StackRadar

CVE-2026-85091

High

Advisory

Published 3 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,651
of 17,805 indexed, latest versions
Container images
2,647
deployed by those charts
Fix available
2 of 5
affected packages

CVE-2026-85091 affecting package zlib 1.3.2-1

Carried by container images the latest versions of 2,651 of 17,805 indexed charts deploy, on 2,647 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.8.dfsg-1ubuntu1, 1:1.2.8.dfsg-1ubuntu1.1, 1:1.2.8.dfsg-2ubuntu4, 1:1.2.8.dfsg-2ubuntu4.1+22 more1:1.3.dfsg+really1.3.1-1+e22,551
zlibapk1.3-r2, 1.3.1-r4, 1.3.1-r5, 1.3.1-r6+6 more1.3.2.1_rc20260601-r095
rsyncdeb3.1.1-3ubuntu1.1, 3.1.1-3ubuntu1.2, 3.1.1-3ubuntu1.3, 3.1.2-2.1ubuntu1+8 moreno fix listed30
klibcdeb2.0.3-0ubuntu1, 2.0.3-0ubuntu1.14.04.3no fix listed7
zlibrpm1.3.1-1.azl3no fix listed1
OSV records
CGA-64hx-6x96-r8f7CGA-6ph6-75jp-484pDEBIAN-CVE-2026-85091UBUNTU-CVE-2026-85091AZL-99090ECHO-2e36-531c-37dd
Also known as
CGA-7955-fhww-9pv3, CGA-m46g-37hm-gpgh

Charts affected

2,651 by stars
ChartLatestAffected imagesRadar Score
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed

Open the chart page →

7,964

Container images carrying it

2,647 by charts deploying them

A fixed version is listed for 2 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
maponyacharles/sceptreai:api-0.1.127b37b092130a
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
maptiler/server:4.8.07e206140057b
zlib@1:1.2.11.dfsg-2ubuntu1.5
no fix listed
1
marcoimme/oidcmock:latestb6035c0721a8
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
mariusm/vingress:0.5.0b3db186c3d72
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
martinhelmich/typo3:12.4c83a4f3fd7ae
zlib@1:1.2.13.dfsg-1
no fix listed
1
mathesar/mathesar:0.12.0091757cb01fe
zlib@1:1.2.13.dfsg-1
no fix listed
1
matrixdotorg/synapse:v1.161.06b95dd129e35
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
zlib@1:1.2.13.dfsg-1
no fix listed
1
matterlabs/external-node:9734bf2-17870579939295dadc06bdf3b
zlib@1:1.2.13.dfsg-1
no fix listed
1
matterlabs/external-node:v24.0.06cbfea4c694a
zlib@1:1.2.13.dfsg-1
no fix listed
1
mautic/mautic:7-apacheeb8cc73d97e1
zlib@1:1.2.13.dfsg-1
no fix listed
1
mawad98/backstage-pyactions:demo99422c56a274
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
mbround18/valheim:3.1.070bd4da591cd
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
mcp/kubernetes:latest5ffbf7f0a8aa
zlib@1:1.2.13.dfsg-1
no fix listed
1
mediagis/nominatim:5.3.27923a8e67197
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
mediagis/nominatim:3.7c15e941485ef
zlib@1:1.2.11.dfsg-2ubuntu1.3
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
memgraph/mcp-memgraph:0.1.13ecdf7faea3f7
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
merlos/zookeeper:3.9.3a38fc7e09ed7
zlib@1:1.2.13.dfsg-1
no fix listed
1
middlewareeng/middleware:0.3.1747d880812f1
zlib@1:1.2.13.dfsg-1
no fix listed
1
milvusdb/etcd:3.5.25-r1fededb2f2d63
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
milvusdb/milvus:v2.2.13a3a55e1c1497
zlib@1:1.2.11.dfsg-2ubuntu1.3
no fix listed
1
mindsdb/mindsdb:latest163011c09299
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
zlib@1:1.2.11.dfsg-2ubuntu1.3
no fix listed
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
zlib@1:1.2.13.dfsg-1
no fix listed
1
miqm/session-scaler:0.1.0c5c211717d9b
zlib@1:1.2.13.dfsg-1
no fix listed
1
mlikiowa/napcat-docker:latest1336a777f9a4
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
mockserver/mockserver:mockserver-8.0.0b8426e0b3c80
zlib@1:1.2.13.dfsg-1
no fix listed
1
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
zlib@1:1.2.13.dfsg-1
no fix listed
1
moreillon/api-proxy:latestd7d4a5463525
zlib@1:1.2.13.dfsg-1
no fix listed
1
moreillon/camera-viewer:lateste418cc694bd5
zlib@1:1.2.13.dfsg-1
no fix listed
1
moreillon/food-manager:lateste8fd856e593d
zlib@1:1.2.13.dfsg-1
no fix listed
1
moreillon/group-manager:latest3caa8f710ee0
zlib@1:1.2.13.dfsg-1
no fix listed
1
moreillon/group-manager-front:latest5f0a38498271
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
moreillon/user-manager-front:v5.1.06597e6b98d21
zlib@1:1.2.13.dfsg-1
no fix listed
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
zlib@1:1.2.13.dfsg-1
no fix listed
1
mshanley80/httpbin2022:latest5b189a70c0fb
zlib@1:1.2.11.dfsg-2ubuntu1.5
no fix listed
1
muhammedgamal/fp23:latest74b4cd69b6fa
zlib@1:1.2.13.dfsg-1
no fix listed
1
muluder/prograncontrollermcord:0.1.843b597a93da7
rsync@3.1.1-3ubuntu1.2
zlib@1:1.2.8.dfsg-2ubuntu4.1
no fix listed
no fix listed
1
murtazashah46/helmfile:latest4d11726cf803
zlib@1:1.2.13.dfsg-1
no fix listed
1
mvance/unbound:1.20.04bf67b567f39
zlib@1:1.2.13.dfsg-1
no fix listed
1
mvance/unbound:1.22.076906da36d18
zlib@1:1.2.13.dfsg-1
no fix listed
1
n3uronhub/n3uron:v1.22.4423a0bdd9cb9
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ncsa/checks:main0b738bbc8d70
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
nelssec/qualys-agent-bootstrapper:v2.1.05e471f0cdeaa
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
netbirdio/management:0.45.10c9994b393ea
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
netbirdio/management:0.60.252682e5f48f9
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
netbirdio/management:0.46.0b0adc4ad4ec6
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
netbirdio/netbird-server:0.78.13086534361a1
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
netbirdio/netbird-server:0.78.2ac6317722f6f
zlib@1:1.3.dfsg-3.1ubuntu2.2
no fix listed
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.