StackRadar

CVE-2026-29168

High

Advisory

Published 5 May 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
37
of 17,781 indexed, latest versions
Container images
34
deployed by those charts
Fix available
3 of 3
affected packages

Apache HTTP Server: mod_md unrestricted OCSP response

Carried by container images the latest versions of 37 of 17,781 indexed charts deploy, on 34 images.

Affected packageAffected versionsFixed inImages
apache2deb2.4.52-1ubuntu4.7, 2.4.57-2, 2.4.58-1ubuntu8.8, 2.4.59-1~deb12u1+6 more2.4.52-1ubuntu4.20, 2.4.58-1ubuntu8.12, 2.4.67-1~deb12u2, 2.4.67-1~deb13u223
apache2apk2.4.62-r0, 2.4.63-r4, 2.4.66-r02.4.67-r09
apachebitnami2.4.54-157, 2.4.65-12.4.672
OSV records
ALPINE-CVE-2026-29168BIT-apache-2026-29168DEBIAN-CVE-2026-29168UBUNTU-CVE-2026-29168
Also known as
USN-8239-1

Charts affected

37 by stars
ChartLatestAffected imagesRadar Score
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
apache2@2.4.65-2
2.4.67-1~deb13u2

Open the chart page →

5,634
bookstackgabe565Verified publisher0.20.01 of 1See more

bookstack gabe565 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
apache2@2.4.62-r0
2.4.67-r0

Open the chart page →

2,811
glpiglpi-conteiner0.1.01 of 3See more

glpi glpi-conteiner 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
apache2@2.4.61-1~deb12u1
2.4.67-1~deb12u2

Open the chart page →

12,170
typo3christianhuthVerified publisher7.7.01 of 2See more

typo3 christianhuth 7.7.0

1 of the 2 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
martinhelmich/typo3:12.4c83a4f3fd7ae
apache2@2.4.66-1~deb12u1
2.4.67-1~deb12u2

Open the chart page →

8,466
dragonfly-stackdragonflyVerified publisher0.1.21 of 7See more

dragonfly-stack dragonfly 0.1.2

1 of the 7 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
dragonflyoss/client:v0.1.82edf3e921f4e0
apache2@2.4.59-1~deb12u1
2.4.67-1~deb12u2

Open the chart page →

18,376
leantimegissilabs1.3.01 of 2See more

leantime gissilabs 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
leantime/leantime:3.3.3ad4bfb0699d3
apache2@2.4.62-r0
2.4.67-r0

Open the chart page →

6,416
phpipamphpipam-helmVerified publisher1.0.122 of 3See more

phpipam phpipam-helm 1.0.12

2 of the 3 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
phpipam/phpipam-cron:v1.7.354468713454e
apache2@2.4.62-r0
2.4.67-r0
phpipam/phpipam-www:v1.7.3ace0efd24830
apache2@2.4.62-r0
2.4.67-r0

Open the chart page →

3,778
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
apache2@2.4.66-1~deb13u1
2.4.67-1~deb13u2

Open the chart page →

7,126
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
apache2@2.4.65-2
2.4.67-1~deb13u2

Open the chart page →

7,696
linkstackadnoctemVerified publisher0.4.01 of 1See more

linkstack adnoctem 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
linkstackorg/linkstack:latest1c8b05399ee4
apache2@2.4.66-r0
2.4.67-r0

Open the chart page →

2,092
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
apache2@2.4.65-2
2.4.67-1~deb13u2

Open the chart page →

7,489
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
apache2@2.4.62-1~deb12u2
2.4.67-1~deb12u2

Open the chart page →

5,778
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
apache2@2.4.57-2
2.4.67-1~deb12u2

Open the chart page →

7,141
smokepingdjjudas21Verified publisher0.1.31 of 1See more

smokeping djjudas21 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
linuxserver/smokeping:2.8.2b7f906899cd3
apache2@2.4.62-r0
2.4.67-r0

Open the chart page →

2,053
duckdb-uiduckdb-ui0.5.21 of 1See more

duckdb-ui duckdb-ui 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
apache2@2.4.65-1~deb12u1
2.4.67-1~deb12u2

Open the chart page →

4,460
heimdallegebackVerified publisher2.0.41 of 1See more

heimdall egeback 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
linuxserver/heimdall:2.6.371597f4461e4
apache2@2.4.62-r0
2.4.67-r0

Open the chart page →

1,664
wordpresseoc-chartsVerified publisher0.14.41 of 1See more

wordpress eoc-charts 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
library/wordpress:6.8.3-apache30bff39330d1
apache2@2.4.65-2
2.4.67-1~deb13u2

Open the chart page →

7,233
matomoeosc-lot-1Verified publisher0.2.01 of 1See more

matomo eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
library/matomo:5.1.2-apache2415789e1602
apache2@2.4.62-1~deb12u2
2.4.67-1~deb12u2

Open the chart page →

5,290
equizequiz0.0.11 of 3See more

equiz equiz 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.67

Open the chart page →

7,541
equizequiz-chart0.0.11 of 3See more

equiz equiz-chart 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.67

Open the chart page →

7,541
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
apache2@2.4.61-1~deb12u1
2.4.67-1~deb12u2

Open the chart page →

12,170
phpmyadminhelmforgeVerified publisher2.0.11 of 1See more

phpmyadmin helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.342a200db07b4
apache2@2.4.65-2
2.4.67-1~deb13u2

Open the chart page →

4,751
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
apache2@2.4.52-1ubuntu4.7
2.4.52-1ubuntu4.20

Open the chart page →

14,290
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
apache2@2.4.66-1~deb12u1
2.4.67-1~deb12u2

Open the chart page →

17,852
kc-chartkc-chart1.0.01 of 3See more

kc-chart kc-chart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
apache2@2.4.57-2
2.4.67-1~deb12u2

Open the chart page →

8,860
kube-wordpress-mysqlkube-wordpress-mysql0.1.01 of 2See more

kube-wordpress-mysql kube-wordpress-mysql 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
library/wordpress:php8.1-apachef73396626d2f
apache2@2.4.65-2
2.4.67-1~deb13u2

Open the chart page →

8,698
webdavlinuxoid690.1.01 of 1See more

webdav linuxoid69 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
ghcr.io/linuxoid69/webdav:1.26.2-r065bacf19caa7
apache2@2.4.62-r0
2.4.67-r0

Open the chart page →

1,081
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
apache2@2.4.57-2
2.4.67-1~deb12u2

Open the chart page →

12,813
matomopetbattle11.0.11 of 2See more

matomo petbattle 11.0.1

1 of the 2 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
apache@2.4.65-1
2.4.67

Open the chart page →

11,061
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
apache2@2.4.65-2
2.4.67-1~deb13u2

Open the chart page →

9,755
phpmyadminsb-helm-charts0.3.01 of 1See more

phpmyadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
apache2@2.4.62-1~deb12u2
2.4.67-1~deb12u2

Open the chart page →

5,315
wordpresssb-helm-charts0.4.01 of 2See more

wordpress sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
library/wordpress:6.4.3-apache8ae66efb09a2
apache2@2.4.57-2
2.4.67-1~deb12u2

Open the chart page →

13,510
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
apache2@2.4.58-1ubuntu8.8
2.4.58-1ubuntu8.12

Open the chart page →

6,094
restic-serverschoolguys-helmcharts0.3.11 of 1See more

restic-server schoolguys-helmcharts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
restic/rest-server:0.14.0d2aff06f47eb
apache2@2.4.63-r4
2.4.67-r0

Open the chart page →

2,257
nagvissvtech-public-helm-charts1.0.01 of 1See more

nagvis svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
apache2@2.4.57-2
2.4.67-1~deb12u2

Open the chart page →

9,102
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
apache2@2.4.62-1~deb12u2
2.4.67-1~deb12u2

Open the chart page →

10,086
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-29168.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
apache2@2.4.57-2
2.4.67-1~deb12u2

Open the chart page →

10,001

Container images carrying it

34 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/phpmyadmin:5.2.16e75aa8f767c
apache2@2.4.62-1~deb12u2
2.4.67-1~deb12u2
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
apache2@2.4.65-2
2.4.67-1~deb13u2
2
vdiogov/glpi-conteiner:latest6945f84f0058
apache2@2.4.61-1~deb12u1
2.4.67-1~deb12u2
2
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.67
2
akaunting/akaunting:3.0.1552811b36ec3a
apache2@2.4.57-2
2.4.67-1~deb12u2
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
apache@2.4.65-1
2.4.67
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
apache2@2.4.65-2
2.4.67-1~deb13u2
1
domainmod/domainmod:4.23.04017bfe4c597
apache2@2.4.57-2
2.4.67-1~deb12u2
1
dragonflyoss/client:v0.1.82edf3e921f4e0
apache2@2.4.59-1~deb12u1
2.4.67-1~deb12u2
1
gulacedia/web-dvwa-new:v367b467d961ca
apache2@2.4.57-2
2.4.67-1~deb12u2
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
apache2@2.4.66-1~deb12u1
2.4.67-1~deb12u2
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
apache2@2.4.57-2
2.4.67-1~deb12u2
1
leantime/leantime:3.3.3ad4bfb0699d3
apache2@2.4.62-r0
2.4.67-r0
1
library/matomo:5.1.2-apache2415789e1602
apache2@2.4.62-1~deb12u2
2.4.67-1~deb12u2
1
library/nextcloud:31.0.6-apache588609d76b21
apache2@2.4.62-1~deb12u2
2.4.67-1~deb12u2
1
library/nextcloud:31.0.10-apacheb7faa1653c39
apache2@2.4.65-2
2.4.67-1~deb13u2
1
library/wordpress:6.4.3-apache8ae66efb09a2
apache2@2.4.57-2
2.4.67-1~deb12u2
1
library/wordpress:php8.1-apachef73396626d2f
apache2@2.4.65-2
2.4.67-1~deb13u2
1
linkstackorg/linkstack:latest1c8b05399ee4
apache2@2.4.66-r0
2.4.67-r0
1
linuxserver/heimdall:2.6.371597f4461e4
apache2@2.4.62-r0
2.4.67-r0
1
linuxserver/smokeping:2.8.2b7f906899cd3
apache2@2.4.62-r0
2.4.67-r0
1
martinhelmich/typo3:12.4c83a4f3fd7ae
apache2@2.4.66-1~deb12u1
2.4.67-1~deb12u2
1
mediagis/nominatim:4.2d0eae7b51374
apache2@2.4.52-1ubuntu4.7
2.4.52-1ubuntu4.20
1
phpipam/phpipam-cron:v1.7.354468713454e
apache2@2.4.62-r0
2.4.67-r0
1
phpipam/phpipam-www:v1.7.3ace0efd24830
apache2@2.4.62-r0
2.4.67-r0
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
apache2@2.4.65-2
2.4.67-1~deb13u2
1
restic/rest-server:0.14.0d2aff06f47eb
apache2@2.4.63-r4
2.4.67-r0
1
snipe/snipe-it:v8.3.1141ebf2386fe
apache2@2.4.58-1ubuntu8.8
2.4.58-1ubuntu8.12
1
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
apache2@2.4.66-1~deb13u1
2.4.67-1~deb13u2
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
apache2@2.4.57-2
2.4.67-1~deb12u2
1
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
apache2@2.4.65-1~deb12u1
2.4.67-1~deb12u2
1
ghcr.io/linuxoid69/webdav:1.26.2-r065bacf19caa7
apache2@2.4.62-r0
2.4.67-r0
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
apache2@2.4.62-r0
2.4.67-r0
1
ghcr.io/monicahq/monica-next:main8be69156acbb
apache2@2.4.65-2
2.4.67-1~deb13u2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.