StackRadar

CVE-2026-85091

High

Advisory

Published 3 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,565
of 17,813 indexed, latest versions
Container images
2,585
deployed by those charts
Fix available
2 of 5
affected packages

CVE-2026-85091 affecting package zlib 1.3.2-1

Carried by container images the latest versions of 2,565 of 17,813 indexed charts deploy, on 2,585 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.8.dfsg-1ubuntu1, 1:1.2.8.dfsg-1ubuntu1.1, 1:1.2.8.dfsg-2ubuntu4, 1:1.2.8.dfsg-2ubuntu4.1+22 more1:1.3.dfsg+really1.3.1-1+e22,506
zlibapk1.3-r2, 1.3.1-r4, 1.3.1-r5, 1.3.1-r6+6 more1.3.2.1_rc20260601-r078
rsyncdeb3.1.1-3ubuntu1.1, 3.1.1-3ubuntu1.2, 3.1.1-3ubuntu1.3, 3.1.2-2.1ubuntu1+8 moreno fix listed30
klibcdeb2.0.3-0ubuntu1, 2.0.3-0ubuntu1.14.04.3no fix listed7
zlibrpm1.3.1-1.azl3no fix listed1
OSV records
CGA-64hx-6x96-r8f7CGA-6ph6-75jp-484pDEBIAN-CVE-2026-85091UBUNTU-CVE-2026-85091AZL-99090ECHO-2e36-531c-37dd
Also known as
CGA-7955-fhww-9pv3, CGA-m46g-37hm-gpgh

Charts affected

2,565 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,585 by charts deploying them

A fixed version is listed for 2 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/paradigmxyz/reth:v1.3.121e5290e8b743
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
ghcr.io/paradigmxyz/reth:v2.2.0505fca5e87d6
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.00b97452674a3
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/parmincloud/haproxy-redis-sentinel:1.0.040a00a6456ae
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
zlib@1:1.2.11.dfsg-0ubuntu2.2
no fix listed
1
ghcr.io/platformrelay/kollect:v0.20.0c95fa31ead03
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/port-labs/port-agent:v0.8.12c92d1e223f5c
zlib@1:1.3.dfsg+really1.3.1-1+e1
1:1.3.dfsg+really1.3.1-1+e2
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/qovery/iam-eks-user-mapper:mainc41e3efc6097
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/quenchworks/images/airflow66d1498b17ca
zlib@1.3.2-r5
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/apisix2b242df1ab22
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/cassandra688f215f101f
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/coolify-appce43126a3842
zlib@1.3.2-r5
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/documentdbbe72db1f2865
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/drupal1969d8357d81
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/excalidraw08a23c56caba
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/floci1c83a712bf07
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/fluent-bit5d4db482f1b6
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/forgejo9fde07ee32a0
zlib@1.3.2-r5
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/harbor-portalc5cf43e186b5
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/httpd8ed83ce04191
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/ingress-nginx0dd302223669
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/jenkinse92dba4e78c5
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/keycloak7e9bd0bbbb31
zlib@1.3.2-r5
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/kongb1f7e7ea8f6c
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/matomoaf1aed4e7bff
zlib@1.3.2-r5
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/neo4jc07746a9527c
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/nextclouda113d014a824
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/nginx19d9321dceb2
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/postgres-documentdbffcc1485b970
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/postgresql601897da3768
zlib@1.3.2-r5
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/postgresql-15797a5233ca46
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/quickwit0235276ec926
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/skywalking92d7131dd02a
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/timescaledb0b9a82dd686b
zlib@1.3.2-r5
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/tomcat2e178bfc5d38
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/wordpress3c2496c062e4
zlib@1.3.2-r5
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/xyopsdd7d8bf3b654
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/zookeeperdf2b3e0adced
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
no fix listed
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.