StackRadar

CVE-2025-28164

Medium

Advisory

Published 27 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
296
of 17,781 indexed, latest versions
Container images
286
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 296 of 17,781 indexed charts deploy, on 286 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.39-2, 1.6.39-2+deb12u1, 1.6.39-2+deb12u3, 1.6.39-2+deb12u4+3 more1.6.43-5ubuntu0.4286
OSV records
DEBIAN-CVE-2025-28164UBUNTU-CVE-2025-28164
Also known as
USN-7993-1

Charts affected

296 by stars
ChartLatestAffected imagesRadar Score
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
langflowai/langflow-frontend:latest54f67f1961fe
libpng1.6@1.6.39-2+deb12u1
no fix listed

Open the chart page →

3,980
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

35,050
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
libpng1.6@1.6.39-2+deb12u1
no fix listed

Open the chart page →

7,201
flaresolverrm0nsterrr-flaresolverrVerified publisher2.4.11 of 1See more

flaresolverr m0nsterrr-flaresolverr 2.4.1

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

6,136
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

5,734
mockservermockserverOfficialVerified publisher7.6.01 of 1See more

mockserver mockserver 7.6.0

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
mockserver/mockserver:mockserver-7.6.080b3b1a26f35
libpng1.6@1.6.39-2+deb12u3
no fix listed

Open the chart page →

1,021
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

13,738
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

37,373
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

5,039
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
libpng1.6@1.6.39-2
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

14,838
opentelemetry-demoopentelemetry-helmVerified publisher0.41.12 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.1

2 of the 34 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:3.0.0-fraud-detection1cdfd1bcf476
libpng1.6@1.6.39-2+deb12u3
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-ade6c593fe75eb
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.4

Open the chart page →

22,420
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

31,844
kimai2robjuz5.0.131 of 2See more

kimai2 robjuz 5.0.13

1 of the 2 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
kimai/kimai2:2.65.06dfc63199654
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

4,693
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
libpng1.6@1.6.39-2+deb12u4
no fix listed

Open the chart page →

5,482
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
libpng1.6@1.6.39-2+deb12u1
no fix listed

Open the chart page →

7,740
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

5,315
kyoorubxkubeVerified publisher0.1.102 of 9See more

kyoo rubxkube 0.1.10

2 of the 9 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
libpng1.6@1.6.39-2
no fix listed
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

30,234
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

38,107
sentry-k8ssentry-k8sVerified publisher1.4.11 of 11See more

sentry-k8s sentry-k8s 1.4.1

1 of the 11 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/getsentry/taskbroker:26.7.264d0da74a578
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

16,449
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

5,676
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

10,380
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

9,102
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

9,102
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

12,581
changedetection-iozekker6Verified publisher1.99.01 of 1See more

changedetection-io zekker6 1.99.0

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.47bb6963b730d
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

2,595
active-mqactivemq-helm-chartVerified publisher1.8.21 of 3See more

active-mq activemq-helm-chart 1.8.2

1 of the 3 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.44.00305c26f19ed
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.4

Open the chart page →

3,188
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

3,820
uptime-kumaadnoctemVerified publisher0.4.11 of 1See more

uptime-kuma adnoctem 0.4.1

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

30,028
akto-testing-db-layerakto1.42.161 of 2See more

akto-testing-db-layer akto 1.42.16

1 of the 2 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
libpng1.6@1.6.43-5ubuntu0.3
1.6.43-5ubuntu0.4

Open the chart page →

5,489
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
libpng1.6@1.6.43-5ubuntu0.3
1.6.43-5ubuntu0.4

Open the chart page →

3,442
esphomealexmorbo-esphomeVerified publisher1.0.01 of 1See more

esphome alexmorbo-esphome 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
esphome/esphome:2024.12.2b2c6322700ac
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

6,324
flaresolverralexmorbo-flaresolverrVerified publisher0.2.01 of 1See more

flaresolverr alexmorbo-flaresolverr 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

27,274
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

5,817
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

7,239
arlas-aiasarlas-stackVerified publisher28.8.01 of 22See more

arlas-aias arlas-stack 28.8.0

1 of the 22 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

40,238
smartorchestratorassist-iot-smart-orchestrator4.0.01 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

1 of the 14 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

45,363
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

32,501
webappavzi-webapp0.1.01 of 1See more

webapp avzi-webapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
avzini/web-app:latestf40b30210ed0
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

6,297
aws9helmaws9helm0.1.04 of 4See more

aws9helm aws9helm 0.1.0

4 of the 4 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
kuzwolka/aws9:main1ad759b961b1
libpng1.6@1.6.39-2
no fix listed
kuzwolka/aws9:news3e8880fbbb96
libpng1.6@1.6.39-2
no fix listed
kuzwolka/aws9:blog4a7707410bf1
libpng1.6@1.6.39-2
no fix listed
kuzwolka/aws9:shop84a9d9766345
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

18,344
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

6,297
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
libpng1.6@1.6.39-2
no fix listed
sysnet4admin/colosseum-prm:log5802bfcd7fed
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

26,996
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

8,323
flaresolverrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

flaresolverr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

27,274
node-appbryopsida0.5.12 of 2See more

node-app bryopsida 0.5.1

2 of the 2 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
libpng1.6@1.6.39-2+deb12u5
no fix listed
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.4

Open the chart page →

14,352
nginx-s3-gatewaycamptocamp31.0.01 of 1See more

nginx-s3-gateway camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss-202503313db8145349a3
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

5,039
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

10,776
caninecanine0.1.101 of 7See more

canine canine 0.1.10

1 of the 7 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/caninehq/canine:latesta058034ca006
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

14,130
catalyst-agentscatalyst-agents0.1.301 of 18See more

catalyst-agents catalyst-agents 0.1.30

1 of the 18 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

15,027
calibre-webcharts-derwitt-devVerified publisher1.1.21 of 1See more

calibre-web charts-derwitt-dev 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

4,911
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-28164.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

8,009

Container images carrying it

286 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/activemq-artemis:2.37.0bae523439ee3
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.4
1
apache/druid:29.0.10cef139b6bf1
libpng1.6@1.6.39-2
no fix listed
1
apache/rocketmq:5.3.0434d8398f996
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.4
1
archivebox/archivebox:0.7.41a5a37331091
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
aristidetm/basic-notebook:3.6.5469dbc951224
libpng1.6@1.6.39-2
no fix listed
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
libpng1.6@1.6.39-2
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
libpng1.6@1.6.39-2
no fix listed
1
atlassian/jira-software:9.7.264a75aa4ec4e
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.4
1
avinash263/pyredis263:latestaa2b8727f1a6
libpng1.6@1.6.39-2
no fix listed
1
avzini/web-app:latestf40b30210ed0
libpng1.6@1.6.39-2
no fix listed
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
libpng1.6@1.6.39-2
no fix listed
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
libpng1.6@1.6.39-2
no fix listed
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
libpng1.6@1.6.39-2
no fix listed
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
libpng1.6@1.6.39-2
no fix listed
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
libpng1.6@1.6.39-2
no fix listed
1
bnjbvr/kresus:0.22.137e216b182c8
libpng1.6@1.6.39-2
no fix listed
1
budibase/database:2.1.0d90f656261c9
libpng1.6@1.6.39-2+deb12u3
no fix listed
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
libpng1.6@1.6.39-2
no fix listed
1
castlemock/castlemock:latestb7f3f1527ba9
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.4
1
castopod/castopod:1.12.101fd37280cbb2
libpng1.6@1.6.39-2
no fix listed
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.4
1
ckulka/baikal:0.10.1-nginx434bdd162247
libpng1.6@1.6.39-2
no fix listed
1
cloudtooling/moodle:5.2.3f4f04e0fc401
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
codedesignplus/ms-emails-grpc:lateste336012bc781
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
codedesignplus/ms-emails-rest:latestac84661c605e
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
collabora/code:24.04.13.2.101dc4ab83977
libpng1.6@1.6.39-2
no fix listed
1
collabora/code:23.05.10.1.105299b452f7f
libpng1.6@1.6.39-2
no fix listed
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
libpng1.6@1.6.39-2+deb12u4
no fix listed
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
libpng1.6@1.6.39-2
no fix listed
1
dannielkil/book-frontend:latest937993927694
libpng1.6@1.6.39-2
no fix listed
1
deconzcommunity/deconz:2.29.2062de2362641
libpng1.6@1.6.39-2
no fix listed
1
dolibarr/dolibarr:24.0.069ec52e3b7ef
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
dolibarr/dolibarr:22.0.47ad88fc9b13c
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
libpng1.6@1.6.39-2
no fix listed
1
dzikoysk/reposilite:3.5.264128c2d7a6ba
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.4
1
emqx/ecp-ui:2.5.1e33e9816f147
libpng1.6@1.6.39-2
no fix listed
1
esphome/esphome:2024.3.09ab8cc88b28c
libpng1.6@1.6.39-2
no fix listed
1
esphome/esphome:2024.12.2b2c6322700ac
libpng1.6@1.6.39-2
no fix listed
1
esphome/esphome:2025.3.0def8b6e4f517
libpng1.6@1.6.39-2
no fix listed
1
felipecs8/app-db-connection-test:v129e06c9c6385
libpng1.6@1.6.39-2
no fix listed
1
firefart/requesttracker:5.0.40d6249906d8c
libpng1.6@1.6.39-2
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
libpng1.6@1.6.39-2
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
libpng1.6@1.6.39-2+deb12u1
no fix listed
1
gchq/accumulo:2.0.1c460bb587d6d
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.4
1
gulacedia/web-dvwa-new:v367b467d961ca
libpng1.6@1.6.39-2
no fix listed
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
libpng1.6@1.6.39-2
no fix listed
1
hazegoodlife/haaze:milksite8d4c63169e14
libpng1.6@1.6.39-2
no fix listed
1
hecrom/myweatherangularclient:1.3.11bb0372939c19
libpng1.6@1.6.39-2
no fix listed
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
libpng1.6@1.6.39-2
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
libpng1.6@1.6.39-2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.