StackRadar

CVE-2026-100078

Medium

Advisory

Published 25 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
29
of 18,035 indexed, latest versions
Container images
30
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 29 of 18,035 indexed charts deploy, on 30 images.

Affected packageAffected versionsFixed inImages
linuxdeb6.8.0-38.38, 6.8.0-39.39, 6.8.0-57.59, 6.8.0-60.63+15 moreno fix listed30
OSV records
UBUNTU-CVE-2026-100078

Charts affected

29 by stars
ChartLatestAffected imagesRadar Score
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
linux@6.8.0-88.89
no fix listed

Open the chart page →

82,191
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
linux@6.8.0-124.124
no fix listed

Open the chart page →

72,642
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
linux@6.8.0-138.138
no fix listed

Open the chart page →

41,757
photoprismandrenarchyVerified publisher8.15.01 of 1See more

photoprism andrenarchy 8.15.0

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
photoprism/photoprism:260728958642220223
linux@7.0.0-28.28
no fix listed

Open the chart page →

48,409
machinarislib42Verified publisher0.2.01 of 1See more

machinaris lib42 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
ghcr.io/guydavis/machinaris:test50a71a30f18e
linux@6.8.0-139.139
no fix listed

Open the chart page →

38,381
nominatimrobjuz6.4.21 of 4See more

nominatim robjuz 6.4.2

1 of the 4 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
mediagis/nominatim:5.3.27923a8e67197
linux@6.8.0-124.124
no fix listed

Open the chart page →

56,319
craftycontrollerdrewburr-labs-helm-chartsVerified publisher0.3.01 of 1See more

craftycontroller drewburr-labs-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
linux@6.8.0-139.139
no fix listed

Open the chart page →

38,573
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
linux@6.8.0-57.59
no fix listed

Open the chart page →

75,225
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
linux@6.8.0-136.136
no fix listed

Open the chart page →

62,572
rstudio-pmrstudioVerified publisher0.20.51 of 1See more

rstudio-pm rstudio 0.20.5

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
posit/package-manager:2026.09.0-ubuntu-24.0468d47a7a8166
linux@6.8.0-139.139
no fix listed

Open the chart page →

36,588
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
linux@7.0.0-28.28
no fix listed

Open the chart page →

49,717
akto-regional-setupakto1.4.41 of 9See more

akto-regional-setup akto 1.4.4

1 of the 9 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
linux@7.0.0-29.29
no fix listed

Open the chart page →

47,736
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
linux@6.8.0-139.139
no fix listed

Open the chart page →

40,554
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
linux@6.8.0-94.96
no fix listed

Open the chart page →

63,302
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
no fix listed

Open the chart page →

79,315
datumcosmicrocks1.0.51 of 2See more

datum cosmicrocks 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
linux@6.8.0-90.91
no fix listed

Open the chart page →

62,922
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:main-local7d2fb04baf44
linux@6.8.0-139.139
no fix listed

Open the chart page →

56,689
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
linux@6.8.0-38.38
no fix listed

Open the chart page →

98,943
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
linux@6.8.0-39.39
no fix listed

Open the chart page →

89,489
komgahelmforgeVerified publisher1.4.161 of 1See more

komga helmforge 1.4.16

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
gotson/komga:1.27.19cf102f5fb78
linux@7.0.0-31.31
no fix listed

Open the chart page →

35,970
homebridgejespernohrVerified publisher0.2.01 of 1See more

homebridge jespernohr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
homebridge/homebridge:latest22cdfca31934
linux@6.8.0-142.142
no fix listed

Open the chart page →

37,060
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
no fix listed

Open the chart page →

73,425
homebridgelbenicio-communityVerified publisher0.1.151 of 1See more

homebridge lbenicio-community 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
homebridge/homebridge:latest22cdfca31934
linux@6.8.0-142.142
no fix listed

Open the chart page →

37,060
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.04 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

4 of the 40 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
linux@6.8.0-136.136
no fix listed
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
linux@6.8.0-136.136
no fix listed
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
linux@6.8.0-136.136
no fix listed
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
linux@6.8.0-136.136
no fix listed

Open the chart page →

234,921
komgarubxkubeVerified publisher0.1.51 of 1See more

komga rubxkube 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
gotson/komga:1.28.1d8f772dce7b3
linux@7.0.0-38.38
no fix listed

Open the chart page →

34,000
seafileschmitzis13.0.131 of 4See more

seafile schmitzis 13.0.13

1 of the 4 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
schmitzis/monorepo:seafile-13.0-latestf7e51ba2fb07
linux@6.8.0-139.139
no fix listed

Open the chart page →

43,234
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
linux@6.8.0-79.79
no fix listed

Open the chart page →

68,547
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
linux@7.0.0-22.22
no fix listed

Open the chart page →

59,885
ocean-network-clientspot1.1.61 of 1See more

ocean-network-client spot 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-100078.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
linux@6.8.0-100.100
no fix listed

Open the chart page →

56,178

Container images carrying it

30 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
homebridge/homebridge:latest22cdfca31934
linux@6.8.0-142.142
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
no fix listed
2
aktosecurity/data-ingestion-service213aded7adc5
linux@6.8.0-94.96
no fix listed
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
linux@7.0.0-28.28
no fix listed
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
linux@7.0.0-29.29
no fix listed
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
linux@6.8.0-138.138
no fix listed
1
gotson/komga:1.27.19cf102f5fb78
linux@7.0.0-31.31
no fix listed
1
gotson/komga:1.28.1d8f772dce7b3
linux@7.0.0-38.38
no fix listed
1
grpl/grapple-cli:0.2.127c00aafee6629
linux@6.8.0-39.39
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
linux@6.8.0-124.124
no fix listed
1
langgenius/dify-plugin-daemon:main-local7d2fb04baf44
linux@6.8.0-139.139
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
linux@6.8.0-88.89
no fix listed
1
mediagis/nominatim:5.3.27923a8e67197
linux@6.8.0-124.124
no fix listed
1
photoprism/photoprism:260601650c6ad5a651
linux@7.0.0-22.22
no fix listed
1
photoprism/photoprism:260728958642220223
linux@7.0.0-28.28
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
linux@6.8.0-38.38
no fix listed
1
posit/package-manager:2026.09.0-ubuntu-24.0468d47a7a8166
linux@6.8.0-139.139
no fix listed
1
qonstrukt/php:8.4-v8-apache089af7925aa1
linux@6.8.0-136.136
no fix listed
1
schmitzis/monorepo:seafile-13.0-latestf7e51ba2fb07
linux@6.8.0-139.139
no fix listed
1
snipe/snipe-it:v8.3.1141ebf2386fe
linux@6.8.0-79.79
no fix listed
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
linux@6.8.0-90.91
no fix listed
1
ghcr.io/guydavis/machinaris:test50a71a30f18e
linux@6.8.0-139.139
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
linux@6.8.0-57.59
no fix listed
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
linux@6.8.0-136.136
no fix listed
1
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
linux@6.8.0-136.136
no fix listed
1
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
linux@6.8.0-136.136
no fix listed
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
linux@6.8.0-136.136
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
linux@6.8.0-139.139
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
linux@6.8.0-100.100
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
linux@6.8.0-139.139
no fix listed
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.