CVE-2026-85091
HighAdvisory
Published 3 Sept 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.3
- base score, highest
- EPSS
- 0.004
- 38th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,654
- of 17,813 indexed, latest versions
- Container images
- 2,678
- deployed by those charts
- Fix available
- 2 of 5
- affected packages
CVE-2026-85091 affecting package zlib 1.3.2-1
Carried by container images the latest versions of 2,654 of 17,813 indexed charts deploy, on 2,678 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| zlibdeb | 1:1.2.8.dfsg-1ubuntu1, 1:1.2.8.dfsg-1ubuntu1.1, 1:1.2.8.dfsg-2ubuntu4, 1:1.2.8.dfsg-2ubuntu4.1+22 more | 1:1.3.dfsg+really1.3.1-1+e2 | 2,599 |
| zlibapk | 1.3-r2, 1.3.1-r4, 1.3.1-r5, 1.3.1-r6+6 more | 1.3.2.1_rc20260601-r0 | 78 |
| rsyncdeb | 3.1.1-3ubuntu1.1, 3.1.1-3ubuntu1.2, 3.1.1-3ubuntu1.3, 3.1.2-2.1ubuntu1+8 more | no fix listed | 30 |
| klibcdeb | 2.0.3-0ubuntu1, 2.0.3-0ubuntu1.14.04.3, 2.0.13-4ubuntu0.2 | no fix listed | 8 |
| zlibrpm | 1.3.1-1.azl3 | no fix listed | 1 |
- OSV records
- CGA-64hx-6x96-r8f7CGA-6ph6-75jp-484pDEBIAN-CVE-2026-85091UBUNTU-CVE-2026-85091AZL-99090ECHO-2e36-531c-37dd
- Also known as
- CGA-7955-fhww-9pv3, CGA-m46g-37hm-gpgh
Charts affected
2,654 by stars
Container images carrying it
2,678 by charts deploying them
A fixed version is listed for 2 of the 5 affected packages.