StackRadar

CVE-2026-46675

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,060
of 17,957 indexed, latest versions
Container images
851
deployed by those charts
Fix available
None
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,060 of 17,957 indexed charts deploy, on 851 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+20 moreno fix listed831
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 moreno fix listed20
OSV records
UBUNTU-CVE-2026-46675DEBIAN-CVE-2026-46675
Trending
Rank 23 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

1,060 by stars
ChartLatestAffected imagesRadar Score
am-pattern-1wso22.6.0-71 of 6See more

am-pattern-1 wso2 2.6.0-7

1 of the 6 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
wso2/wso2am:2.6.0fbe0f4059b74
libpng1.6@1.6.37-2
no fix listed

Open the chart page →

32,105
ei-pattern-1wso26.6.0-33 of 6See more

ei-pattern-1 wso2 6.6.0-3

3 of the 6 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
wso2/wso2ei-analytics-dashboard:6.6.0526a1ccae902
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
wso2/wso2ei-analytics-worker:6.6.021e6b03449ac
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
wso2/wso2ei-integrator:6.6.0790cd8c3a5a2
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed

Open the chart page →

50,862
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
no fix listed

Open the chart page →

7,980
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

1,765
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/nginx:stableb972f831f200
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

1,765
jenkinszanise-jenkins-helm-chart0.1.01 of 1See more

jenkins zanise-jenkins-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

2,766
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

2,916
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libpng1.6@1.6.48-1+deb13u5
no fix listed

Open the chart page →

1,765
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
libpng1.6@1.6.39-2+deb12u5
no fix listed

Open the chart page →

4,916
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-46675.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
libpng1.6@1.6.37-3ubuntu0.5
no fix listed

Open the chart page →

8,586

Container images carrying it

851 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
grpl/grapple-cli:0.2.127c00aafee6629
libpng1.6@1.6.43-5build1
no fix listed
1
guacamole/guacamole:1.5.50f62f6d17ab3
libpng1.6@1.6.37-3build5
no fix listed
1
gulacedia/web-dvwa-new:v367b467d961ca
libpng1.6@1.6.39-2
no fix listed
1
haveagitgat/tdarr:2.00.181256348872ce
libpng1.6@1.6.37-2
no fix listed
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
libpng1.6@1.6.37-2
no fix listed
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
libpng1.6@1.6.37-2
no fix listed
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
libpng1.6@1.6.39-2
no fix listed
1
hazegoodlife/haaze:milksite8d4c63169e14
libpng1.6@1.6.39-2
no fix listed
1
headwindmdm/hmdm:0.1.93550b4840840
libpng1.6@1.6.37-3ubuntu0.5
no fix listed
1
hecrom/myweatherangularclient:1.3.11bb0372939c19
libpng1.6@1.6.39-2
no fix listed
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
libpng1.6@1.6.39-2
no fix listed
1
hivemq/hivemq-edge:2026.14d8250a233cea
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
libpng1.6@1.6.37-3build5
no fix listed
1
hivemq/hivemq-platform-operator:2.2.2a919f990141b
libpng1.6@1.6.57-1
no fix listed
1
hivemq/hivemq-swarm:4.56.08d5f6a6f48b0
libpng1.6@1.6.57-1
no fix listed
1
hmediade/printserver:latest481a552c8e1c
libpng1.6@1.6.37-3build5
no fix listed
1
housewrecker/gaps:latestf417dd0a7547
libpng1.6@1.6.37-2
no fix listed
1
huginn/huginn:4df1217d3055db980a04f293e28016b77826e3caeab0db98264e
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
1
hugohg34/toposervice:0.0.2812a03b3f274
libpng1.6@1.6.37-2
no fix listed
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
libpng@1.2.54-1ubuntu1
no fix listed
1
instill/artifact-backend:b28766ac4a393e601ed
libpng1.6@1.6.48-1+deb13u4
no fix listed
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libpng1.6@1.6.37-2
no fix listed
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
libpng1.6@1.6.37-2
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
libpng1.6@1.6.39-2
no fix listed
1
inventree/inventree:1.5.6b61e6a7534bf
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
ispras/svacer:11-2-042aa9fa9f189
libpng1.6@1.6.37-3build5
no fix listed
1
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
libpng1.6@1.6.37-2
no fix listed
1
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
libpng1.6@1.6.37-2
no fix listed
1
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
libpng1.6@1.6.37-2
no fix listed
1
itzg/bungeecord:latestde76286c0e73
libpng1.6@1.6.57-1
no fix listed
1
itzg/minecraft-server:latest77280d10744f
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
itzg/minecraft-server:2026.9.2de5d1b1a83eb
libpng1.6@1.6.43-5ubuntu0.6
no fix listed
1
jacobalberty/unifi:v7.1.664a3616625dda
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
libpng1.6@1.6.34-1ubuntu0.18.04.2
no fix listed
1
jacobalberty/unifi:5.10.19c409924e2463
libpng@1.2.54-1ubuntu1.1
no fix listed
1
jaedb/iris:latest048cfbf58d57
libpng1.6@1.6.39-2
no fix listed
1
jakowenko/double-take:1.6.0b858bac9e32a
libpng1.6@1.6.37-2
no fix listed
1
jbtronics/part-db1:latestfd68338829ed
libpng1.6@1.6.39-2+deb12u5
no fix listed
1
jellyfin/jellyfin:10.11.81694ff069f0c
libpng1.6@1.6.48-1+deb13u4
no fix listed
1
jellyfin/jellyfin:10.11.717285f9cce63
libpng1.6@1.6.48-1+deb13u4
no fix listed
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
libpng1.6@1.6.39-2
no fix listed
1
jellyfin/jellyfin:10.11.6333b64771663
libpng1.6@1.6.48-1+deb13u1
no fix listed
1
jellyfin/jellyfin:latest78d3ea1207d1
libpng1.6@1.6.48-1+deb13u5
no fix listed
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
libpng1.6@1.6.39-2
no fix listed
1
jellyfin/jellyfin:10.10.77ae36aab93ef
libpng1.6@1.6.39-2
no fix listed
1
jellyfin/jellyfin:10.10.696b09723b22f
libpng1.6@1.6.39-2
no fix listed
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
libpng1.6@1.6.39-2
no fix listed
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
libpng1.6@1.6.39-2
no fix listed
1
jhipster/jhipster-registry:latest7184525acd4d
libpng1.6@1.6.37-2
no fix listed
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.