StackRadar

CVE-2026-39316

Medium

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
206
of 17,781 indexed, latest versions
Container images
177
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 206 of 17,781 indexed charts deploy, on 177 images.

Affected packageAffected versionsFixed inImages
cupsdeb2.1.3-4ubuntu0.3, 2.1.3-4ubuntu0.4, 2.1.3-4ubuntu0.7, 2.1.3-4ubuntu0.10+29 more2.4.1op1-1ubuntu4.20, 2.4.7-1.2ubuntu7.13, 2.4.12-0ubuntu3.9, 2.4.16-1ubuntu1.2167
cupsapk2.4.11-r02.4.18-r010
OSV records
ALPINE-CVE-2026-39316DEBIAN-CVE-2026-39316UBUNTU-CVE-2026-39316
Also known as
USN-8405-1

Charts affected

206 by stars
ChartLatestAffected imagesRadar Score
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39316.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
cups@2.4.7-1.2ubuntu7.9
2.4.7-1.2ubuntu7.13

Open the chart page →

4,305
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39316.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
cups@2.4.7-1.2ubuntu7.3
2.4.7-1.2ubuntu7.13

Open the chart page →

7,628
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39316.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
cups@2.3.1-9ubuntu1.1
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-39316.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
cups@2.3.1-9ubuntu1.1
no fix listed

Open the chart page →

28,605
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-39316.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
cups@2.4.10-3+deb13u2
no fix listed

Open the chart page →

5,560
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39316.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
cups@2.4.1op1-1ubuntu4.10
2.4.1op1-1ubuntu4.20

Open the chart page →

14,100

Container images carrying it

177 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
cups@2.3.1-9ubuntu1.9
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
cups@2.4.2-3+deb12u9
no fix listed
1
gchq/accumulo:2.0.1c460bb587d6d
cups@2.4.7-1.2ubuntu7.3
2.4.7-1.2ubuntu7.13
1
gotenberg/gotenberg:8.30206a6c708fc6
cups@2.4.10-3+deb13u2
no fix listed
1
gotenberg/gotenberg:8.3467097317623a
cups@2.4.10-3+deb13u2
no fix listed
1
gotenberg/gotenberg:8-chromiuma40f92d7419a
cups@2.4.10-3+deb13u2
no fix listed
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
cups@2.1.3-4ubuntu0.4
no fix listed
1
ispras/svacer:11-2-042aa9fa9f189
cups@2.4.1op1-1ubuntu4.11
2.4.1op1-1ubuntu4.20
1
jacobalberty/unifi:v7.1.664a3616625dda
cups@2.2.7-1ubuntu2.8
no fix listed
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
cups@2.2.7-1ubuntu2.10
no fix listed
1
jacobalberty/unifi:5.10.19c409924e2463
cups@2.1.3-4ubuntu0.7
no fix listed
1
jaedb/iris:latest048cfbf58d57
cups@2.4.2-3+deb12u8
no fix listed
1
jlesage/firefox:v25.03.1055c28defe31
cups@2.4.11-r0
2.4.18-r0
1
jordan/icinga2:latestf75025fe8ea8
cups@2.4.2-3+deb12u9
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
cups@2.4.2-3+deb12u9
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
cups@2.4.7-1.2ubuntu7.9
2.4.7-1.2ubuntu7.13
1
library/redmine:6.1.204ac44a2595b
cups@2.4.10-3+deb13u2
no fix listed
1
library/wordpress:6.4.3-apache8ae66efb09a2
cups@2.4.2-3+deb12u5
no fix listed
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
cups@2.4.10-3+deb13u2
no fix listed
1
library/wordpress:php8.1-apachef73396626d2f
cups@2.4.10-3+deb13u2
no fix listed
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
cups@2.2.7-1ubuntu2.8
no fix listed
1
linuxserver/calibre-web:0.6.24241009026e6f
cups@2.4.7-1.2ubuntu7.3
2.4.7-1.2ubuntu7.13
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
cups@2.3.1-9ubuntu1.1
no fix listed
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
cups@2.2.7-1ubuntu2.8
no fix listed
1
linuxserver/unifi-controller:8.0.240ae315a3a456
cups@2.3.1-9ubuntu1.6
no fix listed
1
linuxserver/unifi-controller:7.3.83ab105cc50322
cups@2.3.1-9ubuntu1.2
no fix listed
1
louislam/uptime-kuma:2.5.33e24e96c89ef
cups@2.4.2-3+deb12u9
no fix listed
1
louislam/uptime-kuma:2.0.24c364ef96aad
cups@2.4.2-3+deb12u9
no fix listed
1
louislam/uptime-kuma:2.4.091e963bfda56
cups@2.4.2-3+deb12u9
no fix listed
1
merlos/zookeeper:3.9.3a38fc7e09ed7
cups@2.4.2-3+deb12u8
no fix listed
1
mlikiowa/napcat-docker:latest1336a777f9a4
cups@2.4.1op1-1ubuntu4.11
2.4.1op1-1ubuntu4.20
1
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
cups@2.4.2-3+deb12u9
no fix listed
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
cups@2.4.10-3+deb13u2
no fix listed
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
cups@2.2.7-1ubuntu2.5
no fix listed
1
oneuptime/probe:release6b2d98713711
cups@2.4.2-3+deb12u9
no fix listed
1
onyxdotapp/onyx-backend:latest473fdffe4e67
cups@2.4.10-3+deb13u2
no fix listed
1
openhab/openhab:5.2.1bfd4a60e90da
cups@2.4.10-3+deb13u2
no fix listed
1
openkm/openkm-ce:6.3.113bc465a7461b
cups@2.3.1-9ubuntu1.2
no fix listed
1
owncloud/server:10.15.051d9b74fc2a8
cups@2.3.1-9ubuntu1.8
no fix listed
1
owncloud/server:10.16.274c53d341076
cups@2.4.1op1-1ubuntu4.16
2.4.1op1-1ubuntu4.20
1
penpotapp/backend:2.2.147853d9bb9dd
cups@2.4.1op1-1ubuntu4.11
2.4.1op1-1ubuntu4.20
1
penpotapp/exporter:2.2.15c835ffd87ab
cups@2.4.1op1-1ubuntu4.11
2.4.1op1-1ubuntu4.20
1
photoprism/photoprism:220629-jammy2954334adbda
cups@2.4.1op1-1ubuntu4.1
2.4.1op1-1ubuntu4.20
1
photoprism/photoprism:260601650c6ad5a651
cups@2.4.16-1ubuntu1
2.4.16-1ubuntu1.2
1
photoprism/photoprism:251130db16ee6b1ba3
cups@2.4.12-0ubuntu3.3
2.4.12-0ubuntu3.9
1
photoprism/photoprism:240711-cefc6fd632ca74
cups@2.4.7-1.2ubuntu7.2
2.4.7-1.2ubuntu7.13
1
project2team4/react:latest3ff031a08887
cups@2.3.1-9ubuntu1.1
no fix listed
1
rundeck/rundeck:3.2.74d64fe56f767
cups@2.1.3-4ubuntu0.11
no fix listed
1
rundeck/rundeck:3.0.16b13e8059ad72
cups@2.1.3-4ubuntu0.7
no fix listed
1
saidsef/scapy-containerised:v2025.02f17f7c435891
cups@2.4.11-r0
2.4.18-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.