StackRadar

CVE-2026-23865

Medium

Advisory

Published 2 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
147
of 17,781 indexed, latest versions
Container images
133
deployed by those charts
Fix available
8 of 8
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 147 of 17,781 indexed charts deploy, on 133 images.

Affected packageAffected versionsFixed inImages
freetypedeb2.13.2+dfsg-1build3, 2.13.3+dfsg-1, 2.13.3+dfsg-1build12.13.2+dfsg-1ubuntu0.1, 2.13.3+dfsg-1+deb13u1, 2.13.3+dfsg-1ubuntu0.173
openjdk-8deb8u151-b12-0ubuntu0.16.04.2, 8u171-b11-0ubuntu0.16.04.1, 8u191-b12-2ubuntu0.16.04.1, 8u212-b03-0ubuntu1.18.04.1+11 more8u492-ga~us2-0ubuntu1~16.04.1, 8u492-ga~us2-0ubuntu1~18.04.1, 8u492-ga~us2-0ubuntu1~20.04.1, 8u492-ga~us2-0ubuntu1~22.04.1+1 more22
javabitnami11.0.15-150, 11.0.18-10-1, 11.0.18-10-2, 11.0.20-8-3+12 more11.0.3116
openjdk-ltsdeb11.0.3+7-1ubuntu2~18.04.1, 11.0.8+10-0ubuntu1~18.04.1, 11.0.11+9-0ubuntu2~20.04, 11.0.13+8-0ubuntu1~20.04+6 more11.0.31+11-1ubuntu1~18.04.2, 11.0.31+11-1ubuntu1~20.04.2, 11.0.31+11-1ubuntu1~24.04.216
openjdk-17deb17.0.3+7-0ubuntu0.20.04.1, 17.0.8+7-1~22.04, 17.0.9+9-1~20.04, 17.0.10+7-1~22.04.1+3 more17.0.19+10-1~20.04.2, 17.0.19+10-1~22.04.2, 17.0.19+10-1~24.04.28
Javabitnami11.0.20-8, 11.0.21-10, 17.0.8-7, 17.0.10-13-1+2 more11.0.317
jrebitnami17.0.16-12-0, 17.0.19-11-2, 21.0.8-12-0, 21.0.9-15-011.0.314
openjdk-21deb21.0.5+11-1ubuntu1~24.04, 21.0.7+6~us1-0ubuntu1~24.04, 21.0.11~8ea-121.0.11+10-1~24.04.2, 21.0.11+10-1~26.04.24
OSV records
BIT-java-2026-23865BIT-jre-2026-23865DEBIAN-CVE-2026-23865UBUNTU-CVE-2026-23865
Also known as
BIT-java-min-2026-23865, DSA-6168-1, USN-8086-1, USN-8327-1, USN-8328-1, USN-8330-1, USN-8331-1

Charts affected

147 by stars
ChartLatestAffected imagesRadar Score
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
freetype@2.13.3+dfsg-1
2.13.3+dfsg-1+deb13u1

Open the chart page →

7,126
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
openjdk-lts@11.0.16+8-0ubuntu1~20.04
11.0.31+11-1ubuntu1~20.04.2

Open the chart page →

13,486
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
openjdk-lts@11.0.8+10-0ubuntu1~18.04.1
11.0.31+11-1ubuntu1~18.04.2

Open the chart page →

15,970
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
freetype@2.13.3+dfsg-1
2.13.3+dfsg-1+deb13u1

Open the chart page →

7,696
active-mqactivemq-helm-chartVerified publisher1.8.22 of 3See more

active-mq activemq-helm-chart 1.8.2

2 of the 3 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.44.00305c26f19ed
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1
bitnami/jmx-exporterdigest-pinned9cc4a173c69e
jre@17.0.19-11-2
11.0.31

Open the chart page →

3,188
akto-testing-db-layerakto1.42.161 of 2See more

akto-testing-db-layer akto 1.42.16

1 of the 2 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1

Open the chart page →

5,489
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1

Open the chart page →

3,442
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
openjdk-8@8u372-ga~us1-0ubuntu1~18.04
8u492-ga~us2-0ubuntu1~18.04.1

Open the chart page →

11,553
platform-apiappscodeVerified publisher2026.9.111 of 3See more

platform-api appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
freetype@2.13.3+dfsg-1
2.13.3+dfsg-1+deb13u1

Open the chart page →

37,268
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
freetype@2.13.3+dfsg-1
2.13.3+dfsg-1+deb13u1

Open the chart page →

7,489
arlas-aiasarlas-stackVerified publisher28.8.02 of 22See more

arlas-aias arlas-stack 28.8.0

2 of the 22 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
java@21.0.7-9-0
11.0.31
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
jre@21.0.8-12-0
11.0.31

Open the chart page →

40,238
dltkvassist-iot-data-integrity-verification0.2.02 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openjdk-8@8u171-b11-0ubuntu0.16.04.1
8u492-ga~us2-0ubuntu1~16.04.1
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openjdk-8@8u191-b12-2ubuntu0.16.04.1
8u492-ga~us2-0ubuntu1~16.04.1

Open the chart page →

77,706
dltflassist-iot-dlt-based-fl0.2.02 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openjdk-8@8u171-b11-0ubuntu0.16.04.1
8u492-ga~us2-0ubuntu1~16.04.1
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openjdk-8@8u191-b12-2ubuntu0.16.04.1
8u492-ga~us2-0ubuntu1~16.04.1

Open the chart page →

77,706
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
java@17.0.8-7-5
Java@17.0.8-7
11.0.31
11.0.31

Open the chart page →

9,722
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
freetype@2.13.2+dfsg-1build3
openjdk-21@21.0.7+6~us1-0ubuntu1~24.04
2.13.2+dfsg-1ubuntu0.1
21.0.11+10-1~24.04.2

Open the chart page →

14,352
puppetservercamptocamp31.0.11 of 2See more

puppetserver camptocamp3 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
openjdk-17@17.0.13+11-2ubuntu1~22.04
17.0.19+10-1~22.04.2

Open the chart page →

5,886
distributed-tensorflowcloudnativeapp0.1.11 of 1See more

distributed-tensorflow cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
cheyang/distributed-tf:1.6.046cc34755493
openjdk-8@8u151-b12-0ubuntu0.16.04.2
8u492-ga~us2-0ubuntu1~16.04.1

Open the chart page →

36,094
hlf-couchdbcloudnativeapp1.0.61 of 1See more

hlf-couchdb cloudnativeapp 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
hyperledger/fabric-couchdb:0.4.10c65891b6c237
openjdk-8@8u171-b11-0ubuntu0.16.04.1
8u492-ga~us2-0ubuntu1~16.04.1

Open the chart page →

33,963
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
openjdk-8@8u191-b12-2ubuntu0.16.04.1
8u492-ga~us2-0ubuntu1~16.04.1

Open the chart page →

23,665
seleniumcloudnativeapp1.0.81 of 1See more

selenium cloudnativeapp 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
openjdk-8@8u292-b10-0ubuntu1~20.04
8u492-ga~us2-0ubuntu1~20.04.1

Open the chart page →

11,782
unificloudnativeapp0.4.21 of 1See more

unifi cloudnativeapp 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
jacobalberty/unifi:5.10.19c409924e2463
openjdk-8@8u191-b12-2ubuntu0.16.04.1
8u492-ga~us2-0ubuntu1~16.04.1

Open the chart page →

22,442
clusterfactoryclusterfactory0.2.01 of 5See more

clusterfactory clusterfactory 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
freetype@2.13.3+dfsg-1
2.13.3+dfsg-1+deb13u1

Open the chart page →

7,168
gitea-jenkinsclusterfactory0.1.11 of 5See more

gitea-jenkins clusterfactory 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
freetype@2.13.3+dfsg-1
2.13.3+dfsg-1+deb13u1

Open the chart page →

5,238
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1

Open the chart page →

4,578
sumo-besu-genesisconsensys0.1.751 of 1See more

sumo-besu-genesis consensys 0.1.75

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
openjdk-17@17.0.3+7-0ubuntu0.20.04.1
17.0.19+10-1~20.04.2

Open the chart page →

7,963
sumo-besu-nodeconsensys0.1.751 of 4See more

sumo-besu-node consensys 0.1.75

1 of the 4 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
openjdk-17@17.0.3+7-0ubuntu0.20.04.1
17.0.19+10-1~20.04.2

Open the chart page →

7,963
datumcosmicrocks1.0.51 of 2See more

datum cosmicrocks 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1

Open the chart page →

2,944
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1

Open the chart page →

5,974
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1

Open the chart page →

16,954
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
openjdk-8@8u292-b10-0ubuntu1~20.04
8u492-ga~us2-0ubuntu1~20.04.1

Open the chart page →

11,782
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
openjdk-8@8u252-b09-1~16.04
8u492-ga~us2-0ubuntu1~16.04.1

Open the chart page →

19,802
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
freetype@2.13.3+dfsg-1
2.13.3+dfsg-1+deb13u1

Open the chart page →

13,391
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
openjdk-17@17.0.15+6~us1-0ubuntu1~20.04
17.0.19+10-1~20.04.2

Open the chart page →

7,268
wordpresseoc-chartsVerified publisher0.14.41 of 1See more

wordpress eoc-charts 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
library/wordpress:6.8.3-apache30bff39330d1
freetype@2.13.3+dfsg-1
2.13.3+dfsg-1+deb13u1

Open the chart page →

7,233
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.37.0bae523439ee3
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1

Open the chart page →

12,454
accumulogaffer2.2.12 of 4See more

accumulo gaffer 2.2.1

2 of the 4 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
freetype@2.13.2+dfsg-1build3
openjdk-8@8u442-b06~us1-0ubuntu1~24.04
2.13.2+dfsg-1ubuntu0.1
8u492-ga~us2-0ubuntu1~24.04.1
gchq/hdfs:3.3.35ec58edbb2db
freetype@2.13.2+dfsg-1build3
openjdk-8@8u442-b06~us1-0ubuntu1~24.04
2.13.2+dfsg-1ubuntu0.1
8u492-ga~us2-0ubuntu1~24.04.1

Open the chart page →

16,892
gaffer-road-trafficgaffer2.2.11 of 8See more

gaffer-road-traffic gaffer 2.2.1

1 of the 8 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
freetype@2.13.2+dfsg-1build3
openjdk-8@8u442-b06~us1-0ubuntu1~24.04
2.13.2+dfsg-1ubuntu0.1
8u492-ga~us2-0ubuntu1~24.04.1

Open the chart page →

9,342
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
openjdk-8@8u292-b10-0ubuntu1~18.04
8u492-ga~us2-0ubuntu1~18.04.1

Open the chart page →

19,215
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
openjdk-lts@11.0.11+9-0ubuntu2~20.04
11.0.31+11-1ubuntu1~20.04.2

Open the chart page →

17,702
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
openjdk-8@8u342-b07-0ubuntu1~20.04
8u492-ga~us2-0ubuntu1~20.04.1

Open the chart page →

27,949
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
openjdk-lts@11.0.8+10-0ubuntu1~18.04.1
11.0.31+11-1ubuntu1~18.04.2

Open the chart page →

26,944
rocketmqgengxiankun-charts0.3.01 of 1See more

rocketmq gengxiankun-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
apache/rocketmq:5.3.0434d8398f996
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1

Open the chart page →

4,921
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1

Open the chart page →

49,025
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
openjdk-lts@11.0.18+10-0ubuntu1~20.04.1
11.0.31+11-1ubuntu1~20.04.2

Open the chart page →

15,722
castopodhelmforgeVerified publisher1.2.71 of 3See more

castopod helmforge 1.2.7

1 of the 3 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
castopod/castopod:1.15.54e4f0440520f
freetype@2.13.3+dfsg-1
2.13.3+dfsg-1+deb13u1

Open the chart page →

9,342
chiefonboardinghelmforgeVerified publisher1.1.141 of 3See more

chiefonboarding helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
freetype@2.13.3+dfsg-1
2.13.3+dfsg-1+deb13u1

Open the chart page →

10,849
phpmyadminhelmforgeVerified publisher2.0.11 of 1See more

phpmyadmin helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.342a200db07b4
freetype@2.13.3+dfsg-1
2.13.3+dfsg-1+deb13u1

Open the chart page →

4,751
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
openbas/platform:2.0.5d986d80b0a75
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1

Open the chart page →

25,017
paperlesshpVerified publisher0.1.11 of 5See more

paperless hp 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-23865.

Container imageDigestPackageFixed in
apache/tika:3.3.1.090b7fa1dc018
openjdk-21@21.0.11~8ea-1
21.0.11+10-1~26.04.2

Open the chart page →

26,612

Container images carrying it

133 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openjdk-8@8u171-b11-0ubuntu0.16.04.1
8u492-ga~us2-0ubuntu1~16.04.1
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openjdk-8@8u191-b12-2ubuntu0.16.04.1
8u492-ga~us2-0ubuntu1~16.04.1
4
gchq/hdfs:3.3.35ec58edbb2db
freetype@2.13.2+dfsg-1build3
openjdk-8@8u442-b06~us1-0ubuntu1~24.04
2.13.2+dfsg-1ubuntu0.1
8u492-ga~us2-0ubuntu1~24.04.1
3
guacamole/guacamole:1.6.0f344085e618b
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1
3
jacobalberty/unifi:v10.0.162896c0ab82d33
openjdk-17@17.0.15+6~us1-0ubuntu1~20.04
17.0.19+10-1~20.04.2
3
selenium/hub:3.141.5902f251d48d5f
openjdk-8@8u292-b10-0ubuntu1~20.04
8u492-ga~us2-0ubuntu1~20.04.1
3
signoz/zookeeper:3.7.1fcc4a3288154
java@11.0.20-8-5
Java@11.0.20-8
11.0.31
11.0.31
3
apache/rocketmq:5.4.0319cd8a81ed1
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
freetype@2.13.2+dfsg-1build3
openjdk-17@17.0.11+9-1
2.13.2+dfsg-1ubuntu0.1
17.0.19+10-1~24.04.2
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
java@21.0.8-12-0
11.0.31
2
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
java@11.0.20-8-3
Java@11.0.20-8
11.0.31
11.0.31
2
hookiesolutions/webhookie:latest0629694246ba
openjdk-lts@11.0.11+9-0ubuntu2~20.04
11.0.31+11-1ubuntu1~20.04.2
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
openjdk-17@17.0.3+7-0ubuntu0.20.04.1
17.0.19+10-1~20.04.2
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
freetype@2.13.3+dfsg-1
2.13.3+dfsg-1+deb13u1
2
kurento/kurento-media-server:latest03c0d34d0828
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1
2
library/nginx:1.29.49dd288848f44
freetype@2.13.3+dfsg-1
2.13.3+dfsg-1+deb13u1
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
freetype@2.13.3+dfsg-1
2.13.3+dfsg-1+deb13u1
2
mbentley/omada-controller:4.3f4e682274bed
openjdk-8@8u372-ga~us1-0ubuntu1~18.04
8u492-ga~us2-0ubuntu1~18.04.1
2
opendatacube/ows:latest668cbb41473c
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
freetype@2.13.2+dfsg-1build3
openjdk-21@21.0.7+6~us1-0ubuntu1~24.04
2.13.2+dfsg-1ubuntu0.1
21.0.11+10-1~24.04.2
2
1dev/server:11.9.0cd5b12fe5471
freetype@2.13.2+dfsg-1build3
openjdk-lts@11.0.26+4-1ubuntu1~24.04
2.13.2+dfsg-1ubuntu0.1
11.0.31+11-1ubuntu1~24.04.2
1
5200710/hadoop:3.2.3-java8092d3088a5fb
openjdk-8@8u392-ga-1~20.04
8u492-ga~us2-0ubuntu1~20.04.1
1
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1
1
aktosecurity/data-ingestion-service213aded7adc5
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1
1
anguda/ant-media:2.5c435285fc241
openjdk-lts@11.0.18+10-0ubuntu1~20.04.1
11.0.31+11-1ubuntu1~20.04.2
1
apache/activemq-artemis:2.44.00305c26f19ed
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1
1
apache/activemq-artemis:2.37.0bae523439ee3
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1
1
apache/hertzbeat:1.8.075d48a62748f
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
openjdk-lts@11.0.13+8-0ubuntu1~20.04
11.0.31+11-1ubuntu1~20.04.2
1
apachepulsar/pulsar:2.9.0d056c89b7131
openjdk-lts@11.0.11+9-0ubuntu2~20.04
11.0.31+11-1ubuntu1~20.04.2
1
apachepulsar/pulsar:2.8.2d538416d5afe
openjdk-lts@11.0.13+8-0ubuntu1~20.04
11.0.31+11-1ubuntu1~20.04.2
1
apache/rocketmq:5.3.0434d8398f996
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1
1
apache/tika:3.3.1.090b7fa1dc018
openjdk-21@21.0.11~8ea-1
21.0.11+10-1~26.04.2
1
apache/tika:2.9.0.092d055a84e9e
openjdk-17@17.0.8+7-1~22.04
17.0.19+10-1~22.04.2
1
atlassian/jira-software:9.7.264a75aa4ec4e
freetype@2.13.2+dfsg-1build3
2.13.2+dfsg-1ubuntu0.1
1
bitnami/jmx-exporter9cc4a173c69e
jre@17.0.19-11-2
11.0.31
1
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
java@11.0.25-11-1
11.0.31
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
java@17.0.10-13-2
Java@17.0.10-13-2
11.0.31
11.0.31
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
java@17.0.10-13-1
Java@17.0.10-13-1
11.0.31
11.0.31
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
java@21.0.7-9-0
11.0.31
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
java@17.0.7-7-2
11.0.31
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
java@11.0.18-10-2
11.0.31
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
java@11.0.15-150
11.0.31
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
java@17.0.6-10-4
11.0.31
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
java@17.0.11-12-0
Java@17.0.11-12-0
11.0.31
11.0.31
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
jre@21.0.8-12-0
11.0.31
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
java@17.0.13-12-1
11.0.31
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.