CVE-2026-5119
HighAdvisory
Published 30 Mar 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.2
- base score, highest
- EPSS
- 0.003
- 17th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 56
- of 17,787 indexed, latest versions
- Container images
- 60
- deployed by those charts
- Fix available
- 2 of 3
- affected packages
Red Hat Security Advisory: libsoup security update
Carried by container images the latest versions of 56 of 17,787 indexed charts deploy, on 60 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| libsoup2.4deb | 2.52.2-1ubuntu0.2, 2.52.2-1ubuntu0.3, 2.62.1-1ubuntu0.1, 2.62.1-1ubuntu0.4+8 more | 2.52.2-1ubuntu0.3+esm6, 2.62.1-1ubuntu0.4+esm7, 2.70.0-1ubuntu0.5+esm2, 2.74.2-3ubuntu0.7+1 more | 43 |
| libsoup3deb | 3.0.7-0ubuntu1, 3.2.2-2, 3.4.4-5ubuntu0.5, 3.4.4-5ubuntu0.7+2 more | no fix listed | 8 |
| libsouprpm | 2.62.3-2.el8, 2.62.3-3.el8, 2.62.3-4.el8, 2.62.3-5.el8+1 more | 0:2.62.3-14.el8_10, 0:2.72.0-12.el9_7.6 | 11 |
- OSV records
- DEBIAN-CVE-2026-5119RHSA-2026:13978RHSA-2026:14087UBUNTU-CVE-2026-5119
- Also known as
- RHSA-2026:19356, RHSA-2026:22323, RHSA-2026:22710, RHSA-2026:22716, USN-8523-1
Charts affected
56 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| testing-multitoolsomeblackmagic | 0.1.2 | 1 of 1See more | 30,759 |
| allurestakaterVerified publisher | 1.0.1 | 1 of 1See more | 28,165 |
| kurento_webrtc_demostunner | 0.1.0 | 1 of 2See more | 12,524 |
| stunner-kurento-one2one-callstunner | 0.1.0 | 1 of 2See more | 12,524 |
| rundecksvtech-public-helm-charts | 1.0.0 | 1 of 2See more | 18,828 |
| playwright-synthetic-monitoringwork-adventure | 1.0.1 | 1 of 1See more | 14,172 |
Container images carrying it
60 by charts deploying them
A fixed version is listed for 2 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 6fde1edc0983 | libsoup2.4 | 2.70.0-1ubuntu0.5+esm2 | 1 |
| ghcr.io/ | 3fbe4c29d14c | libsoup2.4 | 2.70.0-1ubuntu0.5+esm2 | 1 |
| ghcr.io/ | 6047599cd78e | libsoup2.4 | 2.70.0-1ubuntu0.5+esm2 | 1 |
| ghcr.io/ | ff2af53897e7 | libsoup2.4 | 2.70.0-1ubuntu0.5+esm2 | 1 |
| ghcr.io/ | 3c8375dc5487 | libsoup2.4 | 2.70.0-1ubuntu0.5+esm2 | 1 |
| ghcr.io/ | 5ecb16015aa8 | libsoup2.4 | 2.70.0-1ubuntu0.5+esm2 | 1 |
| ghcr.io/ | 1dcca70c6446 | libsoup2.4 | 2.70.0-1ubuntu0.5+esm2 | 1 |
| public.ecr.aws/ | 573779e57fae | libsoup2.4 | 2.70.0-1ubuntu0.5+esm2 | 1 |
| quay.io/ | a3b9a07648b6 | libsoup | 0:2.62.3-14.el8_10 | 1 |
| quay.io/ | 6ba82beff18e | libsoup | 0:2.62.3-14.el8_10 | 1 |