StackRadar

CVE-2026-34757

Medium

Advisory

Published 9 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.1
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
761
of 17,787 indexed, latest versions
Container images
699
deployed by those charts
Fix available
4 of 4
affected packages

Security update for libpng16

Carried by container images the latest versions of 761 of 17,787 indexed charts deploy, on 699 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+14 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u5+3 more532
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+4 more1.6.57-r0146
libpng16rpm1.6.40-150600.1.31.6.40-150600.3.20.11
OSV records
ALPINE-CVE-2026-34757DEBIAN-CVE-2026-34757UBUNTU-CVE-2026-34757SUSE-SU-2026:1602-1
Also known as
USN-8251-1, USN-8639-1

Charts affected

761 by stars
ChartLatestAffected imagesRadar Score
squawkvojtechpastyrikVerified publisher0.1.101 of 1See more

squawk vojtechpastyrik 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
libpng@1.6.55-r0
1.6.57-r0

Open the chart page →

400
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

11,444
pageswalter1.0.02 of 3See more

pages walter 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3

Open the chart page →

20,233
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

8,858
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

14,420
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

28,699
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

9,296
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

6,323
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

14,172
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.57-r0

Open the chart page →

13,197

Container images carrying it

699 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/huscker/townsquare-frontend:2.15.2dc6384d10cc8
libpng@1.6.47-r0
1.6.57-r0
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
libpng1.6@1.6.48-1
1.6.48-1+deb13u5
1
ghcr.io/jaydee94/kubeseal-webgui/ui:4.5.34447636e8102
libpng@1.6.47-r0
1.6.57-r0
1
ghcr.io/jeremylong/open-vulnerability-data-mirror:v9.0.49a69aa14dc3e
libpng@1.6.56-r0
1.6.57-r0
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
libpng@1.6.47-r0
1.6.57-r0
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
libpng@1.6.47-r0
1.6.57-r0
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
libpng@1.6.54-r0
1.6.57-r0
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
libpng@1.6.44-r0
1.6.57-r0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
libpng@1.6.43-r0
1.6.57-r0
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
libpng@1.6.55-r0
1.6.57-r0
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
libpng1.6@1.6.48-1
1.6.48-1+deb13u5
1
ghcr.io/monicahq/monica-next:main8be69156acbb
libpng1.6@1.6.48-1
1.6.48-1+deb13u5
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
libpng1.6@1.6.39-2+deb12u1
1.6.39-2+deb12u5
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
libpng1.6@1.6.39-2+deb12u3
1.6.39-2+deb12u5
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/opencost/opencost-ui:1.118.0571f87e528ea
libpng@1.6.47-r0
1.6.57-r0
1
ghcr.io/openrelik/openrelik-ui:latest7f91594d5eb3
libpng@1.6.55-r0
1.6.57-r0
1
ghcr.io/open-telemetry/demo:3.0.0-fraud-detection1cdfd1bcf476
libpng1.6@1.6.39-2+deb12u3
1.6.39-2+deb12u5
1
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/open-telemetry/demo:3.0.0-image-provider93e1585e97ac
libpng@1.6.54-r0
1.6.57-r0
1
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
ghcr.io/open-telemetry/demo:3.0.0-ade6c593fe75eb
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.