StackRadar

CVE-2026-33416

High

Advisory

Published 26 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
62nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
804
of 17,787 indexed, latest versions
Container images
767
deployed by those charts
Fix available
4 of 4
affected packages

Red Hat Security Advisory: libpng security update

Carried by container images the latest versions of 804 of 17,787 indexed charts deploy, on 767 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+12 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u4+3 more514
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+3 more1.6.56-r0144
libpngrpm2:1.5.13-7.el7_2, 2:1.5.13-8.el7, 2:1.6.34-5.el8, 2:1.6.37-12.el9+1 more2:1.5.13-8.el7_9.3, 2:1.6.34-11.el8_10, 2:1.6.37-12.el9_7.489
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
OSV records
ALPINE-CVE-2026-33416DEBIAN-CVE-2026-33416RHSA-2026:18028RHSA-2026:29898RHSA-2026:50808UBUNTU-CVE-2026-33416
Also known as
RHSA-2026:20548, RHSA-2026:20549, RHSA-2026:20550, RHSA-2026:29900, RHSA-2026:29901, RHSA-2026:29902, USN-8251-1, USN-8639-1

Charts affected

804 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u4

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.56-r0

Open the chart page →

13,197
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10

Open the chart page →

6,016

Container images carrying it

767 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
pnnlmiscscripts/k8s-node-image9:1.26.15-nginx-579785e5b82334
libpng@1.6.43-r0
1.6.56-r0
1
pnnlmiscscripts/k8s-node-image9:1.31.7-nginx-7e3e189d9d519
libpng@1.6.44-r0
1.6.56-r0
1
pnnlmiscscripts/k8s-node-image9:1.30.11-nginx-7f9297eea817d
libpng@1.6.44-r0
1.6.56-r0
1
pnnlmiscscripts/k8s-node-image9:1.29.10-nginx-7fcd82530bc8b
libpng@1.6.43-r0
1.6.56-r0
1
postgis/postgis:17-3.4-alpine5a1dbedac34e
libpng@1.6.44-r0
1.6.56-r0
1
praravind1801/helmimages:3.0.0f29d637b9ce1
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
project2team4/react:latest3ff031a08887
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
prom/cloudwatch-exporter:v0.16.071c2e988af06
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
pschichtel/mindustry-server:v145.1b543e9c2d371
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
qumine/minecraft-server:v0.1.15c0b650d51132
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
rabeh/apibootspring:1.0941007b6946e
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
razzy10/product-service:latest702e411956db
libpng@2:1.6.37-12.el9
2:1.6.37-12.el9_7.4
1
reaper99/recipya:v1.2.27f7ec3aeb88c
libpng@1.6.44-r0
1.6.56-r0
1
resouer/redis-slave:v2e2f198b49ba7
libpng@1.2.50-1ubuntu2
1.2.50-1ubuntu2.14.04.3+esm2
1
resurfaceio/resurface:3.7.84d5cda2f64109
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
rm3l/dev-feed-api:latest9a7f732245a3
libpng@2:1.6.37-12.el9
2:1.6.37-12.el9_7.4
1
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
rocketchat/freeswitch:stablecfba5c20a5cc
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
rommapp/romm:5.2.03512f2ca4557
libpng@1.6.54-r0
1.6.56-r0
1
rommapp/romm:4.4.1b909e95d1aab
libpng@1.6.47-r0
1.6.56-r0
1
rraahul/test:latestbfe2c1183bc0
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
rrobetti/ojp:0.1.0-beta1141bd88232b
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
rtuszik/photon-docker:2.4.021549c60f9e6
libpng1.6@1.6.43-5ubuntu0.3
1.6.43-5ubuntu0.6
1
rundeck/rundeck:3.2.74d64fe56f767
libpng@1.2.54-1ubuntu1.1
1.2.54-1ubuntu1.1+esm3
1
rundeck/rundeck:3.0.16b13e8059ad72
libpng@1.2.54-1ubuntu1.1
1.2.54-1ubuntu1.1+esm3
1
ryshe/terraria:latestb1c89f7f359a
libpng1.6@1.6.39-2+deb12u3
1.6.39-2+deb12u4
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
saidsef/scapy-containerised:v2025.02f17f7c435891
libpng@1.6.45-r0
1.6.56-r0
1
santisbon/evwatcher:latestc4e994ca4540
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
santisbon/evworker:lateste807283f8d69
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
santisbon/speedtest:latest8ee3a1697227
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
scrapinghub/splash:3.4.1a5f89bc84606
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
seafileltd/seafile-mc:9.0.106693911bcc40
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
seafileltd/seafile-mc:9.0.97ac833196f60
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
seyiogunniran/my-nginx:1.03a0ed39e5830
libpng@1.6.47-r0
1.6.56-r0
1
shamimkuet/nginx:1.0.2b82902a76a04
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
shaowenchen/ops-server:latest315444f703f4
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
sismics/docs:v1.10f4b0ef019cf1
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
sissbruecker/linkding:1.35.00c5dddf0b37c
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
snipe/snipe-it:v8.3.1141ebf2386fe
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
snipe/snipe-it:v6.0.1455fb7636a98c
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.