StackRadar

CVE-2026-44663

Medium

Advisory

Published 18 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
23
of 17,781 indexed, latest versions
Container images
27
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 23 of 17,781 indexed charts deploy, on 27 images.

Affected packageAffected versionsFixed inImages
openexrdeb2.2.0-10ubuntu2, 2.3.0-6ubuntu0.5, 2.5.7-1, 3.1.5-5.1build3+2 moreno fix listed27
OSV records
UBUNTU-CVE-2026-44663

Charts affected

23 by stars
ChartLatestAffected imagesRadar Score
penpotpenpotOfficialVerified publisher1.9.01 of 4See more

penpot penpot 1.9.0

1 of the 4 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
penpotapp/exporter:2.17.272a8061e8806
openexr@3.1.13-2build1
no fix listed

Open the chart page →

4,314
minecraft-proxyminecraft-server-chartsVerified publisher3.10.01 of 1See more

minecraft-proxy minecraft-server-charts 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
itzg/bungeecord:latest1c59f9631f3b
openexr@3.1.13-2build1
no fix listed

Open the chart page →

3,074
photoprismandrenarchyVerified publisher8.15.01 of 1See more

photoprism andrenarchy 8.15.0

1 of the 1 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
photoprism/photoprism:260728958642220223
openexr@3.1.13-2build1
no fix listed

Open the chart page →

8,825
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
openexr@2.3.0-6ubuntu0.5
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
openexr@2.3.0-6ubuntu0.5
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
openexr@2.3.0-6ubuntu0.5
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
openexr@2.3.0-6ubuntu0.5
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
openexr@2.3.0-6ubuntu0.5
no fix listed

Open the chart page →

113,791
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
openexr@3.1.13-2
no fix listed

Open the chart page →

11,103
smarter-demosmarterOfficialVerified publisher0.1.52 of 7See more

smarter-demo smarter 0.1.5

2 of the 7 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
openexr@2.3.0-6ubuntu0.5
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
openexr@2.3.0-6ubuntu0.5
no fix listed

Open the chart page →

45,832
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
openexr@2.2.0-10ubuntu2
no fix listed

Open the chart page →

77,758
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
openexr@3.1.5-5.1build3
no fix listed

Open the chart page →

16,954
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
openexr@2.3.0-6ubuntu0.5
no fix listed

Open the chart page →

16,123
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
openexr@2.3.0-6ubuntu0.5
no fix listed

Open the chart page →

27,949
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
openexr@2.5.7-1
no fix listed

Open the chart page →

19,503
minecrafthelmforgeVerified publisher1.5.31 of 1See more

minecraft helmforge 1.5.3

1 of the 1 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
itzg/minecraft-server:2026.9.04e29d14082d9
openexr@3.1.5-5.1build3
no fix listed

Open the chart page →

4,639
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
openexr@2.3.0-6ubuntu0.5
no fix listed

Open the chart page →

18,066
penpotkubitodevVerified publisher1.2.11 of 5See more

penpot kubitodev 1.2.1

1 of the 5 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
penpotapp/exporter:2.2.15c835ffd87ab
openexr@2.5.7-1
no fix listed

Open the chart page →

16,877
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
openexr@2.5.7-1
no fix listed

Open the chart page →

10,716
minecraftpaul1365972-mc3.0.11 of 1See more

minecraft paul1365972-mc 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
itzg/minecraft-server:latest8672e335dbef
openexr@3.1.5-5.1build3
no fix listed

Open the chart page →

4,253
game-serverpvillaverdeVerified publisher1.0.51 of 1See more

game-server pvillaverde 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
ghcr.io/itzg/minecraft-server:latestc1a267d9ed6d
openexr@3.1.5-5.1build3
no fix listed

Open the chart page →

4,253
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
openexr@3.1.13-2build1
no fix listed

Open the chart page →

10,348
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
openexr@2.3.0-6ubuntu0.5
no fix listed

Open the chart page →

30,687
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
openexr@3.1.5-5.1build3
no fix listed

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
openexr@3.1.5-5.1build3
no fix listed

Open the chart page →

12,460
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
openexr@3.1.5-5.1build3
no fix listed

Open the chart page →

8,193
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-44663.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openexr@2.5.7-1
no fix listed

Open the chart page →

14,100

Container images carrying it

27 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
kurento/kurento-media-server:latest03c0d34d0828
openexr@3.1.5-5.1build3
no fix listed
2
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
openexr@2.3.0-6ubuntu0.5
no fix listed
1
itzg/bungeecord:latest1c59f9631f3b
openexr@3.1.13-2build1
no fix listed
1
itzg/minecraft-server:2026.9.04e29d14082d9
openexr@3.1.5-5.1build3
no fix listed
1
itzg/minecraft-server:latest8672e335dbef
openexr@3.1.5-5.1build3
no fix listed
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
openexr@2.3.0-6ubuntu0.5
no fix listed
1
livekit/ingress:v1.2.21ab01641b366
openexr@2.5.7-1
no fix listed
1
openkm/openkm-ce:6.3.113bc465a7461b
openexr@2.3.0-6ubuntu0.5
no fix listed
1
penpotapp/exporter:2.2.15c835ffd87ab
openexr@2.5.7-1
no fix listed
1
penpotapp/exporter:2.17.272a8061e8806
openexr@3.1.13-2build1
no fix listed
1
photoprism/photoprism:220629-jammy2954334adbda
openexr@2.5.7-1
no fix listed
1
photoprism/photoprism:260601650c6ad5a651
openexr@3.1.13-2build1
no fix listed
1
photoprism/photoprism:260728958642220223
openexr@3.1.13-2build1
no fix listed
1
photoprism/photoprism:251130db16ee6b1ba3
openexr@3.1.13-2
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
openexr@3.1.5-5.1build3
no fix listed
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
openexr@2.3.0-6ubuntu0.5
no fix listed
1
stashapp/stash-box:latesta534c8afdf39
openexr@3.1.5-5.1build3
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
openexr@2.2.0-10ubuntu2
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openexr@2.5.7-1
no fix listed
1
ghcr.io/itzg/minecraft-server:latestc1a267d9ed6d
openexr@3.1.5-5.1build3
no fix listed
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
openexr@2.3.0-6ubuntu0.5
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
openexr@2.3.0-6ubuntu0.5
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
openexr@2.3.0-6ubuntu0.5
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
openexr@2.3.0-6ubuntu0.5
no fix listed
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
openexr@2.3.0-6ubuntu0.5
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
openexr@2.3.0-6ubuntu0.5
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
openexr@2.3.0-6ubuntu0.5
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.