StackRadar

CVE-2026-5704

Medium

Advisory

Published 6 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,264
of 17,790 indexed, latest versions
Container images
2,237
deployed by those charts
Fix available
2 of 2
affected packages

Security update for tar

Carried by container images the latest versions of 2,264 of 17,790 indexed charts deploy, on 2,237 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+28 more1.27.1-1ubuntu0.1+esm7, 1.28-2.1ubuntu0.2+esm6, 1.29b-2ubuntu0.4+esm4, 1.30+dfsg-7ubuntu0.20.04.4+esm3+4 more2,231
tarrpm1.34-150000.3.34.1, 1.34-150000.3.37.11.34-150000.3.42.16
OSV records
DEBIAN-CVE-2026-5704UBUNTU-CVE-2026-5704ECHO-6544-7e09-569cSUSE-SU-2026:2714-1
Also known as
USN-8477-1, USN-8477-2, USN-8477-3

Charts affected

2,264 by stars
ChartLatestAffected imagesRadar Score
jenkinsjenkinsciOfficialVerified publisher5.9.621 of 2See more

jenkins jenkinsci 5.9.62

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
jenkins/jenkins:2.568.3-jdk21c1e4c349365f
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,538
airflowapache-airflowOfficialVerified publisher1.22.01 of 4See more

airflow apache-airflow 1.22.0

1 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/redis:7.2-bookworm74566c6910d1
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,218
nextcloudnextcloud9.2.61 of 1See more

nextcloud nextcloud 9.2.6

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/nextcloud:34.0.3-apacheb97df9e0e1ee
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

4,584
giteagiteaOfficialVerified publisher12.7.03 of 4See more

gitea gitea 12.7.0

3 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

8,874
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
tar@1.34+dfsg-1ubuntu0.1.22.04.1
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

6,623
authentikgoauthentikOfficialVerified publisher2026.8.21 of 1See more

authentik goauthentik 2026.8.2

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.8.2ff8489a5af4f
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,284
nginx-ingressnginxVerified publisher2.7.21 of 1See more

nginx-ingress nginx 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
nginx/nginx-ingress:5.6.27def79229370
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,000
artifact-hubartifact-hubVerified publisher1.23.02 of 7See more

artifact-hub artifact-hub 1.23.0

2 of the 7 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
tar@1.35+dfsg-3.1
no fix listed
artifacthub/tracker:v1.23.05368d21a6e5c
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

10,840
jupyterhubjupyterhubOfficialVerified publisher4.4.22 of 7See more

jupyterhub jupyterhub 4.4.2

2 of the 7 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
tar@1.34+dfsg-1.2+deb12u1
no fix listed
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

7,937
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

30,217
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

11,394
falcofalcosecurity9.1.01 of 3See more

falco falcosecurity 9.1.0

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.44.17df783d5269a
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

5,398
openebsopenebsOfficialVerified publisher4.6.12 of 35See more

openebs openebs 4.6.1

2 of the 35 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

24,128
backstagebackstageOfficialVerified publisher2.10.11 of 1See more

backstage backstage 2.10.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/backstage/backstage:latest792e262ea504
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,217
rediscloudpirates-redisVerified publisher0.35.01 of 1See more

redis cloudpirates-redis 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

978
mlflowcommunity-chartsVerified publisher1.11.71 of 1See more

mlflow community-charts 1.11.7

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
burakince/mlflow:3.16.0ab4b566644b9
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

641
qdrantqdrantOfficialVerified publisher1.19.11 of 1See more

qdrant qdrant 1.19.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.19.112364fe851b9
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

829
apisixapisix2.17.01 of 3See more

apisix apisix 2.17.0

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,118
dagsterdagsterVerified publisher1.13.222 of 5See more

dagster dagster 1.13.22

2 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
dagster/dagster-celery-k8s:1.13.22e29a64392e12
tar@1.35+dfsg-3.1
no fix listed
dagster/user-code-example:1.13.225947f9ae481c
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,510
zabbixzabbix-communityVerified publisher7.1.05 of 5See more

zabbix zabbix-community 7.1.0

5 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
tar@1.35+dfsg-3.1
no fix listed
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

13,880
keycloakcloudpirates-keycloakVerified publisher0.21.372 of 3See more

keycloak cloudpirates-keycloak 0.21.37

2 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:18.0073e7c8b84e2
tar@1.35+dfsg-3.1
no fix listed
library/postgres:18.64ef4dbc939d6
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

4,428
fluentdfluent0.6.01 of 1See more

fluentd fluent 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.19.3-debian-elasticsearch7-1.1de9cf5f1127a
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,022
netdatanetdataVerified publisher3.7.1731 of 1See more

netdata netdata 3.7.173

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
netdata/netdata:v2.11.0c45c71eb23ff
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,131
node-problem-detectordeliveryheroVerified publisher2.4.11 of 1See more

node-problem-detector deliveryhero 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,984
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

5,399
vaultwardengissilabs1.4.21 of 1See more

vaultwarden gissilabs 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,766
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
tar@1.29b-2ubuntu0.3
1.29b-2ubuntu0.4+esm4

Open the chart page →

5,560
valkeyvalkeyVerified publisher0.12.01 of 1See more

valkey valkey 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
valkey/valkey:9.1.2475ee65cc75c
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

829
postgrescloudpirates-postgresVerified publisher0.20.51 of 1See more

postgres cloudpirates-postgres 0.20.5

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:18.64ef4dbc939d6
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,649
openldap-stack-hahelm-openldapVerified publisher4.3.32 of 5See more

openldap-stack-ha helm-openldap 4.3.3

2 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
jpgouin/openldap:2.6.9-fixbfdd0088c776
tar@1.34+dfsg-1.2+deb12u1
no fix listed
library/debian:latestf324c7ff5432
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

5,968
zammadzammadOfficialVerified publisher18.2.14 of 5See more

zammad zammad 18.2.1

4 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/memcached:1.6.4575c93cc91e76
tar@1.35+dfsg-3.1
no fix listed
library/postgres:18.4a02db8cac496
tar@1.35+dfsg-3.1
no fix listed
library/redis:8.10.1298e5b3bc566
tar@1.35+dfsg-3.1
no fix listed
ghcr.io/zammad/zammad:7.1.3-0014ce435c77651e
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

6,346
chaos-meshchaos-meshVerified publisher2.8.42 of 4See more

chaos-mesh chaos-mesh 2.8.4

2 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
tar@1.34+dfsg-1.2+deb12u1
no fix listed
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.48a8ec8d4c9ea
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

6,415
csi-driver-nfscsi-driver-nfsVerified publisher4.13.41 of 6See more

csi-driver-nfs csi-driver-nfs 4.13.4

1 of the 6 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,391
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
tar@1.34+dfsg-1build3
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

9,197
grafana-agentgrafana0.44.21 of 2See more

grafana-agent grafana 0.44.2

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
grafana/agent:v0.44.23364714a2f64
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

3,526
milvusmilvus4.0.312 of 5See more

milvus milvus 4.0.31

2 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
milvusdb/milvus:v2.2.13a3a55e1c1497
tar@1.30+dfsg-7ubuntu0.20.04.2
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

32,420
mesherymesheryOfficialVerified publisher1.0.701 of 1See more

meshery meshery 1.0.70

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest44b64ee128fb
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,438
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

10,695
signozsignoz0.141.11 of 5See more

signoz signoz 0.141.1

1 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
signoz/signoz-otel-collector:v0.144.972aa1e4c1ec5
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

7,607
weblateweblateOfficialVerified publisher0.5.362 of 3See more

weblate weblate 0.5.36

2 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/redis:latest5927ff3702df
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

6,787
locustdeliveryheroVerified publisher0.35.01 of 1See more

locust deliveryhero 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,817
postgresgroundhog2k1.6.81 of 1See more

postgres groundhog2k 1.6.8

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:18.64ef4dbc939d6
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,649
emqxemqx-operator5.8.91 of 1See more

emqx emqx-operator 5.8.9

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
emqx/emqx:5.8.935b46f7aa7a0
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,728
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

4,819
difydoubanVerified publisher0.10.03 of 6See more

dify douban 0.10.0

3 of the 6 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

19,544
dragonflydragonflyVerified publisher1.8.41 of 3See more

dragonfly dragonfly 1.8.4

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.4a1b52779c4dd
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,830
secrets-store-csi-driversecret-store-csi-driver1.6.11 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

1 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,802
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

3,675
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

6,960
difydify-helmVerified publisher0.38.06 of 11See more

dify dify-helm 0.38.0

6 of the 11 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
tar@1.34+dfsg-1.2+deb12u1
no fix listed
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
langgenius/dify-api:1.16.1dcefa5f7c47c
tar@1.34+dfsg-1.2+deb12u1
no fix listed
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
langgenius/dify-sandbox:0.2.15750e1111426e
tar@1.35+dfsg-3.1
no fix listed
library/nginx:latest05b8cb60c354
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

22,214

Container images carrying it

2,237 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/middleware-labs/mw-kube-agent:1.21.0ff23f452813a
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
tar@1.34+dfsg-1.2
no fix listed
1
ghcr.io/mollyim/mollysocket:1.7.1c675622546a4
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/monicahq/monica-next:main8be69156acbb
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/nowakeai/svc-lb-mux:0.1.37d8fb8e996b6
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/obeone/ollama-exporter:latestf43af285c6e0
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/observal/observal-api:1.13.1153b8b893232
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-03:0.0.0-2026-08-173e56bdd1b90d
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
tar@1.35+dfsg-3.1
no fix listed
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/openlit/openlit-controller:0.10.0165efd4469ea
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/openrelik/openrelik-server:latestce1132261523
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.