StackRadar

CVE-2026-46675

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,050
of 17,966 indexed, latest versions
Container images
840
deployed by those charts
Fix available
None
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,050 of 17,966 indexed charts deploy, on 840 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+20 moreno fix listed820
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 moreno fix listed20
OSV records
UBUNTU-CVE-2026-46675DEBIAN-CVE-2026-46675
Trending
Rank 23 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

1,050 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

840 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/fluxerapp/fluxer-api:2026.820.164808f683541d5374
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
ghcr.io/fluxerapp/fluxer-media-proxy:2026.820.164955ced7544e6b3f
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
ghcr.io/getsentry/taskbroker:26.7.264d0da74a578
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
libpng1.6@1.6.43-5ubuntu0.5
no fix listed
1
ghcr.io/guydavis/machinaris:test50a71a30f18e
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/immich-app/immich-server:v3.2.4d317916b2809
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
libpng1.6@1.6.48-1
no fix listed
1
ghcr.io/jellyfin/jellyfin:12.1008ec8024bda
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
libpng1.6@1.6.43-5build1
no fix listed
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
libpng1.6@1.6.43-5build1
no fix listed
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
libpng1.6@1.6.37-3build5
no fix listed
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
ghcr.io/krateoplatformops/finops-database-handler:0.5.32550427988e3
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/krateoplatformops/finops-webservice-api-mock:0.1.00877e9452d14
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/libretime/icecast:latest4bee94ce480c
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
ghcr.io/linuxserver/audacity:version-3.0.2cdf203db1e50
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/linuxserver/booksonic:version-1.2677efca1065d
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
1
ghcr.io/linuxserver/calibre-web:latest0767226fcf20
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
1
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
1
ghcr.io/linuxserver/duplicati:lateste1fdac6133ad
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
ghcr.io/linuxserver/hedgedoc:version-1.9.0792a12ee976a
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
1
ghcr.io/linuxserver/papermerge:version-v2.0.198ba2dd3f0bd
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
1
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
libpng1.6@1.6.43-5build1
no fix listed
1
ghcr.io/maritimeconnectivity/identityregistry:latest91de8dfffafe
libpng1.6@1.6.57-1
no fix listed
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
libpng1.6@1.6.48-1
no fix listed
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.