StackRadar

CVE-2026-8084

Medium

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
90
of 17,781 indexed, latest versions
Container images
62
deployed by those charts
Fix available
3 of 4
affected packages

OSGeo gdal HDF-EOS Grid File SWapi.c memmove out-of-bounds

Carried by container images the latest versions of 90 of 17,781 indexed charts deploy, on 62 images.

Affected packageAffected versionsFixed inImages
gdaldeb2.4.0+10-0bionic1, 3.0.4+dfsg-1build3, 3.4.1+dfsg-1build4, 3.6.2+dfsg-1+b2+5 moreno fix listed21
gdalpypi2.4.0, 3.0.4, 3.2.2, 3.3.0+9 more3.13.020
gdalbitnami3.9.0, 3.9.2, 3.9.3, 3.10.0+5 more3.13.018
GDALbitnami3.7.0, 3.7.1, 3.7.2, 3.8.1+3 more3.13.011
OSV records
BIT-gdal-2026-8084DEBIAN-CVE-2026-8084PYSEC-2026-2153UBUNTU-CVE-2026-8084

Charts affected

90 by stars
ChartLatestAffected imagesRadar Score
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
gdal@2.4.0
gdal@2.4.0+10-0bionic1
3.13.0
no fix listed

Open the chart page →

22,405
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
gdal@3.8.5
3.13.0

Open the chart page →

6,172
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
gdal@2.4.0
gdal@2.4.0+10-0bionic1
3.13.0
no fix listed

Open the chart page →

24,335
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
gdal@3.11.0
3.13.0

Open the chart page →

4,046
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
gdal@3.10.3+dfsg-1
gdal@3.10.3
no fix listed
3.13.0

Open the chart page →

7,459
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
gdal@3.4.1+dfsg-1build4
no fix listed

Open the chart page →

24,917
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
gdal@3.4.1+dfsg-1build4
no fix listed

Open the chart page →

30,699
doraethereum-helm-chartsVerified publisher1.0.121 of 2See more

dora ethereum-helm-charts 1.0.12

1 of the 2 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:15.3.0-debian-11-r7cc301eef7436
GDAL@3.7.0
3.13.0

Open the chart page →

2,991
hatchet-hahatchetOfficialVerified publisher0.18.01 of 8See more

hatchet-ha hatchet 0.18.0

1 of the 8 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
gdal@3.11.3
3.13.0

Open the chart page →

7,344
hatchet-stackhatchetOfficialVerified publisher0.18.01 of 8See more

hatchet-stack hatchet 0.18.0

1 of the 8 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
gdal@3.11.3
3.13.0

Open the chart page →

7,344
dawarichhelmforgeVerified publisher1.0.01 of 4See more

dawarich helmforge 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
postgis/postgis:18-3.67e00e8c3539f
gdal@3.13.2+dfsg-1.pgdg13+1
no fix listed

Open the chart page →

4,742
openaevhelm-openbasVerified publisher2.0.51 of 7See more

openaev helm-openbas 2.0.5

1 of the 7 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
gdal@3.11.3
3.13.0

Open the chart page →

7,437
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
gdal@3.11.3
3.13.0

Open the chart page →

25,017
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
gdal@3.4.1+dfsg-1build4
no fix listed

Open the chart page →

14,290
ilum-hive-metastoreilumVerified publisher1.2.01 of 2See more

ilum-hive-metastore ilum 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
gdal@3.10.0
3.13.0

Open the chart page →

3,571
ilum-marquezilumVerified publisher6.7.01 of 3See more

ilum-marquez ilum 6.7.0

1 of the 3 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
gdal@3.10.0
3.13.0

Open the chart page →

6,254
plausible-analyticsimioVerified publisher0.4.21 of 5See more

plausible-analytics imio 0.4.2

1 of the 5 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
gdal@3.11.3
3.13.0

Open the chart page →

10,418
daveit-at-mOfficialVerified publisher0.2.152 of 11See more

dave it-at-m 0.2.15

2 of the 11 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
gdal@3.11.3
3.13.0
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
gdal@3.11.3
3.13.0

Open the chart page →

15,089
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
gdal@3.8.4
gdal@3.8.4+dfsg-3ubuntu3
3.13.0
no fix listed

Open the chart page →

45,239
librephotosk8sonlabVerified publisher1.1.61 of 7See more

librephotos k8sonlab 1.1.6

1 of the 7 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
gdal@3.11.3
3.13.0

Open the chart page →

14,801
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r5cf63048c9209
gdal@3.10.0
3.13.0

Open the chart page →

12,062
visual-regression-trackerkokuwa5.1.01 of 4See more

visual-regression-tracker kokuwa 5.1.0

1 of the 4 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r15fdc6979dbc53
gdal@3.9.0
3.13.0

Open the chart page →

9,098
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.03ba6e6f11388
gdal@3.10.0
3.13.0

Open the chart page →

15,369
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
gdal@3.0.4+dfsg-1build3
no fix listed

Open the chart page →

22,658
hiveopstty0.1.81 of 4See more

hive opstty 0.1.8

1 of the 4 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
gdal@3.10.0
3.13.0

Open the chart page →

4,523
planectlplanectlVerified publisher0.7.01 of 10See more

planectl planectl 0.7.0

1 of the 10 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
gdal@3.11.3
3.13.0

Open the chart page →

25,934
polyaxonpolyaxon2.16.41 of 5See more

polyaxon polyaxon 2.16.4

1 of the 5 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1102e2f47a405e
gdal@3.9.2
3.13.0

Open the chart page →

13,741
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
gdal@3.11.1
3.13.0

Open the chart page →

15,591
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
gdal@3.10.0
3.13.0

Open the chart page →

7,413
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
gdal@3.12.2+dfsg-1build2
no fix listed

Open the chart page →

10,348
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
gdal@3.6.2+dfsg-1+b2
gdal@3.6.2
no fix listed
3.13.0

Open the chart page →

11,636
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
gdal@3.8.4+dfsg-3ubuntu3
no fix listed

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
gdal@3.8.4+dfsg-3ubuntu3
no fix listed

Open the chart page →

12,460
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
gdal@3.11.3
3.13.0

Open the chart page →

5,535
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
gdal@3.8.4
gdal@3.8.4+dfsg-3ubuntu3
3.13.0
no fix listed

Open the chart page →

45,239
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
gdal@3.4.1+dfsg-1build4
no fix listed

Open the chart page →

13,459
giteawenerme12.7.01 of 4See more

gitea wenerme 12.7.0

1 of the 4 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
gdal@3.11.3
3.13.0

Open the chart page →

8,811
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
gdal@3.11.3
3.13.0

Open the chart page →

7,624
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
gdal@3.10.0
3.13.0

Open the chart page →

11,577
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-8084.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
gdal@3.8.4
gdal@3.8.4+dfsg-1~jammy0
3.13.0
no fix listed

Open the chart page →

7,849

Container images carrying it

62 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
gdal@3.11.3
3.13.0
11
bitnamilegacy/postgresql:17.5.0:latest42a8200d3597
gdal@3.11.3
3.13.0
5
bitnamilegacy/postgresql:16233f361c5819
gdal@3.10.0
3.13.0
4
bitnamilegacy/postgresql:15.4.0-debian-11-r455dba7e6a514d
GDAL@3.7.2
3.13.0
4
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
gdal@3.11.3
3.13.0
4
bitnamilegacy/postgresql:15.3.0-debian-11-r7cc301eef7436
GDAL@3.7.0
3.13.0
3
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
gdal@3.10.0
3.13.0
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
gdal@3.10.0
3.13.0
3
apache/tika:2.9.2.1-fullae0b86d3c4d0
gdal@3.8.4
gdal@3.8.4+dfsg-3ubuntu3
3.13.0
no fix listed
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
gdal@3.9.2
3.13.0
2
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
gdal@3.11.3
3.13.0
2
kurento/kurento-media-server:latest03c0d34d0828
gdal@3.8.4+dfsg-3ubuntu3
no fix listed
2
opendatacube/ows:latest668cbb41473c
gdal@3.10.0
3.13.0
2
apache/tika:latest-full80072bb73dd3
gdal@3.12.2
gdal@3.12.2+dfsg-1build2
3.13.0
no fix listed
1
apache/tika:3.2.2.0-fullffab324253ed
gdal@3.10.2
3.13.0
1
bitnamilegacy/postgresql:16.4.0-debian-12-r1102e2f47a405e
gdal@3.9.2
3.13.0
1
bitnamilegacy/postgresql:16.1.0-debian-11-r2504f3b0dfdb15
GDAL@3.8.3
3.13.0
1
bitnamilegacy/postgresql:16.1.0-debian-11-r1529e3dd0e7e7a
GDAL@3.8.1
3.13.0
1
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
GDAL@3.9.0
3.13.0
1
bitnamilegacy/postgresql:16.4.03ba6e6f11388
gdal@3.10.0
3.13.0
1
bitnamilegacy/postgresql:15.3.0-debian-11-r775f4cf61668e5
GDAL@3.7.1
3.13.0
1
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
gdal@3.11.1
3.13.0
1
bitnamilegacy/postgresql:15.5.06887635cc793
GDAL@3.8.3
3.13.0
1
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
gdal@3.11.0
3.13.0
1
bitnamilegacy/postgresql:16.2.0-debian-12-r890fda44bfa42
GDAL@3.8.4
3.13.0
1
bitnamilegacy/postgresql:16.0.0-debian-11-r3b8a21df9b747
GDAL@3.7.2
3.13.0
1
bitnamilegacy/postgresql:16.3.0-debian-12-r14cc55da2fa366
GDAL@3.9.0
3.13.0
1
bitnamilegacy/postgresql:17.2.0-debian-12-r5cf63048c9209
gdal@3.10.0
3.13.0
1
bitnamilegacy/postgresql:17.0.0-debian-12-r9d885ac277163
gdal@3.9.3
3.13.0
1
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
gdal@3.10.0
3.13.0
1
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
GDAL@3.8.4
3.13.0
1
bitnamilegacy/postgresql:17.4.0-debian-12-r11fb3806e823c2
gdal@3.10.2
3.13.0
1
bitnamilegacy/postgresql:16.3.0-debian-12-r15fdc6979dbc53
gdal@3.9.0
3.13.0
1
camptocamp/mapserver:latestbf2e8e118c9b
gdal@3.12.1
3.13.0
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
gdal@3.0.4
3.13.0
1
kobotoolbox/kobocat:2.022.24ab15679454415
gdal@3.2.2
3.13.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
gdal@3.2.2
3.13.0
1
mediagis/nominatim:5.3.27923a8e67197
gdal@3.8.4+dfsg-3ubuntu3
no fix listed
1
mediagis/nominatim:3.7c15e941485ef
gdal@3.0.4+dfsg-1build3
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
gdal@3.4.1+dfsg-1build4
no fix listed
1
opendatacube/explorer:latest120457ffcd69
gdal@3.10.3
3.13.0
1
opendatacube/pipelines:wofs-1.225d810e8504b8
gdal@2.4.0
gdal@2.4.0+10-0bionic1
3.13.0
no fix listed
1
opendatacube/restcube:latest91870111837c
gdal@2.4.0
gdal@2.4.0+10-0bionic1
3.13.0
no fix listed
1
opendatacube/wms:latest1b90cdf68831
gdal@2.4.0
gdal@2.4.0+10-0bionic1
3.13.0
no fix listed
1
opendatacube/wps:latest80df355a660b
gdal@3.8.5
3.13.0
1
openelevation/open-elevation:latest82fb21612e86
gdal@3.3.0
3.13.0
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
gdal@3.2.2
3.13.0
1
photoprism/photoprism:260601650c6ad5a651
gdal@3.12.2+dfsg-1build2
no fix listed
1
photoprism/photoprism:260728958642220223
gdal@3.12.2+dfsg-1build2
no fix listed
1
postgis/postgis:18-3.67e00e8c3539f
gdal@3.13.2+dfsg-1.pgdg13+1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.