StackRadar

CVE-2026-85091

High

Advisory

Published 3 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,654
of 17,813 indexed, latest versions
Container images
2,678
deployed by those charts
Fix available
2 of 5
affected packages

CVE-2026-85091 affecting package zlib 1.3.2-1

Carried by container images the latest versions of 2,654 of 17,813 indexed charts deploy, on 2,678 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.8.dfsg-1ubuntu1, 1:1.2.8.dfsg-1ubuntu1.1, 1:1.2.8.dfsg-2ubuntu4, 1:1.2.8.dfsg-2ubuntu4.1+22 more1:1.3.dfsg+really1.3.1-1+e22,599
zlibapk1.3-r2, 1.3.1-r4, 1.3.1-r5, 1.3.1-r6+6 more1.3.2.1_rc20260601-r078
rsyncdeb3.1.1-3ubuntu1.1, 3.1.1-3ubuntu1.2, 3.1.1-3ubuntu1.3, 3.1.2-2.1ubuntu1+8 moreno fix listed30
klibcdeb2.0.3-0ubuntu1, 2.0.3-0ubuntu1.14.04.3, 2.0.13-4ubuntu0.2no fix listed8
zlibrpm1.3.1-1.azl3no fix listed1
OSV records
CGA-64hx-6x96-r8f7CGA-6ph6-75jp-484pDEBIAN-CVE-2026-85091UBUNTU-CVE-2026-85091AZL-99090ECHO-2e36-531c-37dd
Also known as
CGA-7955-fhww-9pv3, CGA-m46g-37hm-gpgh

Charts affected

2,654 by stars
ChartLatestAffected imagesRadar Score
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

493
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,956
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed

Open the chart page →

9,296
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed

Open the chart page →

7,966

Container images carrying it

2,678 by charts deploying them

A fixed version is listed for 2 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/quenchworks/images/harbor-portalc5cf43e186b5
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/httpd8ed83ce04191
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/ingress-nginx0dd302223669
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/jenkinse92dba4e78c5
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/keycloak7e9bd0bbbb31
zlib@1.3.2-r5
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/kongb1f7e7ea8f6c
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/matomoaf1aed4e7bff
zlib@1.3.2-r5
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/neo4jc07746a9527c
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/nextclouda113d014a824
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/nginx19d9321dceb2
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/postgres-documentdbffcc1485b970
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/postgresql601897da3768
zlib@1.3.2-r5
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/postgresql-15797a5233ca46
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/quickwit0235276ec926
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/skywalking92d7131dd02a
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/timescaledb0b9a82dd686b
zlib@1.3.2-r5
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/tomcat2e178bfc5d38
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/wordpress3c2496c062e4
zlib@1.3.2-r5
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/xyopsdd7d8bf3b654
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/quenchworks/images/zookeeperdf2b3e0adced
zlib@1.3.2-r4
1.3.2.1_rc20260601-r0
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
no fix listed
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/reitermarkus/7d2d:main39953b387b61
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/retyc/retyc-k8s-csi:v0.2.01521d4baeb85
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/rss-bridge/rss-bridge:latest606896116558
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/salaboy/fmtok8s-email-service:v0.2.0-nativeb52d5dbac2ca
zlib@1:1.2.11.dfsg-0ubuntu2.1
no fix listed
1
ghcr.io/salaboy/fmtok8s-email-service:v0.1.0-nativecf28472bc460
zlib@1:1.2.11.dfsg-0ubuntu2.1
no fix listed
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/schaka/janitorr:native-stable7cfe1e0c41da
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest917e53402d51
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
zlib@1.3.2-r3
1.3.2.1_rc20260601-r0
1
ghcr.io/securo-finance/securo-backend:0.16.0f452147e07f1
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/sergelogvinov/fluentd:1.19.33273d13f1e75
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
ghcr.io/sergelogvinov/pgbouncer:16.1518f1121ba0a4
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
zlib@1:1.2.13.dfsg-1
no fix listed
1
ghcr.io/sergelogvinov/proxmox-csi-node:v0.20.0e0151137a1c5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.