StackRadar

CVE-2026-34757

Medium

Advisory

Published 9 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.1
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
761
of 17,787 indexed, latest versions
Container images
699
deployed by those charts
Fix available
4 of 4
affected packages

Security update for libpng16

Carried by container images the latest versions of 761 of 17,787 indexed charts deploy, on 699 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+14 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u5+3 more532
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+4 more1.6.57-r0146
libpng16rpm1.6.40-150600.1.31.6.40-150600.3.20.11
OSV records
ALPINE-CVE-2026-34757DEBIAN-CVE-2026-34757UBUNTU-CVE-2026-34757SUSE-SU-2026:1602-1
Also known as
USN-8251-1, USN-8639-1

Charts affected

761 by stars
ChartLatestAffected imagesRadar Score
squawkvojtechpastyrikVerified publisher0.1.101 of 1See more

squawk vojtechpastyrik 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
libpng@1.6.55-r0
1.6.57-r0

Open the chart page →

400
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

11,444
pageswalter1.0.02 of 3See more

pages walter 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3

Open the chart page →

20,233
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

8,858
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

14,420
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

28,699
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

9,296
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

6,323
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

14,172
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.57-r0

Open the chart page →

13,197

Container images carrying it

699 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
openbas/platform:2.0.5d986d80b0a75
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
opencsghq/csgship-portal:v1.2.1865814dc87a1
libpng@1.6.47-r0
1.6.57-r0
1
opendatacube/explorer:latest120457ffcd69
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
opendatacube/pipelines:wofs-1.225d810e8504b8
libpng1.6@1.6.34-1ubuntu0.18.04.1
1.6.34-1ubuntu0.18.04.2+esm3
1
opendatacube/restcube:latest91870111837c
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
opendatacube/wms:latest1b90cdf68831
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
opendatacube/wps:latest80df355a660b
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
openelevation/open-elevation:latest82fb21612e86
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
openkm/openkm-ce:6.3.113bc465a7461b
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
openproject/hocuspocus:release-338001b288dc1359dfb5
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3
1
opsmx11/issuegen:v2.1.05c50ca123d88
libpng@1.2.50-1ubuntu2.14.04.2
1.2.50-1ubuntu2.14.04.3+esm2
1
orbitalreg/orbitalreg-frontend:0.1.04fd449582a3c
libpng@1.6.47-r0
1.6.57-r0
1
owncloud/ocis:7.1.388e7c854517d
libpng@1.6.44-r0
1.6.57-r0
1
owncloud/ocis:8.0.1b38fd8fdd58f
libpng@1.6.55-r0
1.6.57-r0
1
owncloud/server:10.15.051d9b74fc2a8
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
payara/server-full:7.2026.2-jdk2531f1253f0cf8
libpng1.6@1.6.37-3ubuntu0.4
1.6.37-3ubuntu0.5
1
penpotapp/backend:2.2.147853d9bb9dd
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
penpotapp/exporter:2.2.15c835ffd87ab
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
phan2410/dummy-service:0.0.89c6ed6de26ca
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
photoprism/photoprism:220629-jammy2954334adbda
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
photoprism/photoprism:251130db16ee6b1ba3
libpng1.6@1.6.50-1
1.6.50-1ubuntu0.5
1
photoprism/photoprism:240711-cefc6fd632ca74
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
phpipam/phpipam-cron:v1.7.354468713454e
libpng@1.6.44-r0
1.6.57-r0
1
phpipam/phpipam-www:v1.7.3ace0efd24830
libpng@1.6.44-r0
1.6.57-r0
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
libpng1.6@1.6.48-1
1.6.48-1+deb13u5
1
pk910/powfaucet:v2-stable3dcae6a62896
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
pmoscode/excalidraw:v0.18.08ee61554699c
libpng@1.6.47-r0
1.6.57-r0
1
pnnlmiscscripts/k8s-node-image9:1.28.15-nginx-72b91d6a46e06
libpng@1.6.43-r0
1.6.57-r0
1
pnnlmiscscripts/k8s-node-image9:1.25.16-nginx-772c202c43c0aa
libpng@1.6.43-r0
1.6.57-r0
1
pnnlmiscscripts/k8s-node-image9:1.24.17-nginx-882c8dc938b2f9
libpng@1.6.43-r0
1.6.57-r0
1
pnnlmiscscripts/k8s-node-image9:1.27.16-nginx-306e1a36d646a3
libpng@1.6.43-r0
1.6.57-r0
1
pnnlmiscscripts/k8s-node-image9:1.26.15-nginx-579785e5b82334
libpng@1.6.43-r0
1.6.57-r0
1
pnnlmiscscripts/k8s-node-image9:1.31.7-nginx-7e3e189d9d519
libpng@1.6.44-r0
1.6.57-r0
1
pnnlmiscscripts/k8s-node-image9:1.30.11-nginx-7f9297eea817d
libpng@1.6.44-r0
1.6.57-r0
1
pnnlmiscscripts/k8s-node-image9:1.29.10-nginx-7fcd82530bc8b
libpng@1.6.43-r0
1.6.57-r0
1
postgis/postgis:17-3.4-alpine5a1dbedac34e
libpng@1.6.44-r0
1.6.57-r0
1
praravind1801/helmimages:3.0.0f29d637b9ce1
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
project2team4/react:latest3ff031a08887
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
prom/cloudwatch-exporter:v0.16.071c2e988af06
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
pschichtel/mindustry-server:v145.1b543e9c2d371
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
qumine/minecraft-server:v0.1.15c0b650d51132
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
rabeh/apibootspring:1.0941007b6946e
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
libpng1.6@1.6.43-5build1
1.6.43-5ubuntu0.6
1
reaper99/recipya:v1.2.27f7ec3aeb88c
libpng@1.6.44-r0
1.6.57-r0
1
resouer/redis-slave:v2e2f198b49ba7
libpng@1.2.50-1ubuntu2
1.2.50-1ubuntu2.14.04.3+esm2
1
resurfaceio/resurface:3.7.84d5cda2f64109
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.