StackRadar

CVE-2026-32316

High

Advisory

Published 13 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
362
of 17,781 indexed, latest versions
Container images
290
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 362 of 17,781 indexed charts deploy, on 290 images.

Affected packageAffected versionsFixed inImages
jqdeb1.5+dfsg-1, 1.5+dfsg-1ubuntu0.1, 1.5+dfsg-2, 1.6-1ubuntu0.20.04.1+9 more1.5+dfsg-1ubuntu0.1+esm4, 1.5+dfsg-2ubuntu0.1~esm2, 1.6-1ubuntu0.20.04.1+esm2, 1.6-2.1+deb12u2+4 more185
jqapk1.7.1-r0, 1.8.0-r0, 1.8.1-r01.8.2-r0105
OSV records
ALPINE-CVE-2026-32316DEBIAN-CVE-2026-32316UBUNTU-CVE-2026-32316
Also known as
USN-8202-1

Charts affected

362 by stars
ChartLatestAffected imagesRadar Score
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
library/mongo:5.0.217c81758cb295
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2

Open the chart page →

20,270
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2

Open the chart page →

10,006
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
jq@1.8.1-r0
1.8.2-r0

Open the chart page →

1,675
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
jq@1.8.1-r0
1.8.2-r0

Open the chart page →

5,550
simple-mongodbtyk-helm0.1.11 of 1See more

simple-mongodb tyk-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2

Open the chart page →

4,087
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
jq@1.6-2.1
1.6-2.1+deb12u2

Open the chart page →

8,607
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.2

Open the chart page →

9,347
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.2

Open the chart page →

13,459
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
jq@1.7.1-3ubuntu0.24.04.1
1.7.1-3ubuntu0.24.04.2

Open the chart page →

7,628
ciliumvks-helm-chartsVerified publisher1.17.141 of 3See more

cilium vks-helm-charts 1.17.14

1 of the 3 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
jq@1.7.1-3ubuntu0.24.04.1
1.7.1-3ubuntu0.24.04.2

Open the chart page →

4,046
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2

Open the chart page →

28,605
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
jq@1.8.0-r0
1.8.2-r0

Open the chart page →

14,983

Container images carrying it

290 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apache/nifi-registry:1.27.063b8e3e40742
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.2
1
aquasec/kube-bench:v0.15.07a8fa32dce21
jq@1.8.1-r0
1.8.2-r0
1
aristidetm/basic-notebook:3.6.5469dbc951224
jq@1.6-2.1
1.6-2.1+deb12u2
1
arunvelsriram/utils:latest655ad18fd8d6
jq@1.7.1-3ubuntu0.24.04.1
1.7.1-3ubuntu0.24.04.2
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
jq@1.7.1-6+deb13u2
1.7.1-6+deb13u3
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
jq@1.7.1-6+deb13u1
1.7.1-6+deb13u3
1
bitnamilegacy/kubectl:1.301249fc292e84
jq@1.6-2.1
1.6-2.1+deb12u2
1
bitnamilegacy/kubectl:1.3164614ef8290f
jq@1.6-2.1
1.6-2.1+deb12u2
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
jq@1.6-2.1
1.6-2.1+deb12u2
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
jq@1.6-2.1
1.6-2.1+deb12u2
1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
jq@1.6-2.1
1.6-2.1+deb12u2
1
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
jq@1.6-2.1
1.6-2.1+deb12u2
1
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
jq@1.6-2.1
1.6-2.1+deb12u2
1
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
jq@1.6-2.1
1.6-2.1+deb12u2
1
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
jq@1.6-2.1
1.6-2.1+deb12u2
1
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
jq@1.6-2.1
1.6-2.1+deb12u2
1
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
jq@1.6-2.1
1.6-2.1+deb12u2
1
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
jq@1.6-2.1
1.6-2.1+deb12u2
1
bitnamilegacy/os-shell:12-debian-12-r3217444b4b2c96
jq@1.6-2.1
1.6-2.1+deb12u2
1
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
jq@1.6-2.1
1.6-2.1+deb12u2
1
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
jq@1.6-2.1
1.6-2.1+deb12u2
1
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
jq@1.6-2.1
1.6-2.1+deb12u2
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
jq@1.8.1-r0
1.8.2-r0
1
blackducksoftware/blackduck-alert-rabbitmq:8.4.08f422b18d171
jq@1.8.1-r0
1.8.2-r0
1
budibase/apps:3.41.344fe6feab985
jq@1.8.1-r0
1.8.2-r0
1
budibase/proxy:3.41.38d780b6ee602
jq@1.7.1-6+deb13u2
1.7.1-6+deb13u3
1
budibase/worker:3.41.3de5e2e560ce8
jq@1.8.1-r0
1.8.2-r0
1
cheveo/azp-agent:1.0.282240f890884
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.2
1
circleci/runner:launch-agent9bdc62f02162
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
1
cribl/cribl:3.0.2762747cb6796
jq@1.5+dfsg-2
1.5+dfsg-2ubuntu0.1~esm2
1
dependencytrack/frontend:4.14.200560b57a6cf
jq@1.8.1-r0
1.8.2-r0
1
dependencytrack/frontend:latest8854a8320475
jq@1.8.1-r0
1.8.2-r0
1
dgraph/dgraph:v24.1.4b57fa31f9b7f
jq@1.7.1-3ubuntu0.24.04.1
1.7.1-3ubuntu0.24.04.2
1
dobtc/bitcoin:25.1a870f7cb1105
jq@1.6-2.1
1.6-2.1+deb12u2
1
escaping/core-keeper-dedicated:latest87fa79255962
jq@1.7.1-6+deb13u1
1.7.1-6+deb13u3
1
ethpandaops/assertoor:latest1efa2fba6711
jq@1.7.1-6+deb13u2
1.7.1-6+deb13u3
1
factoriotools/factorio:2.0.67-rootlessf7909f7361d6
jq@1.7.1-6+deb13u1
1.7.1-6+deb13u3
1
falcosecurity/falco-driver-loader:0.44.17df783d5269a
jq@1.6-2.1+deb12u1
1.6-2.1+deb12u2
1
filebrowser/filebrowser:v2.63.15-s6dbac07403040
jq@1.8.1-r0
1.8.2-r0
1
filiparag/hetzner_ddns:1.0.15a9cbae7997c
jq@1.8.1-r0
1.8.2-r0
1
fluent/fluent-bit:4.0-debuge76397ef3983
jq@1.6-2.1+deb12u1
1.6-2.1+deb12u2
1
free5gmano/nextepc-mongodb:latest36f806935519
jq@1.5+dfsg-1ubuntu0.1
1.5+dfsg-1ubuntu0.1+esm4
1
gradiant/open5gs-dbctl:0.10.3332031245fce
jq@1.7.1-3build1
1.7.1-3ubuntu0.24.04.2
1
haugene/transmission-openvpn:4.0059216cfae4b
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
1
homeassistant/home-assistant:2026.75a531753cea9
jq@1.8.1-r0
1.8.2-r0
1
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
jq@1.5+dfsg-1ubuntu0.1
1.5+dfsg-1ubuntu0.1+esm4
1
improwised/proxysql:master-6b26e59-171765063828940522e8b7
jq@1.6-2.1
1.6-2.1+deb12u2
1
ixsystems/truecommand:3.2.019c218455cd2
jq@1.7.1-6+deb13u1
1.7.1-6+deb13u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.