StackRadar

CVE-2026-85091

High

Advisory

Published 3 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,660
of 17,828 indexed, latest versions
Container images
2,682
deployed by those charts
Fix available
2 of 5
affected packages

CVE-2026-85091 affecting package zlib 1.3.2-1

Carried by container images the latest versions of 2,660 of 17,828 indexed charts deploy, on 2,682 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.8.dfsg-1ubuntu1, 1:1.2.8.dfsg-1ubuntu1.1, 1:1.2.8.dfsg-2ubuntu4, 1:1.2.8.dfsg-2ubuntu4.1+23 more1:1.3.dfsg+really1.3.1-1+e22,633
zlibapk1.3-r2, 1.3.1-r4, 1.3.1-r5, 1.3.1-r6+6 more1.3.2.1_rc20260601-r048
rsyncdeb3.1.1-3ubuntu1.1, 3.1.1-3ubuntu1.2, 3.1.1-3ubuntu1.3, 3.1.2-2.1ubuntu1+9 moreno fix listed31
klibcdeb2.0.3-0ubuntu1, 2.0.3-0ubuntu1.14.04.3, 2.0.4-9ubuntu2, 2.0.13-4ubuntu0.2no fix listed9
zlibrpm1.3.1-1.azl3no fix listed1
OSV records
CGA-64hx-6x96-r8f7CGA-6ph6-75jp-484pDEBIAN-CVE-2026-85091UBUNTU-CVE-2026-85091AZL-99090ECHO-2e36-531c-37dd
Also known as
CGA-7955-fhww-9pv3, CGA-m46g-37hm-gpgh

Charts affected

2,660 by stars
ChartLatestAffected imagesRadar Score
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,589
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,336
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,965
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,709
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
zlib@1:1.2.11.dfsg-0ubuntu2.2
no fix listed

Open the chart page →

2,482
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,701
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

489
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,589
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed

Open the chart page →

9,340
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed

Open the chart page →

8,105

Container images carrying it

2,682 by charts deploying them

A fixed version is listed for 2 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
valkey/valkey:9.1.1:9.1.1-trixie64e361b630ec
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
5
vaultwarden/server:1.37.2:latest094b5689ed81
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
5
artifacthub/postgres:latest4fd34fa635cc
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
4
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
zlib@1:1.2.13.dfsg-1
no fix listed
4
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
zlib@1:1.2.13.dfsg-1
no fix listed
4
bitnamilegacy/postgresql:16233f361c5819
zlib@1:1.2.13.dfsg-1
no fix listed
4
bitnamilegacy/rabbitmq:4.1.2:4.1.2-debian-12-r1fac502149c40
zlib@1:1.2.13.dfsg-1
no fix listed
4
cloudflare/cloudflared:2026.3.06b599ca3e974
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
4
hyperledger/fabric-ca:latesta70b6ba64a08
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
4
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
rsync@3.1.1-3ubuntu1.2
zlib@1:1.2.8.dfsg-2ubuntu4.1
no fix listed
no fix listed
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
rsync@3.1.1-3ubuntu1.2
zlib@1:1.2.8.dfsg-2ubuntu4.1
no fix listed
no fix listed
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
4
library/mongo:5.0-focal5e15a3f014ed
zlib@1:1.2.11.dfsg-2ubuntu1.5
no fix listed
4
library/mongo:4.2.12-bionic628741415fc9
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
4
library/mongo:4.4.66efa05203990
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
4
library/nginx:1.27.1287ff321f9e3
zlib@1:1.2.13.dfsg-1
no fix listed
4
library/postgres:134689940c6838
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
4
library/postgres:1767f41722b7a8
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
4
library/postgres:16f1c3376c26f2
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
4
library/rabbitmq:3.11-managementc3f70098e01d
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
4
library/redis:latest718f745deb7d
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
4
library/redis:7:7.4:7.4.1171da9275c5f3
zlib@1:1.2.13.dfsg-1
no fix listed
4
mastercloudapps/planner:v1.2340a950b311b2
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
4
opea/llm-tgi:1.00c25aab3f106
zlib@1:1.2.13.dfsg-1
no fix listed
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
4
shashkist/flask-contacts-app:latest581de1fd6084
zlib@1:1.2.13.dfsg-1
no fix listed
4
valkey/valkey:9.0.2930b41430fb7
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
4
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
4
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3.1
no fix listed
4
apache/apisix:3.18.0-ubuntu9ee5df1611f9
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
3
apache/superset:6.1.0:latest16b50bbef664
zlib@1:1.2.13.dfsg-1
no fix listed
3
bitnamilegacy/etcd:latest99b408c15272
zlib@1:1.2.13.dfsg-1
no fix listed
3
bitnamilegacy/kubectl:latestcd354d5b2556
zlib@1:1.2.13.dfsg-1
no fix listed
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
zlib@1:1.2.13.dfsg-1
no fix listed
3
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
zlib@1:1.2.13.dfsg-1
no fix listed
3
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
zlib@1:1.2.13.dfsg-1
no fix listed
3
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
zlib@1:1.2.13.dfsg-1
no fix listed
3
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
zlib@1:1.2.13.dfsg-1
no fix listed
3
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
zlib@1:1.2.13.dfsg-1
no fix listed
3
ciscolabs/rtsp-client:latesta7b60ec88285
zlib@1:1.2.11.dfsg-2ubuntu1.3
no fix listed
3
ciscolabs/rtsp-server:latestb59fc10bb821
zlib@1:1.2.11.dfsg-2ubuntu1.3
no fix listed
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed
3
codeurjc/planner:v1.0800cf520c245
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
3
dgraph/dgraph:v21.12.03b55ea83fffe
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
zlib@1:1.2.13.dfsg-1
no fix listed
3
emberstack/kubernetes-reflector:10.0.6551dbd5880929
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
3
envoyproxy/envoy:v1.31.02bf7f042e396
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
3
fluent/fluent-bit:5.1.2:latestd792375ca8e5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
3
gchq/hdfs:3.3.35ec58edbb2db
zlib@1:1.3.dfsg-3.1ubuntu2
no fix listed
3
guacamole/guacamole:1.6.0f344085e618b
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
3

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.