StackRadar

CVE-2026-48913

High

Advisory

Published 8 Jun 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
52
of 17,781 indexed, latest versions
Container images
50
deployed by those charts
Fix available
3 of 3
affected packages

Apache HTTP Server: mod_http2 memory corruption when file handles exhausted

Carried by container images the latest versions of 52 of 17,781 indexed charts deploy, on 50 images.

Affected packageAffected versionsFixed inImages
apache2deb2.4.41-4ubuntu3.11, 2.4.41-4ubuntu3.12, 2.4.41-4ubuntu3.14, 2.4.41-4ubuntu3.17+17 more2.4.41-4ubuntu3.23+esm5, 2.4.52-1ubuntu4.23, 2.4.58-1ubuntu8.15, 2.4.68-1~deb12u1+1 more43
apache2apk2.4.62-r0, 2.4.63-r4, 2.4.66-r0, 2.4.67-r02.4.68-r04
apachebitnami2.4.65-1, 2.4.68-1, 2.4.68-82.4.683
OSV records
ALPINE-CVE-2026-48913BIT-apache-2026-48913DEBIAN-CVE-2026-48913UBUNTU-CVE-2026-48913
Also known as
USN-8516-1, USN-8571-1

Charts affected

52 by stars
ChartLatestAffected imagesRadar Score
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-48913.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
apache2@2.4.41-4ubuntu3.21
2.4.41-4ubuntu3.23+esm5

Open the chart page →

10,006
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-48913.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
apache2@2.4.57-2
2.4.68-1~deb12u1

Open the chart page →

10,001

Container images carrying it

50 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/phpmyadmin:5.2.16e75aa8f767c
apache2@2.4.62-1~deb12u2
2.4.68-1~deb12u1
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
apache2@2.4.65-2
2.4.68-1~deb13u1
2
vdiogov/glpi-conteiner:latest6945f84f0058
apache2@2.4.61-1~deb12u1
2.4.68-1~deb12u1
2
akaunting/akaunting:3.0.1552811b36ec3a
apache2@2.4.57-2
2.4.68-1~deb12u1
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
apache@2.4.65-1
2.4.68
1
bitnami/wordpress:latest8448af086f92
apache@2.4.68-8
2.4.68
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
apache2@2.4.52-1ubuntu4.21
2.4.52-1ubuntu4.23
1
cloudtooling/moodle:5.2.3f4f04e0fc401
apache@2.4.68-1
2.4.68
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.23+esm5
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
apache2@2.4.65-2
2.4.68-1~deb13u1
1
dolibarr/dolibarr:22.0.47ad88fc9b13c
apache2@2.4.67-1~deb12u2
2.4.68-1~deb12u1
1
domainmod/domainmod:4.23.04017bfe4c597
apache2@2.4.57-2
2.4.68-1~deb12u1
1
dragonflyoss/client:v0.1.82edf3e921f4e0
apache2@2.4.59-1~deb12u1
2.4.68-1~deb12u1
1
espocrm/espocrm:9.3.101b5a24504ed9
apache2@2.4.67-1~deb13u3
2.4.68-1~deb13u1
1
gulacedia/web-dvwa-new:v367b467d961ca
apache2@2.4.57-2
2.4.68-1~deb12u1
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
apache2@2.4.66-1~deb12u1
2.4.68-1~deb12u1
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
apache2@2.4.57-2
2.4.68-1~deb12u1
1
jordan/icinga2:latestf75025fe8ea8
apache2@2.4.67-1~deb12u3
2.4.68-1~deb12u1
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.23+esm5
1
library/matomo:5.1.2-apache2415789e1602
apache2@2.4.62-1~deb12u2
2.4.68-1~deb12u1
1
library/nextcloud:31.0.6-apache588609d76b21
apache2@2.4.62-1~deb12u2
2.4.68-1~deb12u1
1
library/nextcloud:31.0.10-apacheb7faa1653c39
apache2@2.4.65-2
2.4.68-1~deb13u1
1
library/wordpress:6.4.3-apache8ae66efb09a2
apache2@2.4.57-2
2.4.68-1~deb12u1
1
library/wordpress:php8.1-apachef73396626d2f
apache2@2.4.65-2
2.4.68-1~deb13u1
1
linkstackorg/linkstack:latest1c8b05399ee4
apache2@2.4.66-r0
2.4.68-r0
1
linuxserver/bookstack:26.05.202605282ebf97852661
apache2@2.4.67-r0
2.4.68-r0
1
martinhelmich/typo3:12.4c83a4f3fd7ae
apache2@2.4.66-1~deb12u1
2.4.68-1~deb12u1
1
mautic/mautic:7-apacheeb8cc73d97e1
apache2@2.4.67-1~deb12u2
2.4.68-1~deb12u1
1
mediagis/nominatim:3.7c15e941485ef
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.23+esm5
1
mediagis/nominatim:4.2d0eae7b51374
apache2@2.4.52-1ubuntu4.7
2.4.52-1ubuntu4.23
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
apache2@2.4.41-4ubuntu3.14
2.4.41-4ubuntu3.23+esm5
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
apache2@2.4.41-4ubuntu3.14
2.4.41-4ubuntu3.23+esm5
1
owncloud/server:10.15.051d9b74fc2a8
apache2@2.4.41-4ubuntu3.21
2.4.41-4ubuntu3.23+esm5
1
owncloud/server:10.16.274c53d341076
apache2@2.4.52-1ubuntu4.20
2.4.52-1ubuntu4.23
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
apache2@2.4.65-2
2.4.68-1~deb13u1
1
restic/rest-server:0.14.0d2aff06f47eb
apache2@2.4.63-r4
2.4.68-r0
1
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
apache2@2.4.67-1~deb13u3
2.4.68-1~deb13u1
1
snipe/snipe-it:v8.3.1141ebf2386fe
apache2@2.4.58-1ubuntu8.8
2.4.58-1ubuntu8.15
1
snipe/snipe-it:v6.0.1455fb7636a98c
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.23+esm5
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.23+esm5
1
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
apache2@2.4.66-1~deb13u1
2.4.68-1~deb13u1
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
apache2@2.4.57-2
2.4.68-1~deb12u1
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
apache2@2.4.41-4ubuntu3.17
2.4.41-4ubuntu3.23+esm5
1
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
apache2@2.4.65-1~deb12u1
2.4.68-1~deb12u1
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.23+esm5
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
apache2@2.4.62-r0
2.4.68-r0
1
ghcr.io/monicahq/monica-next:main8be69156acbb
apache2@2.4.65-2
2.4.68-1~deb13u1
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
apache2@2.4.67-1~deb13u2
2.4.68-1~deb13u1
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.23+esm5
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
apache2@2.4.67-1~deb12u2
2.4.68-1~deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.