StackRadar

CVE-2026-73566

High

Advisory

Published 24 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
942
of 17,787 indexed, latest versions
Container images
971
deployed by those charts
Fix available
3 of 4
affected packages

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

Carried by container images the latest versions of 942 of 17,787 indexed charts deploy, on 971 images.

Affected packageAffected versionsFixed inImages
tarnpm1.0.3, 2.2.1, 2.2.2, 4.0.2+34 more7.5.21971
node-tardeb1.0.3-2, 2.2.1-1, 4.4.10+ds1-2ubuntu1, 6.1.13+~cs7.0.5-3+1 moreno fix listed7
node-gypapk13.0.0-r013.0.1-r11
npmapk11.17.0-r012.0.1-r21
OSV records
CGA-63gq-6rq6-x5wcCGA-cppm-m8p8-rqr4DEBIAN-CVE-2026-73566GHSA-r292-9mhp-454mUBUNTU-CVE-2026-73566
Also known as
CGA-hm85-254c-g849, CGA-jp96-8764-w59g

Charts affected

942 by stars
ChartLatestAffected imagesRadar Score
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
tar@7.4.3
7.5.21

Open the chart page →

6,226
dbgatedbgate-helm-chartVerified publisher0.1.81 of 1See more

dbgate dbgate-helm-chart 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
dbgate/dbgate:7.2.3f2dc7423ea88
tar@7.5.11
7.5.21

Open the chart page →

1,409
db-operatordb-operatorVerified publisher0.1.01 of 1See more

db-operator db-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
plumdog/db-operator:latest0c2fa2db0357
tar@6.1.11
7.5.21

Open the chart page →

3,042
decisionrules-aksdecisionrules-aksVerified publisher0.2.01 of 2See more

decisionrules-aks decisionrules-aks 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
tar@7.5.11
7.5.21

Open the chart page →

1,139
decisionrules-eksdecisionrules-eksVerified publisher0.3.01 of 2See more

decisionrules-eks decisionrules-eks 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
tar@7.5.11
7.5.21

Open the chart page →

1,139
decisionrules-ingressdecisionrules-ingressVerified publisher0.2.01 of 2See more

decisionrules-ingress decisionrules-ingress 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
tar@7.5.11
7.5.21

Open the chart page →

1,139
decisionrules-ocpdecisionrules-ocpVerified publisher0.1.02 of 4See more

decisionrules-ocp decisionrules-ocp 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
decisionrules/business-intelligence:latest1135a6d4f09b
tar@7.5.11
7.5.21
decisionrules/server:latestf38d8571fa06
tar@7.5.11
7.5.21

Open the chart page →

2,698
defactopsdefactops1.0.91 of 2See more

defactops defactops 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
defactops/defactops-backend:1.0.2307b663c0092a
tar@6.2.0
7.5.21

Open the chart page →

4,353
airtraildefault-ghVerified publisher0.2.21 of 2See more

airtrail default-gh 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
johly/airtrail:v3.11.19f702b91e0e7
tar@7.5.11
7.5.21

Open the chart page →

1,675
homarrdelerVerified publisher1.0.11 of 1See more

homarr deler 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:0.13.4985456bdfb46
tar@6.1.15
7.5.21

Open the chart page →

1,924
demo-multiclust-chartdemo-model-chart1.0.02 of 3See more

demo-multiclust-chart demo-model-chart 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
gtato/demo-multiclus-registrator:1.0.09a744588fab3
tar@6.1.11
7.5.21
gtato/demo-multiclus-registry:1.0.02df5174f3cfd
tar@6.1.11
7.5.21

Open the chart page →

1,770
deploy-elibrarydeploy-elibrary-helm0.1.01 of 1See more

deploy-elibrary deploy-elibrary-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
psorab/elibrary:latest53b68896c4ce
tar@6.1.11
7.5.21

Open the chart page →

7,259
deploy-elibrarydeploy-elibrary-oo0.1.01 of 1See more

deploy-elibrary deploy-elibrary-oo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
jedi132000/nextapp:latestdc2a81e92f23
tar@6.1.11
7.5.21

Open the chart page →

8,154
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
tar@6.2.1
7.5.21

Open the chart page →

2,530
backend-servicedev-krishan-dhaka-charts1.0.31 of 1See more

backend-service dev-krishan-dhaka-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
devkrishan001/backend:latestf1c3acadeabe
tar@6.2.1
7.5.21

Open the chart page →

1,265
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
tar@6.1.11
7.5.21

Open the chart page →

30,150
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
tar@6.1.11
7.5.21

Open the chart page →

29,151
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
tar@7.5.1
7.5.21

Open the chart page →

66,542
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
tar@4.4.15
7.5.21

Open the chart page →

11,957
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
tar@7.5.1
7.5.21

Open the chart page →

66,542
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
tar@4.4.15
7.5.21

Open the chart page →

11,957
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.02 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
tar@4.4.13
7.5.21
oscarsotosanchez/weatherservice:v1.0911ec961d10b
tar@4.4.13
7.5.21

Open the chart page →

27,608
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
epam/ai-dial-admin-frontend:0.20.021d91ad74755
tar@7.5.16
7.5.21

Open the chart page →

4,053
difydify1.0.02 of 4See more

dify dify 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.009b7e8705673
tar@6.2.0
7.5.21
langgenius/dify-web:1.0.0d64914ff0d6d
tar@6.2.1
7.5.21

Open the chart page →

19,063
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
tar@6.2.1
7.5.21

Open the chart page →

4,551
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
node-gyp@13.0.0-r0
npm@11.17.0-r0
tar@7.5.11
13.0.1-r1
12.0.1-r2
7.5.21

Open the chart page →

7,480
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
tar@6.2.0
7.5.21

Open the chart page →

4,217
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
tar@6.2.1
7.5.21

Open the chart page →

2,862
mergeabledoubanVerified publisher0.2.21 of 1See more

mergeable douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/leoquote/mergeable:latest451706815103
tar@4.4.13
7.5.21

Open the chart page →

4,223
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.02 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
tar@4.4.13
7.5.21
oscarsotosanchez/weatherservice:v1.0911ec961d10b
tar@4.4.13
7.5.21

Open the chart page →

24,714
dumpstoredumpstore0.1.12 of 2See more

dumpstore dumpstore 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-73566.

Open the chart page →

4,253
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
tar@2.2.2
7.5.21

Open the chart page →

11,174
clickhouse-monitoringduyet0.1.21 of 2See more

clickhouse-monitoring duyet 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/duyet/clickhouse-monitoring:latest84edfe8a67a8
tar@7.5.15
7.5.21

Open the chart page →

1,051
dyff-frontenddyff-frontendVerified publisher0.20.11 of 1See more

dyff-frontend dyff-frontend 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
tar@6.2.1
7.5.21

Open the chart page →

973
benchmarking-tooleclipse-aeriosVerified publisher1.0.01 of 1See more

benchmarking-tool eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
tar@7.5.15
7.5.21

Open the chart page →

687
self-orchestratoreclipse-aeriosVerified publisher1.2.01 of 1See more

self-orchestrator eclipse-aerios 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
eclipseaerios/self-orchestrator:1.2.08b123bec5679
tar@6.2.1
7.5.21

Open the chart page →

2,397
dashboardedu1.0.01 of 1See more

dashboard edu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
tar@6.2.1
7.5.21

Open the chart page →

1,344
deploy-elibraryeducative-helm-bookapp0.5.01 of 1See more

deploy-elibrary educative-helm-bookapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
tar@6.1.11
7.5.21

Open the chart page →

5,150
node-redegebackVerified publisher2.0.131 of 1See more

node-red egeback 2.0.13

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
nodered/node-red:5.0.410f40d0a83e7
tar@7.5.15
7.5.21

Open the chart page →

975
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
tar@7.5.11
7.5.21

Open the chart page →

30,167
backend-charteks-3-tier-app-chart0.1.01 of 1See more

backend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
arfath29/3-tier-app-backend:latestee0750b18406
tar@4.4.19
7.5.21

Open the chart page →

1,693
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
tar@6.1.0
7.5.21

Open the chart page →

3,745
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
library/node:18-alpine8d6421d663b4
tar@6.2.1
7.5.21

Open the chart page →

2,960
azuriteemberstackVerified publisher1.0.211 of 1See more

azurite emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
tar@7.5.11
7.5.21

Open the chart page →

365
reddarkemmas-chartsVerified publisher0.0.21 of 1See more

reddark emmas-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/0xemma/reddark:main2a115e991894
tar@6.1.14
7.5.21

Open the chart page →

1,998
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
tar@4.4.13
7.5.21
oscarsotosanchez/weatherservice:v1.0911ec961d10b
tar@4.4.13
7.5.21

Open the chart page →

27,349
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
tar@4.4.13
7.5.21
oscarsotosanchez/weatherservice:v1.0911ec961d10b
tar@4.4.13
7.5.21

Open the chart page →

27,314
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
arturisimo/server-urjc:v1.0d8dc4430531e
tar@6.1.11
7.5.21

Open the chart page →

27,188
edp-installepmdedpOfficialVerified publisher3.15.01 of 7See more

edp-install epmdedp 3.15.0

1 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
tar@6.2.1
7.5.21

Open the chart page →

2,034
krci-portalepmdedpVerified publisher0.8.01 of 1See more

krci-portal epmdedp 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
tar@6.2.1
7.5.21

Open the chart page →

839

Container images carrying it

971 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
supabase/storage-api:v1.12.0f983fb50bd95
tar@6.2.1
7.5.21
1
supabase/studio:20241021-9f9b08326d8070c55e9
tar@6.2.1
7.5.21
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
tar@7.5.20
7.5.21
1
supabase/studio:latest94a2a9d2906e
tar@7.5.11
7.5.21
1
svenwal/jsonplaceholder:latestba2f285af432
tar@4.4.19
7.5.21
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-tar@4.4.10+ds1-2ubuntu1
tar@4.4.10
no fix listed
7.5.21
1
sysnet4admin/colosseum-cms:loge74b43c7f492
tar@6.2.1
7.5.21
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
tar@6.2.1
7.5.21
1
taigaio/taiga-events:6.4.00bf2d24a57d9
tar@4.4.13
7.5.21
1
tawfiq58/express-server:latestc707555f6853
tar@6.1.13
7.5.21
1
temporalio/web:1.14.033cfa863d8ce
tar@4.4.19
7.5.21
1
tensorzero/ui:2026.6.0f2563d54724e
tar@7.5.1
7.5.21
1
tenureai/tenure:v1.0.285f5b222df9a5
tar@7.5.16
7.5.21
1
testhubio/testhub-frontend:on-preme86c2db53be8
tar@4.4.13
7.5.21
1
th0th/node-red:4.0.3-debiand06fa39f7406
tar@7.2.0
7.5.21
1
thecloudspark/app-result:1.09a5302cb8312
tar@6.2.1
7.5.21
1
thecodingmachine/workadventure-back:v1.17.764001369dad5
tar@6.1.11
7.5.21
1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
tar@6.1.11
7.5.21
1
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
tar@6.1.11
7.5.21
1
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
tar@6.1.11
7.5.21
1
thelounge/thelounge:4.3.0-alpine0037aa258261
tar@4.4.19
7.5.21
1
thelounge/thelounge:4.2.0-alpine639978459c3a
tar@4.4.13
7.5.21
1
thingsboard/tb-js-executor:3.4.113e1eadf8ace
tar@6.1.11
7.5.21
1
thingsboard/tb-web-ui:3.4.157f98ed53b3d
tar@6.1.11
7.5.21
1
thingsboard/tb-web-ui:3.6.0d388378062cc
tar@6.1.11
7.5.21
1
thmmniii/fbs-collab:v1.27.15d389e3c5ce6
tar@7.4.3
7.5.21
1
thmmniii/fbs-qcm-backend:v1.27.1afbe511e5c24
tar@6.2.1
7.5.21
1
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
tar@6.2.1
7.5.21
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
tar@2.2.1
7.5.21
1
tobirachel/node-project3:v17d9f37154994
tar@6.1.14
7.5.21
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
tar@4.4.13
7.5.21
1
trackerforce/switcher-api:latest28ee0c4e0b88
tar@7.5.19
7.5.21
1
trackerforce/switcher-resolver-node:latest67e2c261f7b4
tar@7.5.19
7.5.21
1
treskon/portrait-ui:DEV-lateste7970783bc8d
tar@6.2.1
7.5.21
1
trufflesuite/ganache-cli:v6.12.2c062707f17f3
tar@4.4.13
7.5.21
1
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
tar@6.1.14
7.5.21
1
tvanro/prerender-alpine:6.4.06909015f0328
tar@4.4.19
7.5.21
1
twentycrm/twenty:v2.22.0e7d9948bf284
tar@7.5.16
7.5.21
1
tzahi12345/youtubedl-material:4.23720b856bd2f
tar@4.4.13
7.5.21
1
ubercadence/web:v3.29.58564a5b44a6d
tar@2.2.2
7.5.21
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
tar@6.2.1
7.5.21
1
unleashorg/unleash-enterprise:7.5.0245aeba40053
tar@7.5.8
7.5.21
1
unleashorg/unleash-proxy:v1.4.82538f89e2685
tar@6.2.1
7.5.21
1
unleashorg/unleash-server:7.5.09adb37e399ba
tar@7.5.8
7.5.21
1
vabene1111/recipes:2.3.50f8d061895e9
tar@7.4.3
7.5.21
1
vcnngr/pnbackend:latesteaf44ad0ad1f
tar@6.2.1
7.5.21
1
veecode/devportalc443520aebf7
tar@7.5.19
7.5.21
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
tar@6.2.1
7.5.21
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
tar@6.1.11
7.5.21
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
tar@6.2.1
7.5.21
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.