StackRadar

CVE-2026-29167

Critical

Advisory

Published 8 Jun 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
58
of 17,781 indexed, latest versions
Container images
56
deployed by those charts
Fix available
4 of 4
affected packages

Apache HTTP Server: mod_ldap per-dir use-after-free

Carried by container images the latest versions of 58 of 17,781 indexed charts deploy, on 56 images.

Affected packageAffected versionsFixed inImages
apache2deb2.4.41-4ubuntu3.11, 2.4.41-4ubuntu3.12, 2.4.41-4ubuntu3.14, 2.4.41-4ubuntu3.17+17 more2.4.41-4ubuntu3.23+esm6, 2.4.52-1ubuntu4.23, 2.4.58-1ubuntu8.15, 2.4.68-1~deb12u1+1 more43
apachebitnami2.4.54-157, 2.4.65-1, 2.4.68-1, 2.4.68-82.4.684
httpdrpm2.4.37-43.module+el8.5.0+13806+b30d9eec.1, 2.4.37-56.module+el8.8.0+18758+b3a9c8da.6, 2.4.37-65.module+el8.10.0+23815+1b5e1c66.7, 2.4.57-8.el9+4 more0:2.4.37-65.module+el8.10.0+24755+06195b95.10, 0:2.4.62-13.el9_8.69
mod_http2rpm1.15.7-10.module+el8.10.0+23369+11a81384.40:1.15.7-10.module+el8.10.0+24521+219dcfc5.71
OSV records
BIT-apache-2026-29167DEBIAN-CVE-2026-29167UBUNTU-CVE-2026-29167RHSA-2026:59347RHSA-2026:64794
Also known as
USN-8516-1, USN-8589-1

Charts affected

58 by stars
ChartLatestAffected imagesRadar Score
wordpressbitnamiVerified publisher33.1.01 of 2See more

wordpress bitnami 33.1.0

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
bitnami/wordpress:latest8448af086f92
apache@2.4.68-8
2.4.68

Open the chart page →

220
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.23+esm6

Open the chart page →

18,509
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
apache2@2.4.65-2
2.4.68-1~deb13u1

Open the chart page →

5,634
dolibarrcowboysysopVerified publisher9.0.31 of 3See more

dolibarr cowboysysop 9.0.3

1 of the 3 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
dolibarr/dolibarr:22.0.47ad88fc9b13c
apache2@2.4.67-1~deb12u2
2.4.68-1~deb12u1

Open the chart page →

9,106
glpiglpi-conteiner0.1.01 of 3See more

glpi glpi-conteiner 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
apache2@2.4.61-1~deb12u1
2.4.68-1~deb12u1

Open the chart page →

12,170
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
httpd@2.4.57-11.el9_4
0:2.4.62-13.el9_8.6

Open the chart page →

7,450
typo3christianhuthVerified publisher7.7.01 of 2See more

typo3 christianhuth 7.7.0

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
martinhelmich/typo3:12.4c83a4f3fd7ae
apache2@2.4.66-1~deb12u1
2.4.68-1~deb12u1

Open the chart page →

8,466
dragonfly-stackdragonflyVerified publisher0.1.21 of 7See more

dragonfly-stack dragonfly 0.1.2

1 of the 7 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
dragonflyoss/client:v0.1.82edf3e921f4e0
apache2@2.4.59-1~deb12u1
2.4.68-1~deb12u1

Open the chart page →

18,376
roundcubeencircle360-ossVerified publisher0.8.31 of 1See more

roundcube encircle360-oss 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
apache2@2.4.67-1~deb13u3
2.4.68-1~deb13u1

Open the chart page →

5,584
owncloudkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

owncloud kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
owncloud/server:10.16.274c53d341076
apache2@2.4.52-1ubuntu4.20
2.4.52-1ubuntu4.23

Open the chart page →

9,858
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
apache2@2.4.66-1~deb13u1
2.4.68-1~deb13u1

Open the chart page →

7,126
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
apache2@2.4.65-2
2.4.68-1~deb13u1

Open the chart page →

7,696
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
apache2@2.4.65-2
2.4.68-1~deb13u1

Open the chart page →

7,489
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
apache2@2.4.41-4ubuntu3.14
2.4.41-4ubuntu3.23+esm6
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
apache2@2.4.41-4ubuntu3.14
2.4.41-4ubuntu3.23+esm6

Open the chart page →

22,568
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
apache2@2.4.62-1~deb12u2
2.4.68-1~deb12u1

Open the chart page →

5,778
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
httpd@2.4.37-56.module+el8.8.0+18758+b3a9c8da.6
0:2.4.37-65.module+el8.10.0+24755+06195b95.10

Open the chart page →

25,151
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
apache2@2.4.57-2
2.4.68-1~deb12u1

Open the chart page →

7,141
webtreesdjjudas21Verified publisher3.0.01 of 1See more

webtrees djjudas21 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
apache2@2.4.67-1~deb13u2
2.4.68-1~deb13u1

Open the chart page →

5,966
duckdb-uiduckdb-ui0.5.21 of 1See more

duckdb-ui duckdb-ui 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
apache2@2.4.65-1~deb12u1
2.4.68-1~deb12u1

Open the chart page →

4,460
wordpresseoc-chartsVerified publisher0.14.41 of 1See more

wordpress eoc-charts 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
library/wordpress:6.8.3-apache30bff39330d1
apache2@2.4.65-2
2.4.68-1~deb13u1

Open the chart page →

7,233
matomoeosc-lot-1Verified publisher0.2.01 of 1See more

matomo eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
library/matomo:5.1.2-apache2415789e1602
apache2@2.4.62-1~deb12u2
2.4.68-1~deb12u1

Open the chart page →

5,290
equizequiz0.0.11 of 3See more

equiz equiz 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.68

Open the chart page →

7,541
equizequiz-chart0.0.11 of 3See more

equiz equiz-chart 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.68

Open the chart page →

7,541
espocrmespocrmVerified publisher1.0.11 of 2See more

espocrm espocrm 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
espocrm/espocrm:9.3.101b5a24504ed9
apache2@2.4.67-1~deb13u3
2.4.68-1~deb13u1

Open the chart page →

6,431
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.23+esm6

Open the chart page →

20,933
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.23+esm6

Open the chart page →

14,659
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
apache2@2.4.67-1~deb12u3
2.4.68-1~deb12u1

Open the chart page →

9,077
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
apache2@2.4.61-1~deb12u1
2.4.68-1~deb12u1

Open the chart page →

12,170
phpmyadminhelmforgeVerified publisher2.0.11 of 1See more

phpmyadmin helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.342a200db07b4
apache2@2.4.65-2
2.4.68-1~deb13u1

Open the chart page →

4,751
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
apache2@2.4.52-1ubuntu4.7
2.4.52-1ubuntu4.23

Open the chart page →

14,290
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
apache2@2.4.66-1~deb12u1
2.4.68-1~deb12u1

Open the chart page →

17,852
kc-chartkc-chart1.0.01 of 3See more

kc-chart kc-chart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
apache2@2.4.57-2
2.4.68-1~deb12u1

Open the chart page →

8,860
phppgadminkfirfer0.1.121 of 1See more

phppgadmin kfirfer 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.23+esm6

Open the chart page →

10,248
kube-wordpress-mysqlkube-wordpress-mysql0.1.01 of 2See more

kube-wordpress-mysql kube-wordpress-mysql 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
library/wordpress:php8.1-apachef73396626d2f
apache2@2.4.65-2
2.4.68-1~deb13u1

Open the chart page →

8,698
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
apache2@2.4.67-1~deb12u2
2.4.68-1~deb12u1

Open the chart page →

8,303
moodlemoodle1.0.31 of 2See more

moodle moodle 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
cloudtooling/moodle:5.2.3f4f04e0fc401
apache@2.4.68-1
2.4.68

Open the chart page →

3,954
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
apache2@2.4.57-2
2.4.68-1~deb12u1

Open the chart page →

12,813
neuralbank-stackneuralbank-stack0.1.01 of 4See more

neuralbank-stack neuralbank-stack 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
httpd@2.4.62-7.el9
0:2.4.62-13.el9_8.6

Open the chart page →

5,191
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
httpd@2.4.62-13.el9_8.1
0:2.4.62-13.el9_8.6

Open the chart page →

7,310
nfl-walletnfl-walletVerified publisher0.1.31 of 4See more

nfl-wallet nfl-wallet 0.1.3

1 of the 4 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
httpd@2.4.37-65.module+el8.10.0+23815+1b5e1c66.7
mod_http2@1.15.7-10.module+el8.10.0+23369+11a81384.4
0:2.4.37-65.module+el8.10.0+24755+06195b95.10
0:1.15.7-10.module+el8.10.0+24521+219dcfc5.7

Open the chart page →

13,041
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.23+esm6

Open the chart page →

22,658
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
httpd@2.4.57-11.el9_4.1
0:2.4.62-13.el9_8.6
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
httpd@2.4.57-8.el9
0:2.4.62-13.el9_8.6

Open the chart page →

18,922
matomopetbattle11.0.11 of 2See more

matomo petbattle 11.0.1

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
apache@2.4.65-1
2.4.68

Open the chart page →

11,061
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.23+esm6

Open the chart page →

9,167
rhbk-neurofacerhbk-neurofaceVerified publisher1.0.01 of 4See more

rhbk-neuroface rhbk-neuroface 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
httpd@2.4.62-13.el9_8.1
0:2.4.62-13.el9_8.6

Open the chart page →

3,781
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
apache2@2.4.52-1ubuntu4.21
2.4.52-1ubuntu4.23

Open the chart page →

7,436
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
apache2@2.4.65-2
2.4.68-1~deb13u1

Open the chart page →

9,755
phpmyadminsb-helm-charts0.3.01 of 1See more

phpmyadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
apache2@2.4.62-1~deb12u2
2.4.68-1~deb12u1

Open the chart page →

5,315
wordpresssb-helm-charts0.4.01 of 2See more

wordpress sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
library/wordpress:6.4.3-apache8ae66efb09a2
apache2@2.4.57-2
2.4.68-1~deb12u1

Open the chart page →

13,510
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
apache2@2.4.58-1ubuntu8.8
2.4.58-1ubuntu8.15

Open the chart page →

6,094

Container images carrying it

56 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
httpd@2.4.62-7.el9
0:2.4.62-13.el9_8.6
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
httpd@2.4.62-13.el9_8.1
0:2.4.62-13.el9_8.6
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
httpd@2.4.62-13.el9_8.1
0:2.4.62-13.el9_8.6
1
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
httpd@2.4.37-65.module+el8.10.0+23815+1b5e1c66.7
mod_http2@1.15.7-10.module+el8.10.0+23369+11a81384.4
0:2.4.37-65.module+el8.10.0+24755+06195b95.10
0:1.15.7-10.module+el8.10.0+24521+219dcfc5.7
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
httpd@2.4.57-8.el9
0:2.4.62-13.el9_8.6
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
apache2@2.4.67-1~deb12u2
2.4.68-1~deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.