StackRadar

CVE-2026-2447

High

Advisory

Published 16 Feb 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
67
of 17,781 indexed, latest versions
Container images
67
deployed by those charts
Fix available
1 of 1
affected package

libvpx - security update

Carried by container images the latest versions of 67 of 17,781 indexed charts deploy, on 67 images.

Affected packageAffected versionsFixed inImages
libvpxdeb1.3.0-2, 1.5.0-2ubuntu1, 1.7.0-3, 1.7.0-3ubuntu0.18.04.1+19 more1.9.0-1+deb11u5, 1.11.0-2ubuntu2.5, 1.12.0-1+deb12u5, 1.14.0-1ubuntu2.3+2 more67
OSV records
DEBIAN-CVE-2026-2447UBUNTU-CVE-2026-2447DLA-4489-1
Also known as
DSA-6143-1, USN-8053-1

Charts affected

67 by stars
ChartLatestAffected imagesRadar Score
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
libvpx@1.7.0-3ubuntu0.18.04.1
no fix listed

Open the chart page →

27,633
cdn-remoteopencord0.2.42 of 3See more

cdn-remote opencord 0.2.4

2 of the 3 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libvpx@1.7.0-3
no fix listed
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
libvpx@1.5.0-2ubuntu1
no fix listed

Open the chart page →

63,223
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libvpx@1.5.0-2ubuntu1
no fix listed

Open the chart page →

42,614
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libvpx@1.5.0-2ubuntu1
no fix listed

Open the chart page →

29,124
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libvpx@1.8.2-1build1
no fix listed

Open the chart page →

9,167
libretimepodzone-chartsVerified publisher0.4.12 of 9See more

libretime podzone-charts 0.4.1

2 of the 9 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-analyzer:latest3d5e236216ad
libvpx@1.9.0-1+deb11u4
1.9.0-1+deb11u5
ghcr.io/libretime/libretime-playout:latest71a8706531aa
libvpx@1.9.0-1+deb11u4
1.9.0-1+deb11u5

Open the chart page →

11,149
mastodonrivals-spaceVerified publisher3.1.21 of 3See more

mastodon rivals-space 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
libvpx@1.9.0-1
1.9.0-1+deb11u5

Open the chart page →

6,026
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
libvpx@1.15.0-2.1
1.15.0-2.1+deb13u1

Open the chart page →

10,605
nadekobotryuunosukeds30.1.21 of 2See more

nadekobot ryuunosukeds3 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
libvpx@1.11.0-2ubuntu2.3
1.11.0-2ubuntu2.5

Open the chart page →

8,619
jellyfinsb-helm-charts0.4.01 of 1See more

jellyfin sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.317c3a8d9dddb
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u5

Open the chart page →

4,105
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libvpx@1.14.0-1ubuntu2.2
1.14.0-1ubuntu2.3

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libvpx@1.14.0-1ubuntu2.2
1.14.0-1ubuntu2.3

Open the chart page →

12,460
jellyfinsudo-kraken-jellyfinVerified publisher2.1.31 of 1See more

jellyfin sudo-kraken-jellyfin 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.6333b64771663
libvpx@1.15.0-2.1
1.15.0-2.1+deb13u1

Open the chart page →

3,389
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u5

Open the chart page →

9,616
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u5

Open the chart page →

3,958
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
libvpx@1.11.0-2ubuntu2.2
1.11.0-2ubuntu2.5

Open the chart page →

9,347
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-2447.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libvpx@1.11.0-2ubuntu2.3
1.11.0-2ubuntu2.5

Open the chart page →

14,100

Container images carrying it

67 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ciscolabs/rtsp-client:latesta7b60ec88285
libvpx@1.8.2-1build1
no fix listed
3
ciscolabs/rtsp-server:latestb59fc10bb821
libvpx@1.8.2-1build1
no fix listed
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
libvpx@1.5.0-2ubuntu1
no fix listed
3
kurento/kurento-media-server:latest03c0d34d0828
libvpx@1.14.0-1ubuntu2.2
1.14.0-1ubuntu2.3
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libvpx@1.11.0-2ubuntu2
1.11.0-2ubuntu2.5
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libvpx@1.8.2-1build1
no fix listed
2
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libvpx@1.10.0-0ubuntu1~20.04.sav0
no fix listed
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
libvpx@1.11.0-2ubuntu2.4
1.11.0-2ubuntu2.5
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
libvpx@1.8.2-1ubuntu0.2
no fix listed
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libvpx@1.8.2-1build1
no fix listed
1
castopod/castopod:1.12.101fd37280cbb2
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u5
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libvpx@1.8.2-1build1
no fix listed
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
libvpx@1.7.0-3ubuntu0.18.04.1
no fix listed
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libvpx@1.7.0-3ubuntu0.18.04.1
no fix listed
1
erlangsolutions/wombatoam:4.1.284680c990147a
libvpx@1.9.0-1
1.9.0-1+deb11u5
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
libvpx@1.8.2-1ubuntu0.4
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
libvpx@1.3.0-2
no fix listed
1
haveagitgat/tdarr:2.00.181256348872ce
libvpx@1.8.2-1build1
no fix listed
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
libvpx@1.8.2-1build1
no fix listed
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libvpx@1.8.2-1build1
no fix listed
1
jaedb/iris:latest048cfbf58d57
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u5
1
jellyfin/jellyfin:10.8.1305a9734d7e83
libvpx@1.9.0-1+deb11u2
1.9.0-1+deb11u5
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u5
1
jellyfin/jellyfin:10.11.6333b64771663
libvpx@1.15.0-2.1
1.15.0-2.1+deb13u1
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u5
1
jellyfin/jellyfin:10.10.77ae36aab93ef
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u5
1
jellyfin/jellyfin:10.10.696b09723b22f
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u5
1
jellyfin/jellyfin:10.8.1ee24f4459a40
libvpx@1.9.0-1
1.9.0-1+deb11u5
1
josh5/unmanic:0.2.64d49c4816260
libvpx@1.11.0-2ubuntu2.2
1.11.0-2ubuntu2.5
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
libvpx@1.9.0-1
1.9.0-1+deb11u5
1
langgenius/dify-api:0.6.11fca918260dd6
libvpx@1.12.0-1+deb12u2
1.12.0-1+deb12u5
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
libvpx@1.14.0-1ubuntu2.2
1.14.0-1ubuntu2.3
1
linuxserver/jellyfin:10.7.72427dde159a2
libvpx@1.8.2-1build1
no fix listed
1
livekit/ingress:v1.2.21ab01641b366
libvpx@1.11.0-2ubuntu2
1.11.0-2ubuntu2.5
1
mlikiowa/napcat-docker:latest1336a777f9a4
libvpx@1.11.0-2ubuntu2.3
1.11.0-2ubuntu2.5
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libvpx@1.7.0-3
no fix listed
1
opea/speecht5:1.0249afad3d268
libvpx@1.12.0-1+deb12u3
1.12.0-1+deb12u5
1
photoprism/photoprism:220629-jammy2954334adbda
libvpx@1.11.0-2ubuntu2
1.11.0-2ubuntu2.5
1
photoprism/photoprism:251130db16ee6b1ba3
libvpx@1.15.0-2.1build1
1.15.0-2.1ubuntu0.1
1
photoprism/photoprism:240711-cefc6fd632ca74
libvpx@1.14.0-1ubuntu2.1
1.14.0-1ubuntu2.3
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
libvpx@1.11.0-2ubuntu2.3
1.11.0-2ubuntu2.5
1
scrapinghub/splash:3.4.1a5f89bc84606
libvpx@1.7.0-3ubuntu0.18.04.1
no fix listed
1
sismics/docs:v1.10f4b0ef019cf1
libvpx@1.7.0-3ubuntu0.18.04.1
no fix listed
1
stashapp/stash:latest24dbd7607174
libvpx@1.8.2-1build1
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libvpx@1.5.0-2ubuntu1
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libvpx@1.11.0-2ubuntu2.3
1.11.0-2ubuntu2.5
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libvpx@1.11.0-2ubuntu2.2
1.11.0-2ubuntu2.5
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libvpx@1.8.2-1build1
no fix listed
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
libvpx@1.15.0-2.1
1.15.0-2.1+deb13u1
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
libvpx@1.8.2-1build1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.