StackRadar

CVE-2026-46675

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,050
of 17,966 indexed, latest versions
Container images
840
deployed by those charts
Fix available
None
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,050 of 17,966 indexed charts deploy, on 840 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+20 moreno fix listed820
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 moreno fix listed20
OSV records
UBUNTU-CVE-2026-46675DEBIAN-CVE-2026-46675
Trending
Rank 19 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

1,050 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

840 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
libpng1.6@1.6.39-2+deb12u1
no fix listed
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/wittdennis/calibre-web:1.1.2953aa0935251
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
libpng1.6@1.6.39-2+deb12u4
no fix listed
1
ghcr.io/zammad/zammad:7.2.0-0011f7b62c718bce
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
libpng1.6@1.6.39-2
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
libpng1.6@1.6.39-2
no fix listed
1
mcr.microsoft.com/playwright/mcp:v0.0.43e101b832b34d
libpng1.6@1.6.39-2
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.70.269a5adbf3f45
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2:latestb53a854bd7c1
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.70.366b0ec8b3de3
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.70.0:latestac89679314c1
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
libpng1.6@1.6.57-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.4_local5bda14f66e8e
libpng1.6@1.6.57-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
libpng1.6@1.6.43-5ubuntu0.3
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
libpng1.6@1.6.57-1
no fix listed
1
public.ecr.aws/aktosecurity/akto-threat-detection:latesta728eb2eaf06
libpng1.6@1.6.57-1
no fix listed
1
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
libpng1.6@1.6.39-2
no fix listed
1
public.ecr.aws/jtekt-corporation/api-key-manager-gui:v0.1.10424fa47fbeb
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
libpng1.6@1.6.39-2
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
libpng1.6@1.6.39-2
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
libpng1.6@1.6.39-2
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
libpng1.6@1.6.39-2
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
libpng1.6@1.6.39-2
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
libpng1.6@1.6.39-2
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libpng1.6@1.6.37-2
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
libpng1.6@1.6.39-2
no fix listed
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
libpng1.6@1.6.37-3build5
no fix listed
1
quay.io/go-skynet/local-ai:latest0632c21ddbe4
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
libpng1.6@1.6.39-2
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libpng@1.2.54-1ubuntu1.1
no fix listed
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
libpng1.6@1.6.57-1
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libpng1.6@1.6.39-2
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.1126450354eba9
libpng1.6@1.6.57-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
libpng1.6@1.6.48-1+deb13u4
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
libpng1.6@1.6.39-2+deb12u5
no fix listed
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.