StackRadar

CVE-2026-14681

Medium

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.2
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
120
of 17,781 indexed, latest versions
Container images
106
deployed by those charts
Fix available
5 of 6
affected packages

PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL

Carried by container images the latest versions of 120 of 17,781 indexed charts deploy, on 106 images.

Affected packageAffected versionsFixed inImages
postgresql-17deb17.5-1, 17.5-1.pgdg130+1, 17.6-0+deb13u1, 17.6-2.pgdg13+1+7 more17.11, 17.11-0+deb13u155
postgresql18apk18.1-r0, 18.2-r0, 18.3-r0, 18.4-r018.5-r026
postgresql17apk17.2-r0, 17.4-r0, 17.5-r0, 17.6-r0+3 more17.11-r012
postgresqlbitnami17.2.0-1, 17.2.0-4, 17.4.0-9, 17.5.0-9+4 more17.11.08
postgresql-18deb18.4-0ubuntu0.26.04.1, 18.4-1.pgdg26.04+118.6-0ubuntu0.26.04.14
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
OSV records
ALPINE-CVE-2026-14681BIT-postgresql-2026-14681DEBIAN-CVE-2026-14681UBUNTU-CVE-2026-14681ECHO-1690-243f-9082
Also known as
USN-8653-1

Charts affected

120 by stars
ChartLatestAffected imagesRadar Score
pgbouncerpostgres-pgbouncerVerified publisher0.4.01 of 1See more

pgbouncer postgres-pgbouncer 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
edoburu/pgbouncer:latest4c1ca296ef52
postgresql18@18.4-r0
18.5-r0

Open the chart page →

651
prompt-dbprompt-dbVerified publisher1.0.71 of 3See more

prompt-db prompt-db 1.0.7

1 of the 3 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
ghcr.io/erlkoenig91/prompt-db-backend:1.0.7ab120359810d
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1

Open the chart page →

3,332
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
postgresql@17.5.0-11
17.11.0

Open the chart page →

15,591
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
postgresql-17@17.6-0+deb13u1
17.11-0+deb13u1

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
postgresql17@17.7-r0
17.11-r0

Open the chart page →

4,499
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
postgresql@17.2.0-1
17.11.0

Open the chart page →

7,413
linkdingrubxkubeVerified publisher1.2.31 of 1See more

linkding rubxkube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.46.20c0a9a04c7eb
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1

Open the chart page →

2,051
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
postgresql-17@17.6-0+deb13u1
17.11-0+deb13u1

Open the chart page →

9,534
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
postgresql-17@17.6-0+deb13u1
17.11-0+deb13u1

Open the chart page →

9,755
pev2schichtelVerified publisher0.3.01 of 1See more

pev2 schichtel 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
dalibo/explain.dalibo.com:2.20.12a0b749c2f7f
postgresql18@18.2-r0
18.5-r0

Open the chart page →

1,178
teamspeak3schichtelVerified publisher1.0.21 of 1See more

teamspeak3 schichtel 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
library/teamspeak:3.13.74d3fa1c0db9a
postgresql18@18.3-r0
18.5-r0

Open the chart page →

774
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
postgresql-18@18.4-0ubuntu0.26.04.1
18.6-0ubuntu0.26.04.1

Open the chart page →

10,348
smtpsmtpVerified publisher1.3.31 of 1See more

smtp smtp 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
postgresql18@18.4-r0
18.5-r0

Open the chart page →

1,437
servicexssl-hep1.8.59 of 16See more

servicex ssl-hep 1.8.5

9 of the 16 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
sslhep/servicex_app:v1.8.51d12f943cec5
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1

Open the chart page →

66,266
mybbsudermanjr0.1.01 of 3See more

mybb sudermanjr 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
mybb/mybb:1.8f2a54bce31c5
postgresql18@18.4-r0
18.5-r0

Open the chart page →

2,157
teamspeaksyntaxerror404Verified publisher1.0.101 of 1See more

teamspeak syntaxerror404 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
library/teamspeak:3.13.815acbc64c92f
postgresql18@18.4-r0
18.5-r0

Open the chart page →

449
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
17.11.0

Open the chart page →

5,535
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
postgresql18@18.4-r0
18.5-r0

Open the chart page →

5,550
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
postgresql17@17.5-r0
17.11-r0

Open the chart page →

14,983
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-14681.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
17.11.0

Open the chart page →

7,624

Container images carrying it

106 by charts deploying them

A fixed version is listed for 5 of the 6 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
17.11.0
11
bitnamilegacy/postgresql:17.5.0:latest42a8200d3597
postgresql@17.5.0-14
17.11.0
5
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
postgresql@17.6.0-0
17.11.0
4
opencsghq/psql:latest57def8e77d0f
postgresql17@17.2-r0
17.11-r0
3
vaultwarden/server:1.37.1ebdfe70701c6
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
3
fireflyiii/core:version-6.5.9fe4ecec4c2ba
postgresql-17@17.8-0+deb13u1
17.11-0+deb13u1
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
postgresql-17@17.9-0+deb13u1
17.11-0+deb13u1
2
taigaio/taiga-back:latest4beed8f62c9f
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
2
alpine/psql:18.339824ef2b7fc
postgresql18@18.3-r0
18.5-r0
1
appwrite/appwrite:1.9.01aaa70127114
postgresql18@18.2-r0
18.5-r0
1
appwrite/appwrite:1.9.6adc7d0e7ec23
postgresql18@18.4-r0
18.5-r0
1
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
postgresql@17.5.0-11
17.11.0
1
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
postgresql@17.5.0-9
17.11.0
1
bitnamilegacy/postgresql:17.2.0-debian-12-r5cf63048c9209
postgresql@17.2.0-4
17.11.0
1
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
postgresql@17.2.0-1
17.11.0
1
bitnamilegacy/postgresql:17.4.0-debian-12-r11fb3806e823c2
postgresql@17.4.0-9
17.11.0
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
postgresql18@18.3-r0
18.5-r0
1
boky/postfix:5.1.0aafc77238423
postgresql-17@17.6-0+deb13u1
17.11-0+deb13u1
1
budibase/apps:3.41.344fe6feab985
postgresql18@18.4-r0
18.5-r0
1
castopod/castopod:1.15.54e4f0440520f
postgresql-17@17.8-0+deb13u1
17.11-0+deb13u1
1
chatwoot/chatwoot:v4.15.167ebc751c171
postgresql17@17.10-r0
17.11-r0
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
postgresql-17@17.9-0+deb13u1
17.11-0+deb13u1
1
coturn/coturn:4.10.0-r1f4c2af06c3c5
postgresql-17@17.9-0+deb13u1
17.11-0+deb13u1
1
cr0hn/ja-shortener:v0.1.414482d0bc4a1
postgresql17@17.5-r0
17.11-r0
1
dalibo/explain.dalibo.com:2.20.12a0b749c2f7f
postgresql18@18.2-r0
18.5-r0
1
docuseal/docuseal:2.4.17493fd7f6728
postgresql18@18.3-r0
18.5-r0
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
postgresql-17@17.6-0+deb13u1
17.11-0+deb13u1
1
edoburu/pgbouncer:latest4c1ca296ef52
postgresql18@18.4-r0
18.5-r0
1
espocrm/espocrm:9.3.101b5a24504ed9
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
1
fireflyiii/core:version-6.6.6ae69fdd95cde
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
1
fluent/fluent-bit:4.2.6a52221a2a3eb
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
1
galaxy/galaxy-stable:v18.018e577a626dfd
postgresql-9.3@9.3.22-0ubuntu0.14.04
no fix listed
1
grafana/oncall:v1.16.5499851658393
postgresql17@17.6-r0
17.11-r0
1
huacnlee/gobackup:v3.1.1560be93229a5
postgresql18@18.4-r0
18.5-r0
1
jupyterjsc/jupyterhub-outpost:2.3.1aea53b13f235
postgresql18@18.4-r0
18.5-r0
1
library/adminer:5.4.2-standalone983261ecc40a
postgresql18@18.4-r0
18.5-r0
1
library/monica:4.1.2-fpm-alpine6d1b2bd0947e
postgresql18@18.4-r0
18.5-r0
1
library/nextcloud:31.0.10-apacheb7faa1653c39
postgresql-17@17.6-0+deb13u1
17.11-0+deb13u1
1
library/postgres:17.5aadf2c0696f5
postgresql-17@17.5-1.pgdg130+1
17.11-0+deb13u1
1
library/postgres:17.10ebba4f4de37f
postgresql-17@17.10-1.pgdg13+1
17.11-0+deb13u1
1
library/python:3.9da5aee29682d
postgresql-17@17.6-0+deb13u1
17.11-0+deb13u1
1
library/redmine:6.1.204ac44a2595b
postgresql-17@17.10-0+deb13u1
17.11-0+deb13u1
1
library/teamspeak:3.13.815acbc64c92f
postgresql18@18.4-r0
18.5-r0
1
library/teamspeak:3.13.74d3fa1c0db9a
postgresql18@18.3-r0
18.5-r0
1
linkstackorg/linkstack:latest1c8b05399ee4
postgresql17@17.8-r0
17.11-r0
1
lissy93/domain-locker:latestd3c95edc0a8b
postgresql18@18.3-r0
18.5-r0
1
mindsdb/mindsdb:latest163011c09299
postgresql-17@17.9-0+deb13u1
17.11-0+deb13u1
1
mybb/mybb:1.8f2a54bce31c5
postgresql18@18.4-r0
18.5-r0
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
postgresql-18@18.4-0ubuntu0.26.04.1
18.6-0ubuntu0.26.04.1
1
novosga/novosga:latest34b9acbe6e51
postgresql18@18.3-r0
18.5-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.