StackRadar

CVE-2026-24401

Medium

Advisory

Published 24 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
211
of 17,781 indexed, latest versions
Container images
178
deployed by those charts
Fix available
2 of 2
affected packages

Security update for avahi

Carried by container images the latest versions of 211 of 17,781 indexed charts deploy, on 178 images.

Affected packageAffected versionsFixed inImages
avahideb0.6.31-4ubuntu1, 0.6.31-4ubuntu1.2, 0.6.32~rc+dfsg-1ubuntu2, 0.6.32~rc+dfsg-1ubuntu2.2+17 more0.6.31-4ubuntu1.3+esm5, 0.6.32~rc+dfsg-1ubuntu2.3+esm5, 0.7-3.1ubuntu1.3+esm4, 0.7-4ubuntu7.3+esm2+3 more177
avahirpm0.8-150600.15.9.10.8-150600.15.15.11
OSV records
DEBIAN-CVE-2026-24401UBUNTU-CVE-2026-24401SUSE-SU-2026:1441-1
Also known as
USN-8269-1

Charts affected

211 by stars
ChartLatestAffected imagesRadar Score
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-24401.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
avahi@0.8-13ubuntu6
0.8-13ubuntu6.2

Open the chart page →

12,460
flaresolverrsudo-kraken-flaresolverrVerified publisher2.1.41 of 1See more

flaresolverr sudo-kraken-flaresolverr 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-24401.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
avahi@0.8-10+deb12u1
no fix listed

Open the chart page →

33,583
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-24401.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
avahi@0.7-4ubuntu7.2
0.7-4ubuntu7.3+esm2

Open the chart page →

18,756
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-24401.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
avahi@0.8-13ubuntu6
0.8-13ubuntu6.2

Open the chart page →

8,193
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-24401.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
avahi@0.7-4ubuntu7.3
0.7-4ubuntu7.3+esm2

Open the chart page →

10,006
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-24401.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
avahi@0.8-13ubuntu6.1
0.8-13ubuntu6.2

Open the chart page →

4,305
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-24401.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
avahi@0.8-13ubuntu6
0.8-13ubuntu6.2

Open the chart page →

7,628
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-24401.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
avahi@0.7-4ubuntu7.1
0.7-4ubuntu7.3+esm2

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-24401.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
avahi@0.7-4ubuntu7.1
0.7-4ubuntu7.3+esm2

Open the chart page →

28,605
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-24401.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
avahi@0.8-16
no fix listed

Open the chart page →

5,560
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-24401.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
avahi@0.8-5ubuntu5.2
0.8-5ubuntu5.5

Open the chart page →

14,100

Container images carrying it

178 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
avahi@0.7-4ubuntu7.1
0.7-4ubuntu7.3+esm2
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
avahi@0.7-4ubuntu7.1
0.7-4ubuntu7.3+esm2
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
avahi@0.7-4ubuntu7.1
0.7-4ubuntu7.3+esm2
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
avahi@0.8-10+deb12u1
no fix listed
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
avahi@0.7-3.1ubuntu1.3
0.7-3.1ubuntu1.3+esm4
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
avahi@0.8-10+deb12u1
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
avahi@0.8-10+deb12u1
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
avahi@0.8-16
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
avahi@0.8-10+deb12u1
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
avahi@0.8-10
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
avahi@0.7-4ubuntu7.1
0.7-4ubuntu7.3+esm2
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
avahi@0.8-10
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
avahi@0.8-16
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
avahi@0.8-16
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
avahi@0.8-16
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
avahi@0.8-10
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
avahi@0.8-16
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
avahi@0.7-4ubuntu7.1
0.7-4ubuntu7.3+esm2
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
avahi@0.7-4ubuntu7.1
0.7-4ubuntu7.3+esm2
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
avahi@0.8-13ubuntu6.1
0.8-13ubuntu6.2
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
avahi@0.8-5ubuntu5.2
0.8-5ubuntu5.5
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
avahi@0.8-5ubuntu5.2
0.8-5ubuntu5.5
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
avahi@0.8-5ubuntu5.2
0.8-5ubuntu5.5
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
avahi@0.8-10
no fix listed
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
avahi@0.8-10+deb12u1
no fix listed
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
avahi@0.8-10+deb12u1
no fix listed
1
ghcr.io/zammad/zammad:7.1.3-0011e65123a43ecc
avahi@0.8-16
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
avahi@0.6.32~rc+dfsg-1ubuntu2.3
0.6.32~rc+dfsg-1ubuntu2.3+esm5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.