StackRadar

CVE-2026-85091

High

Advisory

Published 3 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,608
of 17,803 indexed, latest versions
Container images
2,612
deployed by those charts
Fix available
2 of 5
affected packages

CVE-2026-85091 affecting package zlib 1.3.2-1

Carried by container images the latest versions of 2,608 of 17,803 indexed charts deploy, on 2,612 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.8.dfsg-1ubuntu1, 1:1.2.8.dfsg-1ubuntu1.1, 1:1.2.8.dfsg-2ubuntu4, 1:1.2.8.dfsg-2ubuntu4.1+22 more1:1.3.dfsg+really1.3.1-1+e22,517
zlibapk1.3-r2, 1.3.1-r4, 1.3.1-r5, 1.3.1-r6+6 more1.3.2.1_rc20260601-r094
rsyncdeb3.1.1-3ubuntu1.1, 3.1.1-3ubuntu1.2, 3.1.1-3ubuntu1.3, 3.1.2-2.1ubuntu1+8 moreno fix listed29
klibcdeb2.0.3-0ubuntu1, 2.0.3-0ubuntu1.14.04.3no fix listed7
zlibrpm1.3.1-1.azl3no fix listed1
OSV records
CGA-64hx-6x96-r8f7CGA-6ph6-75jp-484pDEBIAN-CVE-2026-85091UBUNTU-CVE-2026-85091AZL-99090ECHO-2e36-531c-37dd
Also known as
CGA-7955-fhww-9pv3, CGA-m46g-37hm-gpgh
Trending
Rank 39 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

2,608 by stars
ChartLatestAffected imagesRadar Score
quickwitquickwit0.8.171 of 1See more

quickwit quickwit 0.8.17

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

3,526
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed

Open the chart page →

11,597
zillazillaOfficialVerified publisher2.4.31 of 1See more

zilla zilla 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
ghcr.io/aklivity/zilla:2.4.3e33d59dbb606
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed

Open the chart page →

1,750
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

3,000
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed

Open the chart page →

4,288
yopasscloudhippieVerified publisher9.16.01 of 1See more

yopass cloudhippie 9.16.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
jhaals/yopass:14.9.0934e4f2c016f
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

450
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

3,067
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed

Open the chart page →

32,151
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
zlib@1:1.2.13.dfsg-1
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

33,352
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed

Open the chart page →

3,728
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
zlib@1:1.3.dfsg-3.1ubuntu2
no fix listed

Open the chart page →

5,455
grayloggroundhog2k0.13.101 of 1See more

graylog groundhog2k 0.13.10

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
graylog/graylog:7.1.9598bd41fefd5
zlib@1:1.3.dfsg-3.1ubuntu2.2
no fix listed

Open the chart page →

1,149
nextcloudgroundhog2k0.22.61 of 3See more

nextcloud groundhog2k 0.22.6

1 of the 3 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/nextcloud:34.0.4:34.0.4-apache8418c398d767
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

3,852
ilumilumOfficialVerified publisher6.7.34 of 19See more

ilum ilum 6.7.3

4 of the 19 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
zlib@1:1.2.13.dfsg-1
no fix listed
bitnamilegacy/postgresql:16233f361c5819
zlib@1:1.2.13.dfsg-1
no fix listed
ilum/api:6.7.3624fd09528c8
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ilum/marquez:0.54.06e1d709d41f8
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

23,599
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed

Open the chart page →

3,454
lakekeeperlakekeeperVerified publisher0.12.02 of 2See more

lakekeeper lakekeeper 0.12.0

2 of the 2 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
quay.io/lakekeeper/catalog:v0.13.3db2ba6168eb1
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

2,006
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
zlib@1:1.2.13.dfsg-1
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

7,446
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

5,750
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

4,507
netris-controllernetrisai2.8.24 of 14See more

netris-controller netrisai 2.8.2

4 of the 14 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
netrisai/controller-grpc:4.6.0.00753178bf173c2
zlib@1:1.2.11.dfsg-2ubuntu1.5
no fix listed
netrisai/controller-telescope:4.6.0.00414d82948a8b2
zlib@1:1.2.11.dfsg-2ubuntu1.5
no fix listed
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
zlib@1:1.2.11.dfsg-2ubuntu1.5
no fix listed
netrisai/controller-web-session-generator:0.2.0a030a31289f4
zlib@1:1.2.11.dfsg-2ubuntu1.3
no fix listed

Open the chart page →

30,559
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

2,379
syftopenmined0.9.53 of 6See more

syft openmined 0.9.5

3 of the 6 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
zlib@1:1.2.13.dfsg-1
no fix listed
openmined/syft-backend:0.9.5b72f74a68b32
zlib@1.3.1-r5
1.3.2.1_rc20260601-r0
openmined/syft-frontend:0.9.5d11524a3854a
zlib@1.3.1-r5
1.3.2.1_rc20260601-r0

Open the chart page →

17,465
paperless-ngxpaperless-ngxVerified publisher0.3.223 of 3See more

paperless-ngx paperless-ngx 0.3.22

3 of the 3 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
zlib@1:1.2.13.dfsg-1
no fix listed
valkey/valkey:9.1.2c123e3715db6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

8,644
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
platform9community/api-gateway:latest40a4970de568
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
platform9community/customers-service:latest2089811e5cc6
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
platform9community/vets-service:latestd1165c94dfb3
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
platform9community/visits-service:latest8d11b50368c6
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed

Open the chart page →

41,947
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed

Open the chart page →

14,524
selenium3selenium31.2.41 of 1See more

selenium3 selenium3 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed

Open the chart page →

11,890
tbmq-clustertbmq-helm-chartOfficialVerified publisher2.1.02 of 3See more

tbmq-cluster tbmq-helm-chart 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
thingsboard/tbmq-node:2.4.070661025dba5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

3,613
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
zlib@1:1.2.11.dfsg-2ubuntu1.5
no fix listed

Open the chart page →

7,445
plexutkuozdemirVerified publisher2.1.11 of 1See more

plex utkuozdemir 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
linuxserver/plex:1.25.24a13ced2326c
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed

Open the chart page →

6,402
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed

Open the chart page →

2,338
istio-operatorwiremindVerified publisher1.18.21 of 1See more

istio-operator wiremind 1.18.2

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
istio/operator:1.18.270f9d1fe5fff
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed

Open the chart page →

5,690
zabbix-serveraekondratievVerified publisher1.0.63 of 4See more

zabbix-server aekondratiev 1.0.6

3 of the 4 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed

Open the chart page →

30,872
phpmyadminalekcVerified publisher0.3.11 of 1See more

phpmyadmin alekc 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

2,695
crowdatlassian-data-centerVerified publisher2.0.151 of 2See more

crowd atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
atlassian/crowd:7.2.3c81cc7d6bc9e
zlib@1:1.3.dfsg-3.1ubuntu2.2
no fix listed

Open the chart page →

1,556
wazuh-agentavistoVerified publisher4.12.21 of 1See more

wazuh-agent avisto 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

6,556
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
zlib@1:1.2.11.dfsg-2ubuntu1.5
no fix listed

Open the chart page →

12,217
memcachedcloudpirates-memcachedVerified publisher0.14.91 of 1See more

memcached cloudpirates-memcached 0.14.9

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/memcached:1.6.4575c93cc91e76
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,100
cluster-secretclutersecretVerified publisher0.7.01 of 1See more

cluster-secret clutersecret 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

3,076
convoyconvoyVerified publisher3.7.132 of 3See more

convoy convoy 3.7.13

2 of the 3 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
zlib@1:1.2.13.dfsg-1
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

6,128
cortexcortex3.3.82 of 4See more

cortex cortex 3.3.8

2 of the 4 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/memcached:1.6.4575c93cc91e76
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
library/nginx:1.3105b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

4,014
grayloggraylog2OfficialVerified publisher2.0.01 of 2See more

graylog graylog2 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
graylog/graylog-enterprise:7.1.88a1f641cd7aa
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed

Open the chart page →

1,576
valkeygroundhog2k2.3.41 of 1See more

valkey groundhog2k 2.3.4

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
valkey/valkey:9.1.2475ee65cc75c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

854
hasurahasura-extraVerified publisher3.0.11 of 1See more

hasura hasura-extra 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.34.0-ce0111b0204136
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed

Open the chart page →

4,979
docmosthelmforgeVerified publisher1.2.123 of 4See more

docmost helmforge 1.2.12

3 of the 4 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
docmost/docmost:0.96.0b56947fcfd08
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
library/postgres:18.6-trixie4ef4dbc939d6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
library/redis:8.10.1298e5b3bc566
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

4,206
wordpresshelmforgeVerified publisher3.0.61 of 3See more

wordpress helmforge 3.0.6

1 of the 3 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

4,261
coturnjaconiVerified publisher1.0.51 of 1See more

coturn jaconi 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
coturn/coturn:4.10.0-r1f4c2af06c3c5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

3,105
mongooseimmongoose0.4.111 of 1See more

mongooseim mongoose 0.4.11

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
erlangsolutions/mongooseim:6.6.0cc5bf032931f
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed

Open the chart page →

1,321
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed

Open the chart page →

8,704
nginx-ingressnginx-ingress-chartVerified publisher0.0.0-edge1 of 1See more

nginx-ingress nginx-ingress-chart 0.0.0-edge

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
nginx/nginx-ingress:edge520d439f9a9a
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,318
technitium-dnsserverobeoneVerified publisher1.13.01 of 1See more

technitium-dnsserver obeone 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
technitium/dns-server:15.4.0df7d90ef0f7b
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed

Open the chart page →

1,365

Container images carrying it

2,612 by charts deploying them

A fixed version is listed for 2 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
zlib@1:1.2.13.dfsg-1
no fix listed
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
zlib@1:1.2.13.dfsg-1
no fix listed
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
zlib@1:1.2.11.dfsg-0ubuntu2.2
no fix listed
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
quay.io/groundcover/tools:20260719b705e0cbe171
zlib@1:1.3.dfsg+really1.3.1-1+e1
1:1.3.dfsg+really1.3.1-1+e2
1
quay.io/isindir/sops-secrets-operator:0.21.27bba7083dfa0
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
zlib@1:1.2.13.dfsg-1
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
zlib@1:1.2.13.dfsg-1
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
zlib@1:1.2.13.dfsg-1
no fix listed
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
zlib@1:1.2.13.dfsg-1
no fix listed
1
quay.io/kannika/kannika-api:0.18.0bcf9906d5a3c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
quay.io/lakekeeper/catalog:v0.13.3db2ba6168eb1
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
quay.io/maxiv/pieeat:0.9.3099715479210
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
zlib@1:1.2.13.dfsg-1
no fix listed
1
quay.io/mittwald/kube-mail:latest04f1099241fc
zlib@1:1.2.13.dfsg-1
no fix listed
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
zlib@1:1.2.8.dfsg-2ubuntu4.3
no fix listed
1
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
rsync@3.1.1-3ubuntu1.3
zlib@1:1.2.8.dfsg-2ubuntu4.1
no fix listed
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
quay.io/opstree/fluent-bit:5.0.3391eef5a68ff
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
quay.io/opstree/grafana:12.4.3b61c1ed2f015
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
quay.io/opstree/k8s-sidecar:2.7.126aa9bb3386b
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
quay.io/opstree/k8s-sidecar:2.7.37075d455b219
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
quay.io/opstree/memcached:1.6.38-alpine3.22cabbdfd2c3fe
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
zlib@1.3.1-r51
1.3.2.1_rc20260601-r0
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
zlib@1.3.1-r51
1.3.2.1_rc20260601-r0
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
zlib@1.3.1-r51
1.3.2.1_rc20260601-r0
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
zlib@1.3.1-r51
1.3.2.1_rc20260601-r0
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
no fix listed
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
zlib@1:1.2.13.dfsg-1
no fix listed
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
zlib@1:1.2.13.dfsg-1
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
zlib@1:1.2.13.dfsg-1
no fix listed
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
zlib@1:1.2.11.dfsg-0ubuntu2.1
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
1
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
zlib@1:1.2.13.dfsg-1
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
zlib@1:1.2.13.dfsg-1
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
zlib@1:1.2.13.dfsg-1
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
zlib@1:1.2.13.dfsg-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
zlib@1:1.2.13.dfsg-1
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.