StackRadar

CVE-2026-14680

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
319
of 17,781 indexed, latest versions
Container images
305
deployed by those charts
Fix available
9 of 13
affected packages

PostgreSQL type confusion via "internal" arguments

Carried by container images the latest versions of 319 of 17,781 indexed charts deploy, on 305 images.

Affected packageAffected versionsFixed inImages
postgresql-15deb15.3-0+deb12u1, 15.3-1.pgdg120+1, 15.4-2.pgdg120+1, 15.5-0+deb12u1+13 more15.19-0+deb12u1121
postgresql-17deb17.5-1, 17.5-1.pgdg130+1, 17.6-0+deb13u1, 17.6-2.pgdg13+1+7 more17.11, 17.11-0+deb13u155
postgresqlbitnami11.8.0-10, 11.12.0-7, 14.4.0-0, 14.4.0-11+25 more14.24.030
postgresql18apk18.1-r0, 18.2-r0, 18.3-r0, 18.4-r018.5-r026
postgresql-14deb14.3-1.pgdg22.04+1, 14.4-0ubuntu0.22.04.1, 14.5-0ubuntu0.22.04.1, 14.6-1.pgdg22.04+1+6 more14.24-0ubuntu0.22.04.118
postgresql-12deb12.7-0ubuntu0.20.04.1, 12.8-0ubuntu0.20.04.1, 12.9-0ubuntu0.20.04.1, 12.11-0ubuntu0.20.04.1+2 moreno fix listed17
postgresql17apk17.2-r0, 17.4-r0, 17.5-r0, 17.6-r0+3 more17.11-r012
PostgreSQLbitnami15.3.0, 15.4.0, 15.5.0-42, 16.0.0+6 more14.24.011
postgresql-16deb16.2-1ubuntu4, 16.6-0ubuntu0.24.04.1, 16.9-0ubuntu0.24.04.1, 16.10-0ubuntu0.24.04.1+2 more16.15-0ubuntu0.24.04.111
postgresql-10deb10.6-0ubuntu0.18.04.1, 10.10-0ubuntu0.18.04.1, 10.12-0ubuntu0.18.04.1, 10.14-0ubuntu0.18.04.1+1 moreno fix listed6
postgresql-18deb18.4-0ubuntu0.26.04.1, 18.4-1.pgdg26.04+118.6-0ubuntu0.26.04.14
postgresql-9.5deb9.5.10-0ubuntu0.16.04, 9.5.14-0ubuntu0.16.04no fix listed3
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
OSV records
ALPINE-CVE-2026-14680BIT-postgresql-2026-14680DEBIAN-CVE-2026-14680UBUNTU-CVE-2026-14680ECHO-cc36-987c-913e
Also known as
USN-8653-1

Charts affected

319 by stars
ChartLatestAffected imagesRadar Score
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
postgresql-15@15.8-0+deb12u1
15.19-0+deb12u1

Open the chart page →

11,648
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
postgresql-15@15.6-0+deb12u1
15.19-0+deb12u1

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
postgresql-15@15.6-0+deb12u1
15.19-0+deb12u1

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
postgresql-15@15.6-0+deb12u1
15.19-0+deb12u1

Open the chart page →

28,858
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
postgresql-15@15.13-0+deb12u1
15.19-0+deb12u1

Open the chart page →

10,086
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
postgresql-12@12.19-0ubuntu0.20.04.1
no fix listed

Open the chart page →

10,006
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
14.24.0

Open the chart page →

5,535
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
postgresql-15@15.5-0+deb12u1
15.19-0+deb12u1

Open the chart page →

17,323
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
postgresql18@18.4-r0
18.5-r0

Open the chart page →

5,550
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
postgresql-16@16.2-1ubuntu4
16.15-0ubuntu0.24.04.1

Open the chart page →

45,239
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
postgresql-15@15.3-0+deb12u1
15.19-0+deb12u1

Open the chart page →

14,358
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
postgresql-15@15.10-0+deb12u1
15.19-0+deb12u1

Open the chart page →

10,795
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
postgresql-14@14.11-1.pgdg22.04+1
14.24-0ubuntu0.22.04.1

Open the chart page →

13,459
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
postgresql-15@15.6-0+deb12u1
15.19-0+deb12u1

Open the chart page →

7,085
giteawenerme12.7.01 of 4See more

gitea wenerme 12.7.0

1 of the 4 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
postgresql-15@15.13-0+deb12u1
15.19-0+deb12u1

Open the chart page →

8,811
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
postgresql17@17.5-r0
17.11-r0

Open the chart page →

14,983
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
14.24.0

Open the chart page →

7,624
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
postgresql@16.6.0-1
14.24.0

Open the chart page →

11,577
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-14680.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
postgresql-14@14.23-0ubuntu0.22.04.1
14.24-0ubuntu0.22.04.1

Open the chart page →

7,849

Container images carrying it

305 by charts deploying them

A fixed version is listed for 9 of the 13 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
postgresql-17@17.8-0+deb13u1
17.11-0+deb13u1
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
postgresql-15@15.7-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/home-operations/bazarr:1.5.680cb090162b4
postgresql18@18.4-r0
18.5-r0
1
ghcr.io/home-operations/bazarr:1.6.0cd63bbd0986c
postgresql18@18.4-r0
18.5-r0
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
postgresql18@18.2-r0
18.5-r0
1
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
postgresql-17@17.10-1.pgdg13+1
17.11-0+deb13u1
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
postgresql-17@17.6-2.pgdg13+1
17.11-0+deb13u1
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
postgresql-15@15.10-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/kubelauncher/postgresql1a27e11e5925
postgresql-18@18.4-1.pgdg26.04+1
18.6-0ubuntu0.26.04.1
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
postgresql-15@15.8-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
postgresql17@17.4-r0
17.11-r0
1
ghcr.io/linuxserver/syslog-ng:4.10.247fae7f540f9
postgresql18@18.4-r0
18.5-r0
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
postgresql-15@15.10-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/monicahq/monica-next:main8be69156acbb
postgresql-17@17.5-1
17.11-0+deb13u1
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
1
ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0dcb8c731bb1b
postgresql17@17.8-r0
17.11-r0
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
postgresql-15@15.7-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
postgresql-15@15.14-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
postgresql-15@15.13-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
postgresql-15@15.18-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
postgresql-15@15.10-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
postgresql-15@15.8-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
postgresql-17@17.9-0+deb13u1
17.11-0+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
postgresql-17@17.6-0+deb13u1
17.11-0+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
postgresql-17@17.6-0+deb13u1
17.11-0+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
postgresql-15@15.5-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
postgresql-17@17.9-0+deb13u1
17.11-0+deb13u1
1
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
postgresql-15@15.8-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
postgresql-15@15.10-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
postgresql-17@17.6-0+deb13u1
17.11-0+deb13u1
1
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
postgresql-15@15.13-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
postgresql-15@15.15-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
postgresql-15@15.5-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
postgresql-15@15.10-0+deb12u1
15.19-0+deb12u1
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
postgresql-15@15.10-0+deb12u1
15.19-0+deb12u1
1
public.ecr.aws/datadog/cloudprem:v0.1.33bda08753668d
postgresql-16@16.14-0ubuntu0.24.04.1
16.15-0ubuntu0.24.04.1
1
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
postgresql-17@17.10-1.pgdg13+1+e1
17.11
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
postgresql-15@15.8-0+deb12u1
15.19-0+deb12u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
postgresql-15@15.6-0+deb12u1
15.19-0+deb12u1
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
postgresql-15@15.3-0+deb12u1
15.19-0+deb12u1
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
postgresql-15@15.8-0+deb12u1
15.19-0+deb12u1
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
postgresql-15@15.5-0+deb12u1
15.19-0+deb12u1
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
postgresql-15@15.16-0+deb12u1
15.19-0+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.