USN-8477-3

Charts affected

2,264 by stars
ChartLatestAffected imagesRadar Score
palworldpalworld-server-chartVerified publisher2.7.11 of 1See more

palworld palworld-server-chart 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,715
paperless-ngxpaperlessVerified publisher0.4.03 of 3See more

paperless-ngx paperless 0.4.0

3 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/postgresqldigest-pinned926356130b77
tar@1.34+dfsg-1.2+deb12u1
no fix listed
valkey/valkey:9.0.54c64dfeae602
tar@1.35+dfsg-3.1
no fix listed
ghcr.io/paperless-ngx/paperless-ngxdigest-pinnedaa810a36942c
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

8,553
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

6,918
fahclientpcktdmp2.6.01 of 2See more

fahclient pcktdmp 2.6.0

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
foldingathome/fah-gpu:latest5ef7742d1eb4
tar@1.29b-2ubuntu0.2
1.29b-2ubuntu0.4+esm4

Open the chart page →

4,735
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

7,128
spring-boot-api-apppiominVerified publisher0.3.111 of 1See more

spring-boot-api-app piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
tar@1.34+dfsg-1build3
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

7,622
playgroundplayground0.1.11 of 1See more

playground playground 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,849
matomopockostVerified publisher1.3.02 of 3See more

matomo pockost 1.3.0

2 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
tar@1.35+dfsg-3.1
no fix listed
pockost/matomo:5.13.07f5d293cbe4e
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

5,204
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

32,033
postgresqlpostgresql-helm0.1.21 of 1See more

postgresql postgresql-helm 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,649
JenkinsprasoonjenkinsVerified publisher0.1.01 of 1See more

Jenkins prasoonjenkins 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,498
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/mariadb:11.7.2fcc7fcd7114a
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

5,490
prowlerprowler-appVerified publisher0.0.92 of 5See more

prowler prowler-app 0.0.9

2 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/neo4j:2026.02.25ab4ab0358cf
tar@1.35+dfsg-3.1
no fix listed
prowlercloud/prowler-api:5.31.14f252d579be2
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

8,269
pzserverpzserver0.1.171 of 2See more

pzserver pzserver 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
lis314/project-zomboid-docker:latestaa2089c37920
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,224
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
tar@1.35+dfsg-3ubuntu0.3
1.35+dfsg-3ubuntu0.4

Open the chart page →

24,027
minecraft-serverqumine0.1.15001 of 1See more

minecraft-server qumine 0.1.1500

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
qumine/minecraft-server:v0.1.15c0b650d51132
tar@1.34+dfsg-1build3
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

6,868
rabbitmqrabbitmq-magefleet1.2.01 of 1See more

rabbitmq rabbitmq-magefleet 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/rabbitmq:4.1.0-management935b3f84c1e4
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

2,815
napcatredish101Verified publisher0.1.31 of 1See more

napcat redish101 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
mlikiowa/napcat-docker:latest1336a777f9a4
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

7,474
redis-sentinel-gatewayredis-sentinel-gatewayVerified publisher1.0.21 of 1See more

redis-sentinel-gateway redis-sentinel-gateway 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
promzeus/redis-sentinel-gateway:v182f6d56e280b
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,675
redmineredmine-helm-chartVerified publisher0.2.61 of 1See more

redmine redmine-helm-chart 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

4,273
reportportalreportportal-ioOfficialVerified publisher26.8.122 of 15See more

reportportal reportportal-io 26.8.12

2 of the 15 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
tar@1.34+dfsg-1.2+deb12u1
no fix listed
library/postgres:18.4a02db8cac496
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

11,993
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

7,489
retyc-csiretyc-csi0.2.01 of 3See more

retyc-csi retyc-csi 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/retyc/retyc-k8s-csi:v0.2.01521d4baeb85
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,362
atuinrm3lVerified publisher0.11.02 of 3See more

atuin rm3l 0.11.0

2 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r890fda44bfa42
tar@1.34+dfsg-1.2+deb12u1
no fix listed
ghcr.io/atuinsh/atuin:18.12.0e953fa9e36ef
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

6,570
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

9,913
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

10,165
kimai2robjuz5.0.141 of 2See more

kimai2 robjuz 5.0.14

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
kimai/kimai2:2.67.03084f1e5ecdc
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

4,707
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

5,554
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
tar@1.30+dfsg-7ubuntu0.20.04.2
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

6,089
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

7,814
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
tar@1.30+dfsg-7ubuntu0.20.04.2
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

6,921
kube-state-metricsromanow-helm-chartsVerified publisher1.7.21 of 1See more

kube-state-metrics romanow-helm-charts 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/kube-state-metrics:204a3044b384b
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,684
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
tar@1.30+dfsg-7ubuntu0.20.04.2
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

7,570
postgresromanow-helm-chartsVerified publisher1.7.11 of 1See more

postgres romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,649
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

13,018
rstmdbrstmdb0.2.01 of 1See more

rstmdb rstmdb 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
rstmdb/rstmdb:lateste5187f2aaace
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,072
mealiertomik-helm-chartsVerified publisher0.0.21 of 1See more

mealie rtomik-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,952
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

5,332
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
tar@1.29b-2ubuntu0.2
1.29b-2ubuntu0.4+esm4

Open the chart page →

13,558
kyoorubxkubeVerified publisher0.1.104 of 9See more

kyoo rubxkube 0.1.10

4 of the 9 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
tar@1.34+dfsg-1.2+deb12u1
no fix listed
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
tar@1.34+dfsg-1.2+deb12u1
no fix listed
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
tar@1.34+dfsg-1.2+deb12u1
no fix listed
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

30,428
conference-appsalaboy1.0.03 of 7See more

conference-app salaboy 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
salaboy/agenda-service-0967b907d9920c99918e2b91b91937b3digest-pinnedce9ce8293e4e
tar@1.34+dfsg-1ubuntu0.1.22.04.1
1.34+dfsg-1ubuntu0.1.22.04.6
salaboy/c4p-service-a3dc0474cbfa348afcdf47a8eee70ba9digest-pinnedbb64bf14467d
tar@1.34+dfsg-1ubuntu0.1.22.04.1
1.34+dfsg-1ubuntu0.1.22.04.6
salaboy/notifications-service-0e27884e01429ab7e350cb5dff61b525digest-pinned799c35f9f306
tar@1.34+dfsg-1ubuntu0.1.22.04.1
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

11,031
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

38,166
teamcityscalified-teamcityVerified publisher2026.2.01 of 3See more

teamcity scalified-teamcity 2026.2.0

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,649
sceptresceptreai0.1.122 of 5See more

sceptre sceptreai 0.1.12

2 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
maponyacharles/sceptreai:mlflow-0.1.1242d418654ebd
tar@1.35+dfsg-3.1
no fix listed
maponyacharles/sceptreai:api-0.1.127b37b092130a
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

4,424
schemaheroschemahero1.4.01 of 1See more

schemahero schemahero 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
schemahero/schemahero-manager:0.22.11609e1a05cd3
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

2,184
searxngsearxngVerified publisher0.1.111 of 3See more

searxng searxng 0.1.11

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
valkey/valkey:9.1.1-trixie64e361b630ec
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

829
securosecuroVerified publisher0.15.12 of 4See more

securo securo 0.15.1

2 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
pgvector/pgvector:pg16ccc6e83d6e35
tar@1.34+dfsg-1.2+deb12u1
no fix listed
ghcr.io/securo-finance/securo-backend:0.15.162e030110745
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,539
immichsecustorVerified publisher2.0.51 of 1See more

immich secustor 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.12ab6a6273755
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,081
viya4-home-dir-builderselerityVerified publisher1.1.01 of 2See more

viya4-home-dir-builder selerity 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/python:3.12-slim78387bc3881b
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

874
sentry-k8ssentry-k8sVerified publisher1.4.15 of 11See more

sentry-k8s sentry-k8s 1.4.1

5 of the 11 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
library/postgres:16f1c3376c26f2
tar@1.35+dfsg-3.1
no fix listed
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
tar@1.34+dfsg-1.2+deb12u1
no fix listed
ghcr.io/getsentry/snuba:26.7.210f8d164109b
tar@1.35+dfsg-3.1
no fix listed
ghcr.io/getsentry/taskbroker:26.7.264d0da74a578
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

16,599

Container images carrying it

2,237 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/datadoghq/private-action-runner:v1.21.05f5918f843a4
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
tar@1.29b-2ubuntu0.1
1.29b-2ubuntu0.4+esm4
1
gcr.io/google-containers/echoserver:1.910f4dbc8eeeb
tar@1.28-2.1ubuntu0.1
1.28-2.1ubuntu0.2+esm6
1
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
tar@1.28-2.1ubuntu0.1
1.28-2.1ubuntu0.2+esm6
1
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
tar@1.28-2.1ubuntu0.1
1.28-2.1ubuntu0.2+esm6
1
gcr.io/istio-release/pilot:1.11.1c552478f8f11
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
tar@1.28-2.1ubuntu0.1
1.28-2.1ubuntu0.2+esm6
1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
gcr.io/istio-testing/operator:latest8d4576f7b98f
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
1
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
tar@1.28-2.1ubuntu0.1
1.28-2.1ubuntu0.2+esm6
1
gcr.io/ml-pipeline/metadata-envoy:2.3.0e8e263a919ff
tar@1.30+dfsg-7ubuntu0.20.04.4
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
gcr.io/tfx-oss-public/ml_metadata_store_server:1.14.051404ef4419c
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
gcr.io/tfx-oss-public/ml_metadata_store_server:1.5.0db8691752b4c
tar@1.29b-2ubuntu0.2
1.29b-2ubuntu0.4+esm4
1
ghcr.io/98jan/smalland-server/smalland-server:deveb7be822d5b2
tar@1.29b-2ubuntu0.4
1.29b-2ubuntu0.4+esm4
1
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/aeharding/voyager:latest779759172676
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/aetrius/msockperf-server/msockperf-server:main46ae4ea003e0
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/afairgiant/medikeep:v0.70.04c28334f3c79
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/aklivity/zilla:2.4.289c4a2e74863
tar@1.34+dfsg-1ubuntu0.1.22.04.3
1.34+dfsg-1ubuntu0.1.22.04.6
1
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/analogj/scrutiny:v0.9.2-web71be54e99608
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
1
ghcr.io/appscode/csi-driver-cacerts:v0.5.0b6bf1888f9d5
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
1
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
1
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astriaorg/account-monitor:latest4c8b42890035
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astriaorg/auctioneer:pr-18391386b7b5e555
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astriaorg/conductor:1.1.01f97d131b1d1
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astriaorg/evm-bridge-withdrawer:1.0.29c88e1aff357
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astriaorg/hermes:0.5.04f33a0a9f75e
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/astriaorg/sequencer:latest44f82ee0b24c
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astriaorg/sequencer-relayer:latest5f6c74993f08
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/atuinsh/atuin:18.12.0e953fa9e36ef
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.