StackRadar

CVE-2026-34757

Medium

Advisory

Published 9 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.1
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
761
of 17,787 indexed, latest versions
Container images
699
deployed by those charts
Fix available
4 of 4
affected packages

Security update for libpng16

Carried by container images the latest versions of 761 of 17,787 indexed charts deploy, on 699 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+14 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u5+3 more532
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+4 more1.6.57-r0146
libpng16rpm1.6.40-150600.1.31.6.40-150600.3.20.11
OSV records
ALPINE-CVE-2026-34757DEBIAN-CVE-2026-34757UBUNTU-CVE-2026-34757SUSE-SU-2026:1602-1
Also known as
USN-8251-1, USN-8639-1

Charts affected

761 by stars
ChartLatestAffected imagesRadar Score
squawkvojtechpastyrikVerified publisher0.1.101 of 1See more

squawk vojtechpastyrik 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
libpng@1.6.55-r0
1.6.57-r0

Open the chart page →

400
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

11,444
pageswalter1.0.02 of 3See more

pages walter 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3

Open the chart page →

20,233
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

8,858
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

14,420
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

28,699
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

9,296
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

6,323
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

14,172
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.57-r0

Open the chart page →

13,197

Container images carrying it

699 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
stashapp/stash-box:latesta534c8afdf39
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
streamnative/private-cloud-console:v2.3.27-all91e54375e154
libpng@1.6.55-r0
1.6.57-r0
1
structurizr/onpremises:2025.11.094b5ffb5119c8
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
substratusai/verba:v0.4.0-baseURL261695be635eb
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
svcosti/cidrapp:latest8428d87bc5d0
libpng@1.6.47-r0
1.6.57-r0
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
sysnet4admin/colosseum-cms:loge74b43c7f492
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
teknas09/bird-pod:latest12a1fa85c4aa
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
libpng@1.2.54-1ubuntu1
1.2.54-1ubuntu1.1+esm3
1
theradius/loggia:0.463ba348546ec
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
thingsboard/tb-postgres:latest2d17e4e36edc
libpng1.6@1.6.39-2+deb12u1
1.6.39-2+deb12u5
1
thmmniii/fbs-core:v1.27.15438517d9fc2
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
thongngo3301/stakefish:latesta341af5976e3
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libpng@1.2.54-1ubuntu1
1.2.54-1ubuntu1.1+esm3
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
libpng1.6@1.6.48-1+deb13u3
1.6.48-1+deb13u5
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
trinodb/trino:405ee80ab5eeab2
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
trueosiris/vrising:latest9356f98ad561
libpng1.6@1.6.37-3ubuntu0.4
1.6.37-3ubuntu0.5
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
vcnngr/pnfrontend:latest4e4979ab8c41
libpng@1.6.47-r0
1.6.57-r0
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
vlebediantsev/notes-admin-front:latest007c6670ff48
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
vlebediantsev/notes-project-front:latest945675fd2636
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
voltha/voltha-envoy:1.6.059ab2a00f712
libpng@1.2.50-1ubuntu2.14.04.2
1.2.50-1ubuntu2.14.04.3+esm2
1
voltha/voltha-onos:5.1.8e038acb950d3
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
wavefronthq/proxy:9.2d1064d28f6eb
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
wazuh/wazuh-dashboard:4.4.11787550d2358
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
wistefan/mvf:lateste0887302b2d8
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
xeladock/mysql_dns:latest4baf531453f1
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
xeladock/nginx2:latestc259a67b1dff
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
xeotek/kadeck:6.3.439a3b37a17c5
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
xeotek/kadeck:4.2.94c6b04d9ce55
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ymuski/geo-checker:5.0.05ba7fd8c7bdc
libpng@1.6.47-r0
1.6.57-r0
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
libpng@1.6.53-r0
1.6.57-r0
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
libpng@1.6.53-r0
1.6.57-r0
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
libpng@1.6.53-r0
1.6.57-r0
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
libpng@1.6.53-r0
1.6.57-r0
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.