StackRadar

CVE-2026-32316

High

Advisory

Published 13 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
362
of 17,781 indexed, latest versions
Container images
290
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 362 of 17,781 indexed charts deploy, on 290 images.

Affected packageAffected versionsFixed inImages
jqdeb1.5+dfsg-1, 1.5+dfsg-1ubuntu0.1, 1.5+dfsg-2, 1.6-1ubuntu0.20.04.1+9 more1.5+dfsg-1ubuntu0.1+esm4, 1.5+dfsg-2ubuntu0.1~esm2, 1.6-1ubuntu0.20.04.1+esm2, 1.6-2.1+deb12u2+4 more185
jqapk1.7.1-r0, 1.8.0-r0, 1.8.1-r01.8.2-r0105
OSV records
ALPINE-CVE-2026-32316DEBIAN-CVE-2026-32316UBUNTU-CVE-2026-32316
Also known as
USN-8202-1

Charts affected

362 by stars
ChartLatestAffected imagesRadar Score
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
library/mongo:5.0.217c81758cb295
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2

Open the chart page →

20,270
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2

Open the chart page →

10,006
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
jq@1.8.1-r0
1.8.2-r0

Open the chart page →

1,675
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
jq@1.8.1-r0
1.8.2-r0

Open the chart page →

5,550
simple-mongodbtyk-helm0.1.11 of 1See more

simple-mongodb tyk-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2

Open the chart page →

4,087
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
jq@1.6-2.1
1.6-2.1+deb12u2

Open the chart page →

8,607
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.2

Open the chart page →

9,347
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.2

Open the chart page →

13,459
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
jq@1.7.1-3ubuntu0.24.04.1
1.7.1-3ubuntu0.24.04.2

Open the chart page →

7,628
ciliumvks-helm-chartsVerified publisher1.17.141 of 3See more

cilium vks-helm-charts 1.17.14

1 of the 3 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
jq@1.7.1-3ubuntu0.24.04.1
1.7.1-3ubuntu0.24.04.2

Open the chart page →

4,046
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2

Open the chart page →

28,605
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-32316.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
jq@1.8.0-r0
1.8.2-r0

Open the chart page →

14,983

Container images carrying it

290 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
oomk8s/readiness-check:2.0.2875814cc853d
jq@1.5+dfsg-1ubuntu0.1
1.5+dfsg-1ubuntu0.1+esm4
11
library/mongo:5.0.6-focal8e70544b6c76
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
10
oomk8s/readiness-check:2.0.07daa08b81954
jq@1.5+dfsg-1
1.5+dfsg-1ubuntu0.1+esm4
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
jq@1.6-2.1
1.6-2.1+deb12u2
5
library/mongo:4.44be76f674fc4
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
5
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
jq@1.5+dfsg-1ubuntu0.1
1.5+dfsg-1ubuntu0.1+esm4
4
library/mongo:5.0-focal5e15a3f014ed
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
4
library/mongo:4.2.12-bionic628741415fc9
jq@1.5+dfsg-2
1.5+dfsg-2ubuntu0.1~esm2
4
library/mongo:4.4.66efa05203990
jq@1.5+dfsg-2
1.5+dfsg-2ubuntu0.1~esm2
4
linuxserver/sonarr:4.0.19:latest4d9df314875e
jq@1.8.1-r0
1.8.2-r0
4
pihole/pihole:2026.07.2:latestf7d1be836e3b
jq@1.8.1-r0
1.8.2-r0
4
bitnamilegacy/kubectl:latestcd354d5b2556
jq@1.6-2.1
1.6-2.1+deb12u2
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
jq@1.6-2.1
1.6-2.1+deb12u2
3
dgraph/dgraph:v21.12.03b55ea83fffe
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
3
gchq/hdfs:3.3.35ec58edbb2db
jq@1.7.1-3build1
1.7.1-3ubuntu0.24.04.2
3
natsio/nats-box:0.19.28031d190c7ee
jq@1.8.0-r0
1.8.2-r0
3
natsio/nats-box:0.19.7ffce8bd10338
jq@1.8.1-r0
1.8.2-r0
3
selenium/hub:3.141.5902f251d48d5f
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.2
3
quay.io/jupyterhub/configurable-http-proxy:5.2.0522738d5285e
jq@1.8.1-r0
1.8.2-r0
3
alpine/k8s:1.32.12048f8d9c8cc7
jq@1.8.1-r0
1.8.2-r0
2
apache/nifi-registry:1.26.07cdfd8deec92
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.2
2
gisaia/arlas-fam-wui:0.18.13700dcaf7a75
jq@1.8.1-r0
1.8.2-r0
2
gisaia/arlas-wui:28.0.3b83b3e067173
jq@1.8.1-r0
1.8.2-r0
2
gisaia/arlas-wui-builder:28.0.1a35977a5bb7d
jq@1.8.1-r0
1.8.2-r0
2
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
jq@1.8.1-r0
1.8.2-r0
2
jupyterhub/configurable-http-proxy:5.3.0:latest69a7170eeeda
jq@1.8.1-r0
1.8.2-r0
2
library/mongo:8.0.20098862b1339f
jq@1.7.1-3ubuntu0.24.04.1
1.7.1-3ubuntu0.24.04.2
2
library/mongo:5.041108d183e97
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
2
library/mongo:4.2.358b25d51baa1
jq@1.5+dfsg-2
1.5+dfsg-2ubuntu0.1~esm2
2
linuxserver/ddclient:4.0.06468911d00b1
jq@1.8.1-r0
1.8.2-r0
2
linuxserver/jackett:latest609a1830692d
jq@1.8.1-r0
1.8.2-r0
2
mesosphere/kubectl:v1.35.0-alpineea01a9387771
jq@1.8.1-r0
1.8.2-r0
2
wolveix/satisfactory-server:latest:v1.9.10e103700ae6ae
jq@1.6-2.1ubuntu3.1
1.6-2.1ubuntu3.2
2
ghcr.io/astriaorg/astria-geth:latest4249e403225a
jq@1.8.0-r0
1.8.2-r0
2
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
jq@1.8.0-r0
1.8.2-r0
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
jq@1.8.0-r0
1.8.2-r0
2
ghcr.io/home-assistant/home-assistant:2026.9.1:latest612d76760b54
jq@1.8.1-r0
1.8.2-r0
2
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
jq@1.8.1-r0
1.8.2-r0
2
ghcr.io/home-operations/radarr:6.4.3:6.4.3.106450ebb4ae26ee9
jq@1.8.1-r0
1.8.2-r0
2
ghcr.io/home-operations/readarr:0.4.18:0.4.18.28058f7551205fbd
jq@1.8.0-r0
1.8.2-r0
2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
jq@1.8.1-r0
1.8.2-r0
2
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
jq@1.6-2.1+deb12u1
1.6-2.1+deb12u2
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm2
1
airbyte/pod-sweeper:1.5.198d2c39d512e
jq@1.6-2.1
1.6-2.1+deb12u2
1
alpine/k8s:1.36.244ef4942e171
jq@1.8.1-r0
1.8.2-r0
1
alpine/k8s:1.31.106dbe6f391eda
jq@1.8.0-r0
1.8.2-r0
1
alpine/k8s:1.31.137a319b15cfc9
jq@1.8.0-r0
1.8.2-r0
1
alpine/k8s:1.35.6b7a12c5ddf26
jq@1.8.1-r0
1.8.2-r0
1
alpine/k8s:1.35.5d870622d0040
jq@1.8.1-r0
1.8.2-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.