StackRadar

CVE-2026-85091

High

Advisory

Published 3 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,605
of 17,792 indexed, latest versions
Container images
2,608
deployed by those charts
Fix available
2 of 5
affected packages

CVE-2026-85091 affecting package zlib 1.3.2-1

Carried by container images the latest versions of 2,605 of 17,792 indexed charts deploy, on 2,608 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.8.dfsg-1ubuntu1, 1:1.2.8.dfsg-1ubuntu1.1, 1:1.2.8.dfsg-2ubuntu4, 1:1.2.8.dfsg-2ubuntu4.1+22 more1:1.3.dfsg+really1.3.1-1+e22,513
zlibapk1.3-r2, 1.3.1-r4, 1.3.1-r5, 1.3.1-r6+6 more1.3.2.1_rc20260601-r094
rsyncdeb3.1.1-3ubuntu1.1, 3.1.1-3ubuntu1.2, 3.1.1-3ubuntu1.3, 3.1.2-2.1ubuntu1+8 moreno fix listed29
klibcdeb2.0.3-0ubuntu1, 2.0.3-0ubuntu1.14.04.3no fix listed7
zlibrpm1.3.1-1.azl3no fix listed1
OSV records
CGA-64hx-6x96-r8f7CGA-6ph6-75jp-484pDEBIAN-CVE-2026-85091UBUNTU-CVE-2026-85091AZL-99090ECHO-2e36-531c-37dd
Also known as
CGA-7955-fhww-9pv3, CGA-m46g-37hm-gpgh
Trending
Rank 30 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

2,605 by stars
ChartLatestAffected imagesRadar Score
changedetection-iozekker6Verified publisher1.99.01 of 1See more

changedetection-io zekker6 1.99.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.47bb6963b730d
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,630
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

485
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,861
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed

Open the chart page →

9,272
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed

Open the chart page →

7,936

Container images carrying it

2,608 by charts deploying them

A fixed version is listed for 2 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
arthurjguerra18/revwallet:v0.7.12f540af20b307
zlib@1:1.2.13.dfsg-1
no fix listed
1
artifacthub/tracker:v1.23.05368d21a6e5c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
zlib@1:1.2.13.dfsg-1
no fix listed
1
arunvelsriram/utils:latest655ad18fd8d6
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
zlib@1:1.2.11.dfsg-2ubuntu1.5
no fix listed
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
zlib@1:1.2.11.dfsg-2ubuntu1.3
no fix listed
1
assistiot/identity-manager_db:latest0d3e6d35f168
zlib@1:1.2.13.dfsg-1
no fix listed
1
assistiot/location_processing:lateste9bae124095f
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
assistiot/open_api_backend:1.1.230812ba93555
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
zlib@1:1.2.11.dfsg-2ubuntu1.3
no fix listed
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
zlib@1:1.2.13.dfsg-1
no fix listed
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
zlib@1:1.2.13.dfsg-1
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
zlib@1:1.2.13.dfsg-1
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
zlib@1:1.2.11.dfsg-2ubuntu1.5
no fix listed
1
athou/commafeed:6.2.0-postgresql5e388351df1a
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
atlassian/bamboo:12.1.114af4bb6c8d46
zlib@1:1.3.dfsg-3.1ubuntu2.2
no fix listed
1
atlassian/bamboo-agent-base:12.1.1151c2d7274eef
zlib@1:1.3.dfsg-3.1ubuntu2.2
no fix listed
1
atlassian/bitbucket:10.2.705933f2b1cfd
zlib@1:1.3.dfsg-3.1ubuntu2.2
no fix listed
1
atlassian/confluence-server:7.10.03b9222ab32ef
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
atlassian/crowd:7.2.3c81cc7d6bc9e
zlib@1:1.3.dfsg-3.1ubuntu2.2
no fix listed
1
atlassian/crowd:5.2.2ebf761c7d437
zlib@1:1.3.dfsg-3.1ubuntu2.2
no fix listed
1
atlassian/jira-software:8.14.037bc46cbec1a
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
atlassian/jira-software:9.7.264a75aa4ec4e
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
atlassian/jira-software:11.3.11e5548cd4eea8
zlib@1:1.3.dfsg-3.1ubuntu2.2
no fix listed
1
avaprotocol/ap-avs:1.2.0c430ea5c37d6
zlib@1:1.2.13.dfsg-1
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
zlib@1:1.2.13.dfsg-1
no fix listed
1
avzini/web-app:latestf40b30210ed0
zlib@1:1.2.13.dfsg-1
no fix listed
1
baserow/backend:2.3.37c00549b3a6f
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
baserow/backend:1.31.1e0b3c8130b91
zlib@1:1.2.13.dfsg-1
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
zlib@1:1.2.13.dfsg-1
no fix listed
1
baserow/web-frontend:2.3.3566d24c7d9f5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed
1
beanbag/reviewboard:latest6b840f546e1c
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
zlib@1:1.2.13.dfsg-1
no fix listed
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
zlib@1:1.2.11.dfsg-2ubuntu1.5
no fix listed
1
bicarus/mx-notifier:1.1.8bed688d16762
zlib@1:1.2.11.dfsg-2ubuntu1.3
no fix listed
1
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
zlib@1:1.2.13.dfsg-1
no fix listed
1
bitnamilegacy/clickhouse:24.12.3-debian-12-r13cf6544f6c6c
zlib@1:1.2.13.dfsg-1
no fix listed
1
bitnamilegacy/clickhouse:24.12.4c7e70bf1d3fb
zlib@1:1.2.13.dfsg-1
no fix listed
1
bitnamilegacy/clickhouse:24.6.2-debian-12-r3dcc172c6c55f
zlib@1:1.2.13.dfsg-1
no fix listed
1
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
zlib@1:1.2.13.dfsg-1
no fix listed
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
zlib@1:1.2.13.dfsg-1
no fix listed
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
zlib@1:1.2.13.dfsg-1
no fix listed
1
bitnamilegacy/git:latest4b08d0c5af8d
zlib@1:1.2.13.dfsg-1
no fix listed
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
zlib@1:1.2.13.dfsg-1
no fix listed
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
zlib@1:1.2.13.dfsg-1
no fix listed
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
zlib@1:1.2.13.dfsg-1
no fix listed
1
bitnamilegacy/kubectl:1.301249fc292e84
zlib@1:1.2.13.dfsg-1
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.