StackRadar

CVE-2026-6042

Medium

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,055
of 17,790 indexed, latest versions
Container images
1,113
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,055 of 17,790 indexed charts deploy, on 1,113 images.

Affected packageAffected versionsFixed inImages
muslapk1.2.4_git20230717-r4, 1.2.4_git20230717-r5, 1.2.5-r0, 1.2.5-r1+4 more1.2.4_git20230717-r6, 1.2.5-r2, 1.2.5-r10, 1.2.5-r11+2 more1,112
musldeb1.2.2-4no fix listed1
OSV records
ALPINE-CVE-2026-6042UBUNTU-CVE-2026-6042

Charts affected

1,055 by stars
ChartLatestAffected imagesRadar Score
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
musl@1.2.5-r0
1.2.5-r2

Open the chart page →

13,783
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
musl@1.2.5-r0
1.2.5-r2

Open the chart page →

9,395
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
musl@1.2.5-r21
1.2.5-r22

Open the chart page →

1,571
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6

Open the chart page →

569
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-6042.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
musl@1.2.5-r21
1.2.5-r22

Open the chart page →

1,159

Container images carrying it

1,113 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/shivering-isles/dovecot:2.3.214599ada9aa06
musl@1.2.5-r0
1.2.5-r2
1
quay.io/underndog/samba:1.2.0-not-recyclecca801de9fa5
musl@1.2.5-r9
1.2.5-r10
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
musl@1.2.5-r10
1.2.5-r11
1
registry.gitlab.com/dyff/dyff-frontend:0.20.2481be0beaafe
musl@1.2.5-r9
1.2.5-r10
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
musl@1.2.5-r21
1.2.5-r22
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
musl@1.2.5-r21
1.2.5-r22
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
musl@1.2.5-r10
1.2.5-r11
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
musl@1.2.5-r10
1.2.5-r11
1
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
musl@1.2.5-r0
1.2.5-r2
1
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
musl@1.2.5-r8
1.2.5-r10
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
musl@1.2.5-r21
1.2.5-r22
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.