StackRadar

CVE-2026-15059

Medium

Advisory

Published 10 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,842
of 17,790 indexed, latest versions
Container images
1,807
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-15059 affecting package systemd for versions less than 255-34

Carried by container images the latest versions of 1,842 of 17,790 indexed charts deploy, on 1,807 images.

Affected packageAffected versionsFixed inImages
systemddeb249.11-0ubuntu3, 249.11-0ubuntu3.1, 249.11-0ubuntu3.3, 249.11-0ubuntu3.4+47 more249.11-0ubuntu3.22, 255.4-1ubuntu8.17, 257.13-1~deb13u1+e2, 259.5-0ubuntu3.41,802
systemdrpm255-33.azl3255-345
OSV records
DEBIAN-CVE-2026-15059UBUNTU-CVE-2026-15059AZL-95640ECHO-1f2a-a632-ee71
Also known as
USN-8626-1

Charts affected

1,842 by stars
ChartLatestAffected imagesRadar Score
redmineredmine-helm-chartVerified publisher0.2.61 of 1See more

redmine redmine-helm-chart 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

4,273
reportportalreportportal-ioOfficialVerified publisher26.8.123 of 15See more

reportportal reportportal-io 26.8.12

3 of the 15 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
systemd@252.38-1~deb12u1
no fix listed
library/postgres:18.4a02db8cac496
systemd@257.13-1~deb13u1
no fix listed
library/rabbitmq:4.3.4-managementeb5295d08332
systemd@255.4-1ubuntu8.16
255.4-1ubuntu8.17

Open the chart page →

11,993
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
systemd@249.11-0ubuntu3.12
249.11-0ubuntu3.22

Open the chart page →

7,489
retyc-csiretyc-csi0.2.01 of 3See more

retyc-csi retyc-csi 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
ghcr.io/retyc/retyc-k8s-csi:v0.2.01521d4baeb85
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,362
atuinrm3lVerified publisher0.11.02 of 3See more

atuin rm3l 0.11.0

2 of the 3 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r890fda44bfa42
systemd@252.22-1~deb12u1
no fix listed
ghcr.io/atuinsh/atuin:18.12.0e953fa9e36ef
systemd@252.39-1~deb12u1
no fix listed

Open the chart page →

6,570
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
systemd@252.26-1~deb12u2
no fix listed

Open the chart page →

9,913
kimai2robjuz5.0.141 of 2See more

kimai2 robjuz 5.0.14

1 of the 2 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
kimai/kimai2:2.67.03084f1e5ecdc
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

4,707
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
systemd@252.39-1~deb12u1
no fix listed

Open the chart page →

5,554
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
systemd@254.26-1~bpo12+1
no fix listed

Open the chart page →

7,814
kube-state-metricsromanow-helm-chartsVerified publisher1.7.21 of 1See more

kube-state-metrics romanow-helm-charts 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
bitnamilegacy/kube-state-metrics:204a3044b384b
systemd@252.38-1~deb12u1
no fix listed

Open the chart page →

2,684
postgresromanow-helm-chartsVerified publisher1.7.11 of 1See more

postgres romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,649
rstmdbrstmdb0.2.01 of 1See more

rstmdb rstmdb 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
rstmdb/rstmdb:lateste5187f2aaace
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

1,072
mealiertomik-helm-chartsVerified publisher0.0.21 of 1See more

mealie rtomik-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
systemd@257.7-1
no fix listed

Open the chart page →

3,952
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
systemd@252.38-1~deb12u1
no fix listed

Open the chart page →

5,332
kyoorubxkubeVerified publisher0.1.104 of 9See more

kyoo rubxkube 0.1.10

4 of the 9 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
systemd@252.31-1~deb12u1
no fix listed
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
systemd@252.31-1~deb12u1
no fix listed
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
systemd@252.31-1~deb12u1
no fix listed
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
systemd@252.31-1~deb12u1
no fix listed

Open the chart page →

30,428
conference-appsalaboy1.0.03 of 7See more

conference-app salaboy 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
salaboy/agenda-service-0967b907d9920c99918e2b91b91937b3digest-pinnedce9ce8293e4e
systemd@249.11-0ubuntu3.9
249.11-0ubuntu3.22
salaboy/c4p-service-a3dc0474cbfa348afcdf47a8eee70ba9digest-pinnedbb64bf14467d
systemd@249.11-0ubuntu3.9
249.11-0ubuntu3.22
salaboy/notifications-service-0e27884e01429ab7e350cb5dff61b525digest-pinned799c35f9f306
systemd@249.11-0ubuntu3.9
249.11-0ubuntu3.22

Open the chart page →

11,031
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
systemd@252.39-1~deb12u1
no fix listed

Open the chart page →

38,166
teamcityscalified-teamcityVerified publisher2026.2.01 of 3See more

teamcity scalified-teamcity 2026.2.0

1 of the 3 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,649
sceptresceptreai0.1.122 of 5See more

sceptre sceptreai 0.1.12

2 of the 5 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
maponyacharles/sceptreai:mlflow-0.1.1242d418654ebd
systemd@257.13-1~deb13u1
no fix listed
maponyacharles/sceptreai:api-0.1.127b37b092130a
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

4,424
schemaheroschemahero1.4.01 of 1See more

schemahero schemahero 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
schemahero/schemahero-manager:0.22.11609e1a05cd3
systemd@255.4-1ubuntu8.8
255.4-1ubuntu8.17

Open the chart page →

2,184
searxngsearxngVerified publisher0.1.111 of 3See more

searxng searxng 0.1.11

1 of the 3 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
valkey/valkey:9.1.1-trixie64e361b630ec
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

829
securosecuroVerified publisher0.15.12 of 4See more

securo securo 0.15.1

2 of the 4 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
pgvector/pgvector:pg16ccc6e83d6e35
systemd@252.39-1~deb12u2
no fix listed
ghcr.io/securo-finance/securo-backend:0.15.162e030110745
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

3,539
immichsecustorVerified publisher2.0.51 of 1See more

immich secustor 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.12ab6a6273755
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

3,081
viya4-home-dir-builderselerityVerified publisher1.1.01 of 2See more

viya4-home-dir-builder selerity 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
library/python:3.12-slim78387bc3881b
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

874
sentry-k8ssentry-k8sVerified publisher1.4.15 of 11See more

sentry-k8s sentry-k8s 1.4.1

5 of the 11 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
systemd@249.11-0ubuntu3.16
249.11-0ubuntu3.22
library/postgres:16f1c3376c26f2
systemd@257.13-1~deb13u1
no fix listed
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
systemd@252.33-1~deb12u1
no fix listed
ghcr.io/getsentry/snuba:26.7.210f8d164109b
systemd@257.9-1~deb13u1
no fix listed
ghcr.io/getsentry/taskbroker:26.7.264d0da74a578
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

16,599
vuiseriohub1.0.62 of 3See more

vui seriohub 1.0.6

2 of the 3 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
dserio83/velero-api:0.3.16b3d9115fee2
systemd@252.38-1~deb12u1
no fix listed
dserio83/velero-watchdog:0.1.8d5deae589229
systemd@252.36-1~deb12u1
no fix listed

Open the chart page →

11,578
sigscale-csesigscale-cseOfficialVerified publisher1.4.221 of 1See more

sigscale-cse sigscale-cse 1.4.22

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
sigscale/cse:latest67d0c886516b
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

2,297
sigscale-ocssigscale-ocsOfficialVerified publisher1.1.171 of 1See more

sigscale-ocs sigscale-ocs 1.1.17

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
sigscale/ocs:latest3c1bdc9732e2
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

2,297
clickhousesinextraVerified publisher0.22.01 of 1See more

clickhouse sinextra 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.3.1092098d3b31dd
systemd@249.11-0ubuntu3.20
249.11-0ubuntu3.22

Open the chart page →

2,015
mongodb-backupsinextraVerified publisher1.1.01 of 1See more

mongodb-backup sinextra 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
systemd@252.38-1~deb12u1
no fix listed

Open the chart page →

4,277
postgresql-singlesinextraVerified publisher1.15.11 of 1See more

postgresql-single sinextra 1.15.1

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

4,937
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
systemd@252.31-1~deb12u1
no fix listed

Open the chart page →

2,945
snappasssnappassVerified publisher0.4.32 of 3See more

snappass snappass 0.4.3

2 of the 3 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
systemd@257.9-1~deb13u1
no fix listed
valkey/valkey:8.1.61f84517eca8e
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

3,040
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
systemd@257.8-1~deb13u2
no fix listed

Open the chart page →

14,550
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

2,330
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

7,204
postgresql-ha-chartsoldevelo-postgresql-ha-chart16.3.42 of 2See more

postgresql-ha-chart soldevelo-postgresql-ha-chart 16.3.4

2 of the 2 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
soldevelo/pgpool:4.6.3-debian-12-r0044d16a65129
systemd@252.39-1~deb12u1
no fix listed
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

4,604
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
systemd@252.22-1~deb12u1
no fix listed

Open the chart page →

5,699
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
systemd@252.39-1~deb12u1
no fix listed

Open the chart page →

10,450
squidsquid-helmVerified publisher0.1.01 of 1See more

squid squid-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
ubuntu/squid:5.2-22.04_beta723891b5bc74
systemd@249.11-0ubuntu3.17
249.11-0ubuntu3.22

Open the chart page →

2,624
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
graphprotocol/graph-node:v0.37.0f4452cdedd68
systemd@252.31-1~deb12u1
no fix listed

Open the chart page →

4,694
stornxstornxVerified publisher1.1.13 of 9See more

stornx stornx 1.1.1

3 of the 9 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
systemd@255.4-1ubuntu8.12
255.4-1ubuntu8.17
alazidis/stornx:1.1.1602d4f7f090c
systemd@252.39-1~deb12u1
no fix listed
istio/pilot:1.29.1f8b0e412ac4a
systemd@255.4-1ubuntu8.12
255.4-1ubuntu8.17

Open the chart page →

11,735
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
systemd@255.4-1ubuntu8.15
255.4-1ubuntu8.17

Open the chart page →

2,881
supabasesupabse0.8.06 of 11See more

supabase supabse 0.8.0

6 of the 11 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.30.13b709e4a0e5e
systemd@255.4-1ubuntu8.11
255.4-1ubuntu8.17
kong/kong:3.9.16addf50e6bd8
systemd@255.4-1ubuntu8.6
255.4-1ubuntu8.17
supabase/edge-runtime:v1.74.02781daf92394
systemd@252.39-1~deb12u1
no fix listed
supabase/postgres-meta:v0.96.6a84cc713585e
systemd@252.39-1~deb12u1
no fix listed
supabase/realtime:v2.102.3aa1c92c0cf32
systemd@252.39-1~deb12u1
no fix listed
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

18,327
supersonicsupersonicVerified publisher0.3.11 of 2See more

supersonic supersonic 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.92956bd9de830
systemd@249.11-0ubuntu3.12
249.11-0ubuntu3.22

Open the chart page →

2,142
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

3,263
mumblesyntaxerror404Verified publisher1.0.41 of 1See more

mumble syntaxerror404 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
systemd@255.4-1ubuntu8.16
255.4-1ubuntu8.17

Open the chart page →

2,143
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,849
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,849
teamcity-serverteamcity-server3.3.51 of 2See more

teamcity-server teamcity-server 3.3.5

1 of the 2 container images this version deploys carry CVE-2026-15059.

Container imageDigestPackageFixed in
library/haproxy:3.2de601ccc9a79
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

846

Container images carrying it

1,807 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
systemd@252.17-1~deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
systemd@252.30-1~deb12u2
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
systemd@252.39-1~deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
systemd@252.36-1~deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
systemd@252.39-1~deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
systemd@252.39-1~deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
systemd@252.36-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.