StackRadar

CVE-2026-73566

High

Advisory

Published 24 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
931
of 17,787 indexed, latest versions
Container images
959
deployed by those charts
Fix available
3 of 4
affected packages

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

Carried by container images the latest versions of 931 of 17,787 indexed charts deploy, on 959 images.

Affected packageAffected versionsFixed inImages
tarnpm1.0.3, 2.2.1, 2.2.2, 4.0.2+34 more7.5.21959
node-tardeb1.0.3-2, 2.2.1-1, 4.4.10+ds1-2ubuntu1, 6.1.13+~cs7.0.5-3no fix listed6
node-gypapk13.0.0-r013.0.1-r11
npmapk11.17.0-r012.0.1-r21
OSV records
CGA-63gq-6rq6-x5wcCGA-cppm-m8p8-rqr4GHSA-r292-9mhp-454mUBUNTU-CVE-2026-73566
Also known as
CGA-hm85-254c-g849, CGA-jp96-8764-w59g

Charts affected

931 by stars
ChartLatestAffected imagesRadar Score
decisionrules-ocpdecisionrules-ocpVerified publisher0.1.02 of 4See more

decisionrules-ocp decisionrules-ocp 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
decisionrules/business-intelligence:latest1135a6d4f09b
tar@7.5.11
7.5.21
decisionrules/server:latestf38d8571fa06
tar@7.5.11
7.5.21

Open the chart page →

2,685
defactopsdefactops1.0.91 of 2See more

defactops defactops 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
defactops/defactops-backend:1.0.2307b663c0092a
tar@6.2.0
7.5.21

Open the chart page →

4,509
airtraildefault-ghVerified publisher0.2.21 of 2See more

airtrail default-gh 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
johly/airtrail:v3.11.19f702b91e0e7
tar@7.5.11
7.5.21

Open the chart page →

1,662
homarrdelerVerified publisher1.0.11 of 1See more

homarr deler 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:0.13.4985456bdfb46
tar@6.1.15
7.5.21

Open the chart page →

1,924
demo-multiclust-chartdemo-model-chart1.0.02 of 3See more

demo-multiclust-chart demo-model-chart 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
gtato/demo-multiclus-registrator:1.0.09a744588fab3
tar@6.1.11
7.5.21
gtato/demo-multiclus-registry:1.0.02df5174f3cfd
tar@6.1.11
7.5.21

Open the chart page →

1,770
deploy-elibrarydeploy-elibrary-helm0.1.01 of 1See more

deploy-elibrary deploy-elibrary-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
psorab/elibrary:latest53b68896c4ce
tar@6.1.11
7.5.21

Open the chart page →

7,212
deploy-elibrarydeploy-elibrary-oo0.1.01 of 1See more

deploy-elibrary deploy-elibrary-oo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
jedi132000/nextapp:latestdc2a81e92f23
tar@6.1.11
7.5.21

Open the chart page →

8,106
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
tar@6.2.1
7.5.21

Open the chart page →

2,529
backend-servicedev-krishan-dhaka-charts1.0.31 of 1See more

backend-service dev-krishan-dhaka-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
devkrishan001/backend:latestf1c3acadeabe
tar@6.2.1
7.5.21

Open the chart page →

1,264
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
tar@6.1.11
7.5.21

Open the chart page →

30,031
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
tar@6.1.11
7.5.21

Open the chart page →

29,033
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
tar@7.5.1
7.5.21

Open the chart page →

68,240
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
tar@4.4.15
7.5.21

Open the chart page →

11,909
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
tar@7.5.1
7.5.21

Open the chart page →

68,240
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
tar@4.4.15
7.5.21

Open the chart page →

11,909
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.02 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
tar@4.4.13
7.5.21
oscarsotosanchez/weatherservice:v1.0911ec961d10b
tar@4.4.13
7.5.21

Open the chart page →

27,550
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
epam/ai-dial-admin-frontend:0.20.021d91ad74755
tar@7.5.16
7.5.21

Open the chart page →

4,046
difydify1.0.02 of 4See more

dify dify 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.009b7e8705673
tar@6.2.0
7.5.21
langgenius/dify-web:1.0.0d64914ff0d6d
tar@6.2.1
7.5.21

Open the chart page →

19,224
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
tar@6.2.1
7.5.21

Open the chart page →

4,551
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
node-gyp@13.0.0-r0
npm@11.17.0-r0
tar@7.5.11
13.0.1-r1
12.0.1-r2
7.5.21

Open the chart page →

7,459
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
tar@6.2.0
7.5.21

Open the chart page →

4,217
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
tar@6.2.1
7.5.21

Open the chart page →

2,862
mergeabledoubanVerified publisher0.2.21 of 1See more

mergeable douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/leoquote/mergeable:latest451706815103
tar@4.4.13
7.5.21

Open the chart page →

4,223
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.02 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
tar@4.4.13
7.5.21
oscarsotosanchez/weatherservice:v1.0911ec961d10b
tar@4.4.13
7.5.21

Open the chart page →

24,656
dumpstoredumpstore0.1.12 of 2See more

dumpstore dumpstore 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-73566.

Open the chart page →

4,251
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
tar@2.2.2
7.5.21

Open the chart page →

11,174
clickhouse-monitoringduyet0.1.21 of 2See more

clickhouse-monitoring duyet 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/duyet/clickhouse-monitoring:latest84edfe8a67a8
tar@7.5.15
7.5.21

Open the chart page →

1,049
dyff-frontenddyff-frontendVerified publisher0.20.11 of 1See more

dyff-frontend dyff-frontend 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
tar@6.2.1
7.5.21

Open the chart page →

973
benchmarking-tooleclipse-aeriosVerified publisher1.0.01 of 1See more

benchmarking-tool eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
tar@7.5.15
7.5.21

Open the chart page →

687
self-orchestratoreclipse-aeriosVerified publisher1.2.01 of 1See more

self-orchestrator eclipse-aerios 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
eclipseaerios/self-orchestrator:1.2.08b123bec5679
tar@6.2.1
7.5.21

Open the chart page →

2,385
dashboardedu1.0.01 of 1See more

dashboard edu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
tar@6.2.1
7.5.21

Open the chart page →

1,344
deploy-elibraryeducative-helm-bookapp0.5.01 of 1See more

deploy-elibrary educative-helm-bookapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
tar@6.1.11
7.5.21

Open the chart page →

5,112
node-redegebackVerified publisher2.0.131 of 1See more

node-red egeback 2.0.13

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
nodered/node-red:5.0.410f40d0a83e7
tar@7.5.15
7.5.21

Open the chart page →

975
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
tar@7.5.11
7.5.21

Open the chart page →

30,159
backend-charteks-3-tier-app-chart0.1.01 of 1See more

backend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
arfath29/3-tier-app-backend:latestee0750b18406
tar@4.4.19
7.5.21

Open the chart page →

1,693
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
tar@6.1.0
7.5.21

Open the chart page →

3,744
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
library/node:18-alpine8d6421d663b4
tar@6.2.1
7.5.21

Open the chart page →

2,942
azuriteemberstackVerified publisher1.0.211 of 1See more

azurite emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
tar@7.5.11
7.5.21

Open the chart page →

365
reddarkemmas-chartsVerified publisher0.0.21 of 1See more

reddark emmas-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ghcr.io/0xemma/reddark:main2a115e991894
tar@6.1.14
7.5.21

Open the chart page →

1,998
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
tar@4.4.13
7.5.21
oscarsotosanchez/weatherservice:v1.0911ec961d10b
tar@4.4.13
7.5.21

Open the chart page →

27,291
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
tar@4.4.13
7.5.21
oscarsotosanchez/weatherservice:v1.0911ec961d10b
tar@4.4.13
7.5.21

Open the chart page →

27,256
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
arturisimo/server-urjc:v1.0d8dc4430531e
tar@6.1.11
7.5.21

Open the chart page →

27,096
edp-installepmdedpOfficialVerified publisher3.15.01 of 7See more

edp-install epmdedp 3.15.0

1 of the 7 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
tar@6.2.1
7.5.21

Open the chart page →

2,033
krci-portalepmdedpVerified publisher0.8.01 of 1See more

krci-portal epmdedp 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
tar@6.2.1
7.5.21

Open the chart page →

839
hedgedocernail-hedgedoc5.0.01 of 1See more

hedgedoc ernail-hedgedoc 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
tar@6.2.1
7.5.21

Open the chart page →

1,755
assertoorethereum-helm-chartsVerified publisher1.2.01 of 1See more

assertoor ethereum-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ethpandaops/assertoor:latest1efa2fba6711
tar@7.5.15
7.5.21

Open the chart page →

2,891
blobscanethereum-helm-chartsVerified publisher0.1.11 of 1See more

blobscan ethereum-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ethpandaops/blobscan:latest7a9ab6370657
tar@6.1.11
7.5.21

Open the chart page →

1,329
blobscan-indexerethereum-helm-chartsVerified publisher0.1.11 of 1See more

blobscan-indexer ethereum-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
ethpandaops/blobscan-indexer:latestc58eb9ffe446
tar@4.4.19
7.5.21

Open the chart page →

2,114
blockscoutethereum-helm-chartsVerified publisher0.2.31 of 2See more

blockscout ethereum-helm-charts 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
blockscout/blockscout:5.1.5c365a8f2dc12
tar@6.1.11
7.5.21

Open the chart page →

1,928
ethstatsethereum-helm-chartsVerified publisher0.1.41 of 1See more

ethstats ethereum-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-73566.

Container imageDigestPackageFixed in
skylenet/ethstats-server:pow-latestd757cc016198
tar@6.1.11
7.5.21

Open the chart page →

1,109

Container images carrying it

959 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
journeyapps/powersync-service:latestbf46f66e5dcc
tar@7.5.15
7.5.21
1
junktext/getting-started:1.0.5a70936c04aed
tar@4.4.19
7.5.21
1
junktext/getting-started:1.0.34d44adf5a4da2
tar@2.2.2
7.5.21
1
jupyterhub/configurable-http-proxy:3.0.0c36cf3cc1c99
tar@2.2.1
7.5.21
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-tar@6.1.13+~cs7.0.5-3
tar@6.1.13
no fix listed
7.5.21
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
tar@4.4.13
7.5.21
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
tar@6.2.1
7.5.21
1
keyoxide/keyoxide:stable96f27a71269d
tar@6.1.11
7.5.21
1
kitware/cdash:v5.3.0d7767d9b9da4
tar@7.5.16
7.5.21
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
tar@6.1.11
7.5.21
1
koumoul/capture:17108d47be3b2
tar@4.4.12
7.5.21
1
koumoul/openapi-viewer:18eeca2e8285b
tar@2.2.1
7.5.21
1
ktitilayo2/nodejswebapp:latest8bac28058688
tar@6.1.15
7.5.21
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
tar@6.1.11
7.5.21
1
kubebb/component-store:latestfd8ecbd73213
tar@6.2.0
7.5.21
1
kubebb/tamp-portal:v5.6.0fadac6d52470
tar@4.4.13
7.5.21
1
kubebb/tdsf-portal:v5.7.0258458311bc9
tar@4.4.13
7.5.21
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
tar@4.4.19
7.5.21
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
tar@6.1.11
7.5.21
1
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
tar@4.4.8
7.5.21
1
kubevious/backend:1.2.22d9ba6eb46b6
tar@6.2.0
7.5.21
1
kubevious/collector:1.2.1f58226f9d84e
tar@6.1.13
7.5.21
1
kubevious/guard:1.2.19bf567704de2
tar@4.4.19
7.5.21
1
kubevious/parser:1.0.151acf1a1f0b47
tar@4.4.19
7.5.21
1
kubevious/parser:1.2.299ae7a5168c2
tar@6.1.15
7.5.21
1
kubevious/workload-operator:1.0.20b0f4c507eb6
tar@4.4.19
7.5.21
1
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
tar@4.4.13
7.5.21
1
kyleslugg/klusterview:latestba8c36dfdfbd
tar@6.1.11
7.5.21
1
kyso/kyso-front:lateste52595c5c16f
tar@6.1.11
7.5.21
1
laly9999/node-app:1dd0e503913e1
tar@6.2.1
7.5.21
1
laly9999/node-app-dockerized:latest75ae77a20c6c
tar@6.2.0
7.5.21
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
tar@7.4.3
7.5.21
1
langgenius/dify-api:1.16.1dcefa5f7c47c
tar@7.4.3
7.5.21
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
tar@7.5.15
7.5.21
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
tar@7.5.15
7.5.21
1
langgenius/dify-sandbox:0.2.124e65e8a351a2
tar@6.2.0
7.5.21
1
langgenius/dify-web:1.16.187dd47e4e28f
tar@7.4.3
7.5.21
1
langgenius/dify-web:0.6.11a2a294743634
tar@6.2.0
7.5.21
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
tar@6.2.1
7.5.21
1
langgenius/dify-web:1.0.0d64914ff0d6d
tar@6.2.1
7.5.21
1
lavandadelpatio/frontend:latest501c3f31e0bc
tar@4.4.8
7.5.21
1
lbenicio/helm-pilot:0.2.54594a2632510
tar@7.5.11
7.5.21
1
lbenicio/stremio-web:latest732f9003de33
tar@7.5.11
7.5.21
1
leeyoongti/first-app:1.0.021d66cb76352
tar@4.4.13
7.5.21
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
tar@6.2.1
7.5.21
1
library/ghost:6.37.01ef2e532ca4d
tar@7.5.11
7.5.21
1
library/ghost:6.25.12654b1e90413
tar@7.5.11
7.5.21
1
library/ghost:6.41.129773d6be407
tar@7.5.13
7.5.21
1
library/ghost:4.37.0767230c0f263
tar@6.1.11
7.5.21
1
library/ghost:6.39.0-alpine77196da4b0df
tar@7.5.15
7.5.21
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.