StackRadar

CVE-2026-39113

Medium

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.0
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,417
of 17,787 indexed, latest versions
Container images
1,113
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,417 of 17,787 indexed charts deploy, on 1,113 images.

Affected packageAffected versionsFixed inImages
sqlite3deb3.22.0-1, 3.22.0-1ubuntu0.1, 3.22.0-1ubuntu0.2, 3.22.0-1ubuntu0.3+33 more3.46.1-7+e61,113
OSV records
DEBIAN-CVE-2026-39113UBUNTU-CVE-2026-39113ECHO-ba17-0503-20ce

Charts affected

1,417 by stars
ChartLatestAffected imagesRadar Score
ghostcloudpirates-ghostVerified publisher0.20.222 of 3See more

ghost cloudpirates-ghost 0.20.22

2 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/mariadb:12.0.25b6a1eac15b8
sqlite3@3.45.1-1ubuntu2.5
no fix listed
library/mariadb:12.3.3ab1c3dd38194
sqlite3@3.45.1-1ubuntu2.7
no fix listed

Open the chart page →

7,182
clowardenclowarden0.2.31 of 4See more

clowarden clowarden 0.2.3

1 of the 4 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
sqlite3@3.46.1-7
no fix listed

Open the chart page →

5,620
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/convertigo:8.4.3ae605bfcda05
sqlite3@3.45.1-1ubuntu2.7
no fix listed

Open the chart page →

17,475
crossviewcrossviewOfficialVerified publisher4.6.01 of 2See more

crossview crossview 4.6.0

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,803
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
sqlite3@3.46.1-7
no fix listed

Open the chart page →

9,348
defectdojodefectdojo1.9.521 of 4See more

defectdojo defectdojo 1.9.52

1 of the 4 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
defectdojo/defectdojo-django:3.3.100c597abdbb535
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

2,340
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
sqlite3@3.45.1-1ubuntu2
no fix listed

Open the chart page →

4,194
edgelessdbedgelesssysVerified publisher0.3.21 of 1See more

edgelessdb edgelesssys 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
sqlite3@3.31.1-4ubuntu0.5
no fix listed

Open the chart page →

4,868
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
sqlite3@3.31.1-4ubuntu0.5
no fix listed

Open the chart page →

5,302
rsshubgabe565Verified publisher0.8.01 of 3See more

rsshub gabe565 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
diygod/rsshub:latest1d4b508b6357
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,729
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
sqlite3@3.22.0-1ubuntu0.4
no fix listed

Open the chart page →

22,812
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

10,652
network-ups-toolsgeek-cookbookVerified publisher6.4.21 of 1See more

network-ups-tools geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

14,001
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
sqlite3@3.31.1-4ubuntu0.3
no fix listed

Open the chart page →

9,666
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

10,202
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

10,676
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
sqlite3@3.22.0-1ubuntu0.7
no fix listed

Open the chart page →

11,873
gitvotegitvoteVerified publisher1.5.01 of 6See more

gitvote gitvote 1.5.0

1 of the 6 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
sqlite3@3.46.1-7
no fix listed

Open the chart page →

5,627
apimgraviteeioVerified publisher4.12.192 of 4See more

apim graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
sqlite3@3.46.1-7+deb13u1
no fix listed
graviteeio/apim-management-api:4.12.19-debian27374522cd04
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

4,747
nacosgujunxiang0.1.51 of 1See more

nacos gujunxiang 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
sqlite3@3.46.1-9ubuntu0.2
no fix listed

Open the chart page →

1,820
netbirdhelmforgeVerified publisher1.0.101 of 4See more

netbird helmforge 1.0.10

1 of the 4 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

3,012
redishelmforgeVerified publisher3.0.01 of 1See more

redis helmforge 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

968
simple-krr-dashboardhelm-simple-krr-dashboardVerified publisher1.6.21 of 3See more

simple-krr-dashboard helm-simple-krr-dashboard 1.6.2

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
robustadev/krr:v1.30.0b8d782e568c7
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

2,245
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.19.21 of 5See more

infrahub-enterprise infrahub-enterprise 4.19.2

1 of the 5 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/neo4j:2026.05.0-enterprise2caf944aa4a5
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

10,563
coreinstill-aiOfficialVerified publisher0.1.753 of 15See more

core instill-ai 0.1.75

3 of the 15 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
instill/artifact-backend:b28766ac4a393e601ed
sqlite3@3.46.1-7
no fix listed
instill/mgmt-backend:d0933d4ebe12f77a3f9
sqlite3@3.46.1-7
no fix listed
instill/model-backend:611f0f2e980125e5ba5
sqlite3@3.46.1-7
no fix listed

Open the chart page →

30,920
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
sqlite3@3.45.1-1ubuntu2
no fix listed

Open the chart page →

4,357
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
sqlite3@3.45.1-1ubuntu2.7
no fix listed

Open the chart page →

4,546
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
sqlite3@3.31.1-4ubuntu0.5
no fix listed

Open the chart page →

7,375
webdavk8s-webdavVerified publisher0.0.71 of 1See more

webdav k8s-webdav 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/httpd:2.4979c38c2228d
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,693
klancesklances0.1.41 of 1See more

klances klances 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
sqlite3@3.46.1-7
no fix listed

Open the chart page →

1,705
radondb-mysqlkubesphere-testVerified publisher1.0.11 of 3See more

radondb-mysql kubesphere-test 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

7,381
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
sqlite3@3.31.1-4ubuntu0.7
no fix listed

Open the chart page →

11,630
kafdroplsst-sqre0.1.31 of 1See more

kafdrop lsst-sqre 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

7,940
mariadbmariadbVerified publisher0.4.01 of 1See more

mariadb mariadb 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
sqlite3@3.37.2-2ubuntu0.7
no fix listed

Open the chart page →

2,455
memgraph-high-availabilitymemgraphVerified publisher1.4.11 of 2See more

memgraph-high-availability memgraph 1.4.1

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
memgraph/memgraph:3.13.1bd3fe13228f4
sqlite3@3.45.1-1ubuntu2.7
no fix listed

Open the chart page →

1,208
mogenius-operatormogeniusOfficialVerified publisher2.29.01 of 2See more

mogenius-operator mogenius 2.29.0

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
valkey/valkey:9.1.164e361b630ec
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

945
observalobservalVerified publisher1.13.12 of 8See more

observal observal 1.13.1

2 of the 8 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
sqlite3@3.46.1-7+deb13u1
no fix listed
ghcr.io/observal/observal-api:1.13.1153b8b893232
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

5,839
oesopsmxVerified publisher4.0.322 of 25See more

oes opsmx 4.0.32

2 of the 25 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
sqlite3@3.45.1-1ubuntu2.5
no fix listed
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
sqlite3@3.46.1-7
no fix listed

Open the chart page →

107,899
phpmyadminphpmyadminVerified publisher1.0.31 of 1See more

phpmyadmin phpmyadmin 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

2,613
prometheus-prefect-exporterprefectVerified publisher2026.8.71410241 of 1See more

prometheus-prefect-exporter prefect 2026.8.7141024

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
prefecthq/prometheus-prefect-exporter:4.0.050d527a190ae
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,012
repoflowrepoflow-helm-public0.9.12 of 8See more

repoflow repoflow-helm-public 0.9.1

2 of the 8 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.48.10f6c1c4b957d2
sqlite3@3.37.2-2ubuntu0.5
no fix listed
library/elasticsearch:8.15.0310b9fc03b06
sqlite3@3.31.1-4ubuntu0.6
no fix listed

Open the chart page →

13,615
nominatimrobjuz6.4.11 of 4See more

nominatim robjuz 6.4.1

1 of the 4 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
mediagis/nominatim:5.3.27923a8e67197
sqlite3@3.45.1-1ubuntu2.5
no fix listed

Open the chart page →

8,760
rocketmq-clusterrocketmq12.6.01 of 2See more

rocketmq-cluster rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
sqlite3@3.45.1-1ubuntu2.5
no fix listed

Open the chart page →

6,385
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
sqlite3@3.31.1-4ubuntu0.2
no fix listed

Open the chart page →

24,549
lldapself-hosters-by-nightVerified publisher0.5.21 of 2See more

lldap self-hosters-by-night 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
sqlite3@3.46.1-7
no fix listed

Open the chart page →

3,412
skypilotskypilotOfficialVerified publisher0.13.01 of 3See more

skypilot skypilot 0.13.0

1 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

5,889
spartanspartan0.9.11 of 1See more

spartan spartan 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

1,839
freeradiusstartechnicaVerified publisher1.2.01 of 1See more

freeradius startechnica 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.2.8af6fd34a5b78
sqlite3@3.37.2-2ubuntu0.5
no fix listed

Open the chart page →

5,814
sn-platformstreamnative1.11.441 of 9See more

sn-platform streamnative 1.11.44

1 of the 9 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
sqlite3@3.31.1-4ubuntu0.6
no fix listed

Open the chart page →

15,525
pretixtechwolf12Verified publisher2026.7.03 of 3See more

pretix techwolf12 2026.7.0

3 of the 3 container images this version deploys carry CVE-2026-39113.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
sqlite3@3.46.1-7+deb13u1
no fix listed
pretix/standalone:2026.7.05df3b7aa852e
sqlite3@3.46.1-7+deb13u1
no fix listed
valkey/valkey:9.1.08e8d64b405ce
sqlite3@3.46.1-7+deb13u1
no fix listed

Open the chart page →

9,825

Container images carrying it

1,113 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
sqlite3@3.46.1-7+deb13u1
no fix listed
1
quay.io/groundcover/tools:20260719b705e0cbe171
sqlite3@3.46.1-7+e5
3.46.1-7+e6
1
quay.io/isindir/sops-secrets-operator:0.21.27bba7083dfa0
sqlite3@3.46.1-9ubuntu0.2
no fix listed
1
quay.io/maxiv/pieeat:0.9.3099715479210
sqlite3@3.46.1-7+deb13u1
no fix listed
1
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
sqlite3@3.46.1-7+deb13u1
no fix listed
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
sqlite3@3.45.1-1ubuntu2.5
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
sqlite3@3.46.1-7
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
sqlite3@3.45.1-1ubuntu2.6
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
sqlite3@3.46.1-9ubuntu0.2
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
sqlite3@3.46.1-7+deb13u1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
sqlite3@3.46.1-7+deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
sqlite3@3.46.1-7+deb13u1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
sqlite3@3.31.1-4ubuntu0.2
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.