StackRadar

CVE-2026-50142

High

Advisory

Published 2 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
152
of 17,781 indexed, latest versions
Container images
162
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 152 of 17,781 indexed charts deploy, on 162 images.

Affected packageAffected versionsFixed inImages
libheifdeb1.15.1-1, 1.15.1-1+deb12u1, 1.20.2-11.20.2-1ubuntu0.6156
libheifapk1.21.2-r01.23.0-r06
OSV records
ALPINE-CVE-2026-50142DEBIAN-CVE-2026-50142UBUNTU-CVE-2026-50142
Also known as
USN-8526-1

Charts affected

152 by stars
ChartLatestAffected imagesRadar Score
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-50142.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
libheif@1.15.1-1+deb12u1
no fix listed

Open the chart page →

9,117
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-50142.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libheif@1.15.1-1
no fix listed

Open the chart page →

7,673

Container images carrying it

162 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
libheif@1.15.1-1+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
libheif@1.15.1-1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
libheif@1.15.1-1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
libheif@1.15.1-1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
libheif@1.15.1-1
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
libheif@1.15.1-1
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
libheif@1.15.1-1+deb12u1
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
libheif@1.15.1-1
no fix listed
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
libheif@1.15.1-1+deb12u1
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libheif@1.15.1-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
libheif@1.15.1-1+deb12u1
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
libheif@1.15.1-1+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.