StackRadar

CVE-2026-73566

High

Advisory

Published 24 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
940
of 17,781 indexed, latest versions
Container images
969
deployed by those charts
Fix available
3 of 4
affected packages

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

Carried by container images the latest versions of 940 of 17,781 indexed charts deploy, on 969 images.

Affected packageAffected versionsFixed inImages
tarnpm1.0.3, 2.2.1, 2.2.2, 4.0.2+34 more7.5.21969
node-tardeb1.0.3-2, 2.2.1-1, 4.4.10+ds1-2ubuntu1, 6.1.13+~cs7.0.5-3no fix listed6
node-gypapk13.0.0-r013.0.1-r11
npmapk11.17.0-r012.0.1-r21
OSV records
CGA-63gq-6rq6-x5wcCGA-cppm-m8p8-rqr4GHSA-r292-9mhp-454mUBUNTU-CVE-2026-73566
Also known as
CGA-hm85-254c-g849, CGA-jp96-8764-w59g

Charts affected

940 by stars
ChartLatestAffected imagesRadar Score
dbgatedbgate-helm-chartVerified publisher0.1.81 of 1See more

dbgate dbgate-helm-chart 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
dbgate/dbgate:7.2.3f2dc7423ea88
tar@7.5.11
7.5.21

Open the chart page →

1,397
db-operatordb-operatorVerified publisher0.1.01 of 1See more

db-operator db-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
plumdog/db-operator:latest0c2fa2db0357
tar@6.1.11
7.5.21

Open the chart page →

3,042
decisionrules-aksdecisionrules-aksVerified publisher0.2.01 of 2See more

decisionrules-aks decisionrules-aks 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
tar@7.5.11
7.5.21

Open the chart page →

1,138
decisionrules-eksdecisionrules-eksVerified publisher0.3.01 of 2See more

decisionrules-eks decisionrules-eks 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
tar@7.5.11
7.5.21

Open the chart page →

1,138
decisionrules-ingressdecisionrules-ingressVerified publisher0.2.01 of 2See more

decisionrules-ingress decisionrules-ingress 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
tar@7.5.11
7.5.21

Open the chart page →

1,138
decisionrules-ocpdecisionrules-ocpVerified publisher0.1.02 of 4See more

decisionrules-ocp decisionrules-ocp 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
decisionrules/business-intelligence:latest1135a6d4f09b
tar@7.5.11
7.5.21
decisionrules/server:latestf38d8571fa06
tar@7.5.11
7.5.21

Open the chart page →

2,685
defactopsdefactops1.0.91 of 2See more

defactops defactops 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
defactops/defactops-backend:1.0.2307b663c0092a
tar@6.2.0
7.5.21

Open the chart page →

4,509
airtraildefault-ghVerified publisher0.2.21 of 2See more

airtrail default-gh 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
johly/airtrail:v3.11.19f702b91e0e7
tar@7.5.11
7.5.21

Open the chart page →

1,662
homarrdelerVerified publisher1.0.11 of 1See more

homarr deler 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:0.13.4985456bdfb46
tar@6.1.15
7.5.21

Open the chart page →

1,924
demo-multiclust-chartdemo-model-chart1.0.02 of 3See more

demo-multiclust-chart demo-model-chart 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
gtato/demo-multiclus-registrator:1.0.09a744588fab3
tar@6.1.11
7.5.21
gtato/demo-multiclus-registry:1.0.02df5174f3cfd
tar@6.1.11
7.5.21

Open the chart page →

1,770
deploy-elibrarydeploy-elibrary-helm0.1.01 of 1See more

deploy-elibrary deploy-elibrary-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
psorab/elibrary:latest53b68896c4ce
tar@6.1.11
7.5.21

Open the chart page →

7,212
deploy-elibrarydeploy-elibrary-oo0.1.01 of 1See more

deploy-elibrary deploy-elibrary-oo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
jedi132000/nextapp:latestdc2a81e92f23
tar@6.1.11
7.5.21

Open the chart page →

8,106
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
tar@6.2.1
7.5.21

Open the chart page →

2,529
backend-servicedev-krishan-dhaka-charts1.0.31 of 1See more

backend-service dev-krishan-dhaka-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
devkrishan001/backend:latestf1c3acadeabe
tar@6.2.1
7.5.21

Open the chart page →

1,264
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
tar@6.1.11
7.5.21

Open the chart page →

30,031
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
tar@6.1.11
7.5.21

Open the chart page →

29,033
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
tar@7.5.1
7.5.21

Open the chart page →

68,240
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
tar@4.4.15
7.5.21

Open the chart page →

11,909
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
tar@7.5.1
7.5.21

Open the chart page →

68,240
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
tar@4.4.15
7.5.21

Open the chart page →

11,909
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.02 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
tar@4.4.13
7.5.21
oscarsotosanchez/weatherservice:v1.0911ec961d10b
tar@4.4.13
7.5.21

Open the chart page →

27,550
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
epam/ai-dial-admin-frontend:0.20.021d91ad74755
tar@7.5.16
7.5.21

Open the chart page →

4,046
difydify1.0.02 of 4See more

dify dify 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.009b7e8705673
tar@6.2.0
7.5.21
langgenius/dify-web:1.0.0d64914ff0d6d
tar@6.2.1
7.5.21

Open the chart page →

19,224
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
tar@6.2.1
7.5.21

Open the chart page →

4,551
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
node-gyp@13.0.0-r0
npm@11.17.0-r0
tar@7.5.11
13.0.1-r1
12.0.1-r2
7.5.21

Open the chart page →

7,459
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
tar@6.2.0
7.5.21

Open the chart page →

4,217
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
tar@6.2.1
7.5.21

Open the chart page →

2,862
mergeabledoubanVerified publisher0.2.21 of 1See more

mergeable douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/leoquote/mergeable:latest451706815103
tar@4.4.13
7.5.21

Open the chart page →

4,223
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.02 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
tar@4.4.13
7.5.21
oscarsotosanchez/weatherservice:v1.0911ec961d10b
tar@4.4.13
7.5.21

Open the chart page →

24,656
dumpstoredumpstore0.1.12 of 2See more

dumpstore dumpstore 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-73566.

Open the chart page →

4,251
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
tar@2.2.2
7.5.21

Open the chart page →

11,174
clickhouse-monitoringduyet0.1.21 of 2See more

clickhouse-monitoring duyet 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/duyet/clickhouse-monitoring:latest84edfe8a67a8
tar@7.5.15
7.5.21

Open the chart page →

1,049
dyff-frontenddyff-frontendVerified publisher0.20.11 of 1See more

dyff-frontend dyff-frontend 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
tar@6.2.1
7.5.21

Open the chart page →

973
benchmarking-tooleclipse-aeriosVerified publisher1.0.01 of 1See more

benchmarking-tool eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
tar@7.5.15
7.5.21

Open the chart page →

687
self-orchestratoreclipse-aeriosVerified publisher1.2.01 of 1See more

self-orchestrator eclipse-aerios 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
eclipseaerios/self-orchestrator:1.2.08b123bec5679
tar@6.2.1
7.5.21

Open the chart page →

2,385
dashboardedu1.0.01 of 1See more

dashboard edu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
tar@6.2.1
7.5.21

Open the chart page →

1,344
deploy-elibraryeducative-helm-bookapp0.5.01 of 1See more

deploy-elibrary educative-helm-bookapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
tar@6.1.11
7.5.21

Open the chart page →

5,112
node-redegebackVerified publisher2.0.131 of 1See more

node-red egeback 2.0.13

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
nodered/node-red:5.0.410f40d0a83e7
tar@7.5.15
7.5.21

Open the chart page →

975
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
tar@7.5.11
7.5.21

Open the chart page →

30,159
backend-charteks-3-tier-app-chart0.1.01 of 1See more

backend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
arfath29/3-tier-app-backend:latestee0750b18406
tar@4.4.19
7.5.21

Open the chart page →

1,693
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
tar@6.1.0
7.5.21

Open the chart page →

3,744
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
library/node:18-alpine8d6421d663b4
tar@6.2.1
7.5.21

Open the chart page →

2,942
azuriteemberstackVerified publisher1.0.211 of 1See more

azurite emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
tar@7.5.11
7.5.21

Open the chart page →

365
reddarkemmas-chartsVerified publisher0.0.21 of 1See more

reddark emmas-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/0xemma/reddark:main2a115e991894
tar@6.1.14
7.5.21

Open the chart page →

1,998
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
tar@4.4.13
7.5.21
oscarsotosanchez/weatherservice:v1.0911ec961d10b
tar@4.4.13
7.5.21

Open the chart page →

27,291
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
tar@4.4.13
7.5.21
oscarsotosanchez/weatherservice:v1.0911ec961d10b
tar@4.4.13
7.5.21

Open the chart page →

27,256
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
arturisimo/server-urjc:v1.0d8dc4430531e
tar@6.1.11
7.5.21

Open the chart page →

27,096
edp-installepmdedpOfficialVerified publisher3.15.01 of 7See more

edp-install epmdedp 3.15.0

1 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
tar@6.2.1
7.5.21

Open the chart page →

2,033
krci-portalepmdedpVerified publisher0.8.01 of 1See more

krci-portal epmdedp 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
tar@6.2.1
7.5.21

Open the chart page →

839
hedgedocernail-hedgedoc5.0.01 of 1See more

hedgedoc ernail-hedgedoc 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
tar@6.2.1
7.5.21

Open the chart page →

1,755

Container images carrying it

969 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
assistiot/open_api_frontend:1.0.1f11d82defc70
tar@4.4.19
7.5.21
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
tar@4.4.19
7.5.21
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
tar@6.1.11
7.5.21
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
tar@6.1.11
7.5.21
1
aureliengasser/http-folder:1.1.111c4318c2571
tar@4.4.13
7.5.21
1
automatischio/automatisch:0.15.03bace7a12d5f
tar@6.2.1
7.5.21
1
baserow/baserow:1.30.1df0c42eb67e8
tar@6.2.0
7.5.21
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
tar@4.4.13
7.5.21
1
belirta/beli-docker:v1.0.0f65ad0e23b4d
tar@6.1.14
7.5.21
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
tar@6.2.1
7.5.21
1
bicarus/http-https-echo:2785dd6a7e805e
tar@6.1.11
7.5.21
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
tar@6.1.11
7.5.21
1
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
tar@4.4.1
7.5.21
1
blockscout/blockscout:5.1.5c365a8f2dc12
tar@6.1.11
7.5.21
1
bluerange/bluerange-mosquitto:25f1bfbba84832
tar@7.5.1
7.5.21
1
bnjbvr/kresus:0.22.137e216b182c8
tar@7.4.3
7.5.21
1
bnwokoye/nodejswebapp:latest74de7dc7ebfb
tar@6.1.13
7.5.21
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
tar@6.1.0
7.5.21
1
budibase/apps:3.41.344fe6feab985
tar@7.5.11
7.5.21
1
budibase/database:2.1.0d90f656261c9
tar@7.5.11
7.5.21
1
budibase/worker:3.41.3de5e2e560ce8
tar@7.5.11
7.5.21
1
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
tar@4.4.19
7.5.21
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
tar@7.4.3
7.5.21
1
catalysm/csmm:latestf003b35f54d9
tar@6.1.11
7.5.21
1
cccs/assemblyline-ui-frontend:4.7.4.stable174c8e4b6c0483
tar@7.5.11
7.5.21
1
ccjacobs14/amazon:59a9b14a6f09e
tar@6.2.0
7.5.21
1
chainsafe/lodestar:latest5593f6e97912
tar@7.5.19
7.5.21
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
tar@6.2.1
7.5.21
1
chandanteekinavar/findery-market-user-service:1.049e164a9a439
tar@6.1.11
7.5.21
1
chatwoot/chatwoot:v4.15.167ebc751c171
tar@2.2.2
7.5.21
1
chibisafe/chibisafe:latest836467a50792
tar@6.2.1
7.5.21
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
tar@6.2.1
7.5.21
1
chocobozzz/peertube:v8.1.5052712130691
tar@7.5.13
7.5.21
1
christianhuth/node-hostname:1.0.1c07f414a3e4b
tar@7.4.3
7.5.21
1
cnieg/maildev:v1.1.998ee05668915
tar@4.4.13
7.5.21
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
tar@6.1.11
7.5.21
1
codercom/code-server:4.11.0-debian1e2cc688008e
tar@6.1.11
7.5.21
1
codetogether/codetogether:latest4348c8a38752
tar@6.2.1
7.5.21
1
coldatom/containers-security-api:latesteae9e82da080
tar@6.1.13
7.5.21
1
coldatom/containers-security-front:latest7c2fbbb41bcf
tar@6.1.11
7.5.21
1
conduction/conduction-ui-app:devd591f5e6f2a9
tar@6.1.0
7.5.21
1
contane/foreman:0.5.2efb98bdcc4e9
tar@7.4.3
7.5.21
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
tar@7.5.16
7.5.21
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
tar@6.2.1
7.5.21
1
countly/api:25.05.4f4cc7447c4f5
tar@6.2.1
7.5.21
1
countly/countly-server:25.05.4e3c238248f99
tar@6.2.1
7.5.21
1
countly/frontend:25.05.42acbc11499b6
tar@6.2.1
7.5.21
1
cryptexlabs/authf:0.12.11189c07411d7c
tar@6.2.0
7.5.21
1
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
tar@6.2.0
7.5.21
1
cspconsole/report-processor:1.0.279a2d8840bfdf
tar@7.5.11
7.5.21
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.