StackRadar

CVE-2026-33416

High

Advisory

Published 26 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
62nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
804
of 17,787 indexed, latest versions
Container images
767
deployed by those charts
Fix available
4 of 4
affected packages

Red Hat Security Advisory: libpng security update

Carried by container images the latest versions of 804 of 17,787 indexed charts deploy, on 767 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+12 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u4+3 more514
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+3 more1.6.56-r0144
libpngrpm2:1.5.13-7.el7_2, 2:1.5.13-8.el7, 2:1.6.34-5.el8, 2:1.6.37-12.el9+1 more2:1.5.13-8.el7_9.3, 2:1.6.34-11.el8_10, 2:1.6.37-12.el9_7.489
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
OSV records
ALPINE-CVE-2026-33416DEBIAN-CVE-2026-33416RHSA-2026:18028RHSA-2026:29898RHSA-2026:50808UBUNTU-CVE-2026-33416
Also known as
RHSA-2026:20548, RHSA-2026:20549, RHSA-2026:20550, RHSA-2026:29900, RHSA-2026:29901, RHSA-2026:29902, USN-8251-1, USN-8639-1

Charts affected

804 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u4

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.56-r0

Open the chart page →

13,197
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10

Open the chart page →

6,016

Container images carrying it

767 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
libpng1.6@1.6.39-2+deb12u1
1.6.39-2+deb12u4
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
ghcr.io/zystem-io/zymtrace-pub-ui:26.9.1e951adf792cd
libpng@1.6.47-r0
1.6.56-r0
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
libpng1.6@1.6.43-5ubuntu0.3
1.6.43-5ubuntu0.6
1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
libpng@2:1.6.37-12.el9
2:1.6.37-12.el9_7.4
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
libpng@2:1.6.37-12.el9
2:1.6.37-12.el9_7.4
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
libpng@2:1.6.37-12.el9
2:1.6.37-12.el9_7.4
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
libpng@1.6.53-r0
1.6.56-r0
1
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
libpng@1.6.53-r0
1.6.56-r0
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-account:1.18.06b25aac03414
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-product-inventory:1.18.03a5d6dd30f1d
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-product-ordering-management:1.18.042c81c291f6f
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-quote:1.18.0d9ca3a334352
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-resource-catalog:1.18.0b0d853627c59
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-resource-function-activation:1.18.062a5acb63fd1
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-resource-inventory:1.18.0553b4a47730b
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-resource-order-management:1.18.0dd1778ad6203
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-service-catalog:1.18.074b0fad9e155
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-service-inventory:1.18.04be54e8cb5c0
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-service-order-management:1.18.0d2091785d544
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-software-management:1.18.01b74a2f7ba67
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/tmforum-usage-management:1.18.042f190c42926
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.