StackRadar

CVE-2026-6042

Medium

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,056
of 17,787 indexed, latest versions
Container images
1,114
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,056 of 17,787 indexed charts deploy, on 1,114 images.

Affected packageAffected versionsFixed inImages
muslapk1.2.4_git20230717-r4, 1.2.4_git20230717-r5, 1.2.5-r0, 1.2.5-r1+4 more1.2.4_git20230717-r6, 1.2.5-r2, 1.2.5-r10, 1.2.5-r11+2 more1,113
musldeb1.2.2-4no fix listed1
OSV records
ALPINE-CVE-2026-6042UBUNTU-CVE-2026-6042

Charts affected

1,056 by stars
ChartLatestAffected imagesRadar Score
silence-operatorwiremindVerified publisher0.0.81 of 1See more

silence-operator wiremind 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
giantswarm/silence-operator:0.13.0a6cac55aa2d4
musl@1.2.5-r9
1.2.5-r10

Open the chart page →

789
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
musl@1.2.5-r0
1.2.5-r2

Open the chart page →

13,197
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
musl@1.2.5-r0
1.2.5-r2

Open the chart page →

9,381
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
musl@1.2.5-r21
1.2.5-r22

Open the chart page →

1,571
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6

Open the chart page →

569
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
musl@1.2.5-r21
1.2.5-r22

Open the chart page →

1,159

Container images carrying it

1,114 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
volcanosh/vc-webhook-manager:v1.12.1f8b50088a732
musl@1.2.5-r10
1.2.5-r11
1
wagnermanganelli164/webserver-hello-world:0.3.0d4ef27a4f180
musl@1.2.5-r0
1.2.5-r2
1
wait4x/wait4x:3.3.14dcd86307de1
musl@1.2.5-r9
1.2.5-r10
1
wallarm/api-firewall:v0.9.64d45db0ff240
musl@1.2.5-r21
1.2.5-r22
1
wallarm/gateway-control-plane:0.2.0a321bc974a19
musl@1.2.4_git20230717-r5
1.2.4_git20230717-r6
1
wallarm/ingress-controller:5.3.10.1a1fecfdf987e
musl@1.2.5-r1
1.2.5-r2
1
wallarm/node-helpers:6.10.1aecd88b24c51
musl@1.2.5-r10
1.2.5-r11
1
wallarm/node-native-processing:0.23.07db2da8fce0b
musl@1.2.5-r21
1.2.5-r22
1
wallarm/node-next:0.5.24314f3d2b918
musl@1.2.5-r0
1.2.5-r2
1
wallarm/sidecar-controller:1.8.0524f7e6e8c35
musl@1.2.5-r1
1.2.5-r2
1
wmbusmeters/wmbusmeters:release-1.18.0d82715d9ae22
musl@1.2.5-r0
1.2.5-r2
1
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
musl@1.2.5-r9
1.2.5-r10
1
yetiplatform/bloomcheck:dev85683ddfccbb
musl@1.2.5-r9
1.2.5-r10
1
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
musl@1.2.5-r9
1.2.5-r10
1
ymuski/geo-checker:5.0.05ba7fd8c7bdc
musl@1.2.5-r10
1.2.5-r11
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
musl@1.2.5-r9
1.2.5-r10
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
musl@1.2.5-r9
1.2.5-r10
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
musl@1.2.5-r9
1.2.5-r10
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
musl@1.2.5-r9
1.2.5-r10
1
zachomedia/cert-manager-webhook-pdns:v2.5.54940e227a39b
musl@1.2.5-r21
1.2.5-r22
1
zbalogh/reservation-angular-ui:1.0.95eb19e460b3c
musl@1.2.5-r10
1.2.5-r11
1
zimengxiong/excalidash-backend:0.4.271273af713c91
musl@1.2.5-r21
1.2.5-r22
1
zimengxiong/excalidash-frontend:0.4.27242629350b06
musl@1.2.5-r21
1.2.5-r22
1
gcr.io/ml-pipeline/cache-server:2.3.0293941ee4f65
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
gcr.io/ml-pipeline/persistenceagent:2.3.0109ac1b38c41
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
gcr.io/ml-pipeline/scheduledworkflow:2.3.0f7e67e0bc071
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
gcr.io/ml-pipeline/viewer-crd-controller:2.3.08cf8213d69e4
musl@1.2.5-r0
1.2.5-r2
1
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/akpw/mktxp:1.2.17bd6f22f7db0a
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/alekc/samba-docker:v1.1.0cc9a028d9c43
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/angelnu/pod-gateway:v1.13.0a5b032e15f75
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/antnsn/mal-sync:v1.0.52f06e72cef36
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/appscode/ace:v0.2.0b8e03da90e70
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/appscode/acerproxy:v0.2.021de3771fdd5
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/appscode/aceshifter:v0.0.3e5f5c254a55a
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/appscode/capa-vpc-peering-operator:v0.0.4b1557553a2b3
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
musl@1.2.5-r8
1.2.5-r10
1
ghcr.io/appscode/cert-manager-webhook-ace:v0.0.2dc6b5fdcec06
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/appscode/deploy-ui:0.3.6f3e07eff3997
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/appscode/falco-ui-server:v0.0.66ec488d89b56
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/appscode/gcp-credential-manager:v0.1.0b58345fe8209
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/appscode/gh-ci-webhook:v0.0.2036ce246d884e
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/appscode/inbox-ui:0.0.5ae3b0e29daaa
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/appscode/license-proxyserver:v0.0.8d6c2532ea386
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/appscode/marketplace-ui:0.3.1d52177072013
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/appscode/offline-license-server:v0.0.76e4b66308d8f6
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/appscode/scanner:v0.0.2116907aae5de1
musl@1.2.5-r21
1.2.5-r22
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.