StackRadar

CVE-2026-88830

High

Advisory

Published 23 Sept 2026In the index since 25 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
37
of 17,911 indexed, latest versions
Container images
39
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 37 of 17,911 indexed charts deploy, on 39 images.

Affected packageAffected versionsFixed inImages
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.27.2-2ubuntu3.4, 1:1.30.1-4ubuntu6.4+9 moreno fix listed39
OSV records
DEBIAN-CVE-2026-88830UBUNTU-CVE-2026-88830

Charts affected

37 by stars
ChartLatestAffected imagesRadar Score
gitlabgitlabVerified publisher10.4.17 of 21See more

gitlab gitlab 10.4.1

7 of the 21 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/build/cng/certificates:v19.4.104019bb2e325
busybox@1:1.37.0-6+b9
no fix listed
registry.gitlab.com/gitlab-org/build/cng/gitaly:v19.4.198d46dc7e071
busybox@1:1.37.0-6+b9
no fix listed
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.19df7d5aa03fe
busybox@1:1.37.0-6+b9
no fix listed
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabb21661438ee9
busybox@1:1.35.0-4+deb12u1+b1
no fix listed
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.25b0d50fcd5ea
busybox@1:1.37.0-6+b9
no fix listed
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3180688274b2c
busybox@1:1.37.0-6+b9
no fix listed
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.17419aa33eb17
busybox@1:1.37.0-6+b9
no fix listed

Open the chart page →

15,702
nextcloudnextcloud9.3.01 of 1See more

nextcloud nextcloud 9.3.0

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
library/nextcloud:34.0.4-apachea5ace30c695a
busybox@1:1.37.0-6+b9
no fix listed

Open the chart page →

4,188
oneuptimeoneuptimeOfficialVerified publisher14.0.61 of 7See more

oneuptime oneuptime 14.0.6

1 of the 7 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.7623d99d6ae44
busybox@1:1.30.1-7ubuntu3.1
no fix listed

Open the chart page →

8,315
nextcloudgroundhog2k0.22.71 of 3See more

nextcloud groundhog2k 0.22.7

1 of the 3 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
library/nextcloud:35.0.0:35.0.0-apache3e9f6eaa5dc8
busybox@1:1.37.0-6+b9
no fix listed

Open the chart page →

4,207
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
busybox@1:1.37.0-6+b3
no fix listed

Open the chart page →

6,024
openbaogitlabVerified publisher0.19.01 of 1See more

openbao gitlab 0.19.0

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.6.2-gitlab1a80159109e74
busybox@1:1.37.0-6+b9
no fix listed

Open the chart page →

1,529
machinarislib42Verified publisher0.2.01 of 1See more

machinaris lib42 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
ghcr.io/guydavis/machinaris:test50a71a30f18e
busybox@1:1.36.1-6ubuntu3.1
no fix listed

Open the chart page →

38,971
observalobservalVerified publisher1.13.11 of 8See more

observal observal 1.13.1

1 of the 8 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.3810861a2e2d0
busybox@1:1.30.1-7ubuntu3.1
no fix listed

Open the chart page →

6,606
clickhouseclickhouse-alerthawkVerified publisher26.5.01 of 1See more

clickhouse clickhouse-alerthawk 26.5.0

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.584d05b9c205e
busybox@1:1.30.1-7ubuntu3.1
no fix listed

Open the chart page →

1,933
dokudokuOfficialVerified publisher0.1.41 of 3See more

doku doku 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latesta73b5c0fb6f8
busybox@1:1.30.1-7ubuntu3.1
no fix listed

Open the chart page →

1,801
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
busybox@1:1.30.1-4ubuntu6.4
no fix listed

Open the chart page →

12,661
clickhousesinextraVerified publisher0.22.01 of 1See more

clickhouse sinextra 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.3.1092098d3b31dd
busybox@1:1.30.1-7ubuntu3.1
no fix listed

Open the chart page →

2,228
kafka-devwikimedia0.2.01 of 1See more

kafka-dev wikimedia 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
busybox@1:1.21.0-1ubuntu1
no fix listed

Open the chart page →

41,880
alibaba-rsocket-brokeralibaba-rsocket-brokerVerified publisher0.1.31 of 1See more

alibaba-rsocket-broker alibaba-rsocket-broker 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
busybox@1:1.27.2-2ubuntu3.4
no fix listed

Open the chart page →

96,095
opensipschetan-opensips0.1.01 of 1See more

opensips chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
chetangautamm/repo:Opensips_Buildb4b94155ff5a
busybox@1:1.21.0-1ubuntu1.4
no fix listed

Open the chart page →

80,768
guestbookcloudnativeapp0.2.01 of 3See more

guestbook cloudnativeapp 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
resouer/redis-slave:v2e2f198b49ba7
busybox@1:1.21.0-1ubuntu1
no fix listed

Open the chart page →

93,973
galaxy-stablecloudve2.0.02 of 5See more

galaxy-stable cloudve 2.0.0

2 of the 5 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
busybox@1:1.21.0-1ubuntu1
no fix listed
galaxy/galaxy-stable:v18.018e577a626dfd
busybox@1:1.21.0-1ubuntu1
no fix listed

Open the chart page →

175,546
csghubcsghubVerified publisher2.5.02 of 34See more

csghub csghub 2.5.0

2 of the 34 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
busybox@1:1.35.0-4+b3
no fix listed
opencsghq/gitlab-shell:v19.2.580a65ac370da
busybox@1:1.35.0-4+deb12u1+b1
no fix listed

Open the chart page →

52,284
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
busybox@1:1.30.1-7ubuntu3
no fix listed

Open the chart page →

13,540
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
busybox@1:1.30.1-7ubuntu3
no fix listed

Open the chart page →

13,540
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
busybox@1:1.30.1-4ubuntu6.4
no fix listed

Open the chart page →

15,927
clickhousehelmforgeVerified publisher2.0.31 of 1See more

clickhouse helmforge 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.8.108a1589a2dd9a
busybox@1:1.30.1-7ubuntu3.1
no fix listed

Open the chart page →

1,801
nextcloudhelmforgeVerified publisher1.1.11 of 3See more

nextcloud helmforge 1.1.1

1 of the 3 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
library/nextcloud:35.0.1-apache276547e033df
busybox@1:1.37.0-6+b9
no fix listed

Open the chart page →

6,124
deepflowkubesphere-stable6.2.6061 of 8See more

deepflow kubesphere-stable 6.2.606

1 of the 8 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
busybox@1:1.30.1-7ubuntu3
no fix listed

Open the chart page →

18,935
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
busybox@1:1.30.1-7ubuntu3
no fix listed

Open the chart page →

106,629
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
busybox@1:1.30.1-7ubuntu3
no fix listed

Open the chart page →

106,629
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
busybox@1:1.21.0-1ubuntu1
no fix listed

Open the chart page →

41,880
sebaopencord1.0.01 of 17See more

seba opencord 1.0.0

1 of the 17 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
voltha/voltha-envoy:1.6.059ab2a00f712
busybox@1:1.21.0-1ubuntu1
no fix listed

Open the chart page →

388,518
dokuopenlit0.1.41 of 3See more

doku openlit 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latest42acb460c63b
busybox@1:1.30.1-7ubuntu3.1
no fix listed

Open the chart page →

1,801
openpanelopenpanel0.9.01 of 6See more

openpanel openpanel 0.9.0

1 of the 6 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
busybox@1:1.30.1-7ubuntu3.1
no fix listed

Open the chart page →

3,701
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
busybox@1:1.21.0-1ubuntu1
no fix listed

Open the chart page →

26,763
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
busybox@1:1.30.1-7ubuntu3
no fix listed

Open the chart page →

13,540
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
busybox@1:1.37.0-6+b3
no fix listed

Open the chart page →

10,350
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
busybox@1:1.35.0-4+b4
no fix listed

Open the chart page →

10,831
tyk-control-planetyk-helm5.4.11 of 7See more

tyk-control-plane tyk-helm 5.4.1

1 of the 7 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
tykio/tyk-gateway-ee:v5.13.250b3e4f5398a
busybox@1:1.37.0-6+dhi3
no fix listed

Open the chart page →

2,860
tyk-data-planetyk-helm5.4.11 of 3See more

tyk-data-plane tyk-helm 5.4.1

1 of the 3 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
tykio/tyk-gateway-ee:v5.13.250b3e4f5398a
busybox@1:1.37.0-6+dhi3
no fix listed

Open the chart page →

767
tyk-stacktyk-helm5.4.11 of 7See more

tyk-stack tyk-helm 5.4.1

1 of the 7 container images this version deploys carry CVE-2026-88830.

Container imageDigestPackageFixed in
tykio/tyk-gateway-ee:v5.13.250b3e4f5398a
busybox@1:1.37.0-6+dhi3
no fix listed

Open the chart page →

2,850

Container images carrying it

39 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
tykio/tyk-gateway-ee:v5.13.250b3e4f5398a
busybox@1:1.37.0-6+dhi3
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
busybox@1:1.30.1-7ubuntu3
no fix listed
3
wurstmeister/zookeeper:latest7a7fd44a7210
busybox@1:1.21.0-1ubuntu1
no fix listed
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
busybox@1:1.30.1-7ubuntu3
no fix listed
2
anguda/ant-media:2.5c435285fc241
busybox@1:1.30.1-4ubuntu6.4
no fix listed
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
busybox@1:1.21.0-1ubuntu1.4
no fix listed
1
clickhouse/clickhouse-server:latest42acb460c63b
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:26.7623d99d6ae44
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:26.3810861a2e2d0
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:26.584d05b9c205e
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:26.8.108a1589a2dd9a
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:26.3.1092098d3b31dd
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:latesta73b5c0fb6f8
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
busybox@1:1.30.1-7ubuntu3
no fix listed
1
galaxy/galaxy-init:v18.010267bad550e6
busybox@1:1.21.0-1ubuntu1
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
busybox@1:1.21.0-1ubuntu1
no fix listed
1
library/nextcloud:35.0.1-apache276547e033df
busybox@1:1.37.0-6+b9
no fix listed
1
library/nextcloud:35.0.0:35.0.0-apache3e9f6eaa5dc8
busybox@1:1.37.0-6+b9
no fix listed
1
library/nextcloud:31.0.6-apache588609d76b21
busybox@1:1.35.0-4+b4
no fix listed
1
library/nextcloud:34.0.4-apachea5ace30c695a
busybox@1:1.37.0-6+b9
no fix listed
1
library/nextcloud:31.0.10-apacheb7faa1653c39
busybox@1:1.37.0-6+b3
no fix listed
1
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
busybox@1:1.27.2-2ubuntu3.4
no fix listed
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
busybox@1:1.35.0-4+b3
no fix listed
1
opencsghq/gitlab-shell:v19.2.580a65ac370da
busybox@1:1.35.0-4+deb12u1+b1
no fix listed
1
opsmx11/issuegen:v2.1.05c50ca123d88
busybox@1:1.21.0-1ubuntu1
no fix listed
1
resouer/redis-slave:v2e2f198b49ba7
busybox@1:1.21.0-1ubuntu1
no fix listed
1
voltha/voltha-envoy:1.6.059ab2a00f712
busybox@1:1.21.0-1ubuntu1
no fix listed
1
ghcr.io/guydavis/machinaris:test50a71a30f18e
busybox@1:1.36.1-6ubuntu3.1
no fix listed
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
busybox@1:1.30.1-4ubuntu6.4
no fix listed
1
ghcr.io/monicahq/monica-next:main8be69156acbb
busybox@1:1.37.0-6+b3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/certificates:v19.4.104019bb2e325
busybox@1:1.37.0-6+b9
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitaly:v19.4.198d46dc7e071
busybox@1:1.37.0-6+b9
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.19df7d5aa03fe
busybox@1:1.37.0-6+b9
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabb21661438ee9
busybox@1:1.35.0-4+deb12u1+b1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.25b0d50fcd5ea
busybox@1:1.37.0-6+b9
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.6.2-gitlab1a80159109e74
busybox@1:1.37.0-6+b9
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3180688274b2c
busybox@1:1.37.0-6+b9
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.17419aa33eb17
busybox@1:1.37.0-6+b9
no fix listed
1

syft 1.42.1 · advisories as of 27 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.