StackRadar

CVE-2026-34757

Medium

Advisory

Published 9 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.1
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
761
of 17,787 indexed, latest versions
Container images
699
deployed by those charts
Fix available
4 of 4
affected packages

Security update for libpng16

Carried by container images the latest versions of 761 of 17,787 indexed charts deploy, on 699 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+14 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u5+3 more532
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+4 more1.6.57-r0146
libpng16rpm1.6.40-150600.1.31.6.40-150600.3.20.11
OSV records
ALPINE-CVE-2026-34757DEBIAN-CVE-2026-34757UBUNTU-CVE-2026-34757SUSE-SU-2026:1602-1
Also known as
USN-8251-1, USN-8639-1

Charts affected

761 by stars
ChartLatestAffected imagesRadar Score
squawkvojtechpastyrikVerified publisher0.1.101 of 1See more

squawk vojtechpastyrik 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
libpng@1.6.55-r0
1.6.57-r0

Open the chart page →

400
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

11,444
pageswalter1.0.02 of 3See more

pages walter 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3

Open the chart page →

20,233
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

8,858
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

14,420
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

28,699
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

9,296
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

6,323
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

14,172
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.57-r0

Open the chart page →

13,197

Container images carrying it

699 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
castlemock/castlemock:latestb7f3f1527ba9
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
castopod/castopod:1.12.101fd37280cbb2
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
castopod/castopod:1.15.54e4f0440520f
libpng1.6@1.6.48-1+deb13u3
1.6.48-1+deb13u5
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
chandanteekinavar/findery-market-frontend:1.06de5bd44a325
libpng@1.6.44-r0
1.6.57-r0
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
libpng@1.2.50-1ubuntu2.14.04.3
1.2.50-1ubuntu2.14.04.3+esm2
1
cheyang/distributed-tf:1.6.046cc34755493
libpng@1.2.54-1ubuntu1
1.2.54-1ubuntu1.1+esm3
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
libpng@1.6.47-r0
1.6.57-r0
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
libpng1.6@1.6.48-1+deb13u3
1.6.48-1+deb13u5
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
libpng1.6@1.6.37-3ubuntu0.4
1.6.37-3ubuntu0.5
1
ckulka/baikal:0.10.1-nginx434bdd162247
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
clowder/clowder2-frontend:2.0.0-beta.4fe97882672ca
libpng@1.6.47-r0
1.6.57-r0
1
collabora/code:24.04.13.2.101dc4ab83977
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
collabora/code:23.05.10.1.105299b452f7f
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
commerceexperts/searchhub-smartsuggest-service:1.3.0341eebe7239b
libpng@1.6.43-r0
1.6.57-r0
1
copyparty/ac:1.19.200a0a8605062c
libpng@1.6.47-r0
1.6.57-r0
1
countly/countly-server:25.05.4e3c238248f99
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
libpng1.6@1.6.39-2+deb12u4
1.6.39-2+deb12u5
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
dannielkil/book-frontend:latest937993927694
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
daskdev/dask-notebook:1.1.0052630f5ca04
libpng1.6@1.6.34-1ubuntu0.18.04.1
1.6.34-1ubuntu0.18.04.2+esm3
1
datamate/seafile-professional:11.0.202dd66b722464
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
davidy/giphy-app:1.0.2-arm41b2355cc23a
libpng@1.6.44-r0
1.6.57-r0
1
deconzcommunity/deconz:2.29.2062de2362641
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
dellcloud/category:distributed02fc234353a9
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
dellcloud/pages:1.04d2eb25b9225
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
djjudas21/bearhugmugs:0.1.14fa898a52d97
libpng@1.6.44-r0
1.6.57-r0
1
docuseal/docuseal:2.4.17493fd7f6728
libpng@1.6.55-r0
1.6.57-r0
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
libpng1.6@1.6.48-1
1.6.48-1+deb13u5
1
dragonflyoss/client:v0.1.82edf3e921f4e0
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
dremio/dremio-oss:24.1.080ed2e3b7c43
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
drpcorg/dshackle:0.54.08858fae1859d
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
dzikoysk/reposilite:3.5.264128c2d7a6ba
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
libpng@1.6.54-r0
1.6.57-r0
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
libpng1.6@1.6.48-1
1.6.48-1+deb13u5
1
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
libpng@1.6.54-r0
1.6.57-r0
1
eftechcombr/glpi:php-fpm-12.0.0-rc1f3d0ed01709e
libpng@1.6.55-r0
1.6.57-r0
1
elastictranscoder/media:627e21dc963ab3858c6b
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
elastictranscoder/media-storage:f6d861a026208b8c2359
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
emqx/ecp-ui:2.5.1e33e9816f147
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
erenozcan17/react_frontend:v4.56e1b14973f9b
libpng@1.6.47-r0
1.6.57-r0
1
erudikaltd/scoold:1.66.0949c56b57e8f
libpng@1.6.47-r0
1.6.57-r0
1
escaping/core-keeper-dedicated:latest87fa79255962
libpng1.6@1.6.48-1+deb13u3
1.6.48-1+deb13u5
1
esphome/esphome:2024.3.09ab8cc88b28c
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
esphome/esphome:2024.12.2b2c6322700ac
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
esphome/esphome:2025.3.0def8b6e4f517
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
esteban1930/frontend-1:1.8.0f9078279632c
libpng@1.6.47-r0
1.6.57-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.