StackRadar

CVE-2026-32316

High

Advisory

Published 13 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
362
of 17,781 indexed, latest versions
Container images
290
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 362 of 17,781 indexed charts deploy, on 290 images.

Affected packageAffected versionsFixed inImages
jqdeb1.5+dfsg-1, 1.5+dfsg-1ubuntu0.1, 1.5+dfsg-2, 1.6-1ubuntu0.20.04.1+9 more1.5+dfsg-1ubuntu0.1+esm4, 1.5+dfsg-2ubuntu0.1~esm2, 1.6-1ubuntu0.20.04.1+esm2, 1.6-2.1+deb12u2+4 more185
jqapk1.7.1-r0, 1.8.0-r0, 1.8.1-r01.8.2-r0105
OSV records
ALPINE-CVE-2026-32316DEBIAN-CVE-2026-32316UBUNTU-CVE-2026-32316
Also known as
USN-8202-1

Charts affected

362 by stars
ChartLatestAffected imagesRadar Score
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
library/mongo:5.0.217c81758cb295
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2

Open the chart page →

20,270
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2

Open the chart page →

10,006
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
jq@1.8.1-r0
1.8.2-r0

Open the chart page →

1,675
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
jq@1.8.1-r0
1.8.2-r0

Open the chart page →

5,550
simple-mongodbtyk-helm0.1.11 of 1See more

simple-mongodb tyk-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2

Open the chart page →

4,087
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
jq@1.6-2.1
1.6-2.1+deb12u2

Open the chart page →

8,607
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.2

Open the chart page →

9,347
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.2

Open the chart page →

13,459
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
jq@1.7.1-3ubuntu0.24.04.1
1.7.1-3ubuntu0.24.04.2

Open the chart page →

7,628
ciliumvks-helm-chartsVerified publisher1.17.141 of 3See more

cilium vks-helm-charts 1.17.14

1 of the 3 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
jq@1.7.1-3ubuntu0.24.04.1
1.7.1-3ubuntu0.24.04.2

Open the chart page →

4,046
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2

Open the chart page →

28,605
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
jq@1.8.0-r0
1.8.2-r0

Open the chart page →

14,983

Container images carrying it

290 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
jertel/elastalert2:2.31.03cbf63f9b7dc
jq@1.7.1-6+deb13u2
1.7.1-6+deb13u3
1
jmferrer/azure-devops-agent:latest030f68ec6998
jq@1.5+dfsg-1ubuntu0.1
1.5+dfsg-1ubuntu0.1+esm4
1
jordan/icinga2:latestf75025fe8ea8
jq@1.6-2.1+deb12u1
1.6-2.1+deb12u2
1
josh5/unmanic:0.2.64d49c4816260
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.2
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
jq@1.5+dfsg-2
1.5+dfsg-2ubuntu0.1~esm2
1
library/mongo:7.0.140032d2ca20db
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.2
1
library/mongo:4.4.1305678ae4e5e1
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
1
library/mongo:3.6146c1fd999a6
jq@1.5+dfsg-1ubuntu0.1
1.5+dfsg-1ubuntu0.1+esm4
1
library/mongo:5.0.32-focal3b6c281e1c08
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
1
library/mongo:4.4-bionic3d0e6df9fd5b
jq@1.5+dfsg-2
1.5+dfsg-2ubuntu0.1~esm2
1
library/mongo:5.0.14-focal50cae5081ab4
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
1
library/mongo:6.0.12646902910d6a
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.2
1
library/mongo:4.2699d652ed674
jq@1.5+dfsg-2
1.5+dfsg-2ubuntu0.1~esm2
1
library/mongo:4.2.16ca49afbcb2b
jq@1.5+dfsg-2
1.5+dfsg-2ubuntu0.1~esm2
1
library/mongo:6.0.271a63fc2438e
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
1
library/mongo:5.0.217c81758cb295
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
1
library/mongo:7.0.28-jammy88785f6f665a
jq@1.6-2.1ubuntu3.1
1.6-2.1ubuntu3.2
1
library/mongo:4.2.21-bionic9cb28f7291d9
jq@1.5+dfsg-2
1.5+dfsg-2ubuntu0.1~esm2
1
library/mongo:7.0.12ae1cf99fa7bf
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.2
1
library/mongo:4.4.18d23ec07162ca
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
1
library/mongo:8.0.11dca8d11fe467
jq@1.7.1-3build1
1.7.1-3ubuntu0.24.04.2
1
library/neo4j:2026.05.0-enterprise2caf944aa4a5
jq@1.7.1-6+deb13u2
1.7.1-6+deb13u3
1
library/neo4j:2026.02.25ab4ab0358cf
jq@1.7.1-6+deb13u1
1.7.1-6+deb13u3
1
library/neo4j:2026.05.06c162e2432f8
jq@1.7.1-6+deb13u2
1.7.1-6+deb13u3
1
linuxserver/bazarr:latesta20fb11a440d
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/bookstack:26.05.202605282ebf97852661
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
jq@1.5+dfsg-2
1.5+dfsg-2ubuntu0.1~esm2
1
linuxserver/calibre-web:0.6.24241009026e6f
jq@1.7.1-3ubuntu0.24.04.1
1.7.1-3ubuntu0.24.04.2
1
linuxserver/code-server:4.10.1a5e43a05ae79
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.2
1
linuxserver/deluge:2.2.09505c64720af
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/foldingathome:7.6.219a997426d71e
jq@1.7.1-3build1
1.7.1-3ubuntu0.24.04.2
1
linuxserver/heimdall:2.8.3287e48152967
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/jackett:0.24.20929bca08e2e6f1
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/jackett:0.24.2066f1f23e0c9845
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/lidarr:3.1.0c74c32408fdf
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/mariadb:latestcb61ec331e80
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/medusa:v1.0.26-ls2884477fb1ce3ca
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
jq@1.5+dfsg-2
1.5+dfsg-2ubuntu0.1~esm2
1
linuxserver/overseerr:1.35.06108ed066d4a
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/plex:1.25.24a13ced2326c
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
1
linuxserver/prowlarr:version-2.4.0.53974fd7a166c8f4
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/prowlarr:2.5.291844fa2c927
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/prowlarr:2.4.0.5397-ls149a46d0ce0a823
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/qbittorrent:latesta00b6a597a38
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/qbittorrent:5.2.2dd24a5f3db32
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/radarr:version-6.2.1.10461549c4a075496
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/smokeping:2.9.02f4488c9afcd
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/sonarr:version-4.0.17.295202bc962946fe
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/tautulli:latest5ce8c5f82f91
jq@1.8.1-r0
1.8.2-r0
1
linuxserver/unifi-controller:8.0.240ae315a3a456
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.