StackRadar

CVE-2026-19248

High

Advisory

Published 16 Sept 2026In the index since 18 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,832 indexed, latest versions
Container images
10
deployed by those charts
Fix available
None
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 14 of 17,832 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
qtbase-opensource-srcdeb5.5.1+dfsg-16ubuntu7.5, 5.9.5+dfsg-0ubuntu2.6, 5.12.8+dfsg-0ubuntu1, 5.12.8+dfsg-0ubuntu2.1+4 moreno fix listed9
qt6-basedeb6.4.2+dfsg-21.1build5no fix listed1
OSV records
DEBIAN-CVE-2026-19248UBUNTU-CVE-2026-19248

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
games-on-whalesgeek-cookbookVerified publisher1.8.21 of 7See more

games-on-whales geek-cookbook 1.8.2

1 of the 7 container images this version deploys carry CVE-2026-19248.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
qtbase-opensource-src@5.12.8+dfsg-0ubuntu1
no fix listed

Open the chart page →

109,253
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-19248.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
qtbase-opensource-src@5.15.13+dfsg-1ubuntu1
no fix listed

Open the chart page →

55,964
mumblesyntaxerror404Verified publisher1.0.51 of 1See more

mumble syntaxerror404 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-19248.

Container imageDigestPackageFixed in
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
qt6-base@6.4.2+dfsg-21.1build5
no fix listed

Open the chart page →

2,240
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-19248.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
qtbase-opensource-src@5.12.8+dfsg-0ubuntu1
no fix listed

Open the chart page →

116,204
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-19248.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
qtbase-opensource-src@5.12.8+dfsg-0ubuntu2.1
no fix listed

Open the chart page →

111,098
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-19248.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
qtbase-opensource-src@5.12.8+dfsg-0ubuntu2.1
no fix listed

Open the chart page →

18,230
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-19248.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
qtbase-opensource-src@5.15.8+dfsg-11+deb12u2
no fix listed

Open the chart page →

11,081
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-19248.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
qtbase-opensource-src@5.15.3+dfsg-2ubuntu0.1
no fix listed

Open the chart page →

100,549
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2026-19248.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
qtbase-opensource-src@5.15.3+dfsg-2ubuntu0.1
no fix listed

Open the chart page →

100,549
sqlitebrowsernicholaswildeVerified publisher1.0.11 of 1See more

sqlitebrowser nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-19248.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
qtbase-opensource-src@5.9.5+dfsg-0ubuntu2.6
no fix listed

Open the chart page →

23,709
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-19248.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
qtbase-opensource-src@5.5.1+dfsg-16ubuntu7.5
no fix listed

Open the chart page →

63,904
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-19248.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
qtbase-opensource-src@5.5.1+dfsg-16ubuntu7.5
no fix listed

Open the chart page →

43,202
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-19248.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
qtbase-opensource-src@5.5.1+dfsg-16ubuntu7.5
no fix listed

Open the chart page →

29,624
deconzsmall-hack0.1.01 of 1See more

deconz small-hack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-19248.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.26.123c86008d73f
qtbase-opensource-src@5.15.8+dfsg-11
no fix listed

Open the chart page →

13,373

Container images carrying it

10 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
qtbase-opensource-src@5.5.1+dfsg-16ubuntu7.5
no fix listed
3
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
qtbase-opensource-src@5.15.3+dfsg-2ubuntu0.1
no fix listed
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
qtbase-opensource-src@5.12.8+dfsg-0ubuntu1
no fix listed
2
deconzcommunity/deconz:2.29.2062de2362641
qtbase-opensource-src@5.15.8+dfsg-11+deb12u2
no fix listed
1
deconzcommunity/deconz:2.26.123c86008d73f
qtbase-opensource-src@5.15.8+dfsg-11
no fix listed
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
qtbase-opensource-src@5.12.8+dfsg-0ubuntu2.1
no fix listed
1
qonstrukt/php:8.4-v8-apache089af7925aa1
qtbase-opensource-src@5.15.13+dfsg-1ubuntu1
no fix listed
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
qtbase-opensource-src@5.12.8+dfsg-0ubuntu2.1
no fix listed
1
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
qtbase-opensource-src@5.9.5+dfsg-0ubuntu2.6
no fix listed
1
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
qt6-base@6.4.2+dfsg-21.1build5
no fix listed
1

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.