StackRadar

CVE-2026-85396

High

Advisory

Published 3 Sept 2026In the index since 26 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,957 indexed, latest versions
Container images
19
deployed by those charts
Fix available
1 of 1
affected package

rubyzip path traversal vulnerability

Carried by container images the latest versions of 20 of 17,957 indexed charts deploy, on 19 images.

Affected packageAffected versionsFixed inImages
rubyzipgem1.3.0, 2.0.0, 2.3.2, 2.4.1+1 more3.4.019
OSV records
GHSA-47m2-wp7j-p9vc

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
openprojectopenproject-helm-chartsOfficialVerified publisher13.12.01 of 5See more

openproject openproject-helm-charts 13.12.0

1 of the 5 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
openproject/openproject:17.8.0-slim48952034215d
rubyzip@2.4.1
3.4.0

Open the chart page →

21,429
docusealzekker6Verified publisher1.132.01 of 1See more

docuseal zekker6 1.132.0

1 of the 1 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
docuseal/docuseal:3.2.658c76f6d2856
rubyzip@3.2.2
3.4.0

Open the chart page →

149
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
rubyzip@1.3.0
3.4.0

Open the chart page →

11,114
manyfoldself-hosters-by-nightVerified publisher0.7.41 of 1See more

manyfold self-hosters-by-night 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
ghcr.io/manyfold3d/manyfold-solo:0.147.2ed5a792b0e8d
rubyzip@2.4.1
3.4.0

Open the chart page →

521
openprojecthomeenterpriseinc0.5.01 of 1See more

openproject homeenterpriseinc 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
openproject/community:12.0.2734743d11094
rubyzip@2.3.2
3.4.0

Open the chart page →

7,082
redminemt1905027.3.41 of 3See more

redmine mt190502 7.3.4

1 of the 3 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
library/redmine:6.1.204ac44a2595b
rubyzip@2.4.1
3.4.0

Open the chart page →

7,700
redmineredmine-helm-chartVerified publisher0.2.61 of 1See more

redmine redmine-helm-chart 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
rubyzip@2.4.1
3.4.0

Open the chart page →

4,653
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
rubyzip@1.3.0
3.4.0

Open the chart page →

7,789
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
rubyzip@2.4.1
3.4.0

Open the chart page →

5,810
antigenic-docuseal-helm-chartantigenic-docuseal-helm-chartVerified publisher0.2.01 of 1See more

antigenic-docuseal-helm-chart antigenic-docuseal-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
docuseal/docuseal:2.4.17493fd7f6728
rubyzip@3.2.2
3.4.0

Open the chart page →

2,877
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
rubyzip@1.3.0
3.4.0

Open the chart page →

3,416
manyfoldjeffrescVerified publisher1.0.31 of 1See more

manyfold jeffresc 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
rubyzip@2.4.1
3.4.0

Open the chart page →

2,024
deltabadgerk8s-chartsVerified publisher2.0.01 of 1See more

deltabadger k8s-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
rubyzip@2.4.1
3.4.0

Open the chart page →

6,175
gitlabkubesphereVerified publisher4.2.33 of 17See more

gitlab kubesphere 4.2.3

3 of the 17 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
mirrorgitlabcontainers/gitlab-sidekiq-ce:v13.2.294d1431683fa
rubyzip@2.0.0
3.4.0
mirrorgitlabcontainers/gitlab-task-runner-ce:v13.2.29efd73993c34
rubyzip@2.0.0
3.4.0
mirrorgitlabcontainers/gitlab-webservice-ce:v13.2.230393f990f5c
rubyzip@2.0.0
3.4.0

Open the chart page →

39,150
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
rubyzip@2.3.2
3.4.0

Open the chart page →

106,838
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
rubyzip@2.3.2
3.4.0

Open the chart page →

106,838
betydbncsaVerified publisher0.6.11 of 4See more

betydb ncsa 0.6.1

1 of the 4 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
rubyzip@1.3.0
3.4.0

Open the chart page →

10,229
pecanncsaVerified publisher0.6.21 of 15See more

pecan ncsa 0.6.2

1 of the 15 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
rubyzip@1.3.0
3.4.0

Open the chart page →

15,778
redminerestic-pvc-backupVerified publisher0.2.61 of 1See more

redmine restic-pvc-backup 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
rubyzip@2.4.1
3.4.0

Open the chart page →

4,653
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-85396.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
rubyzip@2.4.1
3.4.0

Open the chart page →

11,466

Container images carrying it

19 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/redmine:6.1.3-trixief474a901faec
rubyzip@2.4.1
3.4.0
2
pecan/bety:5.4.1f825d480cd62
rubyzip@1.3.0
3.4.0
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
rubyzip@2.3.2
3.4.0
2
docuseal/docuseal:3.2.658c76f6d2856
rubyzip@3.2.2
3.4.0
1
docuseal/docuseal:2.4.17493fd7f6728
rubyzip@3.2.2
3.4.0
1
library/logstash:7.17.817a4f64e9cf5
rubyzip@1.3.0
3.4.0
1
library/logstash:9.1.233eae14f0867
rubyzip@1.3.0
3.4.0
1
library/redmine:6.1.204ac44a2595b
rubyzip@2.4.1
3.4.0
1
mirrorgitlabcontainers/gitlab-sidekiq-ce:v13.2.294d1431683fa
rubyzip@2.0.0
3.4.0
1
mirrorgitlabcontainers/gitlab-task-runner-ce:v13.2.29efd73993c34
rubyzip@2.0.0
3.4.0
1
mirrorgitlabcontainers/gitlab-webservice-ce:v13.2.230393f990f5c
rubyzip@2.0.0
3.4.0
1
openproject/community:12.0.2734743d11094
rubyzip@2.3.2
3.4.0
1
openproject/openproject:17.8.0-slim48952034215d
rubyzip@2.4.1
3.4.0
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
rubyzip@1.3.0
3.4.0
1
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
rubyzip@2.4.1
3.4.0
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
rubyzip@2.4.1
3.4.0
1
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
rubyzip@2.4.1
3.4.0
1
ghcr.io/manyfold3d/manyfold-solo:0.147.2ed5a792b0e8d
rubyzip@2.4.1
3.4.0
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
rubyzip@2.4.1
3.4.0
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.