StackRadar

CVE-2026-85091

High

Advisory

Published 3 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,633
of 17,821 indexed, latest versions
Container images
2,641
deployed by those charts
Fix available
2 of 5
affected packages

CVE-2026-85091 affecting package zlib 1.3.2-1

Carried by container images the latest versions of 2,633 of 17,821 indexed charts deploy, on 2,641 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.8.dfsg-1ubuntu1, 1:1.2.8.dfsg-1ubuntu1.1, 1:1.2.8.dfsg-2ubuntu4, 1:1.2.8.dfsg-2ubuntu4.1+22 more1:1.3.dfsg+really1.3.1-1+e22,591
zlibapk1.3-r2, 1.3.1-r4, 1.3.1-r5, 1.3.1-r6+6 more1.3.2.1_rc20260601-r049
rsyncdeb3.1.1-3ubuntu1.1, 3.1.1-3ubuntu1.2, 3.1.1-3ubuntu1.3, 3.1.2-2.1ubuntu1+8 moreno fix listed30
klibcdeb2.0.3-0ubuntu1, 2.0.3-0ubuntu1.14.04.3, 2.0.13-4ubuntu0.2no fix listed8
zlibrpm1.3.1-1.azl3no fix listed1
OSV records
CGA-64hx-6x96-r8f7CGA-6ph6-75jp-484pDEBIAN-CVE-2026-85091UBUNTU-CVE-2026-85091AZL-99090ECHO-2e36-531c-37dd
Also known as
CGA-7955-fhww-9pv3, CGA-m46g-37hm-gpgh

Charts affected

2,633 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,641 by charts deploying them

A fixed version is listed for 2 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
clickhouse/clickhouse-server:24.12.6a65ca89ddbe8
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
clickhouse/clickhouse-server:latesta73b5c0fb6f8
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
clickhouse/clickhouse-server:25.3.14.14b627d7a9bc0e
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
clickhouse/clickhouse-server:26.8.3d73903d1b61d
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
clickhouse/clickhouse-server:26.8.2:latestfa394da808cc
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
cloudflare/cloudflared:2026.9.0ff69a2225ad7
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
cloudtooling/moodle:5.2.3f4f04e0fc401
zlib@1:1.2.13.dfsg-1
no fix listed
1
cloudtooling/wordpress:7.1.1db89d95f1d14
zlib@1:1.2.13.dfsg-1
no fix listed
1
cloudve/janis-terminal:latestaf56e77ca587
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
1
cloudve/ttyd:latestd79c1c5881c0
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
zlib@1:1.2.13.dfsg-1
no fix listed
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
zlib@1:1.2.13.dfsg-1
no fix listed
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
zlib@1:1.2.13.dfsg-1
no fix listed
1
cm2network/squad:latest8cba47f53df5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
codedesignplus/ms-emails-grpc:lateste336012bc781
zlib@1:1.2.13.dfsg-1
no fix listed
1
codedesignplus/ms-emails-rest:latestac84661c605e
zlib@1:1.2.13.dfsg-1
no fix listed
1
codedesignplus/ms-licenses-grpc:latest360144457f4d
zlib@1:1.2.13.dfsg-1
no fix listed
1
codedesignplus/ms-modules-grpc:latest3f6aaa32d526
zlib@1:1.2.13.dfsg-1
no fix listed
1
collabora/code:24.04.13.2.101dc4ab83977
zlib@1:1.2.13.dfsg-1
no fix listed
1
collabora/code:23.05.10.1.105299b452f7f
zlib@1:1.2.13.dfsg-1
no fix listed
1
concourse/concourse:8.3.040a143ce5873
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
conductoross/conductor:3.31.09fba127693e6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
consensys/teku:latest3a4f5761ae1c
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
consensys/teku:25.4.1bf6ecd2ea716
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
consensys/web3signer:latestf146a51a1ba3
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
no fix listed
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
zlib@1:1.2.13.dfsg-1
no fix listed
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
zlib@1:1.2.13.dfsg-1
no fix listed
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
cortezaproject/corteza:2024.9.08eb7a26605c9
zlib@1:1.2.11.dfsg-2ubuntu1.5
no fix listed
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
zlib@1:1.2.13.dfsg-1
no fix listed
1
coturn/coturn:4.10.0-r1f4c2af06c3c5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed
1
cradlepoint/pgbouncer:1.0.18f5720b0cd03
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
1
cribl/cribl:3.0.2762747cb6796
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
zlib@1:1.2.8.dfsg-2ubuntu4.3
no fix listed
1
cspconsole/config-provider:1.0.365524a26a6c23
zlib@1:1.2.13.dfsg-1
no fix listed
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
zlib@1:1.2.13.dfsg-1
no fix listed
1
cspconsole/report-collector:1.0.15839750248193b
zlib@1:1.2.13.dfsg-1
no fix listed
1
cspconsole/report-processor:1.0.279a2d8840bfdf
zlib@1:1.2.13.dfsg-1
no fix listed
1
cubejs/cubestore:v1.5.334ac523a9bab
zlib@1:1.2.13.dfsg-1
no fix listed
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
zlib@1:1.2.13.dfsg-1
no fix listed
1
cyverse/irods-csi-driver:v0.12.0aa69d105b292
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
cznic/knot-resolver:v6.4.24ad2e1894b78
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
zlib@1:1.2.13.dfsg-1
no fix listed
1
daedalusproject/base_kubectl:latest6f72b5119eda
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed
1
dagster/dagster-celery-k8s:1.13.230505973033e1
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.