StackRadar

CVE-2026-34757

Medium

Advisory

Published 9 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.1
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
761
of 17,787 indexed, latest versions
Container images
699
deployed by those charts
Fix available
4 of 4
affected packages

Security update for libpng16

Carried by container images the latest versions of 761 of 17,787 indexed charts deploy, on 699 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+14 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u5+3 more532
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+4 more1.6.57-r0146
libpng16rpm1.6.40-150600.1.31.6.40-150600.3.20.11
OSV records
ALPINE-CVE-2026-34757DEBIAN-CVE-2026-34757UBUNTU-CVE-2026-34757SUSE-SU-2026:1602-1
Also known as
USN-8251-1, USN-8639-1

Charts affected

761 by stars
ChartLatestAffected imagesRadar Score
squawkvojtechpastyrikVerified publisher0.1.101 of 1See more

squawk vojtechpastyrik 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
libpng@1.6.55-r0
1.6.57-r0

Open the chart page →

400
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

11,444
pageswalter1.0.02 of 3See more

pages walter 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3

Open the chart page →

20,233
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

8,858
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

14,420
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

28,699
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

9,296
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

6,323
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

14,172
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.57-r0

Open the chart page →

13,197

Container images carrying it

699 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
hazegoodlife/haaze:milksite8d4c63169e14
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
hecrom/myweatherangularclient:1.3.11bb0372939c19
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
hmediade/printserver:latest481a552c8e1c
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
housewrecker/gaps:latestf417dd0a7547
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
hugohg34/toposervice:0.0.2812a03b3f274
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
libpng@1.2.54-1ubuntu1
1.2.54-1ubuntu1.1+esm3
1
instill/artifact-backend:b28766ac4a393e601ed
libpng1.6@1.6.48-1+deb13u4
1.6.48-1+deb13u5
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
intelowlproject/intelowl_nginx:v6.6.12f01e79b8064
libpng@1.6.47-r0
1.6.57-r0
1
ispras/svacer:11-2-042aa9fa9f189
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
jacobalberty/unifi:v7.1.664a3616625dda
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
jacobalberty/unifi:5.10.19c409924e2463
libpng@1.2.54-1ubuntu1.1
1.2.54-1ubuntu1.1+esm3
1
jaedb/iris:latest048cfbf58d57
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
jakowenko/double-take:1.6.0b858bac9e32a
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
jellyfin/jellyfin:10.11.81694ff069f0c
libpng1.6@1.6.48-1+deb13u4
1.6.48-1+deb13u5
1
jellyfin/jellyfin:10.11.717285f9cce63
libpng1.6@1.6.48-1+deb13u4
1.6.48-1+deb13u5
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
jellyfin/jellyfin:10.11.6333b64771663
libpng1.6@1.6.48-1+deb13u1
1.6.48-1+deb13u5
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
jellyfin/jellyfin:10.10.77ae36aab93ef
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
jellyfin/jellyfin:10.10.696b09723b22f
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
jhipster/jhipster-registry:latest7184525acd4d
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
jlesage/firefox:v25.03.1055c28defe31
libpng@1.6.47-r0
1.6.57-r0
1
josh5/unmanic:0.2.64d49c4816260
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
kinseii/wazuh-agent:4.14.17160eb143728
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
knspar/phronetis-operator:0.1.60c4f0543ee58
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
kong/httpbin:latesta6ac46531193
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
libpng1.6@1.6.37-3ubuntu0.4
1.6.37-3ubuntu0.5
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
krontechnology/aapm-service:1.1.39dd602db8baa
libpng1.6@1.6.37-3ubuntu0.4
1.6.37-3ubuntu0.5
1
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
libpng@1.6.54-r0
1.6.57-r0
1
kusionstack/kusion:v0.14.0126c8f0b0976
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
kuzwolka/aws9:main1ad759b961b1
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.