StackRadar

CVE-2026-103111

High

Advisory

Published 30 Sept 2026In the index since 1 Oct 2026
Severity
High
worst across findings
CVSS
7.6
base score, highest
EPSS
0.002
10th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,644
of 17,985 indexed, latest versions
Container images
2,586
deployed by those charts
Fix available
2 of 3
affected packages

CVE-2026-103111 affecting package pcre2 10.48-1

Carried by container images the latest versions of 2,644 of 17,985 indexed charts deploy, on 2,586 images.

Affected packageAffected versionsFixed inImages
pcre2deb10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+13 more10.46-1~deb13u32,396
pcre2apk10.47-r0, 10.47-r1, 10.48-r010.49-r0183
pcre2rpm10.42-3.azl3no fix listed7
OSV records
ALPINE-CVE-2026-103111DEBIAN-CVE-2026-103111UBUNTU-CVE-2026-103111AZL-105119ECHO-bf42-43c6-45fd
Trending
Rank 1 in indexed charts, since 1 Oct 2026. See the ranking →

Charts affected

2,644 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,586 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
pcre2@10.46-1~deb13u1
10.46-1~deb13u3
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
pcre2@10.42-1
no fix listed
2
ghcr.io/libredb/libredb-studio:0.17.0ce4d58724e25
pcre2@10.46-1~deb13u2
10.46-1~deb13u3
2
ghcr.io/lissy93/web-check:latest7e2ef5261764
pcre2@10.42-1
no fix listed
2
ghcr.io/mogenius/mo-backup:latest4f89afef9010
pcre2@10.47-r1
10.49-r0
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
pcre2@10.42-1
no fix listed
2
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
pcre2@10.42-1
no fix listed
2
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
pcre2@10.42-1
no fix listed
2
ghcr.io/opencost/opencost-ui:1.121.2:1.121.399ee2db766a0
pcre2@10.48-r0
10.49-r0
2
ghcr.io/openunison/openunison-kubernetes-operator:1.0.13a0178e08639a
pcre2@10.42-4ubuntu2.1
no fix listed
2
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
pcre2@10.42-1
no fix listed
2
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
pcre2@10.42-1
no fix listed
2
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
pcre2@10.42-1
no fix listed
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
pcre2@10.39-3build1
no fix listed
2
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
pcre2@10.42-1
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
pcre2@10.42-1
no fix listed
2
ghcr.io/unionai-oss/flyteconsole-v2:latestd06cbcbf85dc
pcre2@10.48-r0
10.49-r0
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
pcre2@10.34-7ubuntu0.1
no fix listed
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
pcre2@10.42-4ubuntu2.1
no fix listed
2
quay.io/cilium/cilium-envoy:v1.37.6-1789133542-cbec91f666af0bf742da986d43832932dbb26b82af7382699576
pcre2@10.42-4ubuntu2.1
no fix listed
2
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
pcre2@10.42-1
no fix listed
2
1dev/server:11.9.0cd5b12fe5471
pcre2@10.42-4ubuntu2.1
no fix listed
1
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
pcre2@10.42-1
no fix listed
1
5200710/hadoop:3.2.3-java8092d3088a5fb
pcre2@10.34-7ubuntu0.1
no fix listed
1
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
pcre2@10.46-1~deb13u1
10.46-1~deb13u3
1
aboogie/login_test_backend:new9c41a4483ac8
pcre2@10.42-1
no fix listed
1
actualbudget/actual-server:25.3.158fecd9088b7
pcre2@10.42-1
no fix listed
1
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
pcre2@10.42-4ubuntu2
no fix listed
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
pcre2@10.42-4ubuntu2
no fix listed
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
pcre2@10.34-7
no fix listed
1
agentarea/agentarea-api:latest38fcf6657f5f
pcre2@10.46-1~deb13u2
10.46-1~deb13u3
1
agentarea/agentarea-mcp-runner:latestbe4a11f799b2
pcre2@10.42-1+deb12u1
no fix listed
1
agentarea/agentarea-worker:latest06a5ef356770
pcre2@10.46-1~deb13u2
10.46-1~deb13u3
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
pcre2@10.39-3ubuntu0.1
no fix listed
1
aibrix/metadata-service:v0.7.063fb81a64377
pcre2@10.42-1
no fix listed
1
airbyte/manifest-server:7.28.2deec511b51c3
pcre2@10.42-1
no fix listed
1
airbyte/pod-sweeper:1.5.198d2c39d512e
pcre2@10.42-1
no fix listed
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
pcre2@10.34-7
no fix listed
1
ajilaag/clamav-rest:latestad689c7b75b1
pcre2@10.47-r1
10.49-r0
1
akaunting/akaunting:3.0.1552811b36ec3a
pcre2@10.42-1
no fix listed
1
akeyless/base:latest759e4289fae8
pcre2@10.42-4ubuntu2.1
no fix listed
1
akeyless/gateway:5.4.0d4768a9b089c
pcre2@10.42-4ubuntu2.1
no fix listed
1
aktosecurity/akto-agent-guard-anonymizer:1.1.4d4b100cbdc47
pcre2@10.46-1~deb13u1
10.46-1~deb13u3
1
aktosecurity/akto-agent-guard-embedder:1.1.4dbc566b2376c
pcre2@10.46-1~deb13u1
10.46-1~deb13u3
1
aktosecurity/akto-agent-guard-worker:1.1.4666eaffd5362
pcre2@10.46-1~deb13u1
10.46-1~deb13u3
1
aktosecurity/akto-api-security-dashboard:latest3ecdd301cdbd
pcre2@10.42-4ubuntu2.1
no fix listed
1
aktosecurity/akto-threat-detection-backend:1.18.4b12ce3e2dc71
pcre2@10.46-1build1
no fix listed
1
aktosecurity/akto-threat-detection-backend:latestdffb8c3676ef
pcre2@10.46-1build1
no fix listed
1
aktosecurity/data-ingestion-service213aded7adc5
pcre2@10.42-4ubuntu2.1
no fix listed
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
pcre2@10.46-1build1
no fix listed
1

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.