StackRadar

CVE-2026-5704

Medium

Advisory

Published 6 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,343
of 17,828 indexed, latest versions
Container images
2,333
deployed by those charts
Fix available
2 of 2
affected packages

tar-1.35-8.1 on GA media

Carried by container images the latest versions of 2,343 of 17,828 indexed charts deploy, on 2,333 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+28 more1.27.1-1ubuntu0.1+esm7, 1.28-2.1ubuntu0.2+esm6, 1.29b-2ubuntu0.4+esm4, 1.30+dfsg-7ubuntu0.20.04.4+esm3+4 more2,326
tarrpm1.30-lp152.3.6, 1.34-150000.3.34.1, 1.34-150000.3.37.11.34-150000.3.42.1, 1.35-8.17
OSV records
DEBIAN-CVE-2026-5704UBUNTU-CVE-2026-5704ECHO-6544-7e09-569copenSUSE-SU-2026:11125-1SUSE-SU-2026:2714-1
Also known as
USN-8477-1, USN-8477-2, USN-8477-3

Charts affected

2,343 by stars
ChartLatestAffected imagesRadar Score
wekanwekanVerified publisher11.90.02 of 3See more

wekan wekan 11.90.0

2 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/wekan/ferretdb:latestebed9a5eaae0
tar@1.35+dfsg-3.1
no fix listed
ghcr.io/wekan/wekan:v11.90078ca230c0df
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,677
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

8,637
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
tar@1.35+dfsg-3ubuntu0.1
1.35+dfsg-3ubuntu0.4

Open the chart page →

1,871
budibasebudibase0.0.0-master3 of 7See more

budibase budibase 0.0.0-master

3 of the 7 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
tar@1.34+dfsg-1.2+deb12u1
no fix listed
budibase/proxy:3.41.38d780b6ee602
tar@1.35+dfsg-3.1
no fix listed
library/redis:latest8a1efc5f4795
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

9,696
paperless-ngxfmjstudios0.2.83 of 5See more

paperless-ngx fmjstudios 0.2.8

3 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
apache/tika:2.9.0.092d055a84e9e
tar@1.34+dfsg-1ubuntu0.1.22.04.1
1.34+dfsg-1ubuntu0.1.22.04.6
gotenberg/gotenberg:8.0.1cf0b9a7ca3cf
tar@1.34+dfsg-1.2
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

31,340
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
tar@1.34+dfsg-1build3
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

3,541
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,073
gopaddlegopaddle-liteVerified publisher5.0.01 of 1See more

gopaddle gopaddle-lite 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
gopaddle/gopaddle:5.0435359250b63
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

5,140
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
tar@1.34+dfsg-1ubuntu0.1.22.04.1
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

8,048
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

1,331
quickwitquickwit0.8.171 of 1See more

quickwit quickwit 0.8.17

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,524
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

11,672
zillazillaOfficialVerified publisher2.4.31 of 1See more

zilla zilla 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/aklivity/zilla:2.4.3e33d59dbb606
tar@1.34+dfsg-1ubuntu0.1.22.04.3
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

1,782
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,012
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

4,339
penpotcodechemVerified publisher1.0.102 of 3See more

penpot codechem 1.0.10

2 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
penpotapp/backend:1.16.0-betae978e871be07
tar@1.34+dfsg-1build3
1.34+dfsg-1ubuntu0.1.22.04.6
penpotapp/exporter:1.16.0-betafa7086ad92b1
tar@1.34+dfsg-1build3
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

28,655
connaisseurconnaisseurVerified publisher2.13.01 of 2See more

connaisseur connaisseur 2.13.0

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,951
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
tar@1.34+dfsg-1.2
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
quay.io/devtron/postgres:14.91b594392f7cb
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

33,471
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

3,860
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

5,506
nextcloudgroundhog2k0.22.71 of 3See more

nextcloud groundhog2k 0.22.7

1 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/nextcloud:35.0.0:35.0.0-apache3e9f6eaa5dc8
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,979
ilumilumOfficialVerified publisher6.7.34 of 19See more

ilum ilum 6.7.3

4 of the 19 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/postgresql:16233f361c5819
tar@1.34+dfsg-1.2+deb12u1
no fix listed
ilum/api:6.7.3624fd09528c8
tar@1.35+dfsg-3.1
no fix listed
ilum/marquez:0.54.06e1d709d41f8
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

22,724
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

3,499
lakekeeperlakekeeperVerified publisher0.12.01 of 2See more

lakekeeper lakekeeper 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,015
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

7,442
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

5,784
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

4,518
netris-controllernetrisai2.8.24 of 14See more

netris-controller netrisai 2.8.2

4 of the 14 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
netrisai/controller-grpc:4.6.0.00753178bf173c2
tar@1.30+dfsg-7ubuntu0.20.04.4
1.30+dfsg-7ubuntu0.20.04.4+esm3
netrisai/controller-telescope:4.6.0.00414d82948a8b2
tar@1.30+dfsg-7ubuntu0.20.04.4
1.30+dfsg-7ubuntu0.20.04.4+esm3
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
tar@1.30+dfsg-7ubuntu0.20.04.4
1.30+dfsg-7ubuntu0.20.04.4+esm3
netrisai/controller-web-session-generator:0.2.0a030a31289f4
tar@1.30+dfsg-7ubuntu0.20.04.2
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

30,680
hedgedocnicholaswildeVerified publisher1.1.01 of 1See more

hedgedoc nicholaswilde 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/hedgedoc:version-1.9.0792a12ee976a
tar@1.29b-2ubuntu0.2
1.29b-2ubuntu0.4+esm4

Open the chart page →

12,750
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,414
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

17,512
paperless-ngxpaperless-ngxVerified publisher0.3.223 of 3See more

paperless-ngx paperless-ngx 0.3.22

3 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
tar@1.34+dfsg-1.2+deb12u1
no fix listed
valkey/valkey:9.1.2c123e3715db6
tar@1.35+dfsg-3.1
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

8,685
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
tar@1.29b-2ubuntu0.2
1.29b-2ubuntu0.4+esm4
platform9community/api-gateway:latest40a4970de568
tar@1.29b-2ubuntu0.2
1.29b-2ubuntu0.4+esm4
platform9community/customers-service:latest2089811e5cc6
tar@1.29b-2ubuntu0.2
1.29b-2ubuntu0.4+esm4
platform9community/vets-service:latestd1165c94dfb3
tar@1.29b-2ubuntu0.2
1.29b-2ubuntu0.4+esm4
platform9community/visits-service:latest8d11b50368c6
tar@1.29b-2ubuntu0.2
1.29b-2ubuntu0.4+esm4

Open the chart page →

42,122
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
tar@1.34+dfsg-1ubuntu0.1.22.04.2
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

14,648
selenium3selenium31.2.41 of 1See more

selenium3 selenium3 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
tar@1.30+dfsg-7
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

11,923
tbmq-clustertbmq-helm-chartOfficialVerified publisher2.1.02 of 3See more

tbmq-cluster tbmq-helm-chart 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
tar@1.35+dfsg-3.1
no fix listed
thingsboard/tbmq-node:2.4.070661025dba5
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,615
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
tar@1.30+dfsg-7ubuntu0.20.04.4
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

7,523
plexutkuozdemirVerified publisher2.1.11 of 1See more

plex utkuozdemir 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
linuxserver/plex:1.25.24a13ced2326c
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

6,431
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4

Open the chart page →

2,401
istio-operatorwiremindVerified publisher1.18.21 of 1See more

istio-operator wiremind 1.18.2

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
istio/operator:1.18.270f9d1fe5fff
tar@1.34+dfsg-1ubuntu0.1.22.04.1
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

5,714
zabbix-serveraekondratievVerified publisher1.0.63 of 4See more

zabbix-server aekondratiev 1.0.6

3 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

30,982
phpmyadminalekcVerified publisher0.3.11 of 1See more

phpmyadmin alekc 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache9e915766488a
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,221
wazuh-agentavistoVerified publisher4.12.21 of 1See more

wazuh-agent avisto 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

6,588
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
tar@1.30+dfsg-7ubuntu0.20.04.4
1.30+dfsg-7ubuntu0.20.04.4+esm3

Open the chart page →

12,268
memcachedcloudpirates-memcachedVerified publisher0.14.91 of 1See more

memcached cloudpirates-memcached 0.14.9

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/memcached:1.6.4575c93cc91e76
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,104
cluster-secretclutersecretVerified publisher0.7.01 of 1See more

cluster-secret clutersecret 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,075
convoyconvoyVerified publisher3.7.132 of 3See more

convoy convoy 3.7.13

2 of the 3 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

6,142
cortexcortex3.4.02 of 4See more

cortex cortex 3.4.0

2 of the 4 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
library/memcached:1.6.45d956c0a57fd7
tar@1.35+dfsg-3.1
no fix listed
library/nginx:1.31abe47724e466
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,204
valkeygroundhog2k2.3.41 of 1See more

valkey groundhog2k 2.3.4

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
valkey/valkey:9.1.2c123e3715db6
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

858
hasurahasura-extraVerified publisher3.0.11 of 1See more

hasura hasura-extra 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-5704.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.34.0-ce0111b0204136
tar@1.34+dfsg-1ubuntu0.1.22.04.1
1.34+dfsg-1ubuntu0.1.22.04.6

Open the chart page →

5,023

Container images carrying it

2,333 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
tar@1.35+dfsg-3.1
no fix listed
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
tar@1.35+dfsg-3build1
1.35+dfsg-3ubuntu0.4
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
tar@1.28-2.1ubuntu0.1
1.28-2.1ubuntu0.2+esm6
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
tar@1.35+dfsg-3.1
no fix listed
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
tar@1.34+dfsg-1.2
no fix listed
1
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/certificates:v19.4.01c38ad710b0c
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitaly:v19.4.0704cd68566af
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.0696d798a5c85
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabdc1a8972c640
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.26645e014f75d
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3aca1bb3d5b7e
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.02256b49461fa
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
tar@1.30+dfsg-7ubuntu0.20.04.1
1.30+dfsg-7ubuntu0.20.04.4+esm3
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
tar@1.35+dfsg-3.1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.