CVE-2026-33636
HighAdvisory
Published 26 Mar 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.6
- base score, highest
- EPSS
- 0.007
- 53rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 703
- of 17,787 indexed, latest versions
- Container images
- 642
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Red Hat Security Advisory: libpng security update
Carried by container images the latest versions of 703 of 17,787 indexed charts deploy, on 642 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| libpng1.6deb | 1.6.37-2, 1.6.37-3build5, 1.6.37-3ubuntu0.4, 1.6.39-2+10 more | 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u4, 1.6.43-5ubuntu0.6+2 more | 480 |
| libpngapk | 1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+3 more | 1.6.56-r0 | 144 |
| libpngrpm | 2:1.6.37-12.el9, 2:1.6.37-12.el9_7.1 | 2:1.6.37-12.el9_7.3 | 18 |
- OSV records
- ALPINE-CVE-2026-33636DEBIAN-CVE-2026-33636RHSA-2026:14791UBUNTU-CVE-2026-33636
- Also known as
- RHSA-2026:17524, RHSA-2026:17603, RHSA-2026:17642, USN-8251-1, USN-8639-1
Charts affected
703 by stars
Container images carrying it
642 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.