StackRadar

CVE-2026-34757

Medium

Advisory

Published 9 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.1
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
761
of 17,787 indexed, latest versions
Container images
699
deployed by those charts
Fix available
4 of 4
affected packages

Security update for libpng16

Carried by container images the latest versions of 761 of 17,787 indexed charts deploy, on 699 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+14 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u5+3 more532
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+4 more1.6.57-r0146
libpng16rpm1.6.40-150600.1.31.6.40-150600.3.20.11
OSV records
ALPINE-CVE-2026-34757DEBIAN-CVE-2026-34757UBUNTU-CVE-2026-34757SUSE-SU-2026:1602-1
Also known as
USN-8251-1, USN-8639-1

Charts affected

761 by stars
ChartLatestAffected imagesRadar Score
squawkvojtechpastyrikVerified publisher0.1.101 of 1See more

squawk vojtechpastyrik 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
libpng@1.6.55-r0
1.6.57-r0

Open the chart page →

400
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

11,444
pageswalter1.0.02 of 3See more

pages walter 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3

Open the chart page →

20,233
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

8,858
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

14,420
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

28,699
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

9,296
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

6,323
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

14,172
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.57-r0

Open the chart page →

13,197

Container images carrying it

699 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
apache/gravitino-iceberg-rest:1.3.080136ae753ee
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
apache/hertzbeat:1.8.075d48a62748f
libpng1.6@1.6.43-5ubuntu0.4
1.6.43-5ubuntu0.6
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
libpng1.6@1.6.43-5ubuntu0.4
1.6.43-5ubuntu0.6
1
apache/iotdb:0.13.3-nodeafa47bf1692a
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
apache/kafka:4.1.0bff074a5d005
libpng@1.6.47-r0
1.6.57-r0
1
apache/kafka:3.9.0fbc7d7c428e3
libpng@1.6.44-r0
1.6.57-r0
1
apache/nifi-registry:1.27.063b8e3e40742
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
apachepulsar/pulsar:3.0.79c9947de139d
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
apachepulsar/pulsar:2.9.0d056c89b7131
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
apachepulsar/pulsar:2.8.2d538416d5afe
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
apache/ranger:2.7.076c176e8a0e4
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
apache/rocketmq:5.3.0434d8398f996
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
apache/rocketmq-exporter:0.0.2c8fb51195444
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
apache/skywalking-oap-server:9.2.0133d35d2c263
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
apache/skywalking-ui:9.2.0295f1dc87d98
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
apache/skywalking-ui:8.9.180530f0308a5
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
apache/tika:2.9.0.092d055a84e9e
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
appwrite/appwrite:1.9.01aaa70127114
libpng@1.6.55-r0
1.6.57-r0
1
appwrite/console:8.7.383dcdc8492ac6
libpng@1.6.55-r0
1.6.57-r0
1
appwrite/console:7.5.7aaa11ceab999
libpng@1.6.44-r0
1.6.57-r0
1
aristidetm/basic-notebook:3.6.5469dbc951224
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
assistiot/location_processing:lateste9bae124095f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
assistiot/open_api_backend:1.1.230812ba93555
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
atlassian/confluence-server:7.10.03b9222ab32ef
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
atlassian/jira-software:8.14.037bc46cbec1a
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
atlassian/jira-software:9.7.264a75aa4ec4e
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
avinash263/pyredis263:latestaa2b8727f1a6
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
avzini/web-app:latestf40b30210ed0
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
libpng@1.6.54-r0
1.6.57-r0
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
beyzkaya/blog-frontend:v1.0.0bf412d75c510
libpng@1.6.47-r0
1.6.57-r0
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
bnjbvr/kresus:0.22.137e216b182c8
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
budibase/database:2.1.0d90f656261c9
libpng1.6@1.6.39-2+deb12u3
1.6.39-2+deb12u5
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
carlosmz87/test_helm_frontend:latest79f4b528f42a
libpng@1.6.44-r0
1.6.57-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.