StackRadar

CVE-2026-32249

Medium

Advisory

Published 12 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
17
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 17 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
vimdeb2:9.1.0016-1ubuntu7.3, 2:9.1.0016-1ubuntu7.8, 2:9.1.0016-1ubuntu7.9, 2:9.1.0016-1ubuntu7.10+1 more2:9.1.0016-1ubuntu7.1118
OSV records
DEBIAN-CVE-2026-32249UBUNTU-CVE-2026-32249
Also known as
USN-8171-1

Charts affected

17 by stars
ChartLatestAffected imagesRadar Score
netdatanetdataVerified publisher3.7.1731 of 1See more

netdata netdata 3.7.173

1 of the 1 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
netdata/netdata:v2.11.0c45c71eb23ff
vim@2:9.1.1230-2
no fix listed

Open the chart page →

3,092
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
vim@2:9.1.0016-1ubuntu7.3
2:9.1.0016-1ubuntu7.11

Open the chart page →

4,309
aramid-indexerbiatec-repoVerified publisher3.9.01 of 5See more

aramid-indexer biatec-repo 3.9.0

1 of the 5 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
vim@2:9.1.0016-1ubuntu7.9
2:9.1.0016-1ubuntu7.11

Open the chart page →

13,357
aramid-relaybiatec-repoVerified publisher4.4.11 of 1See more

aramid-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
vim@2:9.1.0016-1ubuntu7.9
2:9.1.0016-1ubuntu7.11

Open the chart page →

5,059
IMgrycapOfficialVerified publisher1.8.01 of 3See more

IM grycap 1.8.0

1 of the 3 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
ghcr.io/grycap/im:latest06a16d4f279f
vim@2:9.1.0016-1ubuntu7.9
2:9.1.0016-1ubuntu7.11

Open the chart page →

4,132
algorand-relaybiatec-repoVerified publisher4.4.11 of 1See more

algorand-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
vim@2:9.1.0016-1ubuntu7.9
2:9.1.0016-1ubuntu7.11

Open the chart page →

5,059
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
vim@2:9.1.0016-1ubuntu7.8
2:9.1.0016-1ubuntu7.11

Open the chart page →

14,352
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
vim@2:9.1.1230-2
no fix listed

Open the chart page →

4,601
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
vim@2:9.1.1230-2
no fix listed

Open the chart page →

5,174
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
vim@2:9.1.0016-1ubuntu7.8
2:9.1.0016-1ubuntu7.11

Open the chart page →

8,967
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
vim@2:9.1.0016-1ubuntu7.8
2:9.1.0016-1ubuntu7.11

Open the chart page →

8,811
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
kitware/cdash:v5.3.0d7767d9b9da4
vim@2:9.1.1230-2
no fix listed

Open the chart page →

12,062
nightingalelogic3579Verified publisher0.3.11 of 6See more

nightingale logic3579 0.3.1

1 of the 6 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
vim@2:9.1.0016-1ubuntu7.10
2:9.1.0016-1ubuntu7.11

Open the chart page →

8,938
agentpolyaxon2.16.43 of 4See more

agent polyaxon 2.16.4

3 of the 4 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
polyaxon/polyaxon-agent:2.16.4eca6952b20e6
vim@2:9.1.1230-2
no fix listed
polyaxon/polyaxon-cli:2.16.4024ff3fa775e
vim@2:9.1.1230-2
no fix listed
polyaxon/polyaxon-streams:2.16.4c186bd9834c0
vim@2:9.1.1230-2
no fix listed

Open the chart page →

10,046
polyaxonpolyaxon2.16.43 of 5See more

polyaxon polyaxon 2.16.4

3 of the 5 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
polyaxon/polyaxon-agent:2.16.4eca6952b20e6
vim@2:9.1.1230-2
no fix listed
polyaxon/polyaxon-api:2.16.42b55c3265a90
vim@2:9.1.1230-2
no fix listed
polyaxon/polyaxon-cli:2.16.4024ff3fa775e
vim@2:9.1.1230-2
no fix listed

Open the chart page →

13,741
runwhen-localrunwhen-contribVerified publisher0.6.171 of 3See more

runwhen-local runwhen-contrib 0.6.17

1 of the 3 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
vim@2:9.1.1230-2
no fix listed

Open the chart page →

3,707
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-32249.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
vim@2:9.1.0016-1ubuntu7.8
2:9.1.0016-1ubuntu7.11

Open the chart page →

6,094

Container images carrying it

18 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
polyaxon/polyaxon-agent:2.16.4eca6952b20e6
vim@2:9.1.1230-2
no fix listed
2
polyaxon/polyaxon-cli:2.16.4024ff3fa775e
vim@2:9.1.1230-2
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
vim@2:9.1.0016-1ubuntu7.8
2:9.1.0016-1ubuntu7.11
2
arunvelsriram/utils:latest655ad18fd8d6
vim@2:9.1.0016-1ubuntu7.8
2:9.1.0016-1ubuntu7.11
1
flashcatcloud/categraf:latest42e6ab16472e
vim@2:9.1.0016-1ubuntu7.10
2:9.1.0016-1ubuntu7.11
1
ixsystems/truecommand:3.2.019c218455cd2
vim@2:9.1.1230-2
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
vim@2:9.1.1230-2
no fix listed
1
netdata/netdata:v2.11.0c45c71eb23ff
vim@2:9.1.1230-2
no fix listed
1
polyaxon/polyaxon-api:2.16.42b55c3265a90
vim@2:9.1.1230-2
no fix listed
1
polyaxon/polyaxon-streams:2.16.4c186bd9834c0
vim@2:9.1.1230-2
no fix listed
1
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
vim@2:9.1.0016-1ubuntu7.9
2:9.1.0016-1ubuntu7.11
1
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
vim@2:9.1.0016-1ubuntu7.9
2:9.1.0016-1ubuntu7.11
1
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
vim@2:9.1.0016-1ubuntu7.9
2:9.1.0016-1ubuntu7.11
1
snipe/snipe-it:v8.3.1141ebf2386fe
vim@2:9.1.0016-1ubuntu7.8
2:9.1.0016-1ubuntu7.11
1
ghcr.io/grycap/im:latest06a16d4f279f
vim@2:9.1.0016-1ubuntu7.9
2:9.1.0016-1ubuntu7.11
1
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
vim@2:9.1.0016-1ubuntu7.3
2:9.1.0016-1ubuntu7.11
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
vim@2:9.1.1230-2
no fix listed
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
vim@2:9.1.1230-2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.