StackRadar

CVE-2026-15146

Medium

Advisory

Published 10 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
505
of 17,787 indexed, latest versions
Container images
488
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 505 of 17,787 indexed charts deploy, on 488 images.

Affected packageAffected versionsFixed inImages
wgetdeb1.15-1ubuntu1, 1.15-1ubuntu1.14.04.1, 1.15-1ubuntu1.14.04.4, 1.17.1-1ubuntu1.3+17 more1.15-1ubuntu1.14.04.5+esm3, 1.17.1-1ubuntu1.5+esm4, 1.19.4-1ubuntu2.2+esm4, 1.20.3-1ubuntu2.1+esm3+3 more488
OSV records
DEBIAN-CVE-2026-15146UBUNTU-CVE-2026-15146
Also known as
USN-8572-1

Charts affected

505 by stars
ChartLatestAffected imagesRadar Score
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-15146.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
wget@1.21.3-1+deb12u1
no fix listed

Open the chart page →

8,824
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-15146.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
wget@1.21.2-2ubuntu1
1.21.2-2ubuntu1.4

Open the chart page →

9,296
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-15146.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
wget@1.21.2-2ubuntu1.1
1.21.2-2ubuntu1.4

Open the chart page →

14,172
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-15146.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
wget@1.21.3-1+b2
no fix listed

Open the chart page →

13,197
clickhousezloi-space1.2.01 of 3See more

clickhouse zloi-space 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-15146.

Container imageDigestPackageFixed in
yandex/clickhouse-server:21.3.204eccfffb01d7
wget@1.20.3-1ubuntu2
1.20.3-1ubuntu2.1+esm3

Open the chart page →

9,250

Container images carrying it

488 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
wget@1.20.3-1ubuntu2
1.20.3-1ubuntu2.1+esm3
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
wget@1.25.0-2ubuntu4
1.25.0-2ubuntu4.3
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
wget@1.25.0-2
no fix listed
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
wget@1.21.3-1+deb12u1
no fix listed
1
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest917e53402d51
wget@1.25.0-2
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
wget@1.21.3-1+b2
no fix listed
1
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
wget@1.20.3-1ubuntu2
1.20.3-1ubuntu2.1+esm3
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
wget@1.20.3-1ubuntu2
1.20.3-1ubuntu2.1+esm3
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
wget@1.21.3-1+deb12u1
no fix listed
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
wget@1.21.3-1+b2
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
wget@1.21.3-1+b2
no fix listed
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
wget@1.21.3-1+b2
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
wget@1.21.3-1+b2
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
wget@1.21.3-1+b2
no fix listed
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
wget@1.19.4-1ubuntu2.2
1.19.4-1ubuntu2.2+esm4
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
wget@1.20.3-1ubuntu2
1.20.3-1ubuntu2.1+esm3
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
wget@1.21.2-2ubuntu1.1
1.21.2-2ubuntu1.4
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
wget@1.19.4-1ubuntu2.2
1.19.4-1ubuntu2.2+esm4
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
wget@1.21.3-1+b2
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
wget@1.21.3-1+b2
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
wget@1.21.3-1+b2
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
wget@1.21.3-1+b2
no fix listed
1
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
wget@1.25.0-2
no fix listed
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
wget@1.21.2-2ubuntu1
1.21.2-2ubuntu1.4
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
wget@1.25.0-2
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
wget@1.21.3-1+b2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
wget@1.21.3-1+deb12u1
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
wget@1.21.3-1+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.