StackRadar

CVE-2026-2436

High

Advisory

Published 26 Mar 2026In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
None
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
libsoup3deb3.0.7-0ubuntu1, 3.2.2-2, 3.4.4-5ubuntu0.5, 3.4.4-5ubuntu0.7+2 moreno fix listed8
libsoup2.4deb2.74.3-1+deb12u1no fix listed2
OSV records
DEBIAN-CVE-2026-2436UBUNTU-CVE-2026-2436

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
selenium-gridselenium-grid0.59.12 of 4See more

selenium-grid selenium-grid 0.59.1

2 of the 4 container images this version deploys carry CVE-2026-2436.

Container imageDigestPackageFixed in
selenium/node-chrome:4.48.0-202609055ac71fd8dd1e
libsoup3@3.4.4-5ubuntu0.7
no fix listed
selenium/node-firefox:4.48.0-2026090574a5c1c90f95
libsoup3@3.4.4-5ubuntu0.7
no fix listed

Open the chart page →

7,028
photoprismandrenarchyVerified publisher8.15.01 of 1See more

photoprism andrenarchy 8.15.0

1 of the 1 container images this version deploys carry CVE-2026-2436.

Container imageDigestPackageFixed in
photoprism/photoprism:260728958642220223
libsoup3@3.6.6-1
no fix listed

Open the chart page →

8,825
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-2436.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
libsoup3@3.6.5-4
no fix listed

Open the chart page →

11,103
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-2436.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
libsoup2.4@2.74.3-1+deb12u1
libsoup3@3.2.2-2
no fix listed
no fix listed

Open the chart page →

12,958
hydrahydraVerified publisher0.9.51 of 2See more

hydra hydra 0.9.5

1 of the 2 container images this version deploys carry CVE-2026-2436.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
libsoup2.4@2.74.3-1+deb12u1
no fix listed

Open the chart page →

9,011
isolated-vmhydraVerified publisher0.9.41 of 1See more

isolated-vm hydra 0.9.4

1 of the 1 container images this version deploys carry CVE-2026-2436.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
libsoup2.4@2.74.3-1+deb12u1
no fix listed

Open the chart page →

7,733
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-2436.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
libsoup3@3.6.6-1
no fix listed

Open the chart page →

10,348
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-2436.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libsoup3@3.4.4-5ubuntu0.5
no fix listed

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-2436.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libsoup3@3.4.4-5ubuntu0.5
no fix listed

Open the chart page →

12,460
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-2436.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libsoup3@3.0.7-0ubuntu1
no fix listed

Open the chart page →

14,100

Container images carrying it

9 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kurento/kurento-media-server:latest03c0d34d0828
libsoup3@3.4.4-5ubuntu0.5
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
libsoup2.4@2.74.3-1+deb12u1
no fix listed
2
jaedb/iris:latest048cfbf58d57
libsoup2.4@2.74.3-1+deb12u1
libsoup3@3.2.2-2
no fix listed
no fix listed
1
photoprism/photoprism:260601650c6ad5a651
libsoup3@3.6.6-1
no fix listed
1
photoprism/photoprism:260728958642220223
libsoup3@3.6.6-1
no fix listed
1
photoprism/photoprism:251130db16ee6b1ba3
libsoup3@3.6.5-4
no fix listed
1
selenium/node-chrome:4.48.0-202609055ac71fd8dd1e
libsoup3@3.4.4-5ubuntu0.7
no fix listed
1
selenium/node-firefox:4.48.0-2026090574a5c1c90f95
libsoup3@3.4.4-5ubuntu0.7
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libsoup3@3.0.7-0ubuntu1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.