StackRadar

CVE-2026-85091

High

Advisory

Published 3 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,647
of 17,821 indexed, latest versions
Container images
2,673
deployed by those charts
Fix available
2 of 5
affected packages

CVE-2026-85091 affecting package zlib 1.3.2-1

Carried by container images the latest versions of 2,647 of 17,821 indexed charts deploy, on 2,673 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.8.dfsg-1ubuntu1, 1:1.2.8.dfsg-1ubuntu1.1, 1:1.2.8.dfsg-2ubuntu4, 1:1.2.8.dfsg-2ubuntu4.1+22 more1:1.3.dfsg+really1.3.1-1+e22,622
zlibapk1.3-r2, 1.3.1-r4, 1.3.1-r5, 1.3.1-r6+6 more1.3.2.1_rc20260601-r050
rsyncdeb3.1.1-3ubuntu1.1, 3.1.1-3ubuntu1.2, 3.1.1-3ubuntu1.3, 3.1.2-2.1ubuntu1+9 moreno fix listed31
klibcdeb2.0.3-0ubuntu1, 2.0.3-0ubuntu1.14.04.3, 2.0.4-9ubuntu2, 2.0.13-4ubuntu0.2no fix listed9
zlibrpm1.3.1-1.azl3no fix listed1
OSV records
CGA-64hx-6x96-r8f7CGA-6ph6-75jp-484pDEBIAN-CVE-2026-85091UBUNTU-CVE-2026-85091AZL-99090ECHO-2e36-531c-37dd
Also known as
CGA-7955-fhww-9pv3, CGA-m46g-37hm-gpgh

Charts affected

2,647 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,673 by charts deploying them

A fixed version is listed for 2 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
zlib@1:1.2.11.dfsg-2ubuntu9.1
no fix listed
2
polyaxon/polyaxon-agent:2.17.0da877a2647fc
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
polyaxon/polyaxon-cli:2.17.0297ed47ed63a
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
proxysql/proxysql:3.0.110e95d1b7cc32
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
qdrant/qdrant:v1.19.112364fe851b9
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
zlib@1:1.2.13.dfsg-1
no fix listed
2
quickwit/quickwit:v0.8.2363ff56ce456
zlib@1:1.2.13.dfsg-1
no fix listed
2
rajnandan1/kener:3.2.1930407afca731
zlib@1:1.2.13.dfsg-1
no fix listed
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
2
redis/redis-stack-server:7.4.0:7.4.0-v172035434f455
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
2
redis/redis-stack-server:7.2.0-v10e44b2b49d059
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
2
rotationalio/quarterdeck:0.16.00e7ad3a031dc
zlib@1:1.2.13.dfsg-1
no fix listed
2
safeglobal/safe-config-service:latest09a5e495c219
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
safeglobal/safe-transaction-service:latest80db836cc5d5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
sigp/lighthouse:v8.1.344aa773dcf27
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
2
sigp/lighthouse:latest9a62bb870545
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
2
sikalabs/hello-world-server:latest5f49bf889a64
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
zlib@1:1.2.11.dfsg-2ubuntu1.5
no fix listed
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
zlib@1:1.2.13.dfsg-1
no fix listed
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
zlib@1:1.2.11.dfsg-2ubuntu1.5
no fix listed
2
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
zlib@1:1.2.11.dfsg-2ubuntu9
no fix listed
2
taigaio/taiga-back:latest4beed8f62c9f
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
taigaio/taiga-protected:latestfd4568a97a59
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
testinprod/op-erigon:latest0a125bd77a2d
zlib@1:1.2.13.dfsg-1
no fix listed
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
2
uffizzi/controller:latest0344805f267b
zlib@1:1.2.13.dfsg-1
no fix listed
2
valkey/valkey:83fbd2e3e4b6e
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
valkey/valkey:9.0.1546304417fea
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
valkey/valkey:8.1.481db6d39e1bb
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
valkey/valkey:9.1.08e8d64b405ce
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
vaultwarden/server:1.37.31587c45feaa4
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
vdiogov/glpi-conteiner:latest6945f84f0058
zlib@1:1.2.13.dfsg-1
no fix listed
2
wolveix/satisfactory-server:latest:v1.9.10e103700ae6ae
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
2
wurstmeister/zookeeper:latest7a7fd44a7210
klibc@2.0.3-0ubuntu1
zlib@1:1.2.8.dfsg-1ubuntu1
no fix listed
no fix listed
2
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
2
gcr.io/cloud-tagging-10302018/gtm-cloud-image:stable688d35c6c544
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
gcr.io/google_containers/kubernetes-dashboard-init-amd64:v1.0.0fbe12aa24de6
zlib@1:1.2.8.dfsg-2ubuntu4.1
no fix listed
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
2
ghcr.io/astriaorg/conductor:latest3ea8164b0eae
zlib@1:1.2.13.dfsg-1
no fix listed
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
zlib@1:1.3.dfsg-3.1ubuntu2.2
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
2
ghcr.io/chroma-core/chroma:1.5.91e0b73a187a2
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
zlib@1:1.2.11.dfsg-2ubuntu9
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
zlib@1:1.2.13.dfsg-1
no fix listed
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
zlib@1:1.2.13.dfsg-1
no fix listed
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
zlib@1:1.2.13.dfsg-1
no fix listed
2

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.