StackRadar

CVE-2026-34757

Medium

Advisory

Published 9 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.1
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
761
of 17,787 indexed, latest versions
Container images
699
deployed by those charts
Fix available
4 of 4
affected packages

Security update for libpng16

Carried by container images the latest versions of 761 of 17,787 indexed charts deploy, on 699 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+14 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u5+3 more532
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+4 more1.6.57-r0146
libpng16rpm1.6.40-150600.1.31.6.40-150600.3.20.11
OSV records
ALPINE-CVE-2026-34757DEBIAN-CVE-2026-34757UBUNTU-CVE-2026-34757SUSE-SU-2026:1602-1
Also known as
USN-8251-1, USN-8639-1

Charts affected

761 by stars
ChartLatestAffected imagesRadar Score
squawkvojtechpastyrikVerified publisher0.1.101 of 1See more

squawk vojtechpastyrik 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
libpng@1.6.55-r0
1.6.57-r0

Open the chart page →

400
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

11,444
pageswalter1.0.02 of 3See more

pages walter 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3

Open the chart page →

20,233
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

8,858
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

14,420
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

28,699
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

9,296
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

6,323
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

14,172
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.57-r0

Open the chart page →

13,197

Container images carrying it

699 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
libpng1.6@1.6.48-1+deb13u3
1.6.48-1+deb13u5
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
libpng1.6@1.6.48-1
1.6.48-1+deb13u5
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
libpng1.6@1.6.48-1
1.6.48-1+deb13u5
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
libpng1.6@1.6.48-1+deb13u4
1.6.48-1+deb13u5
1
ghcr.io/pschichtel/keycloak-webhook-router:main285e226fe7f6
libpng@1.6.44-r0
1.6.57-r0
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
libpng1.6@1.6.43-5ubuntu0.5
1.6.43-5ubuntu0.6
1
ghcr.io/radar-base/radar-app-config/radar-app-config-frontend:0.6.2c5f1e2ca5781
libpng@1.6.44-r0
1.6.57-r0
1
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
libpng1.6@1.6.43-5ubuntu0.5
1.6.43-5ubuntu0.6
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
libpng1.6@1.6.43-5ubuntu0.5
1.6.43-5ubuntu0.6
1
ghcr.io/radar-base/radar-home/radar-home:0.1.71cfe3da9d812
libpng@1.6.44-r0
1.6.57-r0
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
libpng1.6@1.6.43-5ubuntu0.5
1.6.43-5ubuntu0.6
1
ghcr.io/radar-base/radar-rest-source-auth/radar-rest-source-authorizer:4.4.153e096497f7db
libpng@1.6.44-r0
1.6.57-r0
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
libpng1.6@1.6.43-5ubuntu0.5
1.6.43-5ubuntu0.6
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-frontend:0.6.47e27863545fc
libpng@1.6.47-r0
1.6.57-r0
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
libpng1.6@1.6.43-5ubuntu0.5
1.6.43-5ubuntu0.6
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
libpng1.6@1.6.43-5ubuntu0.5
1.6.43-5ubuntu0.6
1
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
libpng@1.6.55-r0
1.6.57-r0
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
libpng1.6@1.6.39-2+deb12u1
1.6.39-2+deb12u5
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
libpng1.6@1.6.39-2+deb12u4
1.6.39-2+deb12u5
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/zystem-io/zymtrace-pub-ui:26.9.1e951adf792cd
libpng@1.6.47-r0
1.6.57-r0
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
libpng1.6@1.6.43-5ubuntu0.3
1.6.43-5ubuntu0.6
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
libpng@1.6.53-r0
1.6.57-r0
1
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
libpng@1.6.53-r0
1.6.57-r0
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libpng@1.2.54-1ubuntu1.1
1.2.54-1ubuntu1.1+esm3
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
libpng1.6@1.6.48-1+deb13u4
1.6.48-1+deb13u5
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.