StackRadar

CVE-2026-11822

High

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,811
of 17,797 indexed, latest versions
Container images
1,559
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,811 of 17,797 indexed charts deploy, on 1,559 images.

Affected packageAffected versionsFixed inImages
sqlite3deb3.8.2-1ubuntu2, 3.8.2-1ubuntu2.1, 3.8.2-1ubuntu2.2, 3.11.0-1ubuntu1+37 more3.37.2-2ubuntu0.6, 3.45.1-1ubuntu2.6, 3.46.1-7+deb13u2, 3.46.1-7+e3+2 more1,482
sqliteapk3.41.2-r4, 3.51.1-r0, 3.51.2-r03.53.4-r077
OSV records
ALPINE-CVE-2026-11822DEBIAN-CVE-2026-11822UBUNTU-CVE-2026-11822ECHO-acfd-ccab-2f14
Also known as
USN-8480-1

Charts affected

1,811 by stars
ChartLatestAffected imagesRadar Score
wordpress-alpinewordpress-alpine1.5.181 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

1 of the 6 container images this version deploys carry CVE-2026-11822.

Container imageDigestPackageFixed in
library/memcached:1.6.45dc561d52bb8a
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2

Open the chart page →

4,080
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-11822.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2

Open the chart page →

5,713
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-11822.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
sqlite3@3.37.2-2ubuntu0.3
3.37.2-2ubuntu0.6

Open the chart page →

14,218
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-11822.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
sqlite3@3.40.1-2+deb12u1
no fix listed

Open the chart page →

11,622
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-11822.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
sqlite3@3.40.1-2
no fix listed
hamzaarshad10/querypodpy:1.7154f38e8668e
sqlite3@3.40.1-2
no fix listed
murtazashah46/helmfile:latest4d11726cf803
sqlite3@3.40.1-2
no fix listed

Open the chart page →

13,813
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-11822.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2

Open the chart page →

1,861
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-11822.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2

Open the chart page →

1,311
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-11822.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2

Open the chart page →

1,861
changedetection-iozekker6Verified publisher1.101.01See more

changedetection-io zekker6 1.101.0

1 container image this version deploys carries CVE-2026-11822.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.6eb4a9f718801
sqlite3@3.40.1-2+deb12u2
no fix listed

Open the chart page →

NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-11822.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2

Open the chart page →

1,861
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-11822.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
sqlite3@3.22.0-1ubuntu0.4
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

9,272

Container images carrying it

1,559 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
cloudve/ttyd:latestd79c1c5881c0
sqlite3@3.22.0-1ubuntu0.4
no fix listed
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
sqlite3@3.40.1-2+deb12u2
no fix listed
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
sqlite3@3.40.1-2+deb12u2
no fix listed
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
sqlite3@3.40.1-2+deb12u2
no fix listed
1
cm2network/squad:latest8cba47f53df5
sqlite3@3.46.1-7
3.46.1-7+deb13u2
1
codedesignplus/ms-emails-grpc:lateste336012bc781
sqlite3@3.40.1-2+deb12u2
no fix listed
1
codedesignplus/ms-emails-rest:latestac84661c605e
sqlite3@3.40.1-2+deb12u2
no fix listed
1
collabora/code:24.04.13.2.101dc4ab83977
sqlite3@3.40.1-2+deb12u1
no fix listed
1
collabora/code:23.05.10.1.105299b452f7f
sqlite3@3.40.1-2
no fix listed
1
conductoross/conductor:3.31.09fba127693e6
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2
1
cortezaproject/corteza:2024.9.08eb7a26605c9
sqlite3@3.31.1-4ubuntu0.6
no fix listed
1
coturn/coturn:4.10.0-r1f4c2af06c3c5
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2
1
countly/countly-server:25.05.4e3c238248f99
sqlite3@3.31.1-4ubuntu0.6
no fix listed
1
cribl/cribl:3.0.2762747cb6796
sqlite3@3.22.0-1ubuntu0.4
no fix listed
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
sqlite3@3.11.0-1ubuntu1.5
no fix listed
1
cspconsole/config-provider:1.0.365524a26a6c23
sqlite3@3.40.1-2+deb12u2
no fix listed
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
sqlite3@3.40.1-2+deb12u2
no fix listed
1
cspconsole/report-collector:1.0.15839750248193b
sqlite3@3.40.1-2+deb12u2
no fix listed
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
sqlite3@3.46.1-7
3.46.1-7+deb13u2
1
cznic/knot-resolver:v6.4.2fe71c5214fdc
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2
1
dagster/dagster-celery-k8s:1.13.230505973033e1
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2
1
dagster/dagster-cloud-agent:1.13.2322036fc83927
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2
1
dalibo/explain.dalibo.com:2.20.12a0b749c2f7f
sqlite@3.51.2-r0
3.53.4-r0
1
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
sqlite3@3.40.1-2+deb12u2
no fix listed
1
daskdev/dask-notebook:1.1.0052630f5ca04
sqlite3@3.22.0-1
no fix listed
1
datalust/seq:5.0.832-pre9c731bb207a6
sqlite3@3.11.0-1ubuntu1
no fix listed
1
datamate/seafile-professional:11.0.202dd66b722464
sqlite3@3.37.2-2ubuntu0.5
3.37.2-2ubuntu0.6
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
sqlite3@3.40.1-2
no fix listed
1
ddosify/selfhosted_backend:3.2.93c11e3182652
sqlite3@3.40.1-2
no fix listed
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
sqlite3@3.40.1-2
no fix listed
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
sqlite3@3.40.1-2
no fix listed
1
decisionrules/ai-engine:latest38c377e7c01e
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2
1
deconzcommunity/deconz:2.29.2062de2362641
sqlite3@3.40.1-2+deb12u1
no fix listed
1
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
sqlite3@3.31.1-4ubuntu0.4
no fix listed
1
defectdojo/defectdojo-django:3.3.100c597abdbb535
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2
1
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
sqlite3@3.46.1-7
3.46.1-7+deb13u2
1
dellcloud/category:distributed02fc234353a9
sqlite3@3.31.1-4ubuntu0.2
no fix listed
1
dellcloud/pages:1.04d2eb25b9225
sqlite3@3.31.1-4ubuntu0.2
no fix listed
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2
1
dependencytrack/apiserver:latestf1da63ed610a
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2
1
devopsgoofy/k8s-platform:latestad865312099f
sqlite3@3.40.1-2+deb12u1
no fix listed
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
sqlite3@3.40.1-2+deb12u1
no fix listed
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
sqlite3@3.31.1-4ubuntu0.3
no fix listed
1
diygod/rsshub:latest1d4b508b6357
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2
1
djjudas21/alertify:0.1.0ba22be670c37
sqlite3@3.40.1-2+deb12u1
no fix listed
1
dniel/api-posts:master45a667852f2a
sqlite3@3.22.0-1ubuntu0.1
no fix listed
1
dobtc/bitcoin:25.1a870f7cb1105
sqlite3@3.40.1-2
no fix listed
1
docmost/docmost:0.96.0b56947fcfd08
sqlite3@3.46.1-7+deb13u1
3.46.1-7+deb13u2
1
docuseal/docuseal:2.4.17493fd7f6728
sqlite@3.51.2-r0
3.53.4-r0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.