StackRadar

CVE-2026-46675

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,060
of 17,957 indexed, latest versions
Container images
851
deployed by those charts
Fix available
None
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,060 of 17,957 indexed charts deploy, on 851 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+20 moreno fix listed831
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 moreno fix listed20
OSV records
UBUNTU-CVE-2026-46675DEBIAN-CVE-2026-46675
Trending
Rank 23 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

1,060 by stars
ChartLatestAffected imagesRadar Score
am-pattern-1wso22.6.0-71 of 6See more

am-pattern-1 wso2 2.6.0-7

1 of the 6 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
wso2/wso2am:2.6.0fbe0f4059b74
libpng1.6@1.6.37-2
no fix listed

Open the chart page →

32,105
ei-pattern-1wso26.6.0-33 of 6See more

ei-pattern-1 wso2 6.6.0-3

3 of the 6 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
wso2/wso2ei-analytics-dashboard:6.6.0526a1ccae902
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
wso2/wso2ei-analytics-worker:6.6.021e6b03449ac
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
wso2/wso2ei-integrator:6.6.0790cd8c3a5a2
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed

Open the chart page →

50,862
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

7,980
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

1,765
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/nginx:stableb972f831f200
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

1,765
jenkinszanise-jenkins-helm-chart0.1.01 of 1See more

jenkins zanise-jenkins-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

2,766
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

2,916
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

1,765
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

4,916
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
libpng1.6@1.6.37-3ubuntu0.5
no fix listed

Open the chart page →

8,586

Container images carrying it

851 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mathesar/mathesar:0.12.0091757cb01fe
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
mautic/mautic:7-apacheeb8cc73d97e1
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
mbround18/valheim:3.1.070bd4da591cd
libpng1.6@1.6.37-3build5
no fix listed
1
mcp/kubernetes:latest5ffbf7f0a8aa
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
mediagis/nominatim:5.3.27923a8e67197
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
mediagis/nominatim:3.7c15e941485ef
libpng1.6@1.6.37-2
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
libpng1.6@1.6.37-3build5
no fix listed
1
merlos/zookeeper:3.9.3a38fc7e09ed7
libpng1.6@1.6.39-2
no fix listed
1
mindsdb/mindsdb:latest163011c09299
libpng1.6@1.6.48-1+deb13u4
no fix listed
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
libpng1.6@1.6.39-2
no fix listed
1
mlikiowa/napcat-docker:latest2cc70b45244a
libpng1.6@1.6.37-3build5
no fix listed
1
mockserver/mockserver:mockserver-8.0.0b8426e0b3c80
libpng1.6@1.6.39-2+deb12u3
no fix listed
1
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
moreillon/api-proxy:latestd7d4a5463525
libpng1.6@1.6.39-2
no fix listed
1
moreillon/camera-viewer:lateste418cc694bd5
libpng1.6@1.6.39-2
no fix listed
1
moreillon/food-manager:lateste8fd856e593d
libpng1.6@1.6.39-2
no fix listed
1
moreillon/group-manager:latest3caa8f710ee0
libpng1.6@1.6.39-2+deb12u4
no fix listed
1
moreillon/group-manager-front:latest5f0a38498271
libpng1.6@1.6.48-1+deb13u4
no fix listed
1
moreillon/user-manager-front:v5.1.06597e6b98d21
libpng1.6@1.6.39-2
no fix listed
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
libpng1.6@1.6.39-2
no fix listed
1
muhammedgamal/fp23:latest74b4cd69b6fa
libpng1.6@1.6.39-2
no fix listed
1
muluder/prograncontrollermcord:0.1.843b597a93da7
libpng@1.2.54-1ubuntu1
no fix listed
1
netapp/trident-protect-utils:v3.0.0cad26cd945d1
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
nethermind/nethermind:1.14.615517708c3b6
libpng1.6@1.6.37-3build5
no fix listed
1
netskopeprivateaccess/publisher_u22:latest0b43204c37d6
libpng1.6@1.6.37-3ubuntu0.6
no fix listed
1
nginxinc/nginx-unprivileged:latest31e97ebaac04
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
libpng1.6@1.6.48-1+deb13u4
no fix listed
1
nginx/nginx-ingress:5.6.33e97f06dce1c
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
nginx/nginx-ingress:edged127d1013198
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
nirmalnaveen/supermario:latest8541a39162f3
libpng1.6@1.6.39-2
no fix listed
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
olvid/bot-daemon:2.0.1e0e6b165d879
libpng1.6@1.6.43-5ubuntu0.5
no fix listed
1
omecproject/c3po-hssdb:master-latest28a90cc26716
libpng1.6@1.6.37-2
no fix listed
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
1
omecproject/onos-progran:1.0.05715e5648aa0
libpng@1.2.54-1ubuntu1
no fix listed
1
oneuptime/probe:release2a170032aee8
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
onosproject/onos:2.2.144914a8d4b3f
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
1
onyxdotapp/onyx-backend:latest60e83a098ae4
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
libpng1.6@1.6.39-2
no fix listed
1
opea/codetrans-ui:1.03ef121f34610
libpng1.6@1.6.39-2
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
libpng1.6@1.6.39-2
no fix listed
1
opea/speecht5:1.0249afad3d268
libpng1.6@1.6.39-2
no fix listed
1
openaev/platform:3.260923.06c512196d956
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
openbas/caldera-server:5.1.0a277796d9724
libpng1.6@1.6.39-2
no fix listed
1
openbas/platform:2.0.5d986d80b0a75
libpng1.6@1.6.43-5build1
no fix listed
1
opencsghq/agenticflow:ee-v0.6.5-241cba9c366f1
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
opencsghq/csgbot:v0.6.9-ee7d0271e26521
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
opendatacube/explorer:latest120457ffcd69
libpng1.6@1.6.43-5build1
no fix listed
1
opendatacube/pipelines:wofs-1.225d810e8504b8
libpng1.6@1.6.34-1ubuntu0.18.04.1
no fix listed
1
opendatacube/restcube:latest91870111837c
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.