StackRadar

CVE-2026-6042

Medium

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,055
of 17,790 indexed, latest versions
Container images
1,113
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,055 of 17,790 indexed charts deploy, on 1,113 images.

Affected packageAffected versionsFixed inImages
muslapk1.2.4_git20230717-r4, 1.2.4_git20230717-r5, 1.2.5-r0, 1.2.5-r1+4 more1.2.4_git20230717-r6, 1.2.5-r2, 1.2.5-r10, 1.2.5-r11+2 more1,112
musldeb1.2.2-4no fix listed1
OSV records
ALPINE-CVE-2026-6042UBUNTU-CVE-2026-6042

Charts affected

1,055 by stars
ChartLatestAffected imagesRadar Score
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
musl@1.2.5-r0
1.2.5-r2

Open the chart page →

13,783
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
musl@1.2.5-r0
1.2.5-r2

Open the chart page →

9,395
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
musl@1.2.5-r21
1.2.5-r22

Open the chart page →

1,571
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6

Open the chart page →

569
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
musl@1.2.5-r21
1.2.5-r22

Open the chart page →

1,159

Container images carrying it

1,113 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/appscode/trickster:v2.0.0cdbbed831f28
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/argelbargel/vault-raft-snapshot-agent:v0.12.5345174727a2b
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/aserto-dev/topaz:0.32.594c708ecf7dc4
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/astriaorg/flame:0.1.0c8af1c5aae40
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/astriaorg/seq-faucet:0.9.0bf3cb9b505b6
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/atolat/open-cache:latestd6105dd73eb4
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/bastienwirtz/homer:v25.11.15c3a0fb561e0
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/bastienwirtz/homer:v25.02.1cf4ae752adbb
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/behappy-project/behappy-tencentcloud-exporter:0.1.3a0ba56e1501b
musl@1.2.4_git20230717-r5
1.2.4_git20230717-r6
1
ghcr.io/beluga-cloud/actual/actualserver:23.12.1c8a0d5ec5a12
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/bensoer/external-secrets-reloader:v0.1.38e31b5a81853
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/bensoer/sibyl:v0.2.06dca4455fde3
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/b-it-projects-gmbh/nvme_exporter:lateste70307b193c6
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/blessingnator/keycloak-mcn-frontend:2.0.1ddd462dbde39
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
musl@1.2.5-r8
1.2.5-r10
1
ghcr.io/bouquet2/copilot-api-docker:v0.7.06b0507a20602
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/browsersec/kubebrowse:sha-09dfa1fb853e9e6372a
musl@1.2.5-r1
1.2.5-r2
1
ghcr.io/browsersec/kubebrowse-frontend:chore-improve-backbd6bea5e487c
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/bryopsida/openmct:main38b6a50a62b2
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/bryopsida/patchwork:mainc01e018bced4
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/caas-team/py-kube-downscaler:26.4.0af05a098b0d2
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/celestiaorg/celestia-app:v3.7.0-arabica23a9ec9b1879
musl@1.2.4_git20230717-r5
1.2.4_git20230717-r6
1
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/chaos-mesh/chaos-mesh:v2.8.0091b906a0b13
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/chaos-mesh/chaos-mesh:v2.7.28bc853c7414c
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/chronicleprotocol/challenger-go:0.1.2c8d5a3c0e966
musl@1.2.5-r1
1.2.5-r2
1
ghcr.io/chronicleprotocol/oracles-updates-exporter:0.0.4992d0e793af6
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/cloudscript-technology/dumpscript:v0.0.42-alpine-edgefce5b6fd161c
musl@1.2.5-r21
1.2.6-r1
1
ghcr.io/cloudscript-technology/k8s-monitoring-app:v0.0.25cab66a6b3574
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/cloudtty/cloudshell:v0.8.900984ba0f0eb
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/clusternet/clusternet-controller-manager:v1.0.02ce077d3d02d
musl@1.2.5-r8
1.2.5-r10
1
ghcr.io/clusternet/clusternet-hub:v1.0.059f75504c5d4
musl@1.2.5-r8
1.2.5-r10
1
ghcr.io/clusternet/clusternet-scheduler:v1.0.0a6ae5aff81ce
musl@1.2.5-r8
1.2.5-r10
1
ghcr.io/cncf/clowarden/dbmigrator:v0.2.3c022fd42de45
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/cncf/clowarden/server:v0.2.3f9379427b917
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/cncf/gitvote/dbmigrator:v1.5.0f1e7efe440da
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/cncf/gitvote/server:v1.5.026167f01c898
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/cndoit18/lxcfs-agent:latest9853bb613cd0
musl@1.2.5-r10
1.2.5-r11
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.