StackRadar

CVE-2026-46675

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,050
of 17,966 indexed, latest versions
Container images
840
deployed by those charts
Fix available
None
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,050 of 17,966 indexed charts deploy, on 840 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+20 moreno fix listed820
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 moreno fix listed20
OSV records
UBUNTU-CVE-2026-46675DEBIAN-CVE-2026-46675
Trending
Rank 19 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

1,050 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

840 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.28.08b02290f4d18
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
ghcr.io/mend/renovate-ee-server:15.6.087b77989f48d
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
ghcr.io/monicahq/monica-next:main8be69156acbb
libpng1.6@1.6.48-1
no fix listed
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
libpng1.6@1.6.39-2+deb12u1
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
libpng1.6@1.6.39-2+deb12u3
no fix listed
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-fraud-detectiona07ee694304b
libpng1.6@1.6.39-2+deb12u3
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
libpng1.6@1.6.43-5build1
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-load-generatorb130d6cee6cb
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-addfd7a4697116
libpng1.6@1.6.43-5build1
no fix listed
1
ghcr.io/openunison/openunison-k8s:1.0.51fbd5ad963d68
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
ghcr.io/openunison/openunison-k8s-react:1.0.2b595875df660
libpng1.6@1.6.37-3ubuntu0.6
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
libpng1.6@1.6.48-1+deb13u3
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
libpng1.6@1.6.48-1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
libpng1.6@1.6.48-1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
libpng1.6@1.6.48-1+deb13u4
no fix listed
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
libpng1.6@1.6.57-1
no fix listed
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
libpng1.6@1.6.43-5ubuntu0.5
no fix listed
1
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
libpng1.6@1.6.43-5ubuntu0.5
no fix listed
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
libpng1.6@1.6.43-5ubuntu0.5
no fix listed
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
libpng1.6@1.6.43-5ubuntu0.5
no fix listed
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
libpng1.6@1.6.43-5ubuntu0.5
no fix listed
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
libpng1.6@1.6.43-5build1
no fix listed
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
libpng1.6@1.6.37-2
no fix listed
1
ghcr.io/steadybit/agent:2.4.6d246bfa55f63
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
libpng1.6@1.6.43-5ubuntu0.5
no fix listed
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
libpng1.6@1.6.43-5ubuntu0.5
no fix listed
1
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
ghcr.io/thm-mni-ii/fbs-core:v2.0.1b585ab8bb7e8
libpng1.6@1.6.57-1
no fix listed
1
ghcr.io/thm-mni-ii/fbs-identity-service:v2.0.1baf79539e5df
libpng1.6@1.6.57-1
no fix listed
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
libpng1.6@1.6.37-3build5
no fix listed
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
libpng1.6@1.6.37-3build5
no fix listed
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
libpng1.6@1.6.37-3build5
no fix listed
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.