StackRadar

CVE-2026-13757

Medium

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,252
of 17,797 indexed, latest versions
Container images
2,262
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: p11-kit security update

Carried by container images the latest versions of 2,252 of 17,797 indexed charts deploy, on 2,262 images.

Affected packageAffected versionsFixed inImages
p11-kitdeb0.23.9-2, 0.23.9-2ubuntu0.1, 0.23.20-1build1, 0.23.20-1ubuntu0.1+8 more0.23.9-2ubuntu0.1+esm1, 0.23.20-1ubuntu0.1+esm1, 0.24.0-6ubuntu0.1, 0.25.3-4ubuntu2.2+1 more2,098
p11-kitrpm0.24.1-2.el9, 0.25.0-1.azl3, 0.25.3-2.el9, 0.25.3-3.el9_5+2 more0:0.26.4-1.el9_8, 0:0.26.4-1.el10_2, 0.26.5-1164
OSV records
DEBIAN-CVE-2026-13757RHSA-2026:49667RHSA-2026:49668RLSA-2026:49667RLSA-2026:49668UBUNTU-CVE-2026-13757AZL-91743ECHO-e3a5-7704-649f
Also known as
USN-8687-1

Charts affected

2,252 by stars
ChartLatestAffected imagesRadar Score
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-13757.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
p11-kit@0.23.9-2ubuntu0.1
0.23.9-2ubuntu0.1+esm1
yandex/clickhouse-server:21.3.204eccfffb01d7
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1

Open the chart page →

9,272
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-13757.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1

Open the chart page →

7,936

Container images carrying it

2,262 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
uffizzi/controller:latest0344805f267b
p11-kit@0.24.1-2
no fix listed
2
vaultwarden/server:1.37.31587c45feaa4
p11-kit@0.25.5-3
no fix listed
2
vdiogov/glpi-conteiner:latest6945f84f0058
p11-kit@0.24.1-2
no fix listed
2
wolveix/satisfactory-server:latest:v1.9.10e103700ae6ae
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
2
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
2
ghcr.io/api7/adc:0.27.1f65f53dd9668
p11-kit@0.24.1-2
no fix listed
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
2
ghcr.io/astriaorg/conductor:latest3ea8164b0eae
p11-kit@0.24.1-2
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
p11-kit@0.24.1-2
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
p11-kit@0.24.1-2
no fix listed
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
p11-kit@0.24.1-2
no fix listed
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
p11-kit@0.24.1-2
no fix listed
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
p11-kit@0.24.1-2
no fix listed
2
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
p11-kit@0.23.9-2
0.23.9-2ubuntu0.1+esm1
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
p11-kit@0.24.1-2
no fix listed
2
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
p11-kit@0.24.1-2
no fix listed
2
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
p11-kit@0.24.1-2
no fix listed
2
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
p11-kit@0.24.1-2
no fix listed
2
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
p11-kit@0.24.1-2
no fix listed
2
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
p11-kit@0.24.1-2
no fix listed
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
2
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
p11-kit@0.24.1-2
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
p11-kit@0.24.1-2
no fix listed
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
2
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2:latestb53a854bd7c1
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
p11-kit@0.25.3-3.el9_5
0:0.26.4-1.el9_8
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
2
quay.io/keycloak/keycloak:26.1.4044a457e0498
p11-kit@0.25.3-3.el9_5
0:0.26.4-1.el9_8
2
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
p11-kit@0.25.3-3.el9_5
0:0.26.4-1.el9_8
2
quay.io/strimzi/drain-cleaner:1.6.15fb28e9f30d0
p11-kit@0.26.2-1.el9
0:0.26.4-1.el9_8
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
p11-kit@0.25.3-3.el9_5
0:0.26.4-1.el9_8
2
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
p11-kit@0.25.3-3.el9_5
0:0.26.4-1.el9_8
2
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
p11-kit@0.24.1-2
no fix listed
2
1dev/server:11.9.0cd5b12fe5471
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
p11-kit@0.24.1-2
no fix listed
1
5200710/hadoop:3.2.3-java8092d3088a5fb
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
a10networks/acos-prometheus-exporter:latest8dc58d434d71
p11-kit@0.23.9-2
0.23.9-2ubuntu0.1+esm1
1
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
p11-kit@0.25.5-3
no fix listed
1
aboogie/login_test_backend:new9c41a4483ac8
p11-kit@0.24.1-2
no fix listed
1
actualbudget/actual-server:25.3.158fecd9088b7
p11-kit@0.24.1-2
no fix listed
1
adamzammit/limesurvey:7.1.1fdb06d62c22e
p11-kit@0.25.5-3
no fix listed
1
adeptiainc/adeptia-connect-migration:4.8.1f1087da3da0b
p11-kit@0.26.2-1.el9
0:0.26.4-1.el9_8
1
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.