StackRadar

CVE-2026-73566

High

Advisory

Published 24 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
942
of 17,787 indexed, latest versions
Container images
971
deployed by those charts
Fix available
3 of 4
affected packages

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

Carried by container images the latest versions of 942 of 17,787 indexed charts deploy, on 971 images.

Affected packageAffected versionsFixed inImages
tarnpm1.0.3, 2.2.1, 2.2.2, 4.0.2+34 more7.5.21971
node-tardeb1.0.3-2, 2.2.1-1, 4.4.10+ds1-2ubuntu1, 6.1.13+~cs7.0.5-3+1 moreno fix listed7
node-gypapk13.0.0-r013.0.1-r11
npmapk11.17.0-r012.0.1-r21
OSV records
CGA-63gq-6rq6-x5wcCGA-cppm-m8p8-rqr4DEBIAN-CVE-2026-73566GHSA-r292-9mhp-454mUBUNTU-CVE-2026-73566
Also known as
CGA-hm85-254c-g849, CGA-jp96-8764-w59g

Charts affected

942 by stars
ChartLatestAffected imagesRadar Score
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
tar@6.1.11
7.5.21

Open the chart page →

4,260
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
tar@6.1.11
7.5.21

Open the chart page →

15,717
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
tar@4.4.13
7.5.21

Open the chart page →

4,405
overseerrgeek-cookbookVerified publisher5.4.21 of 1See more

overseerr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.26.1254d16af8f71
tar@6.1.0
7.5.21

Open the chart page →

3,444
sendgeek-cookbookVerified publisher1.2.21 of 1See more

send geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
tar@6.1.11
7.5.21

Open the chart page →

1,148
tdarrgeek-cookbookVerified publisher4.6.21 of 2See more

tdarr geek-cookbook 4.6.2

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.00.101e3f9328327d
tar@4.4.13
7.5.21

Open the chart page →

31,178
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
tar@6.1.11
7.5.21

Open the chart page →

5,079
uptimerobotgeek-cookbookVerified publisher3.0.41 of 1See more

uptimerobot geek-cookbook 3.0.4

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
tar@4.4.1
7.5.21

Open the chart page →

1,669
youtubedl-materialgeek-cookbookVerified publisher4.4.21 of 1See more

youtubedl-material geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.23720b856bd2f
tar@4.4.13
7.5.21

Open the chart page →

4,410
zigbee2mqttgeek-cookbookVerified publisher9.4.21 of 1See more

zigbee2mqtt geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
tar@4.4.13
7.5.21

Open the chart page →

2,173
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
tar@7.5.11
7.5.21

Open the chart page →

3,135
globalpingglobalpingVerified publisher1.0.111 of 1See more

globalping globalping 1.0.11

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
globalping/globalping-probe:latest8acbd23009fd
tar@7.5.11
7.5.21

Open the chart page →

518
ghostgroundhog2k0.212.121 of 1See more

ghost groundhog2k 0.212.12

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
tar@7.5.11
7.5.21

Open the chart page →

1,948
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
tar@6.2.0
7.5.21

Open the chart page →

4,196
openprojecthomeenterpriseinc0.5.01 of 1See more

openproject homeenterpriseinc 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
openproject/community:12.0.2734743d11094
tar@4.4.13
7.5.21

Open the chart page →

6,810
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
tar@7.5.4
7.5.21

Open the chart page →

12,461
pdc-portali4trustVerified publisher2.3.21 of 1See more

pdc-portal i4trust 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
i4trust/pdc-portal:2.0.03e77858e1219
tar@4.4.13
7.5.21

Open the chart page →

2,723
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
tar@7.4.3
7.5.21

Open the chart page →

15,749
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
library/kibana:7.17.3e2e2031c15be
tar@6.1.11
7.5.21

Open the chart page →

17,365
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
tar@4.4.19
7.5.21

Open the chart page →

3,369
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
tar@6.2.1
7.5.21

Open the chart page →

5,234
keycloak-reporterkeycloak-reporterVerified publisher1.4.151 of 1See more

keycloak-reporter keycloak-reporter 1.4.15

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
tar@7.5.16
7.5.21

Open the chart page →

1,270
kikplatekikplateVerified publisher0.22.01 of 3See more

kikplate kikplate 0.22.0

1 of the 3 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/kikplate/kikplate-web:main34bbb61e8e42
tar@7.5.11
7.5.21

Open the chart page →

2,783
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
tar@6.1.11
7.5.21

Open the chart page →

3,143
difykubeblocksVerified publisher0.5.12 of 5See more

dify kubeblocks 0.5.1

2 of the 5 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.009b7e8705673
tar@6.2.0
7.5.21
langgenius/dify-web:0.6.11a2a294743634
tar@6.2.0
7.5.21

Open the chart page →

20,424
kube-ingress-dash-chartkube-ingress-dashVerified publisher0.3.11 of 1See more

kube-ingress-dash-chart kube-ingress-dash 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/wasilak/kube-ingress-dash:0.3.1ff55992f905c
tar@7.5.1
7.5.21

Open the chart page →

1,506
chibisafel4gVerified publisher0.1.12 of 3See more

chibisafe l4g 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
chibisafe/chibisafe:latest836467a50792
tar@6.2.1
7.5.21
chibisafe/chibisafe-server:latest3da4fcbc1a18
tar@6.2.1
7.5.21

Open the chart page →

5,657
lifecycle-jira-integrationlifecycle-jira-integration1.0.01 of 1See more

lifecycle-jira-integration lifecycle-jira-integration 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
anoopnair/lifecycle-jira-integration:latestd80c73a6089d
tar@6.1.11
7.5.21

Open the chart page →

927
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
tar@6.2.1
7.5.21

Open the chart page →

4,390
litlyxlitlyx0.2.03 of 5See more

litlyx litlyx 0.2.0

3 of the 5 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
litlyx/litlyx-consumer:latest02225e77d316
tar@7.5.2
7.5.21
litlyx/litlyx-dashboard:lateste64ff2d52385
tar@7.4.3
7.5.21
litlyx/litlyx-producer:latest10407f36613f
tar@7.5.2
7.5.21

Open the chart page →

7,915
jspolicyloftVerified publisher0.2.21 of 1See more

jspolicy loft 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
loftsh/jspolicy:0.2.225deb9bd2683
tar@6.1.11
7.5.21

Open the chart page →

2,309
actualbudgetm0nsterrr-actualbudgetVerified publisher2.10.01 of 1See more

actualbudget m0nsterrr-actualbudget 2.10.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
tar@7.5.19
7.5.21

Open the chart page →

1,102
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
tar@2.2.2
7.5.21

Open the chart page →

5,941
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.12 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

2 of the 6 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
tar@4.4.13
7.5.21
fjvela/urjc-fjvela-server:1.0.53c840aebce22
tar@4.4.13
7.5.21

Open the chart page →

19,192
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
tar@6.2.1
7.5.21

Open the chart page →

13,763
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
tar@7.5.11
7.5.21

Open the chart page →

2,576
tristian-idnonkronk0.1.31 of 1See more

tristian-id nonkronk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
nonkronk/tristian-id:latest0a3694d70647
tar@6.1.11
7.5.21

Open the chart page →

1,105
oadaoadaVerified publisher5.0.510 of 11See more

oada oada 5.0.5

10 of the 11 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
oada/auth:4.0.0c0d077e79ef4
tar@7.4.3
7.5.21
oada/http-handler:4.0.0d87efe8ba4b0
tar@7.4.3
7.5.21
oada/rev-graph-update:4.0.0ebc8343f05ff
tar@7.4.3
7.5.21
oada/shares:4.0.0c6ffb4e8ed63
tar@7.4.3
7.5.21
oada/startup:4.0.0fc09495e2f3c
tar@7.4.3
7.5.21
oada/sync-handler:4.0.0b7a2cfc137cf
tar@7.4.3
7.5.21
oada/users:4.0.0b6c562fa5b1b
tar@7.4.3
7.5.21
oada/webhooks:4.0.06590c60de347
tar@7.4.3
7.5.21
oada/well-known:4.0.07943fde43b19
tar@7.4.3
7.5.21
oada/write-handler:4.0.08464c7f48aae
tar@7.4.3
7.5.21

Open the chart page →

13,319
dashdotoben01Verified publisher1.5.01 of 1See more

dashdot oben01 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
mauricenino/dashdot:5.9.2236997816917
tar@6.2.1
7.5.21

Open the chart page →

1,237
kuttone-acre-fundVerified publisher0.2.51 of 1See more

kutt one-acre-fund 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
kutt/kutt:latestfa3d24a89b04
tar@7.5.11
7.5.21

Open the chart page →

454
open5gs-webuiopen5gs-webuiVerified publisher2.3.11 of 2See more

open5gs-webui open5gs-webui 2.3.1

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
tar@6.2.0
7.5.21

Open the chart page →

5,300
open-api-discoveryopen-api-discoveryVerified publisher0.1.11 of 1See more

open-api-discovery open-api-discovery 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
lukasreining/open-api-schema-collector:0.1.050e021c42e33
tar@6.1.11
7.5.21

Open the chart page →

2,473
openccuopenccuVerified publisher3.89.91 of 1See more

openccu openccu 3.89.9

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/openccu/openccu:3.89.9.20260914eaeefd355dca
tar@7.5.11
7.5.21

Open the chart page →

1,405
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
tar@7.4.3
7.5.21

Open the chart page →

6,899
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
tar@6.2.1
7.5.21

Open the chart page →

6,890
patchworkpatchworkVerified publisher0.8.61 of 2See more

patchwork patchwork 0.8.6

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/patchwork:mainc01e018bced4
tar@7.4.3
7.5.21

Open the chart page →

2,084
pdf-editor-helmpdf-editor-web1.0.01 of 4See more

pdf-editor-helm pdf-editor-web 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
tar@6.1.11
7.5.21

Open the chart page →

4,206
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
tar@7.5.13
7.5.21

Open the chart page →

7,075
camophntom0.1.11 of 1See more

camo phntom 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
phntom/camo:2.3.1a9b1304d6c71
tar@4.4.15
7.5.21

Open the chart page →

1,217
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
tar@6.1.11
7.5.21
treskon/portrait-ui:DEV-lateste7970783bc8d
tar@6.2.1
7.5.21

Open the chart page →

31,949

Container images carrying it

971 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
tar@7.5.19
7.5.21
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
tar@4.4.13
7.5.21
1
quay.io/seamware/fdsc-dashboard:0.6.0f7706c316c5a
tar@6.2.1
7.5.21
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
tar@7.5.11
7.5.21
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
tar@6.1.11
7.5.21
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
tar@6.1.11
7.5.21
1
quay.io/soketi/soketi:1.6-16-debian713223456cf1
tar@6.1.11
7.5.21
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
tar@4.4.13
7.5.21
1
quay.io/wekan/wekan:v5.65cb17600883a3
tar@6.1.11
7.5.21
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
tar@7.5.11
7.5.21
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
tar@6.2.1
7.5.21
1
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
tar@6.2.1
7.5.21
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
tar@7.5.11
7.5.21
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
tar@6.2.1
7.5.21
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
tar@7.5.11
7.5.21
1
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
tar@7.5.11
7.5.21
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
tar@4.4.13
7.5.21
1
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
tar@6.1.11
7.5.21
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
tar@7.5.11
7.5.21
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
tar@6.2.1
7.5.21
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
tar@7.5.16
7.5.21
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.