StackRadar

CVE-2026-39316

Medium

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
206
of 17,781 indexed, latest versions
Container images
177
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 206 of 17,781 indexed charts deploy, on 177 images.

Affected packageAffected versionsFixed inImages
cupsdeb2.1.3-4ubuntu0.3, 2.1.3-4ubuntu0.4, 2.1.3-4ubuntu0.7, 2.1.3-4ubuntu0.10+29 more2.4.1op1-1ubuntu4.20, 2.4.7-1.2ubuntu7.13, 2.4.12-0ubuntu3.9, 2.4.16-1ubuntu1.2167
cupsapk2.4.11-r02.4.18-r010
OSV records
ALPINE-CVE-2026-39316DEBIAN-CVE-2026-39316UBUNTU-CVE-2026-39316
Also known as
USN-8405-1

Charts affected

206 by stars
ChartLatestAffected imagesRadar Score
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-39316.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
cups@2.4.7-1.2ubuntu7.9
2.4.7-1.2ubuntu7.13

Open the chart page →

4,305
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-39316.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
cups@2.4.7-1.2ubuntu7.3
2.4.7-1.2ubuntu7.13

Open the chart page →

7,628
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39316.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
cups@2.3.1-9ubuntu1.1
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-39316.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
cups@2.3.1-9ubuntu1.1
no fix listed

Open the chart page →

28,605
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-39316.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
cups@2.4.10-3+deb13u2
no fix listed

Open the chart page →

5,560
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-39316.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
cups@2.4.1op1-1ubuntu4.10
2.4.1op1-1ubuntu4.20

Open the chart page →

14,100

Container images carrying it

177 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
cups@2.3.1-9ubuntu1.1
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
cups@2.3.1-9ubuntu1.1
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
cups@2.3.1-9ubuntu1.1
no fix listed
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
cups@2.3.1-9ubuntu1.1
no fix listed
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
cups@2.4.2-3+deb12u9
no fix listed
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
cups@2.2.7-1ubuntu2.8
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
cups@2.4.2-3+deb12u8
no fix listed
1
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
cups@2.4.7-1.2ubuntu7.9
2.4.7-1.2ubuntu7.13
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
cups@2.3.1-9ubuntu1.2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
cups@2.4.2-3+deb12u8
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
cups@2.4.10-3+deb13u2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
cups@2.4.10-3+deb13u2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
cups@2.4.10-3+deb13u2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
cups@2.4.2-3+deb12u4
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
cups@2.4.10-3+deb13u2
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
cups@2.3.1-9ubuntu1.2
no fix listed
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
cups@2.3.1-9ubuntu1.2
no fix listed
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
cups@2.4.7-1.2ubuntu7.9
2.4.7-1.2ubuntu7.13
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
cups@2.4.1op1-1ubuntu4.8
2.4.1op1-1ubuntu4.20
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
cups@2.4.1op1-1ubuntu4.8
2.4.1op1-1ubuntu4.20
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
cups@2.4.1op1-1ubuntu4.11
2.4.1op1-1ubuntu4.20
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
cups@2.4.2-3+deb12u4
no fix listed
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
cups@2.4.2-3+deb12u9
no fix listed
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
cups@2.4.2-3+deb12u9
no fix listed
1
ghcr.io/zammad/zammad:7.1.3-0011e65123a43ecc
cups@2.4.10-3+deb13u2
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
cups@2.1.3-4ubuntu0.10
no fix listed
1
quay.io/underndog/samba:1.2.0-not-recyclecca801de9fa5
cups@2.4.11-r0
2.4.18-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.