StackRadar

CVE-2026-5119

High

Advisory

Published 30 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
56
of 17,787 indexed, latest versions
Container images
60
deployed by those charts
Fix available
2 of 3
affected packages

Red Hat Security Advisory: libsoup security update

Carried by container images the latest versions of 56 of 17,787 indexed charts deploy, on 60 images.

Affected packageAffected versionsFixed inImages
libsoup2.4deb2.52.2-1ubuntu0.2, 2.52.2-1ubuntu0.3, 2.62.1-1ubuntu0.1, 2.62.1-1ubuntu0.4+8 more2.52.2-1ubuntu0.3+esm6, 2.62.1-1ubuntu0.4+esm7, 2.70.0-1ubuntu0.5+esm2, 2.74.2-3ubuntu0.7+1 more43
libsoup3deb3.0.7-0ubuntu1, 3.2.2-2, 3.4.4-5ubuntu0.5, 3.4.4-5ubuntu0.7+2 moreno fix listed8
libsouprpm2.62.3-2.el8, 2.62.3-3.el8, 2.62.3-4.el8, 2.62.3-5.el8+1 more0:2.62.3-14.el8_10, 0:2.72.0-12.el9_7.611
OSV records
DEBIAN-CVE-2026-5119RHSA-2026:13978RHSA-2026:14087UBUNTU-CVE-2026-5119
Also known as
RHSA-2026:19356, RHSA-2026:22323, RHSA-2026:22710, RHSA-2026:22716, USN-8523-1

Charts affected

56 by stars
ChartLatestAffected imagesRadar Score
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-5119.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2

Open the chart page →

30,759
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-5119.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
libsoup@2.62.3-2.el8
0:2.62.3-14.el8_10

Open the chart page →

28,165
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-5119.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libsoup3@3.4.4-5ubuntu0.5
no fix listed

Open the chart page →

12,524
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-5119.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libsoup3@3.4.4-5ubuntu0.5
no fix listed

Open the chart page →

12,524
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-5119.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2

Open the chart page →

18,828
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-5119.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libsoup2.4@2.74.2-3
libsoup3@3.0.7-0ubuntu1
2.74.2-3ubuntu0.7
no fix listed

Open the chart page →

14,172

Container images carrying it

60 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
libsoup@2.62.3-2.el8
0:2.62.3-14.el8_10
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
libsoup@2.62.3-2.el8
0:2.62.3-14.el8_10
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.