StackRadar

CVE-2026-6042

Medium

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,055
of 17,790 indexed, latest versions
Container images
1,113
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,055 of 17,790 indexed charts deploy, on 1,113 images.

Affected packageAffected versionsFixed inImages
muslapk1.2.4_git20230717-r4, 1.2.4_git20230717-r5, 1.2.5-r0, 1.2.5-r1+4 more1.2.4_git20230717-r6, 1.2.5-r2, 1.2.5-r10, 1.2.5-r11+2 more1,112
musldeb1.2.2-4no fix listed1
OSV records
ALPINE-CVE-2026-6042UBUNTU-CVE-2026-6042

Charts affected

1,055 by stars
ChartLatestAffected imagesRadar Score
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
musl@1.2.5-r0
1.2.5-r2

Open the chart page →

13,783
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
musl@1.2.5-r0
1.2.5-r2

Open the chart page →

9,395
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
musl@1.2.5-r21
1.2.5-r22

Open the chart page →

1,571
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6

Open the chart page →

569
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
musl@1.2.5-r21
1.2.5-r22

Open the chart page →

1,159

Container images carrying it

1,113 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/openfaasltd/postgres-connector:0.2.3379e583a0a75
musl@1.2.5-r8
1.2.5-r10
1
ghcr.io/openfaasltd/pro-builder:0.6.06c17297f9098
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/openfaasltd/rabbitmq-connector:0.1.2349f7dca95ec
musl@1.2.5-r8
1.2.5-r10
1
ghcr.io/openfaasltd/sns-connector:0.2.0e9ab76a4ec77
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/openfaasltd/sqs-connector:0.3.4d44ed3b3128c
musl@1.2.5-r8
1.2.5-r10
1
ghcr.io/openlit/openlit-operator:0.0.2457bb5ada68b
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/openrelik/openrelik-ui:latest7f91594d5eb3
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/open-telemetry/demo:1.12.0-productcatalogservice008b9b662289
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/open-telemetry/demo:1.12.0-checkoutservice380eccdc29e9
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/open-telemetry/demo:1.12.0-cartservice89730afa0b5d
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/open-telemetry/demo:3.0.0-image-provider93e1585e97ac
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/parca-dev/parca:v0.24.23776500fde82
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/pbufio/registry:v0.4.177a36c035b4b
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/pixelfederation/unbound:1.24.2_0fce820a03964
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/plausible/community-edition:v3.0.114c1afde21d6
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/pschichtel/keycloak-webhook-router:main285e226fe7f6
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/pyrra-dev/pyrra:v0.8.10e02ef538ef0
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/radar-base/radar-app-config/radar-app-config-frontend:0.6.2c5f1e2ca5781
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/radar-base/radar-home/radar-home:0.1.71cfe3da9d812
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/radar-base/radar-rest-source-auth/radar-rest-source-authorizer:4.4.153e096497f7db
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-frontend:0.6.47e27863545fc
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/riverqueue/riverui:0.5.32dc54179b25a
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/sagernet/sing-box:v1.12.03c1ee82d450d
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/sergelogvinov/haproxy:2.8.6-alpine3.19b1c7063c66ac
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/sergelogvinov/tabix:22.05.17a6e3e996a4ae
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
musl@1.2.4_git20230717-r5
1.2.5-r2
1
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/szpadel/languagetool-server:6.568fdab22b2a9
musl@1.2.5-r0
1.2.5-r2
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/techno-tim/littlelink-server:latest735a1fcd078b
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
musl@1.2.5-r10
1.2.5-r11
1
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
musl@1.2.5-r21
1.2.5-r22
1
ghcr.io/tjm/vault-gcp-secrets:v1.19.59f157fe035f1
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
musl@1.2.5-r9
1.2.5-r10
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
musl@1.2.5-r9
1.2.5-r10
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.