StackRadar

CVE-2026-34757

Medium

Advisory

Published 9 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.1
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
761
of 17,787 indexed, latest versions
Container images
699
deployed by those charts
Fix available
4 of 4
affected packages

Security update for libpng16

Carried by container images the latest versions of 761 of 17,787 indexed charts deploy, on 699 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+14 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u5+3 more532
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+4 more1.6.57-r0146
libpng16rpm1.6.40-150600.1.31.6.40-150600.3.20.11
OSV records
ALPINE-CVE-2026-34757DEBIAN-CVE-2026-34757UBUNTU-CVE-2026-34757SUSE-SU-2026:1602-1
Also known as
USN-8251-1, USN-8639-1

Charts affected

761 by stars
ChartLatestAffected imagesRadar Score
squawkvojtechpastyrikVerified publisher0.1.101 of 1See more

squawk vojtechpastyrik 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
libpng@1.6.55-r0
1.6.57-r0

Open the chart page →

400
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

11,444
pageswalter1.0.02 of 3See more

pages walter 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3

Open the chart page →

20,233
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

8,858
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

14,420
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

28,699
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

9,296
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

6,323
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

14,172
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.57-r0

Open the chart page →

13,197

Container images carrying it

699 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
evoapicloud/evolution-manager:latestcbfeb314afb9
libpng@1.6.47-r0
1.6.57-r0
1
featurehub/dacha2:1.9.1c8d5551b5e40
libpng@1.6.47-r0
1.6.57-r0
1
featurehub/edge:1.9.198ad426737f6
libpng@1.6.47-r0
1.6.57-r0
1
featurehub/mr:1.9.1477d8bf771a9
libpng@1.6.47-r0
1.6.57-r0
1
felipecs8/app-db-connection-test:v129e06c9c6385
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
firefart/requesttracker:5.0.40d6249906d8c
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
flowable/flowable-rest:7.1.0b7ae287502cd
libpng@1.6.44-r0
1.6.57-r0
1
fluent/fluent-bit:4.0-debuge76397ef3983
libpng1.6@1.6.39-2+deb12u1
1.6.39-2+deb12u5
1
flyway/flyway:9.1545b5d7cdc75a
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
fnzv/dump1090:latestb3079b95c336
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
folioci/mod-agreements:latest29c3f233a498
libpng@1.6.43-r0
1.6.57-r0
1
folioci/mod-authtoken:latest995a25a33133
libpng@1.6.55-r0
1.6.57-r0
1
folioci/mod-courses:latest68ca414f5596
libpng@1.6.55-r0
1.6.57-r0
1
folioci/mod-ldp:latestb55696fd9065
libpng@1.6.44-r0
1.6.57-r0
1
folioci/mod-licenses:latestcfd6109bf477
libpng@1.6.43-r0
1.6.57-r0
1
folioci/mod-oa:latestae3b069d4ba5
libpng@1.6.43-r0
1.6.57-r0
1
folioci/mod-search:latest44d7ee9acdf6
libpng@1.6.47-r0
1.6.57-r0
1
folioci/mod-serials-management:latest571fa1ffe8c9
libpng@1.6.43-r0
1.6.57-r0
1
folioci/mod-service-interaction:latestf53c327a48e8
libpng@1.6.43-r0
1.6.57-r0
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
galaxy/galaxy-init:v18.010267bad550e6
libpng@1.2.50-1ubuntu2.14.04.2
1.2.50-1ubuntu2.14.04.3+esm2
1
galaxy/galaxy-stable:v18.018e577a626dfd
libpng@1.2.50-1ubuntu2.14.04.2
1.2.50-1ubuntu2.14.04.3+esm2
1
gchq/accumulo:2.0.1c460bb587d6d
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
libpng@1.6.47-r0
1.6.57-r0
1
gdrocha/togglr-frontend:1.0.0ffbc1571c234
libpng@1.6.47-r0
1.6.57-r0
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
gethue/hue:4.10.05702b2c37ff9
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
gethue/hue:latest7d5c1b9f8a79
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
goccx/go-file-server-ui:latest784b35910d52
libpng@1.6.43-r0
1.6.57-r0
1
gotenberg/gotenberg:8.30206a6c708fc6
libpng1.6@1.6.48-1+deb13u4
1.6.48-1+deb13u5
1
gotson/komga:0.99.49b15ea6bfc30
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
graylog/graylog:6.1.1019de1aff48c2
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
gridgain/community:8.9.11d32d182a0e6a
libpng@1.6.43-r0
1.6.57-r0
1
grpl/grapple-cli:0.2.127c00aafee6629
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
guacamole/guacamole:1.5.50f62f6d17ab3
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
gulacedia/web-dvwa-new:v367b467d961ca
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.57-r0
1
haveagitgat/tdarr:2.00.181256348872ce
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.