StackRadar

CVE-2026-61801

Medium

Advisory

Published 8 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
630
of 18,071 indexed, latest versions
Container images
314
deployed by those charts
Fix available
1 of 1
affected package

github.com/moby/sys/user has a possible DoS via unbounded parsing of user and group database files

Carried by container images the latest versions of 630 of 18,071 indexed charts deploy, on 314 images.

Affected packageAffected versionsFixed inImages
github.com/moby/sys/usergolangv0.1.0, v0.2.0, v0.3.0, v0.4.00.4.1314
OSV records
GHSA-mjcv-p78q-w5fw
Trending
Rank 20 in indexed charts, since 9 Oct 2026. See the ranking →

Charts affected

630 by stars
ChartLatestAffected imagesRadar Score
simple-mongodbtyk-helm0.1.11 of 1See more

simple-mongodb tyk-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

4,705
unlaunla0.10.01 of 3See more

unla unla 0.10.0

1 of the 3 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/postgres:16ca0bd484cb98
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

10,512
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/postgres:alpine77f585114c32
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

48,354
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/postgres:16-alpine721873c34ceb
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

5,867
devportalveecode-platform-nextVerified publisher1.0.31 of 1See more

devportal veecode-platform-next 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnede5c84f744994
github.com/moby/sys/user@v0.4.0
0.4.1

Open the chart page →

1,792
velocityvelocity1.0.01 of 2See more

velocity velocity 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/postgres:16-alpine721873c34ceb
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

1,186
bugsinkvictorlane0.3.71 of 2See more

bugsink victorlane 0.3.7

1 of the 2 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/mariadb:12.0-noble607835cd628b
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

4,462
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

21,258
postgresappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

postgresapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/postgres:latest74935e722416
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

1,636
voteappvoting-app-helm-charts-repoVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/postgres:latestfc973eb97c9f
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

9,572
postgresappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

postgresapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/postgres:latest74935e722416
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

1,636
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/postgres:latestfc973eb97c9f
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

9,572
voting-app-envvoting-example-with-env0.0.31 of 6See more

voting-app-env voting-example-with-env 0.0.3

1 of the 6 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/postgres:18.3-alpine3.2354451ecb8ab3
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

8,038
gateway-control-planewallarmVerified publisher0.2.01 of 2See more

gateway-control-plane wallarm 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg17b346edcdb51a
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

1,886
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

21,258
wardnwardnVerified publisher0.1.01 of 3See more

wardn wardn 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/postgres:16-alpine721873c34ceb
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

837
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/mariadb:107db29378d4fd
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

11,002
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

30,446
mesherywener1.0.701 of 1See more

meshery wener 1.0.70

1 of the 1 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest44b64ee128fb
github.com/moby/sys/user@v0.4.0
0.4.1

Open the chart page →

1,841
rancherwener2.15.22 of 2See more

rancher wener 2.15.2

2 of the 2 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.20c3d8e570255
github.com/moby/sys/user@v0.4.0
0.4.1
rancher/shell:v0.8.21eeed72d4eda
github.com/moby/sys/user@v0.4.0
0.4.1

Open the chart page →

2,326
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/moby/sys/user@v0.4.0
0.4.1

Open the chart page →

2,723
mesherywenerme1.0.701 of 1See more

meshery wenerme 1.0.70

1 of the 1 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest44b64ee128fb
github.com/moby/sys/user@v0.4.0
0.4.1

Open the chart page →

1,841
rancherwenerme2.15.22 of 2See more

rancher wenerme 2.15.2

2 of the 2 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.20c3d8e570255
github.com/moby/sys/user@v0.4.0
0.4.1
rancher/shell:v0.8.21eeed72d4eda
github.com/moby/sys/user@v0.4.0
0.4.1

Open the chart page →

2,326
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/postgres:15-alpinef7d23353e1b1
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

16,229
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/postgres:1874935e722416
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

4,254
wordpress-alpinewordpress-alpine1.5.191 of 6See more

wordpress-alpine wordpress-alpine 1.5.19

1 of the 6 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/mariadb:12.3.2628f228f0fd5
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

4,567
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/mysql:latest9d48c42f8341
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

3,459
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/mariadb:lts2bdff1534a7e
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

5,540
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/mongo:latestbac22ea7710d
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

15,282
zoo-project-druzoo-projectOfficialVerified publisher0.10.91 of 6See more

zoo-project-dru zoo-project 0.10.9

1 of the 6 container images this version deploys carry CVE-2026-61801.

Container imageDigestPackageFixed in
library/postgres:18.6-alpine3.2477f585114c32
github.com/moby/sys/user@v0.1.0
0.4.1

Open the chart page →

6,941

Container images carrying it

314 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/codefresh/dind:3.0.250885ab519dac
github.com/moby/sys/user@v0.4.0
0.4.1
1
quay.io/fossa/postgres:17.2-15af45ac79f38
github.com/moby/sys/user@v0.1.0
0.4.1
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
github.com/moby/sys/user@v0.4.0
0.4.1
1
quay.io/kubescape/kubescape:v4.0.14418fa941ecc0
github.com/moby/sys/user@v0.4.0
0.4.1
1
quay.io/kubescape/node-agent:v0.3.2192044ed750f5e
github.com/moby/sys/user@v0.4.0
0.4.1
1
quay.io/nuclio/dashboard:1.17.9-amd64708fe10f099a
github.com/moby/sys/user@v0.4.0
0.4.1
1
quay.io/openshift/origin-cli:latest10fef10863a3
github.com/moby/sys/user@v0.4.0
0.4.1
1
quay.io/operator-framework/catalogd:v1.8.06ff40fa6257f
github.com/moby/sys/user@v0.4.0
0.4.1
1
quay.io/operator-framework/olm40d0363f4aa6
github.com/moby/sys/user@v0.1.0
0.4.1
1
quay.io/operator-framework/olm:v0.46.04404599eb7b7
github.com/moby/sys/user@v0.4.0
0.4.1
1
quay.io/operator-framework/operator-controller:v1.8.0bca5dfcc67ca
github.com/moby/sys/user@v0.4.0
0.4.1
1
quay.io/rhdh/rhdh-hub-rhel9:latest4f8c0f8a8ee0
github.com/moby/sys/user@v0.4.0
0.4.1
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.6.2-gitlab13bc2e20d60d1
github.com/moby/sys/user@v0.4.0
0.4.1
1
registry.gitlab.com/xrow-public/ci-tools/tools:mainaa62b23f2b5e
github.com/moby/sys/user@v0.4.0
0.4.1
1

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.