StackRadar

CVE-2026-39113

Medium

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.0
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,418
of 17,790 indexed, latest versions
Container images
1,119
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,418 of 17,790 indexed charts deploy, on 1,119 images.

Affected packageAffected versionsFixed inImages
sqlite3deb3.22.0-1, 3.22.0-1ubuntu0.1, 3.22.0-1ubuntu0.2, 3.22.0-1ubuntu0.3+33 more3.46.1-7+e61,119
OSV records
DEBIAN-CVE-2026-39113UBUNTU-CVE-2026-39113ECHO-ba17-0503-20ce

Charts affected

1,418 by stars
ChartLatestAffected imagesRadar Score
kubernetes-netskope-publisherkubernetes-netskope-publisherVerified publisher1.5.01 of 2See more

kubernetes-netskope-publisher kubernetes-netskope-publisher 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
netskopeprivateaccess/publisher_u22:latest93e2fd164a93
sqlite3@3.37.2-2ubuntu0.7
no fix listed

Open the chart page →

3,586
deepflowkubesphere-stable6.2.6061 of 8See more

deepflow kubesphere-stable 6.2.606

1 of the 8 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
sqlite3@3.31.1-4ubuntu0.4
no fix listed

Open the chart page →

18,420
iomeshkubesphere-stable1.1.01 of 25See more

iomesh kubesphere-stable 1.1.0

1 of the 25 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
iomesh/csi-driver:v2.7.25d3f9bf9240b
sqlite3@3.37.2-2ubuntu0.3
no fix listed

Open the chart page →

48,954
IOMeshkubesphere-stable1.2.01 of 25See more

IOMesh kubesphere-stable 1.2.0

1 of the 25 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
iomesh/csi-driver:v2.8.01a151f602451
sqlite3@3.37.2-2ubuntu0.3
no fix listed

Open the chart page →

46,639
pulsarkubesphere-stable2.7.131 of 3See more

pulsar kubesphere-stable 2.7.13

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

14,401
clickhousekubesphere-testVerified publisher0.1.11 of 2See more

clickhouse kubesphere-test 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
radondb/clickhouse-server:v21.1.3.32-stable4732df471073
sqlite3@3.22.0-1ubuntu0.4
no fix listed

Open the chart page →

6,705
mongodbkubesphere-testVerified publisher0.3.21 of 2See more

mongodb kubesphere-test 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/mongo:4.2.16ca49afbcb2b
sqlite3@3.22.0-1ubuntu0.1
no fix listed

Open the chart page →

9,631
mysqlkubesphere-testVerified publisher1.0.21 of 3See more

mysql kubesphere-test 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

7,384
xenondbkubesphere-testVerified publisher1.0.01 of 3See more

xenondb kubesphere-test 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

7,384
kubevoipkubevoipOfficialVerified publisher0.6.81 of 1See more

kubevoip kubevoip 0.6.8

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/kubevoip/kubevoip:v0.6.841c603a93642
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,097
kube-wordpress-mysqlkube-wordpress-mysql0.1.01 of 2See more

kube-wordpress-mysql kube-wordpress-mysql 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/wordpress:php8.1-apachef73396626d2f
sqlite3@3.46.1-7
no fix listed

Open the chart page →

8,767
penpotkubitodevVerified publisher1.2.12 of 5See more

penpot kubitodev 1.2.1

2 of the 5 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
sqlite3@3.37.2-2ubuntu0.3
no fix listed
penpotapp/exporter:2.2.15c835ffd87ab
sqlite3@3.37.2-2ubuntu0.3
no fix listed

Open the chart page →

16,976
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.41 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

1 of the 9 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
sqlite3@3.46.1-7
no fix listed

Open the chart page →

20,386
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
sqlite3@3.37.2-2ubuntu0.3
no fix listed

Open the chart page →

6,913
fstyr-ddp-keycloak-application-platform-configkvalitetsitVerified publisher0.1.131 of 1See more

fstyr-ddp-keycloak-application-platform-config kvalitetsit 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
sqlite3@3.45.1-1ubuntu2.1
no fix listed

Open the chart page →

3,148
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
sqlite3@3.22.0-1ubuntu0.4
no fix listed

Open the chart page →

16,539
nginx-chartkyb-nginx0.1.01 of 1See more

nginx-chart kyb-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,849
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
sqlite3@3.22.0-1ubuntu0.3
no fix listed

Open the chart page →

26,377
pageslatif-pages1.0.02 of 3See more

pages latif-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
sqlite3@3.31.1-4ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
sqlite3@3.22.0-1ubuntu0.3
no fix listed

Open the chart page →

20,242
pageslavanya-pages1.0.02 of 3See more

pages lavanya-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
sqlite3@3.31.1-4ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
sqlite3@3.22.0-1ubuntu0.3
no fix listed

Open the chart page →

20,242
homebridgelbenicio-communityVerified publisher0.1.151 of 1See more

homebridge lbenicio-community 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
sqlite3@3.45.1-1ubuntu2.7
no fix listed

Open the chart page →

2,215
smtplbenicio-communityVerified publisher0.1.31 of 1See more

smtp lbenicio-community 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,259
jenkinsleechistest2.7.11 of 2See more

jenkins leechistest 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

4,445
kinesaliteleprechaun-charts0.1.21 of 1See more

kinesalite leprechaun-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
instructure/kinesalite:latest34400d82f28f
sqlite3@3.31.1-4ubuntu0.6
no fix listed

Open the chart page →

4,273
vaultwardenleprechaun-charts0.1.281 of 1See more

vaultwarden leprechaun-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.1ebdfe70701c6
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

2,057
libredb-studiolibredb-studio-oci0.1.631 of 1See more

libredb-studio libredb-studio-oci 0.1.63

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.15.04b696f960ac1
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,244
librenmslibrenms10.1.11 of 5See more

librenms librenms 10.1.1

1 of the 5 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

3,149
weblinzhengen0.1.71 of 1See more

web linzhengen 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,849
listmonklistmonk-chartVerified publisher2.0.11 of 2See more

listmonk listmonk-chart 2.0.1

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

3,091
pocketbase-halitesql0.0.31 of 1See more

pocketbase-ha litesql 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/litesql/pocketbase-ha:latestc5b28608958b
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,138
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
sqlite3@3.37.2-2ubuntu0.1
no fix listed

Open the chart page →

10,780
pagesliviu884422-pages1.0.02 of 3See more

pages liviu884422-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
sqlite3@3.31.1-4ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
sqlite3@3.22.0-1ubuntu0.3
no fix listed

Open the chart page →

20,242
web-chartljw-ktcloudlab0.1.01 of 1See more

web-chart ljw-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,849
llmarinerllmariner1.53.11 of 21See more

llmariner llmariner 1.53.1

1 of the 21 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
sqlite3@3.46.1-7
no fix listed

Open the chart page →

12,150
jellyfinlmatfyVerified publisher0.1.31 of 1See more

jellyfin lmatfy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11aefb67e6a7ff
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

2,626
nightingalelogic3579Verified publisher0.3.12 of 6See more

nightingale logic3579 0.3.1

2 of the 6 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
sqlite3@3.45.1-1ubuntu2.5
no fix listed
flashcatcloud/nightingale:8.5.1421acb36181b
sqlite3@3.46.1-7
no fix listed

Open the chart page →

9,062
clickhouselohmag0.2.01 of 1See more

clickhouse lohmag 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.17ab1738a64b70
sqlite3@3.22.0-1ubuntu0.4
no fix listed

Open the chart page →

5,913
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

17,858
redislsst-sqre1.2.11 of 1See more

redis lsst-sqre 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

978
elastictranscoderluiscajl0.46.04 of 4See more

elastictranscoder luiscajl 0.46.0

4 of the 4 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
elastictranscoder/media:627e21dc963ab3858c6b
sqlite3@3.22.0-1ubuntu0.4
no fix listed
elastictranscoder/media-storage:f6d861a026208b8c2359
sqlite3@3.22.0-1ubuntu0.4
no fix listed
elastictranscoder/transcoder:627e21dcb4a0327029e6
sqlite3@3.22.0-1ubuntu0.4
no fix listed
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
sqlite3@3.22.0-1ubuntu0.4
no fix listed

Open the chart page →

58,245
plex-rclone-wireguardluiscajl1.0.191 of 2See more

plex-rclone-wireguard luiscajl 1.0.19

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:latest7f9a1d574958
sqlite3@3.46.1-9ubuntu0.2
no fix listed

Open the chart page →

854
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
sqlite3@3.46.1-7
no fix listed

Open the chart page →

4,669
jellyfinm0nsterrr-jellyfinVerified publisher2.3.51 of 1See more

jellyfin m0nsterrr-jellyfin 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

2,626
kea-exporterm0nsterrr-kea-exporterVerified publisher2.2.11 of 1See more

kea-exporter m0nsterrr-kea-exporter 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,067
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
sqlite3@3.37.2-2ubuntu0.3
no fix listed

Open the chart page →

24,537
demoshopmakaira2.4.02 of 4See more

demoshop makaira 2.4.0

2 of the 4 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
sqlite3@3.46.1-7+deb13u1
no fix listed
library/php:8.4-fpm59fa733c9af6
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

4,489
plane-mcp-servermakeplaneVerified publisher1.0.02 of 2See more

plane-mcp-server makeplane 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
makeplane/plane-mcp-server:v0.3.071b7252adef0
sqlite3@3.46.1-7+deb13u1
no fix listed
valkey/valkey:9.1.164e361b630ec
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

2,602
marge-botmarge-bot-helm1.3.51 of 1See more

marge-bot marge-bot-helm 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.16.0b59f01bc0418
sqlite3@3.46.1-7
no fix listed

Open the chart page →

3,597
circleci-runnermatic-insurance0.1.11 of 1See more

circleci-runner matic-insurance 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
circleci/runner:launch-agent9bdc62f02162
sqlite3@3.31.1-4ubuntu0.6
no fix listed

Open the chart page →

4,152
nginxmatic-insurance1.1.11 of 1See more

nginx matic-insurance 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,849

Container images carrying it

1,119 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
sqlite3@3.37.2-2
no fix listed
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
sqlite3@3.45.1-1ubuntu2.1
no fix listed
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
sqlite3@3.45.1-1ubuntu2.4
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
sqlite3@3.37.2-2ubuntu0.1
no fix listed
1
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
sqlite3@3.46.1-7+deb13u1
no fix listed
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
sqlite3@3.22.0-1ubuntu0.6
no fix listed
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
sqlite3@3.46.1-7+deb13u1
no fix listed
1
quay.io/groundcover/tools:20260719b705e0cbe171
sqlite3@3.46.1-7+e5
3.46.1-7+e6
1
quay.io/isindir/sops-secrets-operator:0.21.27bba7083dfa0
sqlite3@3.46.1-9ubuntu0.2
no fix listed
1
quay.io/maxiv/pieeat:0.9.3099715479210
sqlite3@3.46.1-7+deb13u1
no fix listed
1
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
sqlite3@3.46.1-7+deb13u1
no fix listed
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
sqlite3@3.45.1-1ubuntu2.5
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
sqlite3@3.46.1-7
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
sqlite3@3.45.1-1ubuntu2.6
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
sqlite3@3.46.1-9ubuntu0.2
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
sqlite3@3.46.1-7+deb13u1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
sqlite3@3.46.1-7+deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
sqlite3@3.46.1-7+deb13u1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
sqlite3@3.31.1-4ubuntu0.2
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.