StackRadar

CVE-2026-39113

Medium

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.0
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,418
of 17,790 indexed, latest versions
Container images
1,119
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,418 of 17,790 indexed charts deploy, on 1,119 images.

Affected packageAffected versionsFixed inImages
sqlite3deb3.22.0-1, 3.22.0-1ubuntu0.1, 3.22.0-1ubuntu0.2, 3.22.0-1ubuntu0.3+33 more3.46.1-7+e61,119
OSV records
DEBIAN-CVE-2026-39113UBUNTU-CVE-2026-39113ECHO-ba17-0503-20ce

Charts affected

1,418 by stars
ChartLatestAffected imagesRadar Score
eoloplantmca-eoloplaner0.1.03 of 7See more

eoloplant mca-eoloplaner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
hugohg34/toposervice:0.0.2812a03b3f274
sqlite3@3.31.1-4ubuntu0.2
no fix listed
library/mongo:5.0.6-focal8e70544b6c76
sqlite3@3.31.1-4ubuntu0.2
no fix listed
library/rabbitmq:3.9-management8a279e9396a8
sqlite3@3.37.2-2ubuntu0.3
no fix listed

Open the chart page →

29,746
mcp-hangarmcp-hangarVerified publisher0.15.201 of 1See more

mcp-hangar mcp-hangar 0.15.20

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/mcp-hangar/mcp-hangar:2.19.14f92e139cd33
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

829
mcroutermcrouterVerified publisher0.2.01 of 2See more

mcrouter mcrouter 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/memcached:1.6.4226983a43c918
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

2,306
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
sqlite3@3.46.1-7
no fix listed

Open the chart page →

9,765
mdai-hubmdai-hubVerified publisher0.10.11 of 14See more

mdai-hub mdai-hub 0.10.1

1 of the 14 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
sqlite3@3.46.1-7
no fix listed

Open the chart page →

4,818
dependency-trackmediamarktsaturn1.9.21 of 2See more

dependency-track mediamarktsaturn 1.9.2

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.14.21ba4f004e1ec
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

3,840
cleanuparrmedia-servarrVerified publisher0.19.11 of 1See more

cleanuparr media-servarr 0.19.1

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/cleanuparr/cleanuparr:2.10.68136c3beda7a
sqlite3@3.45.1-1ubuntu2.7
no fix listed

Open the chart page →

1,436
tinymediamanagermedia-servarrVerified publisher1.6.21 of 2See more

tinymediamanager media-servarr 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

8,147
memgraph-mcpmemgraphVerified publisher1.0.01 of 1See more

memgraph-mcp memgraph 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
memgraph/mcp-memgraph:0.1.13ecdf7faea3f7
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,699
kubeaddons-catalogmesosphere0.1.161 of 2See more

kubeaddons-catalog mesosphere 0.1.16

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

12,052
nvidiamesosphere0.4.41 of 2See more

nvidia mesosphere 0.4.4

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
nvidia/dcgm-exporter:2.2.9-2.4.1-ubuntu20.0491b20b66d1cd
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

10,490
testmesosphere0.1.01 of 1See more

test mesosphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,849
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

68,417
multusmesosphere-stable0.1.11 of 1See more

multus mesosphere-stable 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.4-thick3c20900b5381
sqlite3@3.46.1-7
no fix listed

Open the chart page →

1,800
istio-operatormetakube1.12.01 of 1See more

istio-operator metakube 1.12.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
istio/operator:1.12.06cfce8a071b9
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

8,950
elasticmicroboxlabs0.3.01 of 1See more

elastic microboxlabs 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/elasticsearch:8.17.32cc40b15dff8
sqlite3@3.31.1-4ubuntu0.6
no fix listed

Open the chart page →

4,297
miot-harnessmicroboxlabs0.7.01 of 1See more

miot-harness microboxlabs 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,163
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

5,154
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

4,625
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.19.0cafa03b94dac
sqlite3@3.22.0-1ubuntu0.4
no fix listed

Open the chart page →

12,858
folding-at-homemidokura-communityVerified publisher0.0.31 of 1See more

folding-at-home midokura-community 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
linuxserver/foldingathome:7.6.219a997426d71e
sqlite3@3.45.1-1ubuntu2
no fix listed

Open the chart page →

2,943
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
sqlite3@3.31.1-4ubuntu0.5
no fix listed

Open the chart page →

11,281
parent-chartmid-proje0.1.01 of 3See more

parent-chart mid-proje 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
youssef11gaber10/flask-service:latest9c727fcfde76
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,796
mini-blogmini-blog-helm0.1.01 of 3See more

mini-blog mini-blog-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

13,107
MINTmint8.0.23 of 15See more

MINT mint 8.0.2

3 of the 15 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
sqlite3@3.46.1-7+deb13u1
no fix listed
library/redis:latest298e5b3bc566
sqlite3@3.46.1-7+deb13u1
no fix listed
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
sqlite3@3.31.1-4ubuntu0.3
no fix listed

Open the chart page →

43,532
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest4aef81c53168
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

10,683
standard-application-stackmintel11.4.11 of 12See more

standard-application-stack mintel 11.4.1

1 of the 12 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
localstack/localstack:latest3fe5b51caec8
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

10,613
helmmirasys-chart0.1.01 of 4See more

helm mirasys-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

4,382
simplewebappmlohrVerified publisher1.1.01 of 1See more

simplewebapp mlohr 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,849
mariadbmmontesVerified publisher0.3.01 of 1See more

mariadb mmontes 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/mariadb:10.7.307e06f2e7ae9
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

10,112
mongodbmmontesVerified publisher0.5.01 of 1See more

mongodb mmontes 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/mongo:4.4.1305678ae4e5e1
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

7,151
reporting-nifi-processor-svcmojaloop0.0.21 of 3See more

reporting-nifi-processor-svc mojaloop 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/mongo:6.0.271a63fc2438e
sqlite3@3.31.1-4ubuntu0.4
no fix listed

Open the chart page →

6,224
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
sqlite3@3.31.1-4ubuntu0.7
no fix listed

Open the chart page →

5,220
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

26,022
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

15,727
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2ebf761c7d437
sqlite3@3.45.1-1ubuntu2.7
no fix listed

Open the chart page →

5,719
codimdmt1905027.2.21 of 3See more

codimd mt190502 7.2.2

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,649
commafeedmt1905028.2.02 of 3See more

commafeed mt190502 8.2.0

2 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
athou/commafeed:6.2.0-postgresql5e388351df1a
sqlite3@3.46.1-7
no fix listed
library/postgres:184ef4dbc939d6
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

3,733
filestashmt1905024.0.01 of 1See more

filestash mt190502 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
machines/filestash:latest0b8fc005e52e
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

3,536
keycloakmt1905021.4.61 of 3See more

keycloak mt190502 1.4.6

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

2,924
memosmt1905027.3.21 of 3See more

memos mt190502 7.3.2

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

2,473
minifluxmt1905021.1.61 of 3See more

miniflux mt190502 1.1.6

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

2,692
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
sqlite3@3.31.1-4ubuntu0.7
no fix listed

Open the chart page →

6,649
open-webuimt1905022.3.101 of 3See more

open-webui mt190502 2.3.10

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,649
paperless-ngxmt1905027.6.142 of 4See more

paperless-ngx mt190502 7.6.14

2 of the 4 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
sqlite3@3.46.1-7+deb13u1
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
sqlite3@3.46.1-7
no fix listed

Open the chart page →

12,027
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

4,041
vaultwardenmt1905027.3.42 of 3See more

vaultwarden mt190502 7.3.4

2 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
sqlite3@3.46.1-7+deb13u1
no fix listed
vaultwarden/server:1.35.443498a94b22f
sqlite3@3.46.1-7
no fix listed

Open the chart page →

4,756
vikunjamt1905027.1.21 of 3See more

vikunja mt190502 7.1.2

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

2,991
backendmulti-chart-app0.1.01 of 1See more

backend multi-chart-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,849
frontendmulti-chart-app0.1.01 of 1See more

frontend multi-chart-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,849

Container images carrying it

1,119 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
sqlite3@3.37.2-2
no fix listed
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
sqlite3@3.45.1-1ubuntu2.1
no fix listed
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
sqlite3@3.45.1-1ubuntu2.4
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
sqlite3@3.37.2-2ubuntu0.1
no fix listed
1
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
sqlite3@3.46.1-7+deb13u1
no fix listed
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
sqlite3@3.22.0-1ubuntu0.6
no fix listed
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
sqlite3@3.46.1-7+deb13u1
no fix listed
1
quay.io/groundcover/tools:20260719b705e0cbe171
sqlite3@3.46.1-7+e5
3.46.1-7+e6
1
quay.io/isindir/sops-secrets-operator:0.21.27bba7083dfa0
sqlite3@3.46.1-9ubuntu0.2
no fix listed
1
quay.io/maxiv/pieeat:0.9.3099715479210
sqlite3@3.46.1-7+deb13u1
no fix listed
1
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
sqlite3@3.46.1-7+deb13u1
no fix listed
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
sqlite3@3.45.1-1ubuntu2.5
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
sqlite3@3.46.1-7
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
sqlite3@3.45.1-1ubuntu2.6
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
sqlite3@3.46.1-9ubuntu0.2
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
sqlite3@3.46.1-7+deb13u1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
sqlite3@3.46.1-7+deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
sqlite3@3.46.1-7+deb13u1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
sqlite3@3.31.1-4ubuntu0.2
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.