Package Search Help

You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.

Search by package name:
my-package (implicit)
name:my-package (explicit)

Search by package filename:
filename:my-package.ext 

Search by package tag:
tag:latest 

Search by package version:
version:1.0.0  prerelease:true (prereleases)
prerelease:false (no prereleases)

Search by package architecture:
architecture:x86_64 

Search by package distribution:
distribution:el 

Search by package license:
license:MIT 

Search by package format:
format:deb 

Search by package status:
status:in_progress 

Search by package file checksum:
checksum:5afba 

Search by package security status:
severity:critical 

Search by package vulnerabilities:
vulnerabilities:>1 
vulnerabilities:<1000 

Search by # of package downloads:
downloads:>8 
downloads:<100 

Search by package type:
type:binary 
type:source 

Search by package size (bytes):
size:>50000 
size:<10000 

Search by dependency name/version:
dependency:log4j 
dependency:log4j=1.0.0 
dependency:log4j>1.0.0 

Search by uploaded date:
uploaded:>"1 day ago" 
uploaded:<"August 14, 2022 EST" 

Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY 

Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true

Search by repository:
repository:repo-name

Search by last download date:
last_downloaded:<"30 days ago" 
last_downloaded:>"August 14, 2022 EST" 

Search queries for all Debian-specific (and related) package types

Search by component:
deb_component:unstable

Search queries for all Maven-specific (and related) package types

Search by group ID:
maven_group_id:org.apache

Search queries for all Docker-specific (and related) package types

Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)

Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)

Search queries for all Generic-specific package types

Search by file path:
generic_filepath:path/to/file.txt

Search by directory:
generic_directory:path/to

Field type modifiers (depending on the type, you can influence behaviour)

For all queries, you can use:
~foo for negation

For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching

For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal

Need a secure and centralised artifact repository to deliver Alpine, Cargo, CocoaPods, Composer, Conan, Conda, CRAN, Dart, Debian, Docker, Generic, Go, Helm, Hex, HuggingFace, LuaRocks, Maven, MCP, Nix, npm, NuGet, P2, Python, RedHat, Ruby, Swift, Terraform, Vagrant, VSX, Raw & More packages?

Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.

With support for all major package formats, you can trust us to manage your software supply chain.

Start My Free Trial
 Public — eventstore eventstore (Kurrent) / kurrent-latest
A certifiably-awesome public package repository curated by Kurrent, hosted by Cloudsmith.

Docker logo kurrentdb  26.2.2

One-liner (summary)

A certifiably-awesome package curated by trainstation, hosted by Cloudsmith.

Description

A certifiably-awesome package curated by trainstation, hosted by Cloudsmith.

License

Unknown

Size

223.5 MB

Downloads

29

Status  Completed
Checksum (MD5) 597183eb862734cdcfbcefe98183a98b
Checksum (SHA-1) 376614f723602293f38488a3767963b10111f821
Checksum (SHA-256) ddcea222b6b2088ed13a886ca77ac64c00cbd43cf3c962a5353e784b323d282f
Checksum (SHA-512) 94bd9803a6c03246256e476c91309f075f796dd778d6b46fef11071606f2c62d78…
GPG Signature
GPG Fingerprint 02a89004460aa252035d6b7d094442d90ad50bcd
Storage Region  Dublin, Ireland
Type  Binary (contains binaries and binary artifacts)
Uploaded At 3 days, 22 hours ago
Uploaded By Uploaded by trainstation
Slug Id kurrentdb-8323
Unique Id TvauhnWiOYuW
Version (Raw) 26.2.2
Version (Parsed)
  • Major: 26
  • Minor: 2
  • Patch: 2
  • Type: SemVer (Strict)
Orig Version (Raw) ddcea222b6b2088ed13a886ca77ac64c00cbd43cf3c962a5353e784b323d282f
Orig Version (Parsed)
  • Type: Unknown
  docker-specific metadata
Image Digest sha256:ddcea222b6b2088ed13a886ca77ac64c00cbd43cf3c962a5353e784b323d282f
Config Digest sha256:6f2a0cfb0d56aba07f94dd2a5841e9b7cb48ee9a1a8a62de36af4dbbe6107b29
V1 OCI Index Digest sha256:7634dd899d2e241653e0e9ff790e3656304d4ccb06ce9677544d3b1a00c08853
V1 Distribution (Signed) Digest sha256:124471c59c990976bdb6f9ceb453b91ac9c186dffc742a227b45977fda6aa59c
V1 OCI Digest sha256:257784f89cd896a510ece33a5473f22b5cfdee6d26d25536022eeefc3f5f8580
V2 Distribution List Digest sha256:22546d3ad024b3aa66ba03f14146f19664ad12e56290ed4d5861e101a72cbfb2
V1 Distribution Digest sha256:bc78fdb3a24be0002599f253efe0e7e2ebae3736c22467fcdbab810d605a605e
V2 Distribution Digest sha256:ddcea222b6b2088ed13a886ca77ac64c00cbd43cf3c962a5353e784b323d282f
  extended metadata
Manifest Type V2 Distribution
Architecture amd64
Config
Created 2026-10-07 06:57:04 UTC
Os linux

This package was uploaded with the following V2 Distribution manifest:

{
   "schemaVersion": 2,
   "mediaType": "application/vnd.docker.distribution.manifest.v2+json",
   "config": {
      "mediaType": "application/vnd.docker.container.image.v1+json",
      "size": 6952,
      "digest": "sha256:bd914b7ded43d781611b22277736558ab94119e738efb65a35be7ec7571a3e93"
   },
   "layers": [
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 30630248,
         "digest": "sha256:8e14801291b4460216bf22d63410b92922d16fd0fdfdc50a58224a35c8469045"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 16779051,
         "digest": "sha256:cc5f75342e9df50121ed06b98a4c3c1ef540823947e47b876b2bead3d4de22af"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 3568,
         "digest": "sha256:371202940c24d6658420d820bcc0cdb5df77c67038777ad559a9206eac8041f4"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 38080229,
         "digest": "sha256:5a2a8005bc2229db548e0979b9c188b79525b45ff61b8c6ca30a0e5150d37e6b"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 2760792,
         "digest": "sha256:9b74616da7f101bde015533a8fef17276f1cc142bc83bb9e8054307a46324bc4"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 1328,
         "digest": "sha256:7ef36c7a101d43815280126a0744f3f1f29eadcd5da981f88b2b641d4adfc15f"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 146105295,
         "digest": "sha256:edde6f921c20eec086698ccf28e946f06afff73228fc84ba7e474762f2fd8409"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 32,
         "digest": "sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 193,
         "digest": "sha256:86d33c6933de6594e2bf4a504a1fd08c42628c8d813fc5632f9c3ad370de4ec6"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 190,
         "digest": "sha256:8c63e834202aac2d596d43ee98e7a01d2b3c87d6e3435da17b5ce15a18497d2f"
      }
   ]
}
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG RELEASE
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG LAUNCHPAD_BUILD_ARCH
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL org.opencontainers.image.version=24.04
32 bytes
Digest: sha256:8e14801291b4460216bf22d63410b92922d16fd0fdfdc50a58224a35c8469045
Command: /bin/sh -c #(nop) ADD file:7121eb4a5ba391efb4ba9a38c532d1c5dc2d22d276f04e062f357eea36ee62c4 in /
29.2 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) CMD ["/bin/bash"]
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV APP_UID=1654 ASPNETCORE_HTTP_PORTS=8080 DOTNET_RUNNING_IN_CONTAINER=true
32 bytes
Digest: sha256:cc5f75342e9df50121ed06b98a4c3c1ef540823947e47b876b2bead3d4de22af
Command: RUN /bin/sh -c apt-get update && apt-get install -y --no-install-recommends ca-certificates libc6 libgcc-s1 libicu74 libssl3t64 libstdc++6 tzdata tzdata-legacy && rm -rf /var/lib/apt/lists/* # buildkit
16.0 MB
Digest: sha256:371202940c24d6658420d820bcc0cdb5df77c67038777ad559a9206eac8041f4
Command: RUN /bin/sh -c groupadd --gid=$APP_UID app && useradd --no-log-init --uid=$APP_UID --gid=$APP_UID --create-home app # buildkit
3.5 KB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG DATABASE_ARCHIVE_DIR=kurrentdb-26.2.2-linux-x64.tar.gz
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG UID=1001
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG GID=1001
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV LANGUAGE=en_US:en DEBIAN_FRONTEND=noninteractive ACCEPT_EULA=Y
32 bytes
Digest: sha256:5a2a8005bc2229db548e0979b9c188b79525b45ff61b8c6ca30a0e5150d37e6b
Command: RUN |3 DATABASE_ARCHIVE_DIR=kurrentdb-26.2.2-linux-x64.tar.gz UID=1001 GID=1001 /bin/sh -c apt-get update && apt-get upgrade -y && apt-get clean # buildkit
36.3 MB
Digest: sha256:9b74616da7f101bde015533a8fef17276f1cc142bc83bb9e8054307a46324bc4
Command: RUN |3 DATABASE_ARCHIVE_DIR=kurrentdb-26.2.2-linux-x64.tar.gz UID=1001 GID=1001 /bin/sh -c apt update && apt install -y adduser curl && rm -rf /var/lib/apt/lists/* # buildkit
2.6 MB
Digest: sha256:7ef36c7a101d43815280126a0744f3f1f29eadcd5da981f88b2b641d4adfc15f
Command: RUN |3 DATABASE_ARCHIVE_DIR=kurrentdb-26.2.2-linux-x64.tar.gz UID=1001 GID=1001 /bin/sh -c addgroup --gid ${GID} "kurrent" && adduser --disabled-password --gecos "" --ingroup "kurrent" --no-create-home --uid ${UID} "kurrent" # buildkit
1.3 KB
Digest: sha256:edde6f921c20eec086698ccf28e946f06afff73228fc84ba7e474762f2fd8409
Command: COPY --chown=kurrent:kurrent kurrentdb-26.2.2-linux-x64.tar.gz /opt/kurrentdb/ # buildkit
139.3 MB
Digest: sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1
Command: WORKDIR /opt/kurrentdb
32 bytes
Digest: sha256:86d33c6933de6594e2bf4a504a1fd08c42628c8d813fc5632f9c3ad370de4ec6
Command: RUN |3 DATABASE_ARCHIVE_DIR=kurrentdb-26.2.2-linux-x64.tar.gz UID=1001 GID=1001 /bin/sh -c mkdir -p /var/lib/kurrentdb && mkdir -p /var/log/kurrentdb && mkdir -p /etc/kurrentdb && chown -R kurrent:kurrent /var/lib/kurrentdb /var/log/kurrentdb /etc/kurrentdb # buildkit
193 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: USER kurrent
32 bytes
Digest: sha256:8c63e834202aac2d596d43ee98e7a01d2b3c87d6e3435da17b5ce15a18497d2f
Command: RUN |3 DATABASE_ARCHIVE_DIR=kurrentdb-26.2.2-linux-x64.tar.gz UID=1001 GID=1001 /bin/sh -c echo "NodeIp: 0.0.0.0\nReplicationIp: 0.0.0.0" >> /etc/kurrentdb/kurrentdb.conf # buildkit
190 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: VOLUME [/var/lib/kurrentdb]
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: VOLUME [/var/log/kurrentdb]
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: EXPOSE map[1112/tcp:{}]
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: EXPOSE map[1113/tcp:{}]
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: EXPOSE map[2113/tcp:{}]
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: HEALTHCHECK &{["CMD-SHELL" "curl --fail --insecure https://localhost:2113/health/live || curl --fail http://localhost:2113/health/live || exit 1"] "5s" "5s" "0s" "0s" '\x18'}
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/opt/kurrentdb/kurrentd"]
32 bytes
  Docker logo
kurrentdb
 26.2.2
29 Uploaded by trainstation
 Older Docker logo
kurrentdb
 26.2.1
30 Uploaded by trainstation
 Older Docker logo
kurrentdb
 26.2.0
44 Uploaded by trainstation
 Older Docker logo
kurrentdb
 26.1.3
241.2 MB — 1 week, 1 day ago
28 Uploaded by trainstation
 Older Docker logo
kurrentdb
 26.1.2
239.5 MB — 2 months ago
69 Uploaded by trainstation
 Older Docker logo
kurrentdb
 26.1.1
240.2 MB — 3 months ago
154 Uploaded by trainstation
 Older Docker logo
kurrentdb
 26.1.0
655 Uploaded by trainstation
 Older Docker logo
kurrentdb
 26.0.3
578 Uploaded by trainstation
 Older Docker logo
kurrentdb
 26.0.2
30962 Uploaded by trainstation
 Older Docker logo
kurrentdb
 26.0.1
245.6 MB — 8 months ago
17221 Uploaded by trainstation
 Older Docker logo
kurrentdb
 26.0.0
5524 Uploaded by trainstation
 Older Docker logo
kurrentdb
 25.1.4
5127 Uploaded by trainstation
 Older Docker logo
kurrentdb
19 Uploaded by trainstation
 Older Docker logo
kurrentdb
 25.1.3
376.1 MB — 8 months ago
777 Uploaded by trainstation
 Older Docker logo
kurrentdb
337.0 MB — 8 months ago
16 Uploaded by trainstation
 Older Docker logo
kurrentdb
 25.1.1
13740 Uploaded by trainstation
 Older Docker logo
kurrentdb
20 Uploaded by trainstation
 Older Docker logo
kurrentdb
 25.1.0
4442 Uploaded by trainstation
 Older Docker logo
kurrentdb
480 Uploaded by trainstation
 Older Docker logo
kurrentdb
 25.0.1
11055 Uploaded by trainstation

Last scanned

3 days, 22 hours ago

Scan result

Vulnerable

Vulnerability count

11

Max. severity

High
Target: TvauhnWiOYuW.sbom-cyclonedx.json (ubuntu 24.04)
MEDIUM

CVE-2026-18374: glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string

Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.

Package Name: libc-bin
Installed Version: 2.39-0ubuntu8.9
Fixed Version:

References: www.openwall.com access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-89092: glibc: nscd stack overflow leads to degraded DNS resolution

The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of this bug needs a system that has nscd enabled and using an untrusted DNS server for name resolution, with the compromised DNS server being capable of processing records large enough to result in a stack overflow in an nscd thread stack.  During experimentation, bind 9 was unable to handle large records, but that could change in future or with a different name server.  In typical installations, nscd is executed in an isolated context as its own user without a shell, due to which any compromise of that service is isolated. There is a remote possibility of nscd cache corruption if an attacker manages to get the stack pointer into a desired point in the heap, potentially resulting in other caches in nscd being overwritten with corrupt data through the stack overflow, until the buggy code path eventually results in a crash. Finally, a crash in nscd may result in performance degradation when resolving names, but it does not result in a denial of service.

Package Name: libc-bin
Installed Version: 2.39-0ubuntu8.9
Fixed Version:

References: www.openwall.com access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-18374: glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string

Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.

Package Name: libc6
Installed Version: 2.39-0ubuntu8.9
Fixed Version:

References: www.openwall.com access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-89092: glibc: nscd stack overflow leads to degraded DNS resolution

The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of this bug needs a system that has nscd enabled and using an untrusted DNS server for name resolution, with the compromised DNS server being capable of processing records large enough to result in a stack overflow in an nscd thread stack.  During experimentation, bind 9 was unable to handle large records, but that could change in future or with a different name server.  In typical installations, nscd is executed in an isolated context as its own user without a shell, due to which any compromise of that service is isolated. There is a remote possibility of nscd cache corruption if an attacker manages to get the stack pointer into a desired point in the heap, potentially resulting in other caches in nscd being overwritten with corrupt data through the stack overflow, until the buggy code path eventually results in a crash. Finally, a crash in nscd may result in performance degradation when resolving names, but it does not result in a denial of service.

Package Name: libc6
Installed Version: 2.39-0ubuntu8.9
Fixed Version:

References: www.openwall.com access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-86145: pcre2: PCRE2: Out-of-bounds write allows arbitrary code execution via crafted regular expressions

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).

Package Name: libpcre2-8-0
Installed Version: 10.42-4ubuntu2.1
Fixed Version:

References: www.openwall.com access.redhat.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-89161: pcre2: PCRE2: Memory corruption vulnerability in pcre2_jit_match

In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.

Package Name: libpcre2-8-0
Installed Version: 10.42-4ubuntu2.1
Fixed Version:

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-18477: tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.

Package Name: tar
Installed Version: 1.35+dfsg-3ubuntu0.4
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com creativecommons.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-18508: tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

Package Name: tar
Installed Version: 1.35+dfsg-3ubuntu0.4
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com creativecommons.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-85091: zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ...

zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.

Package Name: zlib1g
Installed Version: 1:1.3.dfsg-3.1ubuntu2.2
Fixed Version:

References: gist.github.com github.com github.com www.cve.org www.vulncheck.com
LOW

CVE-2025-5222: icu: Stack buffer overflow in the SRBRoot::addTag function

A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.

Package Name: libicu74
Installed Version: 74.2-1ubuntu3.1
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com lists.debian.org nvd.nist.gov unicode-org.atlassian.net www.cve.org
LOW

CVE-2026-40228: systemd: systemd-journald: Unintended output to user terminals via logger command

In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.

Package Name: libsystemd0
Installed Version: 255.4-1ubuntu8.17
Fixed Version:

References: www.openwall.com access.redhat.com nvd.nist.gov www.cve.org www.openwall.com
LOW

CVE-2026-40228: systemd: systemd-journald: Unintended output to user terminals via logger command

In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.

Package Name: libudev1
Installed Version: 255.4-1ubuntu8.17
Fixed Version:

References: www.openwall.com access.redhat.com nvd.nist.gov www.cve.org www.openwall.com
LOW

CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Package Name: login
Installed Version: 1:4.13+dfsg1-4ubuntu3.2
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
LOW

CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Package Name: passwd
Installed Version: 1:4.13+dfsg1-4ubuntu3.2
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
Target: opt/kurrentdb/KurrentDB.deps.json
HIGH

CVE-2025-6965: sqlite: Integer Truncation in SQLite

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

Package Name: SQLitePCLRaw.lib.e_sqlite3
Installed Version: 2.1.11
Fixed Version:

References: seclists.org seclists.org seclists.org seclists.org seclists.org www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com cert-portal.siemens.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org www.oracle.com www.sqlite.org

You can embed a badge in another website that shows this or the latest version of this package.

To embed the badge for this specific package version, use the following:

[![This version of 'kurrentdb' @ Cloudsmith](https://api-dkr.cloudsmith.com/v1/badges/version/eventstore/kurrent-latest/docker/kurrentdb/26.2.2/a=amd64;xpo=linux/?render=true)](https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/ddcea222b6b2088ed13a886ca77ac64c00cbd43cf3c962a5353e784b323d282f/a=amd64;xpo=linux/)
|This version of 'kurrentdb' @ Cloudsmith|
.. |This version of 'kurrentdb' @ Cloudsmith| image:: https://api-dkr.cloudsmith.com/v1/badges/version/eventstore/kurrent-latest/docker/kurrentdb/26.2.2/a=amd64;xpo=linux/?render=true
   :target: https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/ddcea222b6b2088ed13a886ca77ac64c00cbd43cf3c962a5353e784b323d282f/a=amd64;xpo=linux/
image::https://api-dkr.cloudsmith.com/v1/badges/version/eventstore/kurrent-latest/docker/kurrentdb/26.2.2/a=amd64;xpo=linux/?render=true[link="https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/ddcea222b6b2088ed13a886ca77ac64c00cbd43cf3c962a5353e784b323d282f/a=amd64;xpo=linux/",title="This version of 'kurrentdb' @ Cloudsmith"]
<a href="https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/ddcea222b6b2088ed13a886ca77ac64c00cbd43cf3c962a5353e784b323d282f/a=amd64;xpo=linux/"><img src="https://api-dkr.cloudsmith.com/v1/badges/version/eventstore/kurrent-latest/docker/kurrentdb/26.2.2/a=amd64;xpo=linux/?render=true" alt="This version of 'kurrentdb' @ Cloudsmith" /></a>

rendered as: This version of 'kurrentdb' @ Cloudsmith

To embed the badge for the latest package version, use the following:

[![Latest version of 'kurrentdb' @ Cloudsmith](https://api-dkr.cloudsmith.com/v1/badges/version/eventstore/kurrent-latest/docker/kurrentdb/latest/a=amd64;xpo=linux/?render=true&show_latest=true)](https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/latest/a=amd64;xpo=linux/)
|Latest version of 'kurrentdb' @ Cloudsmith|
.. |Latest version of 'kurrentdb' @ Cloudsmith| image:: https://api-dkr.cloudsmith.com/v1/badges/version/eventstore/kurrent-latest/docker/kurrentdb/latest/a=amd64;xpo=linux/?render=true&show_latest=true
   :target: https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/latest/a=amd64;xpo=linux/
image::https://api-dkr.cloudsmith.com/v1/badges/version/eventstore/kurrent-latest/docker/kurrentdb/latest/a=amd64;xpo=linux/?render=true&show_latest=true[link="https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/latest/a=amd64;xpo=linux/",title="Latest version of 'kurrentdb' @ Cloudsmith"]
<a href="https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/latest/a=amd64;xpo=linux/"><img src="https://api-dkr.cloudsmith.com/v1/badges/version/eventstore/kurrent-latest/docker/kurrentdb/latest/a=amd64;xpo=linux/?render=true&show_latest=true" alt="Latest version of 'kurrentdb' @ Cloudsmith" /></a>

rendered as: Latest version of 'kurrentdb' @ Cloudsmith

These instructions assume you have setup the repository first (or read it).

To pull kurrentdb @ reference/tag latest:

docker pull docker.eventstore.com/kurrent-latest/kurrentdb:latest

To refer to this image after pulling in a Dockerfile, specify the following:

FROM docker.eventstore.com/kurrent-latest/kurrentdb:latest

Note: You should replace latest with an alternative reference to pull, such as: 26.2, 26.2.2, 16be319b-0810-4517-8e04-9e9fb247710d and 26.2.2-x64-10.0-noble.

Top