StackRadar

CVE-2026-23469

Medium

Advisory

Published 3 Apr 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,803 indexed, latest versions
Container images
21
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 20 of 17,803 indexed charts deploy, on 21 images.

Affected packageAffected versionsFixed inImages
linuxdeb6.8.0-38.38, 6.8.0-39.39, 6.8.0-57.59, 6.8.0-60.63+10 more6.8.0-139.13921
OSV records
UBUNTU-CVE-2026-23469
Also known as
USN-8729-1

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
linux@6.8.0-88.89
6.8.0-139.139

Open the chart page →

70,047
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
linux@6.8.0-124.124
6.8.0-139.139

Open the chart page →

59,806
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
linux@6.8.0-138.138
6.8.0-139.139

Open the chart page →

32,151
nominatimrobjuz6.4.21 of 4See more

nominatim robjuz 6.4.2

1 of the 4 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
mediagis/nominatim:5.3.27923a8e67197
linux@6.8.0-124.124
6.8.0-139.139

Open the chart page →

46,200
craftycontrollerdrewburr-labs-helm-chartsVerified publisher0.3.01 of 1See more

craftycontroller drewburr-labs-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
linux@6.8.0-134.134
6.8.0-139.139

Open the chart page →

38,780
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
linux@6.8.0-57.59
6.8.0-139.139

Open the chart page →

64,698
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
linux@6.17.0-7.7
no fix listed

Open the chart page →

35,111
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
linux@6.8.0-136.136
6.8.0-139.139

Open the chart page →

51,893
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
linux@6.8.0-94.96
6.8.0-139.139

Open the chart page →

53,616
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
6.8.0-139.139

Open the chart page →

68,447
datumcosmicrocks1.0.51 of 2See more

datum cosmicrocks 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
linux@6.8.0-90.91
6.8.0-139.139

Open the chart page →

53,250
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:main-localda995c129e2f
linux@6.8.0-138.138
6.8.0-139.139

Open the chart page →

47,013
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
linux@6.8.0-38.38
6.8.0-139.139

Open the chart page →

87,945
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
linux@6.8.0-39.39
6.8.0-139.139

Open the chart page →

78,760
homebridgejespernohrVerified publisher0.2.01 of 1See more

homebridge jespernohr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
linux@6.8.0-138.138
6.8.0-139.139

Open the chart page →

29,715
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
6.8.0-139.139

Open the chart page →

62,809
homebridgelbenicio-communityVerified publisher0.1.151 of 1See more

homebridge lbenicio-community 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
linux@6.8.0-138.138
6.8.0-139.139

Open the chart page →

29,715
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.04 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

4 of the 40 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
linux@6.8.0-136.136
6.8.0-139.139
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
linux@6.8.0-136.136
6.8.0-139.139
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
linux@6.8.0-136.136
6.8.0-139.139
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
linux@6.8.0-136.136
6.8.0-139.139

Open the chart page →

184,580
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
linux@6.8.0-79.79
6.8.0-139.139

Open the chart page →

58,090
ocean-network-clientspot1.1.61 of 1See more

ocean-network-client spot 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-23469.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
linux@6.8.0-100.100
6.8.0-139.139

Open the chart page →

46,567

Container images carrying it

21 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
homebridge/homebridge:latest77c685a40911
linux@6.8.0-138.138
6.8.0-139.139
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
6.8.0-139.139
2
aktosecurity/data-ingestion-service213aded7adc5
linux@6.8.0-94.96
6.8.0-139.139
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
linux@6.8.0-138.138
6.8.0-139.139
1
grpl/grapple-cli:0.2.127c00aafee6629
linux@6.8.0-39.39
6.8.0-139.139
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
linux@6.8.0-124.124
6.8.0-139.139
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
linux@6.8.0-88.89
6.8.0-139.139
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
linux@6.8.0-138.138
6.8.0-139.139
1
mediagis/nominatim:5.3.27923a8e67197
linux@6.8.0-124.124
6.8.0-139.139
1
photoprism/photoprism:251130db16ee6b1ba3
linux@6.17.0-7.7
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
linux@6.8.0-38.38
6.8.0-139.139
1
qonstrukt/php:8.4-v8-apache089af7925aa1
linux@6.8.0-136.136
6.8.0-139.139
1
snipe/snipe-it:v8.3.1141ebf2386fe
linux@6.8.0-79.79
6.8.0-139.139
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
linux@6.8.0-90.91
6.8.0-139.139
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
linux@6.8.0-57.59
6.8.0-139.139
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
linux@6.8.0-136.136
6.8.0-139.139
1
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
linux@6.8.0-136.136
6.8.0-139.139
1
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
linux@6.8.0-136.136
6.8.0-139.139
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
linux@6.8.0-136.136
6.8.0-139.139
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
linux@6.8.0-100.100
6.8.0-139.139
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
linux@6.8.0-134.134
6.8.0-139.139
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.