StackRadar

CVE-2026-15146

Medium

Advisory

Published 10 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
505
of 17,781 indexed, latest versions
Container images
488
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 505 of 17,781 indexed charts deploy, on 488 images.

Affected packageAffected versionsFixed inImages
wgetdeb1.15-1ubuntu1, 1.15-1ubuntu1.14.04.1, 1.15-1ubuntu1.14.04.4, 1.17.1-1ubuntu1.3+17 more1.15-1ubuntu1.14.04.5+esm3, 1.17.1-1ubuntu1.5+esm4, 1.19.4-1ubuntu2.2+esm4, 1.20.3-1ubuntu2.1+esm3+3 more488
OSV records
DEBIAN-CVE-2026-15146UBUNTU-CVE-2026-15146
Also known as
USN-8572-1

Charts affected

505 by stars
ChartLatestAffected imagesRadar Score
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-15146.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
wget@1.21.3-1+deb12u1
no fix listed

Open the chart page →

9,117
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-15146.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
wget@1.21.2-2ubuntu1
1.21.2-2ubuntu1.4

Open the chart page →

9,248
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-15146.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
wget@1.21.2-2ubuntu1.1
1.21.2-2ubuntu1.4

Open the chart page →

14,100
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-15146.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
wget@1.21.3-1+b2
no fix listed

Open the chart page →

13,677
clickhousezloi-space1.2.01 of 3See more

clickhouse zloi-space 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-15146.

Container imageDigestPackageFixed in
yandex/clickhouse-server:21.3.204eccfffb01d7
wget@1.20.3-1ubuntu2
1.20.3-1ubuntu2.1+esm3

Open the chart page →

9,207

Container images carrying it

488 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
wget@1.20.3-1ubuntu1
1.20.3-1ubuntu2.1+esm3
1
aktosecurity/data-ingestion-service213aded7adc5
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
wget@1.25.0-2ubuntu4
1.25.0-2ubuntu4.3
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
wget@1.25.0-2ubuntu4
1.25.0-2ubuntu4.3
1
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
wget@1.21.2-2ubuntu1.1
1.21.2-2ubuntu1.4
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
wget@1.21.2-2ubuntu1.1
1.21.2-2ubuntu1.4
1
anguda/ant-media:2.5c435285fc241
wget@1.20.3-1ubuntu2
1.20.3-1ubuntu2.1+esm3
1
anujdatar/cups:25.07.01685df04a643b
wget@1.21.3-1+deb12u1
no fix listed
1
apache/activemq-artemis:2.44.00305c26f19ed
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
apache/activemq-artemis:2.37.0bae523439ee3
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
wget@1.21.2-2ubuntu1.1
1.21.2-2ubuntu1.4
1
apache/hertzbeat:1.8.075d48a62748f
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
apache/nifi-registry:1.27.063b8e3e40742
wget@1.21.2-2ubuntu1.1
1.21.2-2ubuntu1.4
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
wget@1.21.2-2ubuntu1
1.21.2-2ubuntu1.4
1
apachepulsar/pulsar:3.0.79c9947de139d
wget@1.21.2-2ubuntu1.1
1.21.2-2ubuntu1.4
1
apache/ranger:2.7.076c176e8a0e4
wget@1.21.2-2ubuntu1.1
1.21.2-2ubuntu1.4
1
apache/rocketmq:5.3.0434d8398f996
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
apache/rocketmq-exporter:0.0.2c8fb51195444
wget@1.21.2-2ubuntu1
1.21.2-2ubuntu1.4
1
apache/skywalking-oap-server:9.2.0133d35d2c263
wget@1.21.2-2ubuntu1
1.21.2-2ubuntu1.4
1
apache/skywalking-ui:9.2.0295f1dc87d98
wget@1.21.2-2ubuntu1
1.21.2-2ubuntu1.4
1
archivebox/archivebox:0.7.41a5a37331091
wget@1.21.3-1+deb12u1
no fix listed
1
aristidetm/basic-notebook:3.6.5469dbc951224
wget@1.21.3-1+b2
no fix listed
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
wget@1.21.3-1+b2
no fix listed
1
arunvelsriram/utils:latest655ad18fd8d6
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
wget@1.20.3-1ubuntu2
1.20.3-1ubuntu2.1+esm3
1
assistiot/location_processing:lateste9bae124095f
wget@1.21.2-2ubuntu1
1.21.2-2ubuntu1.4
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
wget@1.21.3-1+b2
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
wget@1.20.3-1ubuntu2
1.20.3-1ubuntu2.1+esm3
1
atlassian/confluence-server:7.10.03b9222ab32ef
wget@1.21.2-2ubuntu1
1.21.2-2ubuntu1.4
1
atlassian/jira-software:8.14.037bc46cbec1a
wget@1.21.2-2ubuntu1
1.21.2-2ubuntu1.4
1
atlassian/jira-software:9.7.264a75aa4ec4e
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
avinash263/pyredis263:latestaa2b8727f1a6
wget@1.21.3-1+b2
no fix listed
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
wget@1.21.3-1+deb12u1
no fix listed
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
wget@1.20.3-1ubuntu2
1.20.3-1ubuntu2.1+esm3
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
wget@1.20.3-1ubuntu2
1.20.3-1ubuntu2.1+esm3
1
blockstream/bitcoind:27.29472492530e3
wget@1.21.3-1+b2
no fix listed
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
wget@1.21.3-1+b2
no fix listed
1
bnjbvr/kresus:0.22.137e216b182c8
wget@1.21.3-1+b2
no fix listed
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
wget@1.20.3-1ubuntu1
1.20.3-1ubuntu2.1+esm3
1
budibase/database:2.1.0d90f656261c9
wget@1.21.3-1+deb12u1
no fix listed
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
wget@1.21.3-1+b2
no fix listed
1
castlemock/castlemock:latestb7f3f1527ba9
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
wget@1.21.4-1ubuntu4.1
1.21.4-1ubuntu4.4
1
chetangautamm/repo:sipp.v3e7f7049e1544
wget@1.20.3-1ubuntu1
1.20.3-1ubuntu2.1+esm3
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
wget@1.25.0-2
no fix listed
1
chriseaton/adventureworks:latest54c3384ce701
wget@1.21.2-2ubuntu1.1
1.21.2-2ubuntu1.4
1
circleci/runner:launch-agent9bdc62f02162
wget@1.20.3-1ubuntu2.1
1.20.3-1ubuntu2.1+esm3
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
wget@1.21.2-2ubuntu1.1
1.21.2-2ubuntu1.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.