StackRadar

CVE-2026-33416

High

Advisory

Published 26 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
62nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
804
of 17,787 indexed, latest versions
Container images
767
deployed by those charts
Fix available
4 of 4
affected packages

Red Hat Security Advisory: libpng security update

Carried by container images the latest versions of 804 of 17,787 indexed charts deploy, on 767 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+12 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u4+3 more514
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+3 more1.6.56-r0144
libpngrpm2:1.5.13-7.el7_2, 2:1.5.13-8.el7, 2:1.6.34-5.el8, 2:1.6.37-12.el9+1 more2:1.5.13-8.el7_9.3, 2:1.6.34-11.el8_10, 2:1.6.37-12.el9_7.489
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
OSV records
ALPINE-CVE-2026-33416DEBIAN-CVE-2026-33416RHSA-2026:18028RHSA-2026:29898RHSA-2026:50808UBUNTU-CVE-2026-33416
Also known as
RHSA-2026:20548, RHSA-2026:20549, RHSA-2026:20550, RHSA-2026:29900, RHSA-2026:29901, RHSA-2026:29902, USN-8251-1, USN-8639-1

Charts affected

804 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u4

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.56-r0

Open the chart page →

13,197
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10

Open the chart page →

6,016

Container images carrying it

767 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
elastictranscoder/media:627e21dc963ab3858c6b
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
elastictranscoder/media-storage:f6d861a026208b8c2359
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
emqx/ecp-ui:2.5.1e33e9816f147
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
erenozcan17/react_frontend:v4.56e1b14973f9b
libpng@1.6.47-r0
1.6.56-r0
1
erudikaltd/scoold:1.66.0949c56b57e8f
libpng@1.6.47-r0
1.6.56-r0
1
escaping/core-keeper-dedicated:latest87fa79255962
libpng1.6@1.6.48-1+deb13u3
1.6.48-1+deb13u4
1
esphome/esphome:2024.3.09ab8cc88b28c
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
esphome/esphome:2024.12.2b2c6322700ac
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
esphome/esphome:2025.3.0def8b6e4f517
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
esteban1930/frontend-1:1.8.0f9078279632c
libpng@1.6.47-r0
1.6.56-r0
1
evoapicloud/evolution-manager:latestcbfeb314afb9
libpng@1.6.47-r0
1.6.56-r0
1
featurehub/dacha2:1.9.1c8d5551b5e40
libpng@1.6.47-r0
1.6.56-r0
1
featurehub/edge:1.9.198ad426737f6
libpng@1.6.47-r0
1.6.56-r0
1
featurehub/mr:1.9.1477d8bf771a9
libpng@1.6.47-r0
1.6.56-r0
1
felipecs8/app-db-connection-test:v129e06c9c6385
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
firefart/requesttracker:5.0.40d6249906d8c
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
fiware/mintaka:0.7.092a3c5cf43c0
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
fiware/mintaka:latestefc6793388cc
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10
1
flowable/flowable-rest:7.1.0b7ae287502cd
libpng@1.6.44-r0
1.6.56-r0
1
fluent/fluent-bit:4.0-debuge76397ef3983
libpng1.6@1.6.39-2+deb12u1
1.6.39-2+deb12u4
1
flyway/flyway:9.1545b5d7cdc75a
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
fnzv/dump1090:latestb3079b95c336
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
folioci/mod-agreements:latest29c3f233a498
libpng@1.6.43-r0
1.6.56-r0
1
folioci/mod-authtoken:latest995a25a33133
libpng@1.6.55-r0
1.6.56-r0
1
folioci/mod-courses:latest68ca414f5596
libpng@1.6.55-r0
1.6.56-r0
1
folioci/mod-ldp:latestb55696fd9065
libpng@1.6.44-r0
1.6.56-r0
1
folioci/mod-licenses:latestcfd6109bf477
libpng@1.6.43-r0
1.6.56-r0
1
folioci/mod-oa:latestae3b069d4ba5
libpng@1.6.43-r0
1.6.56-r0
1
folioci/mod-search:latest44d7ee9acdf6
libpng@1.6.47-r0
1.6.56-r0
1
folioci/mod-serials-management:latest571fa1ffe8c9
libpng@1.6.43-r0
1.6.56-r0
1
folioci/mod-service-interaction:latestf53c327a48e8
libpng@1.6.43-r0
1.6.56-r0
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
galaxy/galaxy-init:v18.010267bad550e6
libpng@1.2.50-1ubuntu2.14.04.2
1.2.50-1ubuntu2.14.04.3+esm2
1
galaxy/galaxy-stable:v18.018e577a626dfd
libpng@1.2.50-1ubuntu2.14.04.2
1.2.50-1ubuntu2.14.04.3+esm2
1
gchq/accumulo:2.0.1c460bb587d6d
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
libpng@1.6.47-r0
1.6.56-r0
1
gdrocha/togglr-frontend:1.0.0ffbc1571c234
libpng@1.6.47-r0
1.6.56-r0
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
gethue/hue:4.10.05702b2c37ff9
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.