StackRadar

CVE-2026-34238

Medium

Advisory

Published 13 Apr 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
106
of 17,781 indexed, latest versions
Container images
114
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 106 of 17,781 indexed charts deploy, on 114 images.

Affected packageAffected versionsFixed inImages
imagemagickdeb8:6.8.9.9-7ubuntu5.9, 8:6.9.10.23+dfsg-2.1ubuntu11.4, 8:6.9.11.60+dfsg-1.3build2, 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+17 more8:6.9.11.60+dfsg-1.6+deb12u9, 8:7.1.1.43+dfsg1-1+deb13u8114
OSV records
DEBIAN-CVE-2026-34238UBUNTU-CVE-2026-34238

Charts affected

106 by stars
ChartLatestAffected imagesRadar Score
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-34238.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u9

Open the chart page →

28,858
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-34238.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u3
8:6.9.11.60+dfsg-1.6+deb12u9

Open the chart page →

10,086
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-34238.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u9

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-34238.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u9

Open the chart page →

14,358
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-34238.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u9

Open the chart page →

10,795
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-34238.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
imagemagick@8:6.9.12.98+dfsg1-5.2build2
no fix listed

Open the chart page →

7,628

Container images carrying it

114 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u4
8:6.9.11.60+dfsg-1.6+deb12u9
3
gjeanmart/safe-ganache-node:latest926264c8f2d1
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u9
2
library/python:3.7eedf63967cdb
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u9
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u8
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u9
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u9
2
akaunting/akaunting:3.0.1552811b36ec3a
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u9
1
apache/tika:latest-full80072bb73dd3
imagemagick@8:7.1.2.18+dfsg1-1
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u9
1
avinash263/pyredis263:latestaa2b8727f1a6
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u9
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u3
8:6.9.11.60+dfsg-1.6+deb12u9
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u3
8:6.9.11.60+dfsg-1.6+deb12u9
1
bnjbvr/kresus:0.22.137e216b182c8
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u9
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u9
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
imagemagick@8:7.1.1.43+dfsg1-1+deb13u6
8:7.1.1.43+dfsg1-1+deb13u8
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
imagemagick@8:7.1.1.43+dfsg1-1
8:7.1.1.43+dfsg1-1+deb13u8
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u8
1
felipecs8/app-db-connection-test:v129e06c9c6385
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u9
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u3
8:6.9.11.60+dfsg-1.6+deb12u9
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u9
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u9
1
itzg/bungeecord:latest1c59f9631f3b
imagemagick@8:7.1.2.18+dfsg1-1
no fix listed
1
itzg/minecraft-server:2026.9.04e29d14082d9
imagemagick@8:6.9.12.98+dfsg1-5.2build2
no fix listed
1
itzg/minecraft-server:latest8672e335dbef
imagemagick@8:6.9.12.98+dfsg1-5.2build2
no fix listed
1
knspar/phronetis-operator:0.1.60c4f0543ee58
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u9
1
laly9999/node-app:1dd0e503913e1
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u3
8:6.9.11.60+dfsg-1.6+deb12u9
1
library/nextcloud:31.0.6-apache588609d76b21
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u3
8:6.9.11.60+dfsg-1.6+deb12u9
1
library/nextcloud:31.0.10-apacheb7faa1653c39
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u8
1
library/node:208f693eaa7e0a
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u8
8:6.9.11.60+dfsg-1.6+deb12u9
1
library/python:3.8d41127070014
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u9
1
library/python:3.9da5aee29682d
imagemagick@8:7.1.1.43+dfsg1-1+deb13u2
8:7.1.1.43+dfsg1-1+deb13u8
1
library/wordpress:6.4.3-apache8ae66efb09a2
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u9
1
library/wordpress:php8.1-apachef73396626d2f
imagemagick@8:7.1.1.43+dfsg1-1+deb13u3
8:7.1.1.43+dfsg1-1+deb13u8
1
linuxserver/calibre-web:0.6.24241009026e6f
imagemagick@8:6.9.12.98+dfsg1-5.2build2
no fix listed
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
imagemagick@8:6.9.10.23+dfsg-2.1ubuntu11.4
no fix listed
1
mindsdb/mindsdb:latest163011c09299
imagemagick@8:7.1.1.43+dfsg1-1+deb13u7
8:7.1.1.43+dfsg1-1+deb13u8
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u9
1
moreillon/api-proxy:latestd7d4a5463525
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u3
8:6.9.11.60+dfsg-1.6+deb12u9
1
moreillon/food-manager:lateste8fd856e593d
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u3
8:6.9.11.60+dfsg-1.6+deb12u9
1
moreillon/group-manager:latest3caa8f710ee0
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u7
8:6.9.11.60+dfsg-1.6+deb12u9
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
imagemagick@8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u9
1
muhammedgamal/fp23:latest74b4cd69b6fa
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u9
1
opea/codegen-ui:1.02bee4eb66f3e
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u9
1
opea/codetrans-ui:1.03ef121f34610
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u9
1
opea/docsum-ui:1.07f854e9bffaf
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u9
1
openkm/openkm-ce:6.3.113bc465a7461b
imagemagick@8:6.9.10.23+dfsg-2.1ubuntu11.4
no fix listed
1
openproject/hocuspocus:release-338001b288dc1359dfb5
imagemagick@8:6.9.11.60+dfsg-1.6+deb12u3
8:6.9.11.60+dfsg-1.6+deb12u9
1
owncloud/server:10.16.274c53d341076
imagemagick@8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
no fix listed
1
owncloud/server:10.16.3b3f9efdcd7f7
imagemagick@8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
no fix listed
1
penpotapp/backend:2.2.147853d9bb9dd
imagemagick@8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.