StackRadar

CVE-2026-67354

Medium

Advisory

Published 20 Jul 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
141
of 17,781 indexed, latest versions
Container images
125
deployed by those charts
Fix available
1 of 1
affected package

Guzzle: URI fragments disclosed in redirect Referer headers

Carried by container images the latest versions of 141 of 17,781 indexed charts deploy, on 125 images.

Affected packageAffected versionsFixed inImages
guzzlehttp/guzzlecomposer5.3.4, 6.3.0, 6.3.3, 6.5.3+22 more7.15.1125
OSV records
GHSA-h95v-h523-3mw8

Charts affected

141 by stars
ChartLatestAffected imagesRadar Score
medewerkercatalogusmedewerkercatalogus1.0.01 of 3See more

medewerkercatalogus medewerkercatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

7,327
memo-componentmemo-component1.0.01 of 3See more

memo-component memo-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/memo-component-php:latestef77f4c089a1
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

7,510
fossologymidokura-communityVerified publisher0.2.21 of 2See more

fossology midokura-community 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
fossology/fossology:4.2.18bd1f22ba7bb
guzzlehttp/guzzle@7.5.0
7.15.1

Open the chart page →

3,294
moodlemoodle1.0.31 of 2See more

moodle moodle 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
cloudtooling/moodle:5.2.3f4f04e0fc401
guzzlehttp/guzzle@7.10.0
7.15.1

Open the chart page →

3,954
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
guzzlehttp/guzzle@7.7.0
7.15.1

Open the chart page →

12,813
librenmsnimbolus0.5.11 of 3See more

librenms nimbolus 0.5.1

1 of the 3 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
librenms/librenms:24.11.00920bc9117a8
guzzlehttp/guzzle@7.9.2
7.15.1

Open the chart page →

2,293
notification-componentnotification-component1.0.01 of 4See more

notification-component notification-component 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

7,527
commonground-gatewayopencatalogi1.5.31 of 7See more

commonground-gateway opencatalogi 1.5.3

1 of the 7 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
guzzlehttp/guzzle@6.5.8
7.15.1

Open the chart page →

9,724
orderregistratiecomponentorderregistratiecomponent1.0.01 of 3See more

orderregistratiecomponent orderregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/orderregistratiecomponent-php:latestd17257e4fa27
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

7,492
firefly-iiiphntom0.2.101 of 2See more

firefly-iii phntom 0.2.10

1 of the 2 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
phntom/fireflyiii:version-5.7.5f881ea5fbbf1
guzzlehttp/guzzle@7.4.2
7.15.1

Open the chart page →

1,813
procestypecatalogusprocestypecatalogus1.1.01 of 4See more

procestypecatalogus procestypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/procestypecatalogus-php:latest956c4fb64796
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

7,429
productenendienstencatalogusproductenendienstencatalogus1.0.01 of 3See more

productenendienstencatalogus productenendienstencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/productenendienstencatalogus-php:latest7242da105081
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

7,510
panproto-application-nldesign0.1.01 of 5See more

pan proto-application-nldesign 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
conduction/pan-php:dev24f03c57568f
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

8,725
proto-component-commongroundproto-component-commonground1.0.01 of 3See more

proto-component-commonground proto-component-commonground 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

7,510
laravel-workerrenoki-co1.1.01 of 1See more

laravel-worker renoki-co 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
guzzlehttp/guzzle@7.3.0
7.15.1

Open the chart page →

5,687
review-componentreview-component1.0.01 of 3See more

review-component review-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/review-component-php:latestafe623824b82
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

7,491
shopwarerobjuz2.0.01 of 6See more

shopware robjuz 2.0.0

1 of the 6 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
shyim/shopware:6.4.6.0a951c0e6b836
guzzlehttp/guzzle@7.4.0
7.15.1

Open the chart page →

2,972
mauticromholdings0.1.31 of 3See more

mautic romholdings 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
guzzlehttp/guzzle@6.3.0
7.15.1

Open the chart page →

2,939
grocysarab97Verified publisher0.1.11 of 1See more

grocy sarab97 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
linuxserver/grocy:4.0.1f8f5f96b6ea8
guzzlehttp/guzzle@7.7.0
7.15.1

Open the chart page →

2,449
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
guzzlehttp/guzzle@7.9.2
7.15.1

Open the chart page →

9,755
bookstackschmitzis0.1.11 of 1See more

bookstack schmitzis 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
solidnerd/bookstack:21.12762ffd5c51d3
guzzlehttp/guzzle@7.4.1
7.15.1

Open the chart page →

2,751
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
guzzlehttp/guzzle@7.9.3
7.15.1

Open the chart page →

6,094
typo3schoolguys-helmcharts0.4.21 of 1See more

typo3 schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
guzzlehttp/guzzle@7.11.0
7.15.1

Open the chart page →

4,836
wallabagsebtiz13-chartsVerified publisher0.6.01 of 1See more

wallabag sebtiz13-charts 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
guzzlehttp/guzzle@5.3.4
7.15.1

Open the chart page →

1,136
cachetsergiotocaliniVerified publisher1.0.01 of 1See more

cachet sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
cachethq/docker:2.3.15a61ff0f67ea7
guzzlehttp/guzzle@6.3.3
7.15.1

Open the chart page →

1,896
commonground-gatewayskeleton-pip0.1.71 of 5See more

commonground-gateway skeleton-pip 0.1.7

1 of the 5 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
guzzlehttp/guzzle@6.5.8
7.15.1

Open the chart page →

2,825
icingawebsvtech-public-helm-charts1.0.01 of 2See more

icingaweb svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icingaweb2:v1.0.2a59d0b81dde2
guzzlehttp/guzzle@7.8.1
7.15.1

Open the chart page →

2,038
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

7,480
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

3,993
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
guzzlehttp/guzzle@7.9.2
7.15.1

Open the chart page →

10,086
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
guzzlehttp/guzzle@7.8.1
7.15.1

Open the chart page →

10,006
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

7,510
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

7,429
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
guzzlehttp/guzzle@6.5.8
7.15.1

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
guzzlehttp/guzzle@7.2.0
7.15.1

Open the chart page →

2,132
tool-quickstatementswbstack0.4.01 of 1See more

tool-quickstatements wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/wbstack/quickstatements:1.3.588423e422ea8
guzzlehttp/guzzle@7.4.0
7.15.1

Open the chart page →

1,698
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
guzzlehttp/guzzle@6.5.5
7.15.1

Open the chart page →

7,552
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-67354.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
guzzlehttp/guzzle@7.10.0
7.15.1

Open the chart page →

1,042

Container images carrying it

125 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
linuxserver/heimdall:2.8.3287e48152967
guzzlehttp/guzzle@7.13.3
7.15.1
1
linuxserver/heimdall:2.6.371597f4461e4
guzzlehttp/guzzle@7.8.1
7.15.1
1
lycheeorg/lychee-laravel:v4.3.0308c0e6231da
guzzlehttp/guzzle@7.3.0
7.15.1
1
martinhelmich/typo3:12.4c83a4f3fd7ae
guzzlehttp/guzzle@7.10.0
7.15.1
1
mautic/mautic:v4-apache94ea4acf4049
guzzlehttp/guzzle@7.4.5
7.15.1
1
mautic/mautic:7-apacheeb8cc73d97e1
guzzlehttp/guzzle@7.10.5
7.15.1
1
michaelepitech/sample-app:latestaf51d61c19f5
guzzlehttp/guzzle@7.7.0
7.15.1
1
n22107670/sample-app:0.4.08f3072db7aeb
guzzlehttp/guzzle@7.7.0
7.15.1
1
openemr/openemr:6.1.089eaa6d9a4e3
guzzlehttp/guzzle@7.4.1
7.15.1
1
owncloud/server:10.15.051d9b74fc2a8
guzzlehttp/guzzle@7.8.1
7.15.1
1
owncloud/server:10.16.274c53d341076
guzzlehttp/guzzle@7.8.1
7.15.1
1
owncloud/server:10.16.3b3f9efdcd7f7
guzzlehttp/guzzle@7.10.0
7.15.1
1
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
guzzlehttp/guzzle@7.10.1
7.15.1
1
pe46dro/xbackbone-docker:3.3.309dfe3aa10f6
guzzlehttp/guzzle@6.5.5
7.15.1
1
phntom/fireflyiii:version-5.7.5f881ea5fbbf1
guzzlehttp/guzzle@7.4.2
7.15.1
1
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
guzzlehttp/guzzle@7.10.4
7.15.1
1
roundcube/roundcubemail:1.5.3-apachea8ea6fd751dc
guzzlehttp/guzzle@6.5.8
7.15.1
1
shlinkio/shlink:2.7.1c6729db1d3a8
guzzlehttp/guzzle@7.3.0
7.15.1
1
shyim/shopware:6.4.6.0a951c0e6b836
guzzlehttp/guzzle@7.4.0
7.15.1
1
snipe/snipe-it:v8.3.1141ebf2386fe
guzzlehttp/guzzle@7.9.3
7.15.1
1
snipe/snipe-it:v6.0.1455fb7636a98c
guzzlehttp/guzzle@7.4.5
7.15.1
1
solidnerd/bookstack:21.12762ffd5c51d3
guzzlehttp/guzzle@7.4.1
7.15.1
1
svtechnmaa/svtech_icingaweb2:v1.0.2a59d0b81dde2
guzzlehttp/guzzle@7.8.1
7.15.1
1
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
guzzlehttp/guzzle@6.5.8
7.15.1
1
wallabag/wallabag:2.4.25e4c26a7fb4a
guzzlehttp/guzzle@5.3.4
7.15.1
1
ghcr.io/cedar2025/xboard:latest896e4926e0d7
guzzlehttp/guzzle@7.10.0
7.15.1
1
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/memo-component-php:latestef77f4c089a1
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/orderregistratiecomponent-php:latestd17257e4fa27
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/procestypecatalogus-php:latest956c4fb64796
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/productenendienstencatalogus-php:latest7242da105081
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/review-component-php:latestafe623824b82
guzzlehttp/guzzle@6.5.5
7.15.1
1
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
guzzlehttp/guzzle@6.5.5
7.15.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.