StackRadar

CVE-2026-85091

High

Advisory

Published 3 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,660
of 17,828 indexed, latest versions
Container images
2,682
deployed by those charts
Fix available
2 of 5
affected packages

CVE-2026-85091 affecting package zlib 1.3.2-1

Carried by container images the latest versions of 2,660 of 17,828 indexed charts deploy, on 2,682 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.8.dfsg-1ubuntu1, 1:1.2.8.dfsg-1ubuntu1.1, 1:1.2.8.dfsg-2ubuntu4, 1:1.2.8.dfsg-2ubuntu4.1+23 more1:1.3.dfsg+really1.3.1-1+e22,633
zlibapk1.3-r2, 1.3.1-r4, 1.3.1-r5, 1.3.1-r6+6 more1.3.2.1_rc20260601-r048
rsyncdeb3.1.1-3ubuntu1.1, 3.1.1-3ubuntu1.2, 3.1.1-3ubuntu1.3, 3.1.2-2.1ubuntu1+9 moreno fix listed31
klibcdeb2.0.3-0ubuntu1, 2.0.3-0ubuntu1.14.04.3, 2.0.4-9ubuntu2, 2.0.13-4ubuntu0.2no fix listed9
zlibrpm1.3.1-1.azl3no fix listed1
OSV records
CGA-64hx-6x96-r8f7CGA-6ph6-75jp-484pDEBIAN-CVE-2026-85091UBUNTU-CVE-2026-85091AZL-99090ECHO-2e36-531c-37dd
Also known as
CGA-7955-fhww-9pv3, CGA-m46g-37hm-gpgh

Charts affected

2,660 by stars
ChartLatestAffected imagesRadar Score
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,589
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,336
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,965
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,709
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
zlib@1:1.2.11.dfsg-0ubuntu2.2
no fix listed

Open the chart page →

2,482
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,701
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

489
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed

Open the chart page →

1,589
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed

Open the chart page →

9,340
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-85091.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed

Open the chart page →

8,105

Container images carrying it

2,682 by charts deploying them

A fixed version is listed for 2 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
dellcloud/pages:monitor6ba7b22caacd
zlib@1:1.2.11.dfsg-2ubuntu1.2
no fix listed
80
flyway/flyway:6.4.422d97ceb0c47
zlib@1:1.2.11.dfsg-0ubuntu2
no fix listed
80
library/nginx:1.31:latest:trixieabe47724e466
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
63
library/nginx:1.31:1.31.5:latest:trixie05b8cb60c354
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
42
library/postgres:18:18.6:18.6-trixie:latest4ef4dbc939d6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
39
library/postgres:18:18.6:18.6-trixie:latest86c951e05bf5
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
29
library/redis:8.10.1:latest298e5b3bc566
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
24
jenkins/jenkins:2.568.3-jdk21:2.568.3-lts-jdk21:ltsc1e4c349365f
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
17
ghcr.io/quenchworks/images/postgresql919b69c5c86b
zlib@1.3.2-r5
1.3.2.1_rc20260601-r0
16
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
zlib@1:1.2.11.dfsg-0ubuntu2.2
no fix listed
13
library/nginx:stabled5792f71a949
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
13
library/redis:8.10.1:latest8a1efc5f4795
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
12
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
zlib@1:1.2.13.dfsg-1
no fix listed
11
oomk8s/readiness-check:2.0.2875814cc853d
rsync@3.1.1-3ubuntu1.2
zlib@1:1.2.8.dfsg-2ubuntu4.1
no fix listed
no fix listed
11
library/mongo:5.0.6-focal8e70544b6c76
zlib@1:1.2.11.dfsg-2ubuntu1.3
no fix listed
10
library/nginx:stable0aa2d81d65bc
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
10
library/rabbitmq:3.9-management8a279e9396a8
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
10
library/kong:3.6a42d2b4503e7
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
8
library/mongo:8:8.3.8:latest5211c51171f5
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
8
library/postgres:16a3b7f434b2dc
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
8
library/rabbitmq:3.13-management:3-managemente582c0bc7766
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
8
valkey/valkey:9.1.2:latestc123e3715db6
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
8
cloudflare/cloudflared:2026.9.1:latestb269e8abd07a
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
7
library/postgres:17f4c66b820c6f
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
7
bitnamilegacy/postgresql:17.5.0:latest42a8200d3597
zlib@1:1.2.13.dfsg-1
no fix listed
6
bitnamilegacy/rabbitmq:4.1.3:4.1.3-debian-12-r19e635efba431
zlib@1:1.2.13.dfsg-1
no fix listed
6
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
zlib@1:1.2.13.dfsg-1
no fix listed
6
jellyfin/jellyfin:10.11:10.11.11:latestaefb67e6a7ff
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
6
library/kong:3.912972ce1ab63
zlib@1:1.3.dfsg-3.1ubuntu2.2
no fix listed
6
library/mariadb:10:10.117f22313fc130
zlib@1:1.2.11.dfsg-2ubuntu9.2
no fix listed
6
library/mariadb:13.0.2:latestd4fdec0510ad
zlib@1:1.3.dfsg+really1.3.1-1ubuntu3.1
no fix listed
6
library/mariadb:12.3.3:latest:ltsdd9b303aed4f
zlib@1:1.3.dfsg-3.1ubuntu2.1
no fix listed
6
library/postgres:18.4a02db8cac496
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
6
oomk8s/readiness-check:2.0.07daa08b81954
rsync@3.1.1-3ubuntu1.2
zlib@1:1.2.8.dfsg-2ubuntu4.1
no fix listed
no fix listed
6
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
zlib@1:1.2.13.dfsg-1
no fix listed
6
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
zlib@1:1.2.13.dfsg-1
no fix listed
6
quay.io/devtron/postgres:14.91b594392f7cb
zlib@1:1.2.13.dfsg-1
no fix listed
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
zlib@1:1.2.13.dfsg-1
no fix listed
5
flaresolverr/flaresolverr:latest:v3.5.0139dfee1c6f8
zlib@1:1.2.13.dfsg-1
no fix listed
5
library/httpd:2.4:2.4.68:latest454942557d44
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
5
library/mongo:4.44be76f674fc4
zlib@1:1.2.11.dfsg-2ubuntu1.5
no fix listed
5
library/mongo:8:8.3.11:latest5d7043a4ffe0
zlib@1:1.3.dfsg-3.1ubuntu2.2
no fix listed
5
library/phpmyadmin:5.2.3-apache:latest9e915766488a
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
5
library/postgres:122f2a8c2a7d10
zlib@1:1.2.13.dfsg-1
no fix listed
5
library/postgres:14816cf7d06ec3
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
5
library/postgres:15dfbbb0ad8cab
zlib@1:1.3.dfsg+really1.3.1-1+b1
no fix listed
5
library/redis:7.2:7.2-bookworm0637954999d0
zlib@1:1.2.13.dfsg-1
no fix listed
5
library/redis:6:6.2e7b96daa9a18
zlib@1:1.2.13.dfsg-1
no fix listed
5
solsson/kafka:latest41e5d8f6f290
zlib@1:1.2.11.dfsg-2ubuntu1.3
no fix listed
5

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.