StackRadar

CVE-2026-33416

High

Advisory

Published 26 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
62nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
804
of 17,787 indexed, latest versions
Container images
767
deployed by those charts
Fix available
4 of 4
affected packages

Red Hat Security Advisory: libpng security update

Carried by container images the latest versions of 804 of 17,787 indexed charts deploy, on 767 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+12 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u4+3 more514
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+3 more1.6.56-r0144
libpngrpm2:1.5.13-7.el7_2, 2:1.5.13-8.el7, 2:1.6.34-5.el8, 2:1.6.37-12.el9+1 more2:1.5.13-8.el7_9.3, 2:1.6.34-11.el8_10, 2:1.6.37-12.el9_7.489
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
OSV records
ALPINE-CVE-2026-33416DEBIAN-CVE-2026-33416RHSA-2026:18028RHSA-2026:29898RHSA-2026:50808UBUNTU-CVE-2026-33416
Also known as
RHSA-2026:20548, RHSA-2026:20549, RHSA-2026:20550, RHSA-2026:29900, RHSA-2026:29901, RHSA-2026:29902, USN-8251-1, USN-8639-1

Charts affected

804 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u4

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.56-r0

Open the chart page →

13,197
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10

Open the chart page →

6,016

Container images carrying it

767 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
vlebediantsev/notes-project-front:latest945675fd2636
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
voltha/voltha-envoy:1.6.059ab2a00f712
libpng@1.2.50-1ubuntu2.14.04.2
1.2.50-1ubuntu2.14.04.3+esm2
1
voltha/voltha-onos:5.1.8e038acb950d3
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
wavefronthq/proxy:9.2d1064d28f6eb
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
wazuh/wazuh-dashboard:4.4.11787550d2358
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
wistefan/mvf:lateste0887302b2d8
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
xeladock/mysql_dns:latest4baf531453f1
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
xeladock/nginx2:latestc259a67b1dff
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
xeotek/kadeck:6.3.439a3b37a17c5
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
xeotek/kadeck:4.2.94c6b04d9ce55
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
ymuski/geo-checker:5.0.05ba7fd8c7bdc
libpng@1.6.47-r0
1.6.56-r0
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
libpng@1.6.53-r0
1.6.56-r0
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
libpng@1.6.53-r0
1.6.56-r0
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
libpng@1.6.53-r0
1.6.56-r0
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
libpng@1.6.53-r0
1.6.56-r0
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
libpng1.6@1.6.43-5ubuntu0.4
1.6.43-5ubuntu0.6
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
libpng1.6@1.6.43-5ubuntu0.4
1.6.43-5ubuntu0.6
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
zbalogh/reservation-angular-ui:1.0.95eb19e460b3c
libpng@1.6.47-r0
1.6.56-r0
1
zimengxiong/excalidash-frontend:0.4.27242629350b06
libpng@1.6.54-r0
1.6.56-r0
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
libpng@1.6.53-r0
1.6.56-r0
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/appscode/deploy-ui:0.3.6f3e07eff3997
libpng@1.6.44-r0
1.6.56-r0
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
libpng1.6@1.6.48-1
1.6.48-1+deb13u4
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/appscode/inbox-ui:0.0.5ae3b0e29daaa
libpng@1.6.47-r0
1.6.56-r0
1
ghcr.io/appscode/marketplace-ui:0.3.1d52177072013
libpng@1.6.44-r0
1.6.56-r0
1
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/blessingnator/keycloak-mcn-frontend:2.0.1ddd462dbde39
libpng@1.6.55-r0
1.6.56-r0
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
libpng1.6@1.6.43-5ubuntu0.5
1.6.43-5ubuntu0.6
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
ghcr.io/colanode/web:latestbcad696f03ee
libpng@1.6.47-r0
1.6.56-r0
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
libpng1.6@1.6.43-5ubuntu0.3
1.6.43-5ubuntu0.6
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
libpng1.6@1.6.48-1+deb13u1
1.6.48-1+deb13u4
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.