StackRadar

CVE-2026-2781

Critical

Advisory

Published 24 Feb 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
155
of 17,781 indexed, latest versions
Container images
146
deployed by those charts
Fix available
1 of 1
affected package

nss - security update

Carried by container images the latest versions of 155 of 17,781 indexed charts deploy, on 146 images.

Affected packageAffected versionsFixed inImages
nssdeb2:3.17.1-0ubuntu0.14.04.1, 2:3.28.4-0ubuntu0.14.04.3, 2:3.28.4-0ubuntu0.16.04.3, 2:3.28.4-0ubuntu0.16.04.4+27 more2:3.28.4-0ubuntu0.14.04.5+esm13, 2:3.28.4-0ubuntu0.16.04.14+esm5, 2:3.35-2ubuntu2.16+esm1, 2:3.61-1+deb11u5+6 more146
OSV records
DEBIAN-CVE-2026-2781UBUNTU-CVE-2026-2781DLA-4508-1
Also known as
DSA-6149-1, USN-8071-1, USN-8071-2

Charts affected

155 by stars
ChartLatestAffected imagesRadar Score
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-2781.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
nss@2:3.87.1-1+deb12u1
2:3.87.1-1+deb12u2

Open the chart page →

10,795
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-2781.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nss@2:3.49.1-1ubuntu1.5
2:3.98-0ubuntu0.20.04.2+esm1

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-2781.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nss@2:3.49.1-1ubuntu1.5
2:3.98-0ubuntu0.20.04.2+esm1

Open the chart page →

28,605
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-2781.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
nss@2:3.98-0ubuntu0.20.04.2
2:3.98-0ubuntu0.20.04.2+esm1

Open the chart page →

6,285
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-2781.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
nss@2:3.98-0ubuntu0.22.04.2
2:3.98-0ubuntu0.22.04.3

Open the chart page →

14,100

Container images carrying it

146 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
nss@2:3.28.4-0ubuntu0.16.04.3
2:3.28.4-0ubuntu0.16.04.14+esm5
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
nss@2:3.28.4-0ubuntu0.16.04.5
2:3.28.4-0ubuntu0.16.04.14+esm5
4
gchq/hdfs:3.3.35ec58edbb2db
nss@2:3.98-1build1
2:3.98-1ubuntu0.1
3
jacobalberty/unifi:v10.0.162896c0ab82d33
nss@2:3.98-0ubuntu0.20.04.2
2:3.98-0ubuntu0.20.04.2+esm1
3
selenium/hub:3.141.5902f251d48d5f
nss@2:3.49.1-1ubuntu1.5
2:3.98-0ubuntu0.20.04.2+esm1
3
apache/tika:2.9.2.1-fullae0b86d3c4d0
nss@2:3.98-1build1
2:3.98-1ubuntu0.1
2
hookiesolutions/webhookie:latest0629694246ba
nss@2:3.49.1-1ubuntu1.5
2:3.98-0ubuntu0.20.04.2+esm1
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
nss@2:3.49.1-1ubuntu1.8
2:3.98-0ubuntu0.20.04.2+esm1
2
kurento/kurento-media-server:latest03c0d34d0828
nss@2:3.98-1build1
2:3.98-1ubuntu0.1
2
mbentley/omada-controller:4.3f4e682274bed
nss@2:3.35-2ubuntu2.16
2:3.35-2ubuntu2.16+esm1
2
postgis/postgis:15-3.3a2fc46b52819
nss@2:3.61-1+deb11u3
2:3.61-1+deb11u5
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
nss@2:3.87.1-1
2:3.87.1-1+deb12u2
2
wurstmeister/zookeeper:latest7a7fd44a7210
nss@2:3.17.1-0ubuntu0.14.04.1
2:3.28.4-0ubuntu0.14.04.5+esm13
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
nss@2:3.98-1build1
2:3.98-1ubuntu0.1
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
nss@2:3.87.1-1+deb12u1
2:3.87.1-1+deb12u2
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
nss@2:3.49.1-1ubuntu1.5
2:3.98-0ubuntu0.20.04.2+esm1
2
1dev/server:11.9.0cd5b12fe5471
nss@2:3.98-1build1
2:3.98-1ubuntu0.1
1
5200710/hadoop:3.2.3-java8092d3088a5fb
nss@2:3.49.1-1ubuntu1.9
2:3.98-0ubuntu0.20.04.2+esm1
1
anguda/ant-media:2.5c435285fc241
nss@2:3.49.1-1ubuntu1.9
2:3.98-0ubuntu0.20.04.2+esm1
1
anujdatar/cups:25.07.01685df04a643b
nss@2:3.87.1-1+deb12u1
2:3.87.1-1+deb12u2
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
nss@2:3.49.1-1ubuntu1.6
2:3.98-0ubuntu0.20.04.2+esm1
1
apachepulsar/pulsar:2.9.0d056c89b7131
nss@2:3.49.1-1ubuntu1.5
2:3.98-0ubuntu0.20.04.2+esm1
1
apachepulsar/pulsar:2.8.2d538416d5afe
nss@2:3.49.1-1ubuntu1.6
2:3.98-0ubuntu0.20.04.2+esm1
1
apache/tika:2.9.0.092d055a84e9e
nss@2:3.68.2-0ubuntu1.2
2:3.98-0ubuntu0.22.04.3
1
bitnamilegacy/openldap:2.6.8-debian-12-r16e412c178ef9
nss@2:3.87.1-1
2:3.87.1-1+deb12u2
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
nss@2:3.49.1-1ubuntu1.5
2:3.98-0ubuntu0.20.04.2+esm1
1
camerahub/camerahub:0.36.23a5af37dd6e1b
nss@2:3.61-1+deb11u3
2:3.61-1+deb11u5
1
cheyang/distributed-tf:1.6.046cc34755493
nss@2:3.28.4-0ubuntu0.16.04.3
2:3.28.4-0ubuntu0.16.04.14+esm5
1
countly/api:25.05.4f4cc7447c4f5
nss@2:3.61-1+deb11u3
2:3.61-1+deb11u5
1
countly/countly-server:25.05.4e3c238248f99
nss@2:3.98-0ubuntu0.20.04.2
2:3.98-0ubuntu0.20.04.2+esm1
1
countly/frontend:25.05.42acbc11499b6
nss@2:3.61-1+deb11u3
2:3.61-1+deb11u5
1
datamate/seafile-professional:11.0.202dd66b722464
nss@2:3.98-0ubuntu0.22.04.2
2:3.98-0ubuntu0.22.04.3
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
nss@2:3.87.1-1
2:3.87.1-1+deb12u2
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
nss@2:3.61-1+deb11u3
2:3.61-1+deb11u5
1
ddosify/selfhosted_backend:3.2.93c11e3182652
nss@2:3.87.1-1
2:3.87.1-1+deb12u2
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
nss@2:3.87.1-1
2:3.87.1-1+deb12u2
1
dragonflyoss/client:v0.1.82edf3e921f4e0
nss@2:3.87.1-1
2:3.87.1-1+deb12u2
1
eclipseaerios/openldap:2.6.30208743f315e
nss@2:3.61-1+deb11u3
2:3.61-1+deb11u5
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
nss@2:3.98-0ubuntu0.20.04.2
2:3.98-0ubuntu0.20.04.2+esm1
1
fluent/fluent-bit:4.0-debuge76397ef3983
nss@2:3.87.1-1+deb12u1
2:3.87.1-1+deb12u2
1
galaxy/galaxy-init:v18.010267bad550e6
nss@2:3.28.4-0ubuntu0.14.04.3
2:3.28.4-0ubuntu0.14.04.5+esm13
1
galaxy/galaxy-stable:v18.018e577a626dfd
nss@2:3.28.4-0ubuntu0.14.04.3
2:3.28.4-0ubuntu0.14.04.5+esm13
1
gchq/accumulo:2.0.1c460bb587d6d
nss@2:3.98-1build1
2:3.98-1ubuntu0.1
1
graylog/graylog:6.1.1019de1aff48c2
nss@2:3.98-0ubuntu0.22.04.2
2:3.98-0ubuntu0.22.04.3
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
nss@2:3.28.4-0ubuntu0.16.04.3
2:3.28.4-0ubuntu0.16.04.14+esm5
1
iamdorsah/bastillion:v0.1db83a0254d81
nss@2:3.61-1+deb11u2
2:3.61-1+deb11u5
1
ispras/svacer:11-2-042aa9fa9f189
nss@2:3.98-0ubuntu0.22.04.2
2:3.98-0ubuntu0.22.04.3
1
ixsystems/truecommand:3.2.019c218455cd2
nss@2:3.110-1
2:3.110-1+deb13u1
1
jacobalberty/unifi:v7.1.664a3616625dda
nss@2:3.35-2ubuntu2.14
2:3.35-2ubuntu2.16+esm1
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
nss@2:3.35-2ubuntu2.16
2:3.35-2ubuntu2.16+esm1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.