StackRadar

CVE-2026-33416

High

Advisory

Published 26 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
62nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
804
of 17,787 indexed, latest versions
Container images
767
deployed by those charts
Fix available
4 of 4
affected packages

Red Hat Security Advisory: libpng security update

Carried by container images the latest versions of 804 of 17,787 indexed charts deploy, on 767 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+12 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u4+3 more514
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+3 more1.6.56-r0144
libpngrpm2:1.5.13-7.el7_2, 2:1.5.13-8.el7, 2:1.6.34-5.el8, 2:1.6.37-12.el9+1 more2:1.5.13-8.el7_9.3, 2:1.6.34-11.el8_10, 2:1.6.37-12.el9_7.489
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
OSV records
ALPINE-CVE-2026-33416DEBIAN-CVE-2026-33416RHSA-2026:18028RHSA-2026:29898RHSA-2026:50808UBUNTU-CVE-2026-33416
Also known as
RHSA-2026:20548, RHSA-2026:20549, RHSA-2026:20550, RHSA-2026:29900, RHSA-2026:29901, RHSA-2026:29902, USN-8251-1, USN-8639-1

Charts affected

804 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u4

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.56-r0

Open the chart page →

13,197
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10

Open the chart page →

6,016

Container images carrying it

767 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
libpng@2:1.6.37-12.el9
2:1.6.37-12.el9_7.4
1
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
libpng@2:1.6.37-12.el9_7.1
2:1.6.37-12.el9_7.4
1
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
libpng@2:1.6.37-12.el9_7.1
2:1.6.37-12.el9_7.4
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libpng@1.2.54-1ubuntu1.1
1.2.54-1ubuntu1.1+esm3
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
libpng@2:1.6.37-12.el9
2:1.6.37-12.el9_7.4
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.