StackRadar

CVE-2026-5704

Medium

Advisory

Published 6 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,264
of 17,790 indexed, latest versions
Container images
2,237
deployed by those charts
Fix available
2 of 2
affected packages

Security update for tar

Carried by container images the latest versions of 2,264 of 17,790 indexed charts deploy, on 2,237 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+28 more1.27.1-1ubuntu0.1+esm7, 1.28-2.1ubuntu0.2+esm6, 1.29b-2ubuntu0.4+esm4, 1.30+dfsg-7ubuntu0.20.04.4+esm3+4 more2,231
tarrpm1.34-150000.3.34.1, 1.34-150000.3.37.11.34-150000.3.42.16
OSV records
DEBIAN-CVE-2026-5704UBUNTU-CVE-2026-5704ECHO-6544-7e09-569cSUSE-SU-2026:2714-1
Also known as
USN-8477-1, USN-8477-2, USN-8477-3

Charts affected

2,264 by stars
ChartLatestAffected imagesRadar Score
nebraskanebraska3.0.01 of 2See more

nebraska nebraska 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.042a8200d3597
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

4,077
observalobservalVerified publisher1.13.12 of 8See more

observal observal 1.13.1

2 of the 8 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
tar@1.35+dfsg-3.1
no fix listed
ghcr.io/observal/observal-api:1.13.1153b8b893232
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

5,916
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

5,244
oesopsmxVerified publisher4.0.323 of 25See more

oes opsmx 4.0.32

3 of the 25 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
tar@1.28-2.1ubuntu0.1
1.28-2.1ubuntu0.2+esm6
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

108,315
part-dbpart-dbVerified publisher0.1.21 of 1See more

part-db part-db 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
jbtronics/part-db1:latest5db71f6db59d
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,344
redispascaliskeVerified publisher2.1.01 of 1See more

redis pascaliske 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/redis:8.0.3be0a135f1955
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,869
phpmyadminphpmyadminVerified publisher1.0.31 of 1See more

phpmyadmin phpmyadmin 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,650
prometheus-prefect-exporterprefectVerified publisher2026.8.71410241 of 1See more

prometheus-prefect-exporter prefect 2026.8.7141024

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
prefecthq/prometheus-prefect-exporter:4.0.050d527a190ae
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,022
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/nginx:1.27.409369da6b103
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

5,465
repoflowrepoflow-helm-public0.9.13 of 8See more

repoflow repoflow-helm-public 0.9.1

3 of the 8 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.48.10f6c1c4b957d2
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
library/elasticsearch:8.15.0310b9fc03b06
tar@1.30+dfsg-7ubuntu0.20.04.4
1.30+dfsg-7ubuntu0.20.04.4+esm3
library/postgres:16.24aea012537ed
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

13,647
nominatimrobjuz6.4.12 of 4See more

nominatim robjuz 6.4.1

2 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
mediagis/nominatim:5.3.27923a8e67197
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

8,783
rocketmq-clusterrocketmq12.6.01 of 2See more

rocketmq-cluster rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

6,400
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

24,566
satisfactory-serversatisfactoryVerified publisher0.1.61 of 1See more

satisfactory-server satisfactory 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.10e103700ae6ae
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

3,469
lldapself-hosters-by-nightVerified publisher0.5.21 of 2See more

lldap self-hosters-by-night 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,423
skypilotskypilotOfficialVerified publisher0.13.01 of 3See more

skypilot skypilot 0.13.0

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

5,926
kafka-chartsoldevelo-kafka-chart32.4.41 of 1See more

kafka-chart soldevelo-kafka-chart 32.4.4

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,377
spartanspartan0.9.11 of 1See more

spartan spartan 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,849
freeradiusstartechnicaVerified publisher1.2.01 of 1See more

freeradius startechnica 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.2.8af6fd34a5b78
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

5,810
sn-platformstreamnative1.11.441 of 9See more

sn-platform streamnative 1.11.44

1 of the 9 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
tar@1.30+dfsg-7ubuntu0.20.04.4
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

15,564
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/nginx:1.27.3fb197595ebe7
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

7,075
pretixtechwolf12Verified publisher2026.7.03 of 3See more

pretix techwolf12 2026.7.0

3 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
tar@1.35+dfsg-3.1
no fix listed
pretix/standalone:2026.7.05df3b7aa852e
tar@1.35+dfsg-3.1
no fix listed
valkey/valkey:9.1.08e8d64b405ce
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

9,894
mealieth-chartsVerified publisher0.5.11 of 1See more

mealie th-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,827
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
thmmniii/fbs-core:v1.27.15438517d9fc2
tar@1.34+dfsg-1build3
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

28,634
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
tar@1.34+dfsg-1ubuntu0.1.22.04.1
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

10,373
crossplaneupbound-stable2.4.1-up.11 of 5See more

crossplane upbound-stable 2.4.1-up.1

1 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,649
huginnutkuozdemirVerified publisher2.2.11 of 4See more

huginn utkuozdemir 2.2.1

1 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
tar@1.29b-2ubuntu0.2
1.29b-2ubuntu0.4+esm4

Open the chart page →

18,177
structurizrvirtualrootVerified publisher0.5.01 of 1See more

structurizr virtualroot 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
structurizr/onpremises:2025.11.094b5ffb5119c8
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

4,418
vrijbrpvrijbrpVerified publisher0.1.51 of 5See more

vrijbrp vrijbrp 0.1.5

1 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

8,836
wasmcloud-chartwasmcloud-chartVerified publisher0.7.21 of 2See more

wasmcloud-chart wasmcloud-chart 0.7.2

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
wasmcloud/wasmcloud:0.81.05c7acfe7e8e1
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

3,478
wgerwgerOfficialVerified publisher1.0.05 of 8See more

wger wger 1.0.0

5 of the 8 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latestbf46f66e5dcc
tar@1.35+dfsg-3.1
no fix listed
library/nginx:stabled5792f71a949
tar@1.35+dfsg-3.1
no fix listed
library/postgres:15.186eb0add3b77c
tar@1.35+dfsg-3.1
no fix listed
library/redis:8.8.0234c902a2db4
tar@1.35+dfsg-3.1
no fix listed
wger/server:2.6997ead43aabd
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

8,634
windmillwindmill4.0.2641 of 3See more

windmill windmill 4.0.264

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,649
paperlesszekker6Verified publisher11.8.01 of 1See more

paperless zekker6 11.8.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

4,651
paperless-ngxadnoctemVerified publisher0.4.23 of 5See more

paperless-ngx adnoctem 0.4.2

3 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
apache/tika:2.9.0.092d055a84e9e
tar@1.34+dfsg-1ubuntu0.1.22.04.1
1.34+dfsg-1ubuntu0.1.22.04.6
gotenberg/gotenberg:8.36.087c16b9f3642
tar@1.35+dfsg-3.1
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

19,828
github-actions-runneradwerx0.10.31 of 1See more

github-actions-runner adwerx 0.10.3

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

13,671
agentareaagentareaVerified publisher0.0.184 of 16See more

agentarea agentarea 0.0.18

4 of the 16 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
agentarea/agentarea-api:latest9e15e16fa758
tar@1.35+dfsg-3.1
no fix listed
agentarea/agentarea-mcp-runner:latestd3c209a5d531
tar@1.34+dfsg-1.2+deb12u1
no fix listed
agentarea/agentarea-worker:latest1e5cb68ee77a
tar@1.35+dfsg-3.1
no fix listed
valkey/valkey:9.0.1546304417fea
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

15,049
akeyless-api-gatewayakeyless-services-helmVerified publisher1.62.231 of 1See more

akeyless-api-gateway akeyless-services-helm 1.62.23

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
akeyless/base:latest759e4289fae8
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

2,411
icat-k8salba-helm-chartsVerified publisher1.1.01 of 4See more

icat-k8s alba-helm-charts 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
payara/server-full:7.2026.2-jdk2531f1253f0cf8
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

3,746
jellyfinalekcVerified publisher0.9.01 of 1See more

jellyfin alekc 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,626
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.02 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
tar@1.35+dfsg-3.1
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

12,092
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
tar@1.29b-2ubuntu0.3
1.29b-2ubuntu0.4+esm4

Open the chart page →

12,081
mariadbalphani-helm-chartsVerified publisher10.10.31 of 1See more

mariadb alphani-helm-charts 10.10.3

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/mariadb:10.10.2bfc25a68e113
tar@1.34+dfsg-1build3
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

8,387
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

5,971
alazanteonVerified publisher0.12.01 of 1See more

alaz anteon 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ddosify/alaz:v0.12.0ea602056d9ce
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,395
anteonanteonVerified publisher2.6.42 of 13See more

anteon anteon 2.6.4

2 of the 13 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ddosify/selfhosted_backend:3.2.93c11e3182652
tar@1.34+dfsg-1.2+deb12u1
no fix listed
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

22,304
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

7,794
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

5,249
s3dartur9010Verified publisher1.0.11 of 1See more

s3d artur9010 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,736
arvancloud-webhookarvancloud-webhookVerified publisher1.0.01 of 1See more

arvancloud-webhook arvancloud-webhook 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.00b97452674a3
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,327
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

17,951

Container images carrying it

2,237 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/datadoghq/private-action-runner:v1.21.05f5918f843a4
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
tar@1.29b-2ubuntu0.1
1.29b-2ubuntu0.4+esm4
1
gcr.io/google-containers/echoserver:1.910f4dbc8eeeb
tar@1.28-2.1ubuntu0.1
1.28-2.1ubuntu0.2+esm6
1
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
tar@1.28-2.1ubuntu0.1
1.28-2.1ubuntu0.2+esm6
1
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
tar@1.28-2.1ubuntu0.1
1.28-2.1ubuntu0.2+esm6
1
gcr.io/istio-release/pilot:1.11.1c552478f8f11
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
tar@1.28-2.1ubuntu0.1
1.28-2.1ubuntu0.2+esm6
1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
gcr.io/istio-testing/operator:latest8d4576f7b98f
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
1
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
tar@1.28-2.1ubuntu0.1
1.28-2.1ubuntu0.2+esm6
1
gcr.io/ml-pipeline/metadata-envoy:2.3.0e8e263a919ff
tar@1.30+dfsg-7ubuntu0.20.04.4
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
gcr.io/tfx-oss-public/ml_metadata_store_server:1.14.051404ef4419c
tar@1.30+dfsg-7ubuntu0.20.04.3
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
gcr.io/tfx-oss-public/ml_metadata_store_server:1.5.0db8691752b4c
tar@1.29b-2ubuntu0.2
1.29b-2ubuntu0.4+esm4
1
ghcr.io/98jan/smalland-server/smalland-server:deveb7be822d5b2
tar@1.29b-2ubuntu0.4
1.29b-2ubuntu0.4+esm4
1
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/aeharding/voyager:latest779759172676
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/aetrius/msockperf-server/msockperf-server:main46ae4ea003e0
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/afairgiant/medikeep:v0.70.04c28334f3c79
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/aklivity/zilla:2.4.289c4a2e74863
tar@1.34+dfsg-1ubuntu0.1.22.04.3
1.34+dfsg-1ubuntu0.1.22.04.6
1
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/analogj/scrutiny:v0.9.2-web71be54e99608
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
1
ghcr.io/appscode/csi-driver-cacerts:v0.5.0b6bf1888f9d5
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
1
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
1
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astriaorg/account-monitor:latest4c8b42890035
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astriaorg/auctioneer:pr-18391386b7b5e555
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astriaorg/conductor:1.1.01f97d131b1d1
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astriaorg/evm-bridge-withdrawer:1.0.29c88e1aff357
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astriaorg/hermes:0.5.04f33a0a9f75e
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/astriaorg/sequencer:latest44f82ee0b24c
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/astriaorg/sequencer-relayer:latest5f6c74993f08
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/atuinsh/atuin:18.12.0e953fa9e36ef
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.