StackRadar

CVE-2026-2903

Medium

Advisory

Published 22 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
63
of 17,781 indexed, latest versions
Container images
50
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 63 of 17,781 indexed charts deploy, on 50 images.

Affected packageAffected versionsFixed inImages
re2cdeb3.0-2, 4.1-1no fix listed50
OSV records
DEBIAN-CVE-2026-2903

Charts affected

63 by stars
ChartLatestAffected imagesRadar Score
wp-chartprojet-devops0.1.01 of 2See more

wp-chart projet-devops 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-2903.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
re2c@4.1-1
no fix listed

Open the chart page →

5,203
simple-coffeerubxkubeVerified publisher0.1.01 of 1See more

simple-coffee rubxkube 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-2903.

Container imageDigestPackageFixed in
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
re2c@4.1-1
no fix listed

Open the chart page →

2,460
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-2903.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
re2c@4.1-1
no fix listed

Open the chart page →

9,755
phpmyadminsb-helm-charts0.3.01 of 1See more

phpmyadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-2903.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
re2c@3.0-2
no fix listed

Open the chart page →

5,315
wordpresssb-helm-charts0.4.01 of 2See more

wordpress sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-2903.

Container imageDigestPackageFixed in
library/wordpress:6.4.3-apache8ae66efb09a2
re2c@3.0-2
no fix listed

Open the chart page →

13,510
wordpressschichtelVerified publisher0.10.101 of 2See more

wordpress schichtel 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-2903.

Container imageDigestPackageFixed in
library/wordpress:6.9.4-fpmad4a8bae2eb4
re2c@4.1-1
no fix listed

Open the chart page →

8,184
typo3schoolguys-helmcharts0.4.21 of 1See more

typo3 schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-2903.

Container imageDigestPackageFixed in
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
re2c@3.0-2
no fix listed

Open the chart page →

4,836
wordpress-mysqlsikalabs0.1.21 of 2See more

wordpress-mysql sikalabs 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-2903.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
re2c@4.1-1
no fix listed

Open the chart page →

3,826
nagvissvtech-public-helm-charts1.0.01 of 1See more

nagvis svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-2903.

Container imageDigestPackageFixed in
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
re2c@3.0-2
no fix listed

Open the chart page →

9,102
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-2903.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
re2c@4.1-1
no fix listed

Open the chart page →

5,704
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-2903.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
re2c@3.0-2
no fix listed

Open the chart page →

10,086
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-2903.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
re2c@3.0-2
no fix listed

Open the chart page →

10,001
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-2903.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
re2c@4.1-1
no fix listed

Open the chart page →

5,560

Container images carrying it

50 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/phpmyadmin:5.2.3-apache:latest3a8a8d6b5289
re2c@4.1-1
no fix listed
7
library/wordpress:7.1.0-apache:latest5a93c470ae82
re2c@4.1-1
no fix listed
6
fireflyiii/core:version-6.5.9fe4ecec4c2ba
re2c@4.1-1
no fix listed
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
re2c@4.1-1
no fix listed
2
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
re2c@4.1-1
no fix listed
2
library/phpmyadmin:5.2.16e75aa8f767c
re2c@3.0-2
no fix listed
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
re2c@4.1-1
no fix listed
2
vdiogov/glpi-conteiner:latest6945f84f0058
re2c@3.0-2
no fix listed
2
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
re2c@4.1-1
no fix listed
1
adamzammit/limesurvey:7.0.15e75e2f455c8d
re2c@4.1-1
no fix listed
1
akaunting/akaunting:3.0.1552811b36ec3a
re2c@3.0-2
no fix listed
1
castopod/castopod:1.12.101fd37280cbb2
re2c@3.0-2
no fix listed
1
castopod/castopod:1.15.54e4f0440520f
re2c@4.1-1
no fix listed
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
re2c@3.0-2
no fix listed
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
re2c@4.1-1
no fix listed
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
re2c@4.1-1
no fix listed
1
dolibarr/dolibarr:24.0.069ec52e3b7ef
re2c@3.0-2
no fix listed
1
dolibarr/dolibarr:22.0.47ad88fc9b13c
re2c@3.0-2
no fix listed
1
domainmod/domainmod:4.23.04017bfe4c597
re2c@3.0-2
no fix listed
1
espocrm/espocrm:9.3.101b5a24504ed9
re2c@4.1-1
no fix listed
1
fireflyiii/core:version-6.6.6ae69fdd95cde
re2c@4.1-1
no fix listed
1
glpi/glpi:latest4b681082a79e
re2c@4.1-1
no fix listed
1
gulacedia/web-dvwa-new:v367b467d961ca
re2c@3.0-2
no fix listed
1
kimai/kimai2:2.65.06dfc63199654
re2c@3.0-2
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
re2c@4.1-1
no fix listed
1
kixote/typemill4e9dff179519
re2c@4.1-1
no fix listed
1
kixote/typemill628f79a08cc7
re2c@4.1-1
no fix listed
1
library/drupal:11.4.6-php8.5-apache-bookworm28f7931ecbcb
re2c@3.0-2
no fix listed
1
library/matomo:5.1.2-apache2415789e1602
re2c@3.0-2
no fix listed
1
library/matomo:5.13.0-apache8e6bdd396496
re2c@4.1-1
no fix listed
1
library/nextcloud:31.0.6-apache588609d76b21
re2c@3.0-2
no fix listed
1
library/nextcloud:31.0.10-apacheb7faa1653c39
re2c@4.1-1
no fix listed
1
library/php:8.4-fpm59fa733c9af6
re2c@4.1-1
no fix listed
1
library/wordpress:6.4.3-apache8ae66efb09a2
re2c@3.0-2
no fix listed
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
re2c@4.1-1
no fix listed
1
library/wordpress:php8.1-apachef73396626d2f
re2c@4.1-1
no fix listed
1
martinhelmich/typo3:12.4c83a4f3fd7ae
re2c@3.0-2
no fix listed
1
mautic/mautic:7-apacheeb8cc73d97e1
re2c@3.0-2
no fix listed
1
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
re2c@3.0-2
no fix listed
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
re2c@4.1-1
no fix listed
1
pockost/matomo:5.13.07f5d293cbe4e
re2c@4.1-1
no fix listed
1
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
re2c@4.1-1
no fix listed
1
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
re2c@4.1-1
no fix listed
1
serversideup/php:8.5-fpm-nginx8f8c2f010ac5
re2c@4.1-1
no fix listed
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
re2c@3.0-2
no fix listed
1
ghcr.io/monicahq/monica-next:main8be69156acbb
re2c@4.1-1
no fix listed
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
re2c@4.1-1
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
re2c@3.0-2
no fix listed
1
ghcr.io/yourls/yourls:1.10.69b220ea83329
re2c@4.1-1
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
re2c@3.0-2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.