StackRadar

CVE-2026-18649

High

Advisory

Published 6 Aug 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
gst-plugins-good1.0deb1.14.5-0ubuntu1~18.04.1, 1.16.2-1ubuntu2.1, 1.16.3-0ubuntu1.1, 1.16.3-0ubuntu1.3+5 moreno fix listed11
OSV records
DEBIAN-CVE-2026-18649UBUNTU-CVE-2026-18649

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
smarter-demosmarterOfficialVerified publisher0.1.52 of 7See more

smarter-demo smarter 0.1.5

2 of the 7 container images this version deploys carry CVE-2026-18649.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
gst-plugins-good1.0@1.16.3-0ubuntu1.1
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
gst-plugins-good1.0@1.16.3-0ubuntu1.1
no fix listed

Open the chart page →

45,832
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-18649.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
gst-plugins-good1.0@1.16.3-0ubuntu1.3
no fix listed

Open the chart page →

64,489
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-18649.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
gst-plugins-good1.0@1.22.0-5+deb12u2
no fix listed

Open the chart page →

12,958
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-18649.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
gst-plugins-good1.0@1.16.3-0ubuntu1.1
no fix listed

Open the chart page →

27,949
hydrahydraVerified publisher0.9.51 of 2See more

hydra hydra 0.9.5

1 of the 2 container images this version deploys carry CVE-2026-18649.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
gst-plugins-good1.0@1.22.0-5+deb12u3
no fix listed

Open the chart page →

9,011
isolated-vmhydraVerified publisher0.9.41 of 1See more

isolated-vm hydra 0.9.4

1 of the 1 container images this version deploys carry CVE-2026-18649.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
gst-plugins-good1.0@1.22.0-5+deb12u3
no fix listed

Open the chart page →

7,733
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-18649.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
gst-plugins-good1.0@1.16.2-1ubuntu2.1
no fix listed

Open the chart page →

18,066
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-18649.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
gst-plugins-good1.0@1.14.5-0ubuntu1~18.04.1
no fix listed

Open the chart page →

27,633
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18649.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
gst-plugins-good1.0@1.20.3-0ubuntu1.5
no fix listed

Open the chart page →

7,295
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-18649.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
gst-plugins-good1.0@1.24.2-1ubuntu1.2
no fix listed

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-18649.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
gst-plugins-good1.0@1.24.2-1ubuntu1.2
no fix listed

Open the chart page →

12,460
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-18649.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
gst-plugins-good1.0@1.20.3-0ubuntu1.1
no fix listed

Open the chart page →

14,100

Container images carrying it

11 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
kurento/kurento-media-server:latest03c0d34d0828
gst-plugins-good1.0@1.24.2-1ubuntu1.2
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
gst-plugins-good1.0@1.22.0-5+deb12u3
no fix listed
2
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
gst-plugins-good1.0@1.16.3-0ubuntu1.3
no fix listed
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
gst-plugins-good1.0@1.16.2-1ubuntu2.1
no fix listed
1
jaedb/iris:latest048cfbf58d57
gst-plugins-good1.0@1.22.0-5+deb12u2
no fix listed
1
openkm/openkm-ce:6.3.113bc465a7461b
gst-plugins-good1.0@1.16.3-0ubuntu1.1
no fix listed
1
scrapinghub/splash:3.4.1a5f89bc84606
gst-plugins-good1.0@1.14.5-0ubuntu1~18.04.1
no fix listed
1
trueosiris/vrising:latest9356f98ad561
gst-plugins-good1.0@1.20.3-0ubuntu1.5
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
gst-plugins-good1.0@1.20.3-0ubuntu1.1
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
gst-plugins-good1.0@1.16.3-0ubuntu1.1
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
gst-plugins-good1.0@1.16.3-0ubuntu1.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.