StackRadar

CVE-2026-46675

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,060
of 17,957 indexed, latest versions
Container images
851
deployed by those charts
Fix available
None
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,060 of 17,957 indexed charts deploy, on 851 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+20 moreno fix listed831
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 moreno fix listed20
OSV records
UBUNTU-CVE-2026-46675DEBIAN-CVE-2026-46675
Trending
Rank 23 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

1,060 by stars
ChartLatestAffected imagesRadar Score
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

8,017
games-on-whalesangelnu2.0.03 of 7See more

games-on-whales angelnu 2.0.0

3 of the 7 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
libpng1.6@1.6.37-3build5
no fix listed
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libpng1.6@1.6.37-2
no fix listed
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
libpng1.6@1.6.37-2
no fix listed

Open the chart page →

123,452
antrea-uiantreaVerified publisher0.8.01 of 2See more

antrea-ui antrea 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

3,621
kesque-dashboardapache-pulsar-helm-chart-repo0.0.51 of 5See more

kesque-dashboard apache-pulsar-helm-chart-repo 0.0.5

1 of the 5 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

4,101
apispringbootHelmapispringboot0.1.01 of 1See more

apispringbootHelm apispringboot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
rabeh/apibootspring:1.0941007b6946e
libpng1.6@1.6.37-3build5
no fix listed

Open the chart page →

6,525
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
libpng1.6@1.6.37-3build5
no fix listed

Open the chart page →

4,377
inbox-server-distributedappscodeVerified publisher2025.12.252 of 4See more

inbox-server-distributed appscode 2025.12.25

2 of the 4 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
libpng1.6@1.6.37-3build5
no fix listed
ghcr.io/appscode/inbox-server:latest536358d7b17e
libpng1.6@1.6.37-3build5
no fix listed

Open the chart page →

16,805
james-komposeappscodeVerified publisher0.1.02 of 4See more

james-kompose appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
libpng1.6@1.6.37-3build5
no fix listed
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
libpng1.6@1.6.37-3build5
no fix listed

Open the chart page →

18,188
platform-apiappscodeVerified publisher2026.9.111 of 3See more

platform-api appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
libpng1.6@1.6.48-1
no fix listed

Open the chart page →

39,991
s3proxyappscodeVerified publisher2026.9.111 of 1See more

s3proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
libpng1.6@1.6.37-3build5
no fix listed

Open the chart page →

3,494
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
libpng1.6@1.6.48-1
no fix listed

Open the chart page →

8,197
argonix-apiargonix0.5.51 of 4See more

argonix-api argonix 0.5.5

1 of the 4 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:0.5.5aa0e3efe5840
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

5,360
arlas-aiasarlas-stackVerified publisher28.9.01 of 22See more

arlas-aias arlas-stack 28.9.0

1 of the 22 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

42,292
dltkvassist-iot-data-integrity-verification0.2.02 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
libpng@1.2.54-1ubuntu1
no fix listed
hyperledger/fabric-couchdb:0.4.15f6c724592abf
libpng@1.2.54-1ubuntu1.1
no fix listed

Open the chart page →

200,508
dltflassist-iot-dlt-based-fl0.2.02 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
libpng@1.2.54-1ubuntu1
no fix listed
hyperledger/fabric-couchdb:0.4.15f6c724592abf
libpng@1.2.54-1ubuntu1.1
no fix listed

Open the chart page →

200,508
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
libpng1.6@1.6.37-3build5
no fix listed

Open the chart page →

10,468
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
libpng1.6@1.6.37-3build5
no fix listed

Open the chart page →

93,324
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
libpng1.6@1.6.37-2
no fix listed

Open the chart page →

8,360
smartorchestratorassist-iot-smart-orchestrator4.0.01 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

1 of the 14 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

47,425
videoaugmentationassist-iot-video-augmentation0.1.02 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
libpng1.6@1.6.37-2
no fix listed
library/nginx:latestabe47724e466
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

80,979
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
libpng1.6@1.6.37-3build5
no fix listed
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

34,130
bamboo-agentatlassian-data-centerVerified publisher2.0.151 of 1See more

bamboo-agent atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
atlassian/bamboo-agent-base:12.1.1147d6dadc050e
libpng1.6@1.6.43-5ubuntu0.6
no fix listed

Open the chart page →

1,650
webappavzi-webapp0.1.01 of 1See more

webapp avzi-webapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
avzini/web-app:latestf40b30210ed0
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

6,604
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

6,873
aws9helmaws9helm0.1.04 of 4See more

aws9helm aws9helm 0.1.0

4 of the 4 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
kuzwolka/aws9:main1ad759b961b1
libpng1.6@1.6.39-2
no fix listed
kuzwolka/aws9:news3e8880fbbb96
libpng1.6@1.6.39-2
no fix listed
kuzwolka/aws9:blog4a7707410bf1
libpng1.6@1.6.39-2
no fix listed
kuzwolka/aws9:shop84a9d9766345
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

19,584
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

6,604
bookinfobasictechno0.1.03 of 6See more

bookinfo basictechno 0.1.0

3 of the 6 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
libpng1.6@1.6.37-2
no fix listed
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
libpng1.6@1.6.37-2
no fix listed
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
libpng1.6@1.6.37-2
no fix listed

Open the chart page →

21,655
my-nginx-appbassant-nginx-app0.1.01 of 1See more

my-nginx-app bassant-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/nginx:stable0aa2d81d65bc
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

1,765
mealiebdclark-helm-chartsVerified publisher0.1.151 of 1See more

mealie bdclark-helm-charts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

4,622
immichbear0.1.11 of 2See more

immich bear 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

7,555
webappbenc-uk1.4.31 of 1See more

webapp benc-uk 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/nginx:latestcfb8a89ac237
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

1,765
pagesberrutig-pages1.0.02 of 3See more

pages berrutig-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed

Open the chart page →

20,652
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed

Open the chart page →

90,946
bdbablackduck2026.9.01 of 9See more

bdba blackduck 2026.9.0

1 of the 9 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
blackducksoftware/bdba-frontend:2026.9.10afa8763ccb8
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

7,927
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
libpng1.6@1.6.37-2
no fix listed

Open the chart page →

13,766
bluespacebluespace0.3.01 of 1See more

bluespace bluespace 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

1,765
colosseumbook-k8sinfra-v21.0.183 of 5See more

colosseum book-k8sinfra-v2 1.0.18

3 of the 5 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-agg:logbc25b152d88e
libpng1.6@1.6.37-3ubuntu0.5
no fix listed
sysnet4admin/colosseum-cms:loge74b43c7f492
libpng1.6@1.6.39-2
no fix listed
sysnet4admin/colosseum-prm:log5802bfcd7fed
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

29,409
jaegerbook-k8sinfra-v23.4.02 of 5See more

jaeger book-k8sinfra-v2 3.4.0

2 of the 5 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libpng1.6@1.6.37-3build5
no fix listed
library/cassandra:3.11.65aa8400b4b3b
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed

Open the chart page →

19,898
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

8,619
flaresolverrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

flaresolverr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

29,537
tenantsbrbarmex-tenant2.0.01 of 1See more

tenants brbarmex-tenant 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

1,765
pagesbrian-pages1.0.02 of 3See more

pages brian-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed

Open the chart page →

20,652
pagesbrixton-mayuribhavsar23-pages1.0.02 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed

Open the chart page →

20,652
pagesbrixton-pages1.0.02 of 3See more

pages brixton-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed

Open the chart page →

20,652
node-appbryopsida0.5.12 of 2See more

node-app bryopsida 0.5.1

2 of the 2 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/node:lts64af3819f927
libpng1.6@1.6.39-2+deb12u5
no fix listed
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
libpng1.6@1.6.43-5build1
no fix listed

Open the chart page →

79,935
nginx-chartbtrepoVerified publisher0.1.01 of 1See more

nginx-chart btrepo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

1,765
postgresqlbuall-charts0.1.21 of 1See more

postgresql buall-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
buall/postgres-stack:18.6881a785642cb
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

4,166
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
dellcloud/category:distributed02fc234353a9
libpng1.6@1.6.37-2
no fix listed

Open the chart page →

11,839
pages-microservicebusi-adsVerified publisher1.0.02 of 3See more

pages-microservice busi-ads 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed

Open the chart page →

20,652
gotenbergbysamioVerified publisher0.2.01 of 1See more

gotenberg bysamio 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8-chromium0d28ae9a9644
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

6,909

Container images carrying it

851 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
libpng1.6@1.6.39-2+deb12u5
no fix listed
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.