StackRadar

CVE-2026-2447

High

Advisory

Published 16 Feb 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
67
of 17,781 indexed, latest versions
Container images
67
deployed by those charts
Fix available
1 of 1
affected package

libvpx - security update

Carried by container images the latest versions of 67 of 17,781 indexed charts deploy, on 67 images.

Affected packageAffected versionsFixed inImages
libvpxdeb1.3.0-2, 1.5.0-2ubuntu1, 1.7.0-3, 1.7.0-3ubuntu0.18.04.1+19 more1.9.0-1+deb11u5, 1.11.0-2ubuntu2.5, 1.12.0-1+deb12u5, 1.14.0-1ubuntu2.3+2 more67
OSV records
DEBIAN-CVE-2026-2447UBUNTU-CVE-2026-2447DLA-4489-1
Also known as
DSA-6143-1, USN-8053-1

Charts affected

67 by stars
ChartLatestAffected imagesRadar Score
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
libvpx@1.7.0-3ubuntu0.18.04.1
no fix listed

Open the chart page →

27,633
cdn-remoteopencord0.2.42 of 3See more

cdn-remote opencord 0.2.4

2 of the 3 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libvpx@1.7.0-3
no fix listed
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
libvpx@1.5.0-2ubuntu1
no fix listed

Open the chart page →

63,223
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libvpx@1.5.0-2ubuntu1
no fix listed

Open the chart page →

42,614
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libvpx@1.5.0-2ubuntu1
no fix listed

Open the chart page →

29,124
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libvpx@1.8.2-1build1
no fix listed

Open the chart page →

9,167
libretimepodzone-chartsVerified publisher0.4.12 of 9See more

libretime podzone-charts 0.4.1

2 of the 9 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-analyzer:latest3d5e236216ad
libvpx@1.9.0-1+deb11u4
1.9.0-1+deb11u5
ghcr.io/libretime/libretime-playout:latest71a8706531aa
libvpx@1.9.0-1+deb11u4
1.9.0-1+deb11u5

Open the chart page →

11,149
mastodonrivals-spaceVerified publisher3.1.21 of 3See more

mastodon rivals-space 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
libvpx@1.9.0-1
1.9.0-1+deb11u5

Open the chart page →

6,026
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
libvpx@1.15.0-2.1
1.15.0-2.1+deb13u1

Open the chart page →

10,605
nadekobotryuunosukeds30.1.21 of 2See more

nadekobot ryuunosukeds3 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
libvpx@1.11.0-2ubuntu2.3
1.11.0-2ubuntu2.5

Open the chart page →

8,619
jellyfinsb-helm-charts0.4.01 of 1See more

jellyfin sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.317c3a8d9dddb
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u5

Open the chart page →

4,105
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libvpx@1.14.0-1ubuntu2.2
1.14.0-1ubuntu2.3

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libvpx@1.14.0-1ubuntu2.2
1.14.0-1ubuntu2.3

Open the chart page →

12,460
jellyfinsudo-kraken-jellyfinVerified publisher2.1.31 of 1See more

jellyfin sudo-kraken-jellyfin 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.6333b64771663
libvpx@1.15.0-2.1
1.15.0-2.1+deb13u1

Open the chart page →

3,389
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u5

Open the chart page →

9,616
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u5

Open the chart page →

3,958
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
libvpx@1.11.0-2ubuntu2.2
1.11.0-2ubuntu2.5

Open the chart page →

9,347
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libvpx@1.11.0-2ubuntu2.3
1.11.0-2ubuntu2.5

Open the chart page →

14,100

Container images carrying it

67 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
libvpx@1.8.2-1build1
no fix listed
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libvpx@1.8.2-1build1
no fix listed
1
ghcr.io/libretime/libretime-analyzer:latest3d5e236216ad
libvpx@1.9.0-1+deb11u4
1.9.0-1+deb11u5
1
ghcr.io/libretime/libretime-playout:latest71a8706531aa
libvpx@1.9.0-1+deb11u4
1.9.0-1+deb11u5
1
ghcr.io/linuxoid69/motion:4.7.0-0.1.0f0f000c3fc47
libvpx@1.9.0-1+deb11u3
1.9.0-1+deb11u5
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
libvpx@1.7.0-3ubuntu0.18.04.1
no fix listed
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
libvpx@1.9.0-1
1.9.0-1+deb11u5
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
libvpx@1.12.0-1+deb12u4
1.12.0-1+deb12u5
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u5
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
libvpx@1.15.0-2.1
1.15.0-2.1+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
libvpx@1.15.0-2.1
1.15.0-2.1+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
libvpx@1.9.0-1
1.9.0-1+deb11u5
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libvpx@1.12.0-1+deb12u2
1.12.0-1+deb12u5
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
libvpx@1.9.0-1
1.9.0-1+deb11u5
1
ghcr.io/savonet/liquidsoap:v2.0.19e08148e1055
libvpx@1.9.0-1
1.9.0-1+deb11u5
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
libvpx@1.8.2-1build1
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libvpx@1.8.2-1build1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.