StackRadar

CVE-2026-13757

Medium

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,261
of 17,805 indexed, latest versions
Container images
2,255
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: p11-kit security update

Carried by container images the latest versions of 2,261 of 17,805 indexed charts deploy, on 2,255 images.

Affected packageAffected versionsFixed inImages
p11-kitdeb0.23.9-2, 0.23.9-2ubuntu0.1, 0.23.20-1build1, 0.23.20-1ubuntu0.1+8 more0.23.9-2ubuntu0.1+esm1, 0.23.20-1ubuntu0.1+esm1, 0.24.0-6ubuntu0.1, 0.25.3-4ubuntu2.2+1 more2,091
p11-kitrpm0.24.1-2.el9, 0.25.0-1.azl3, 0.25.3-2.el9, 0.25.3-3.el9_5+2 more0:0.26.4-1.el9_8, 0:0.26.4-1.el10_2, 0.26.5-1164
OSV records
DEBIAN-CVE-2026-13757RHSA-2026:49667RHSA-2026:49668RLSA-2026:49667RLSA-2026:49668UBUNTU-CVE-2026-13757AZL-91743ECHO-e3a5-7704-649f
Also known as
USN-8687-1

Charts affected

2,261 by stars
ChartLatestAffected imagesRadar Score
xkopsxkops0.1.04 of 5See more

xkops xkops 0.1.0

4 of the 5 container images this version deploys carry CVE-2026-13757.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
p11-kit@0.24.1-2
no fix listed
hamzaarshad10/querypodpy:1.7154f38e8668e
p11-kit@0.24.1-2
no fix listed
library/mongo:latest5211c51171f5
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
murtazashah46/helmfile:latest4d11726cf803
p11-kit@0.24.1-2
no fix listed

Open the chart page →

13,875
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-13757.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
p11-kit@0.25.3-4ubuntu2
0.25.3-4ubuntu2.2

Open the chart page →

2,156
nightingalexxl-job-adminVerified publisher0.2.111See more

nightingale xxl-job-admin 0.2.11

1 container image this version deploys carries CVE-2026-13757.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2

Open the chart page →

pgcatxxl-job-adminVerified publisher0.3.31See more

pgcat xxl-job-admin 0.3.3

1 container image this version deploys carries CVE-2026-13757.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
p11-kit@0.24.1-2
no fix listed

Open the chart page →

nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13757.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
p11-kit@0.25.5-3
no fix listed

Open the chart page →

1,879
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13757.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
p11-kit@0.25.5-3
no fix listed

Open the chart page →

1,879
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13757.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
p11-kit@0.24.1-2
no fix listed

Open the chart page →

2,710
changedetection-iozekker6Verified publisher1.102.01See more

changedetection-io zekker6 1.102.0

1 container image this version deploys carries CVE-2026-13757.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
p11-kit@0.24.1-2
no fix listed

Open the chart page →

NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-13757.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
p11-kit@0.25.5-3
no fix listed

Open the chart page →

1,879
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-13757.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
p11-kit@0.23.9-2ubuntu0.1
0.23.9-2ubuntu0.1+esm1
yandex/clickhouse-server:21.3.204eccfffb01d7
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1

Open the chart page →

9,280
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-13757.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1

Open the chart page →

7,949

Container images carrying it

2,255 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quickwit/quickwit:v0.8.1d29332bdadcc
p11-kit@0.24.1-2
no fix listed
1
qumine/minecraft-server:v0.1.15c0b650d51132
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
qxip/qryn:3.2.3977acc9c7a9fd
p11-kit@0.24.1-2
no fix listed
1
rabeh/apibootspring:1.0941007b6946e
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
radondb/clickhouse-server:v21.1.3.32-stable4732df471073
p11-kit@0.23.9-2ubuntu0.1
0.23.9-2ubuntu0.1+esm1
1
razorbladex401/dayz:latest6a4d79248e7d
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
razzy10/product-service:latest702e411956db
p11-kit@0.25.3-3.el9_5
0:0.26.4-1.el9_8
1
readysettech/sqp:latest588f3507280e
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
readysettech/sqp-duckdb:latest67a83203ce60
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
reallibrephotos/librephotos-proxy:1.0.398a13dabbadc
p11-kit@0.25.5-3
no fix listed
1
redash/redash:25.8.000d813437db5
p11-kit@0.24.1-2
no fix listed
1
redash/redash:26.3.0c5c9148f5c38
p11-kit@0.24.1-2
no fix listed
1
redimp/otterwiki:2778bf30da3da
p11-kit@0.24.1-2
no fix listed
1
redislabs/operator:8.0.18-119078e713bb6a
p11-kit@0.25.3-3.el9_5
0:0.26.4-1.el9_8
1
redis/redis-stack-server:6.2.6-v251a58f32d412
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
redis/redis-stack-server:latest798ab84d9f26
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
redis/redis-stack-server:7.4.0-v0887cf87cc744
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
redpandadata/redpanda:latest468bd13a9f2b
p11-kit@0.25.5-3
no fix listed
1
resurfaceio/resurface:3.7.84d5cda2f64109
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
rezachalak/bzen-mongo:1.0.034f694325191
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
rhasspy/wyoming-piper:2.3.169b7f797ae3a
p11-kit@0.24.1-2
no fix listed
1
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
p11-kit@0.24.1-2
no fix listed
1
rhasspy/wyoming-whisper:3.5.0308b7959a925
p11-kit@0.24.1-2
no fix listed
1
rm3l/dev-feed-api:latest9a7f732245a3
p11-kit@0.24.1-2.el9
0:0.26.4-1.el9_8
1
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
rnwood/smtp4dev:3.6.1912304153668
p11-kit@0.24.1-2
no fix listed
1
robotshop/rs-mongodb:latest119b545823cd
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
rocketadmin/rocketadmin:1.17.710955ef540b9
p11-kit@0.24.1-2
no fix listed
1
rocketchat/freeswitch:stablecfba5c20a5cc
p11-kit@0.24.1-2
no fix listed
1
rotationalio/endeavor:1.3.0ac566baddc06
p11-kit@0.24.1-2
no fix listed
1
rotationalio/genoa:1.2.03ab583519215
p11-kit@0.24.1-2
no fix listed
1
rotationalio/honu:0.5.069fd30c2e31c
p11-kit@0.24.1-2
no fix listed
1
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
p11-kit@0.25.5-3
no fix listed
1
rraahul/test:latestbfe2c1183bc0
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
rrobetti/ojp:0.1.0-beta1141bd88232b
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
rstmdb/rstmdb:lateste5187f2aaace
p11-kit@0.24.1-2
no fix listed
1
rtuszik/photon-docker:2.4.021549c60f9e6
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
ryshe/terraria:latestb1c89f7f359a
p11-kit@0.24.1-2
no fix listed
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
ryuunosukeds3/orbital:latest0879f7261b10
p11-kit@0.24.1-2
no fix listed
1
salaboy/agenda-service-0967b907d9920c99918e2b91b91937b3ce9ce8293e4e
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
salaboy/c4p-service-a3dc0474cbfa348afcdf47a8eee70ba9bb64bf14467d
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
salaboy/notifications-service-0e27884e01429ab7e350cb5dff61b525799c35f9f306
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
santisbon/evwatcher:latestc4e994ca4540
p11-kit@0.24.1-2
no fix listed
1
santisbon/evworker:lateste807283f8d69
p11-kit@0.24.1-2
no fix listed
1
santisbon/speedtest:latest8ee3a1697227
p11-kit@0.24.1-2
no fix listed
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
p11-kit@0.24.1-2
no fix listed
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
p11-kit@0.24.1-2
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.