StackRadar

CVE-2026-33416

High

Advisory

Published 26 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
62nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
804
of 17,787 indexed, latest versions
Container images
767
deployed by those charts
Fix available
4 of 4
affected packages

Red Hat Security Advisory: libpng security update

Carried by container images the latest versions of 804 of 17,787 indexed charts deploy, on 767 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+12 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u4+3 more514
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+3 more1.6.56-r0144
libpngrpm2:1.5.13-7.el7_2, 2:1.5.13-8.el7, 2:1.6.34-5.el8, 2:1.6.37-12.el9+1 more2:1.5.13-8.el7_9.3, 2:1.6.34-11.el8_10, 2:1.6.37-12.el9_7.489
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
OSV records
ALPINE-CVE-2026-33416DEBIAN-CVE-2026-33416RHSA-2026:18028RHSA-2026:29898RHSA-2026:50808UBUNTU-CVE-2026-33416
Also known as
RHSA-2026:20548, RHSA-2026:20549, RHSA-2026:20550, RHSA-2026:29900, RHSA-2026:29901, RHSA-2026:29902, USN-8251-1, USN-8639-1

Charts affected

804 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u4

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.56-r0

Open the chart page →

13,197
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10

Open the chart page →

6,016

Container images carrying it

767 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/elasticsearch:8.12.215d4647fd491
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
bnjbvr/kresus:0.22.137e216b182c8
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
budibase/database:2.1.0d90f656261c9
libpng1.6@1.6.39-2+deb12u3
1.6.39-2+deb12u4
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
carlosmz87/test_helm_frontend:latest79f4b528f42a
libpng@1.6.44-r0
1.6.56-r0
1
castlemock/castlemock:latestb7f3f1527ba9
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
castopod/castopod:1.12.101fd37280cbb2
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
castopod/castopod:1.15.54e4f0440520f
libpng1.6@1.6.48-1+deb13u3
1.6.48-1+deb13u4
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
chandanteekinavar/findery-market-frontend:1.06de5bd44a325
libpng@1.6.44-r0
1.6.56-r0
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
libpng@1.2.50-1ubuntu2.14.04.3
1.2.50-1ubuntu2.14.04.3+esm2
1
cheyang/distributed-tf:1.6.046cc34755493
libpng@1.2.54-1ubuntu1
1.2.54-1ubuntu1.1+esm3
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
libpng@1.6.47-r0
1.6.56-r0
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
libpng1.6@1.6.48-1+deb13u3
1.6.48-1+deb13u4
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
libpng1.6@1.6.37-3ubuntu0.4
1.6.37-3ubuntu0.5
1
ckulka/baikal:0.10.1-nginx434bdd162247
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
clowder/clowder2-frontend:2.0.0-beta.4fe97882672ca
libpng@1.6.47-r0
1.6.56-r0
1
codetogether/codetogether:latest4348c8a38752
libpng@2:1.6.37-12.el9
2:1.6.37-12.el9_7.4
1
collabora/code:24.04.13.2.101dc4ab83977
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
collabora/code:23.05.10.1.105299b452f7f
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
commerceexperts/searchhub-smartsuggest-service:1.3.0341eebe7239b
libpng@1.6.43-r0
1.6.56-r0
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
copyparty/ac:1.19.200a0a8605062c
libpng@1.6.47-r0
1.6.56-r0
1
countly/countly-server:25.05.4e3c238248f99
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
dannielkil/book-frontend:latest937993927694
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
daskdev/dask-notebook:1.1.0052630f5ca04
libpng1.6@1.6.34-1ubuntu0.18.04.1
1.6.34-1ubuntu0.18.04.2+esm3
1
datamate/seafile-professional:11.0.202dd66b722464
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
davidy/giphy-app:1.0.2-arm41b2355cc23a
libpng@1.6.44-r0
1.6.56-r0
1
deconzcommunity/deconz:2.29.2062de2362641
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
dellcloud/category:distributed02fc234353a9
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
dellcloud/pages:1.04d2eb25b9225
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
djjudas21/bearhugmugs:0.1.14fa898a52d97
libpng@1.6.44-r0
1.6.56-r0
1
docuseal/docuseal:2.4.17493fd7f6728
libpng@1.6.55-r0
1.6.56-r0
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
libpng1.6@1.6.48-1
1.6.48-1+deb13u4
1
dragonflyoss/client:v0.1.82edf3e921f4e0
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
dremio/dremio-oss:24.1.080ed2e3b7c43
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
drpcorg/dshackle:0.54.08858fae1859d
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
dzikoysk/reposilite:3.5.264128c2d7a6ba
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
libpng@1.6.54-r0
1.6.56-r0
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
libpng1.6@1.6.48-1
1.6.48-1+deb13u4
1
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
libpng@1.6.54-r0
1.6.56-r0
1
eftechcombr/glpi:php-fpm-12.0.0-rc1f3d0ed01709e
libpng@1.6.55-r0
1.6.56-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.