StackRadar

CVE-2026-23459

High

Advisory

Published 3 Apr 2026In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.004
32nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
28
of 18,053 indexed, latest versions
Container images
29
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 28 of 18,053 indexed charts deploy, on 29 images.

Affected packageAffected versionsFixed inImages
linuxdeb6.8.0-38.38, 6.8.0-39.39, 6.8.0-57.59, 6.8.0-60.63+12 moreno fix listed29
OSV records
UBUNTU-CVE-2026-23459

Charts affected

28 by stars
ChartLatestAffected imagesRadar Score
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
linux@6.8.0-88.89
no fix listed

Open the chart page →

82,159
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
linux@6.8.0-124.124
no fix listed

Open the chart page →

72,701
bitbucketatlassian-data-centerVerified publisher2.0.171 of 1See more

bitbucket atlassian-data-center 2.0.17

1 of the 1 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
atlassian/bitbucket:10.2.85aed3d8cb4bc
linux@6.8.0-146.146
no fix listed

Open the chart page →

36,151
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
linux@6.8.0-138.138
no fix listed

Open the chart page →

41,747
bambooatlassian-data-centerVerified publisher2.0.171 of 2See more

bamboo atlassian-data-center 2.0.17

1 of the 2 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
atlassian/bamboo:12.1.12eb98d6fbeee7
linux@6.8.0-146.146
no fix listed

Open the chart page →

36,867
machinarislib42Verified publisher0.2.01 of 1See more

machinaris lib42 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
ghcr.io/guydavis/machinaris:test50a71a30f18e
linux@6.8.0-139.139
no fix listed

Open the chart page →

38,326
nominatimrobjuz6.4.21 of 4See more

nominatim robjuz 6.4.2

1 of the 4 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
mediagis/nominatim:5.3.27923a8e67197
linux@6.8.0-124.124
no fix listed

Open the chart page →

56,274
craftycontrollerdrewburr-labs-helm-chartsVerified publisher0.3.01 of 1See more

craftycontroller drewburr-labs-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
linux@6.8.0-139.139
no fix listed

Open the chart page →

38,558
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
linux@6.8.0-57.59
no fix listed

Open the chart page →

75,143
mend-renovate-enterprise-editionmend-renovateVerified publisher10.7.01 of 2See more

mend-renovate-enterprise-edition mend-renovate 10.7.0

1 of the 2 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
ghcr.io/mend/renovate-ee-server:15.7.063e0ca823222
linux@6.8.0-146.146
no fix listed

Open the chart page →

37,078
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
linux@6.17.0-7.7
no fix listed

Open the chart page →

36,798
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
linux@6.8.0-136.136
no fix listed

Open the chart page →

62,589
rstudio-pmrstudioVerified publisher0.20.51 of 1See more

rstudio-pm rstudio 0.20.5

1 of the 1 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
posit/package-manager:2026.09.0-ubuntu-24.0468d47a7a8166
linux@6.8.0-139.139
no fix listed

Open the chart page →

36,547
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
linux@6.8.0-139.139
no fix listed

Open the chart page →

40,513
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
linux@6.8.0-94.96
no fix listed

Open the chart page →

63,225
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
no fix listed

Open the chart page →

78,904
datumcosmicrocks1.0.51 of 2See more

datum cosmicrocks 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
linux@6.8.0-90.91
no fix listed

Open the chart page →

62,845
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:main-local4b07ca30ab2a
linux@6.8.0-146.146
no fix listed

Open the chart page →

56,064
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
linux@6.8.0-38.38
no fix listed

Open the chart page →

98,902
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
linux@6.8.0-39.39
no fix listed

Open the chart page →

89,412
homebridgejespernohrVerified publisher0.2.01 of 1See more

homebridge jespernohr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
homebridge/homebridge:latest22cdfca31934
linux@6.8.0-142.142
no fix listed

Open the chart page →

37,029
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
no fix listed

Open the chart page →

73,370
homebridgelbenicio-communityVerified publisher0.1.151 of 1See more

homebridge lbenicio-community 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
homebridge/homebridge:latest22cdfca31934
linux@6.8.0-142.142
no fix listed

Open the chart page →

37,029
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.04 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

4 of the 40 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
linux@6.8.0-136.136
no fix listed
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
linux@6.8.0-136.136
no fix listed
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
linux@6.8.0-136.136
no fix listed
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
linux@6.8.0-136.136
no fix listed

Open the chart page →

235,017
minecraftpaul1365972-mc3.0.11 of 1See more

minecraft paul1365972-mc 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
itzg/minecraft-server:latest7b728e72b26b
linux@6.8.0-146.146
no fix listed

Open the chart page →

39,123
seafileschmitzis13.0.131 of 4See more

seafile schmitzis 13.0.13

1 of the 4 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
schmitzis/monorepo:seafile-13.0-latestf7e51ba2fb07
linux@6.8.0-139.139
no fix listed

Open the chart page →

43,203
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
linux@6.8.0-79.79
no fix listed

Open the chart page →

68,485
ocean-network-clientspot1.1.61 of 1See more

ocean-network-client spot 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-23459.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
linux@6.8.0-100.100
no fix listed

Open the chart page →

56,095

Container images carrying it

29 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
homebridge/homebridge:latest22cdfca31934
linux@6.8.0-142.142
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
no fix listed
2
aktosecurity/data-ingestion-service213aded7adc5
linux@6.8.0-94.96
no fix listed
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
linux@6.8.0-138.138
no fix listed
1
atlassian/bamboo:12.1.12eb98d6fbeee7
linux@6.8.0-146.146
no fix listed
1
atlassian/bitbucket:10.2.85aed3d8cb4bc
linux@6.8.0-146.146
no fix listed
1
grpl/grapple-cli:0.2.127c00aafee6629
linux@6.8.0-39.39
no fix listed
1
itzg/minecraft-server:latest7b728e72b26b
linux@6.8.0-146.146
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
linux@6.8.0-124.124
no fix listed
1
langgenius/dify-plugin-daemon:main-local4b07ca30ab2a
linux@6.8.0-146.146
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
linux@6.8.0-88.89
no fix listed
1
mediagis/nominatim:5.3.27923a8e67197
linux@6.8.0-124.124
no fix listed
1
photoprism/photoprism:251130db16ee6b1ba3
linux@6.17.0-7.7
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
linux@6.8.0-38.38
no fix listed
1
posit/package-manager:2026.09.0-ubuntu-24.0468d47a7a8166
linux@6.8.0-139.139
no fix listed
1
qonstrukt/php:8.4-v8-apache089af7925aa1
linux@6.8.0-136.136
no fix listed
1
schmitzis/monorepo:seafile-13.0-latestf7e51ba2fb07
linux@6.8.0-139.139
no fix listed
1
snipe/snipe-it:v8.3.1141ebf2386fe
linux@6.8.0-79.79
no fix listed
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
linux@6.8.0-90.91
no fix listed
1
ghcr.io/guydavis/machinaris:test50a71a30f18e
linux@6.8.0-139.139
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
linux@6.8.0-57.59
no fix listed
1
ghcr.io/mend/renovate-ee-server:15.7.063e0ca823222
linux@6.8.0-146.146
no fix listed
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
linux@6.8.0-136.136
no fix listed
1
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
linux@6.8.0-136.136
no fix listed
1
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
linux@6.8.0-136.136
no fix listed
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
linux@6.8.0-136.136
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
linux@6.8.0-139.139
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
linux@6.8.0-100.100
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
linux@6.8.0-139.139
no fix listed
1

syft 1.42.1 · advisories as of 8 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.