StackRadar

CVE-2026-33416

High

Advisory

Published 26 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
62nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
804
of 17,787 indexed, latest versions
Container images
767
deployed by those charts
Fix available
4 of 4
affected packages

Red Hat Security Advisory: libpng security update

Carried by container images the latest versions of 804 of 17,787 indexed charts deploy, on 767 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+12 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u4+3 more514
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+3 more1.6.56-r0144
libpngrpm2:1.5.13-7.el7_2, 2:1.5.13-8.el7, 2:1.6.34-5.el8, 2:1.6.37-12.el9+1 more2:1.5.13-8.el7_9.3, 2:1.6.34-11.el8_10, 2:1.6.37-12.el9_7.489
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
OSV records
ALPINE-CVE-2026-33416DEBIAN-CVE-2026-33416RHSA-2026:18028RHSA-2026:29898RHSA-2026:50808UBUNTU-CVE-2026-33416
Also known as
RHSA-2026:20548, RHSA-2026:20549, RHSA-2026:20550, RHSA-2026:29900, RHSA-2026:29901, RHSA-2026:29902, USN-8251-1, USN-8639-1

Charts affected

804 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u4

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.56-r0

Open the chart page →

13,197
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-33416.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libpng@2:1.6.34-5.el8
2:1.6.34-11.el8_10

Open the chart page →

6,016

Container images carrying it

767 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
nginxinc/nginx-unprivileged:1.27.4-alpine62a904036bfc
libpng@1.6.47-r0
1.6.56-r0
1
nginxinc/nginx-unprivileged:1.29.0-alpine3.2282dcf28da5a8
libpng@1.6.47-r0
1.6.56-r0
1
nginxinc/nginx-unprivileged:mainline-alpinee93571f3d083
libpng@1.6.55-r0
1.6.56-r0
1
nirmalnaveen/supermario:latest8541a39162f3
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
libpng@1.6.44-r0
1.6.56-r0
1
olvid/bot-daemon:2.0.1e0e6b165d879
libpng1.6@1.6.43-5ubuntu0.5
1.6.43-5ubuntu0.6
1
omecproject/c3po-hssdb:master-latest28a90cc26716
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
omecproject/onos-progran:1.0.05715e5648aa0
libpng@1.2.54-1ubuntu1
1.2.54-1ubuntu1.1+esm3
1
onosproject/onos:2.2.144914a8d4b3f
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
opea/chatqna-conversation-ui:v0.9bdb9ec215872
libpng@1.6.43-r0
1.6.56-r0
1
opea/codegen-ui:1.02bee4eb66f3e
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
opea/codetrans-ui:1.03ef121f34610
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
opea/docsum-ui:1.07f854e9bffaf
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
opea/speecht5:1.0249afad3d268
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
openbas/caldera-server:5.1.0a277796d9724
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
openbas/platform:2.0.5d986d80b0a75
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
opencsghq/csgship-portal:v1.2.1865814dc87a1
libpng@1.6.47-r0
1.6.56-r0
1
opendatacube/explorer:latest120457ffcd69
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
opendatacube/pipelines:wofs-1.225d810e8504b8
libpng1.6@1.6.34-1ubuntu0.18.04.1
1.6.34-1ubuntu0.18.04.2+esm3
1
opendatacube/restcube:latest91870111837c
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
opendatacube/wms:latest1b90cdf68831
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
opendatacube/wps:latest80df355a660b
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
openelevation/open-elevation:latest82fb21612e86
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
openkm/openkm-ce:6.3.113bc465a7461b
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
openproject/hocuspocus:release-338001b288dc1359dfb5
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
opsmx11/issuegen:v2.1.05c50ca123d88
libpng@1.2.50-1ubuntu2.14.04.2
1.2.50-1ubuntu2.14.04.3+esm2
1
orbitalreg/orbitalreg-frontend:0.1.04fd449582a3c
libpng@1.6.47-r0
1.6.56-r0
1
owncloud/ocis:7.1.388e7c854517d
libpng@1.6.44-r0
1.6.56-r0
1
owncloud/ocis:8.0.1b38fd8fdd58f
libpng@1.6.55-r0
1.6.56-r0
1
owncloud/server:10.15.051d9b74fc2a8
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
payara/server-full:7.2026.2-jdk2531f1253f0cf8
libpng1.6@1.6.37-3ubuntu0.4
1.6.37-3ubuntu0.5
1
penpotapp/backend:2.2.147853d9bb9dd
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
penpotapp/exporter:2.2.15c835ffd87ab
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
phan2410/dummy-service:0.0.89c6ed6de26ca
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
photoprism/photoprism:220629-jammy2954334adbda
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
photoprism/photoprism:251130db16ee6b1ba3
libpng1.6@1.6.50-1
1.6.50-1ubuntu0.5
1
photoprism/photoprism:240711-cefc6fd632ca74
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
phpipam/phpipam-cron:v1.7.354468713454e
libpng@1.6.44-r0
1.6.56-r0
1
phpipam/phpipam-www:v1.7.3ace0efd24830
libpng@1.6.44-r0
1.6.56-r0
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
libpng1.6@1.6.48-1
1.6.48-1+deb13u4
1
pk910/powfaucet:v2-stable3dcae6a62896
libpng1.6@1.6.39-2
1.6.39-2+deb12u4
1
pmoscode/excalidraw:v0.18.08ee61554699c
libpng@1.6.47-r0
1.6.56-r0
1
pnnlmiscscripts/k8s-node-image9:1.28.15-nginx-72b91d6a46e06
libpng@1.6.43-r0
1.6.56-r0
1
pnnlmiscscripts/k8s-node-image9:1.25.16-nginx-772c202c43c0aa
libpng@1.6.43-r0
1.6.56-r0
1
pnnlmiscscripts/k8s-node-image9:1.24.17-nginx-882c8dc938b2f9
libpng@1.6.43-r0
1.6.56-r0
1
pnnlmiscscripts/k8s-node-image9:1.27.16-nginx-306e1a36d646a3
libpng@1.6.43-r0
1.6.56-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.