StackRadar

CVE-2026-5119

High

Advisory

Published 30 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
56
of 17,787 indexed, latest versions
Container images
60
deployed by those charts
Fix available
2 of 3
affected packages

Red Hat Security Advisory: libsoup security update

Carried by container images the latest versions of 56 of 17,787 indexed charts deploy, on 60 images.

Affected packageAffected versionsFixed inImages
libsoup2.4deb2.52.2-1ubuntu0.2, 2.52.2-1ubuntu0.3, 2.62.1-1ubuntu0.1, 2.62.1-1ubuntu0.4+8 more2.52.2-1ubuntu0.3+esm6, 2.62.1-1ubuntu0.4+esm7, 2.70.0-1ubuntu0.5+esm2, 2.74.2-3ubuntu0.7+1 more43
libsoup3deb3.0.7-0ubuntu1, 3.2.2-2, 3.4.4-5ubuntu0.5, 3.4.4-5ubuntu0.7+2 moreno fix listed8
libsouprpm2.62.3-2.el8, 2.62.3-3.el8, 2.62.3-4.el8, 2.62.3-5.el8+1 more0:2.62.3-14.el8_10, 0:2.72.0-12.el9_7.611
OSV records
DEBIAN-CVE-2026-5119RHSA-2026:13978RHSA-2026:14087UBUNTU-CVE-2026-5119
Also known as
RHSA-2026:19356, RHSA-2026:22323, RHSA-2026:22710, RHSA-2026:22716, USN-8523-1

Charts affected

56 by stars
ChartLatestAffected imagesRadar Score
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-5119.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2

Open the chart page →

30,759
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-5119.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
libsoup@2.62.3-2.el8
0:2.62.3-14.el8_10

Open the chart page →

28,165
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-5119.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libsoup3@3.4.4-5ubuntu0.5
no fix listed

Open the chart page →

12,524
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-5119.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libsoup3@3.4.4-5ubuntu0.5
no fix listed

Open the chart page →

12,524
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-5119.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2

Open the chart page →

18,828
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-5119.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libsoup2.4@2.74.2-3
libsoup3@3.0.7-0ubuntu1
2.74.2-3ubuntu0.7
no fix listed

Open the chart page →

14,172

Container images carrying it

60 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
libsoup2.4@2.52.2-1ubuntu0.3
2.52.2-1ubuntu0.3+esm6
3
kurento/kurento-media-server:latest03c0d34d0828
libsoup3@3.4.4-5ubuntu0.5
no fix listed
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
libsoup2.4@2.74.3-1+deb12u1
no fix listed
2
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
libsoup2.4@2.74.2-3ubuntu0.5
2.74.2-3ubuntu0.7
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
codetogether/codetogether:latest4348c8a38752
libsoup@2.72.0-8.el9
0:2.72.0-12.el9_7.6
1
countly/countly-server:25.05.4e3c238248f99
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
libsoup2.4@2.70.0-1ubuntu0.5
2.70.0-1ubuntu0.5+esm2
1
gurolakman/oam:4.0.0ed8fd2062548
libsoup@2.62.3-5.el8
0:2.62.3-14.el8_10
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
libsoup@2.62.3-4.el8
0:2.62.3-14.el8_10
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
libsoup@2.62.3-4.el8
0:2.62.3-14.el8_10
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
libsoup@2.62.3-4.el8
0:2.62.3-14.el8_10
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
libsoup@2.62.3-4.el8
0:2.62.3-14.el8_10
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
libsoup@2.62.3-4.el8
0:2.62.3-14.el8_10
1
gurolakman/ussigw-core:1.0.48739565c3ea2
libsoup@2.62.3-4.el8
0:2.62.3-14.el8_10
1
haveagitgat/tdarr:2.00.181256348872ce
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
hazelcast/management-center:5.3.2f9d34300d330
libsoup@2.62.3-3.el8
0:2.62.3-14.el8_10
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
jaedb/iris:latest048cfbf58d57
libsoup2.4@2.74.3-1+deb12u1
libsoup3@3.2.2-2
no fix listed
no fix listed
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
libsoup2.4@2.62.1-1ubuntu0.4
2.62.1-1ubuntu0.4+esm7
1
livekit/ingress:v1.2.21ab01641b366
libsoup2.4@2.74.2-3
2.74.2-3ubuntu0.7
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libsoup2.4@2.62.1-1ubuntu0.1
2.62.1-1ubuntu0.4+esm7
1
openkm/openkm-ce:6.3.113bc465a7461b
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
photoprism/photoprism:220629-jammy2954334adbda
libsoup2.4@2.74.2-3
2.74.2-3ubuntu0.7
1
photoprism/photoprism:260601650c6ad5a651
libsoup3@3.6.6-1
no fix listed
1
photoprism/photoprism:260728958642220223
libsoup3@3.6.6-1
no fix listed
1
photoprism/photoprism:251130db16ee6b1ba3
libsoup3@3.6.5-4
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
libsoup2.4@2.74.3-6ubuntu1
2.74.3-6ubuntu1.7
1
project2team4/react:latest3ff031a08887
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
scrapinghub/splash:3.4.1a5f89bc84606
libsoup2.4@2.62.1-1ubuntu0.4
2.62.1-1ubuntu0.4+esm7
1
seafileltd/seafile-mc:9.0.106693911bcc40
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
seafileltd/seafile-mc:10.0.170628f29c663
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
seafileltd/seafile-mc:9.0.97ac833196f60
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
selenium/node-chrome:4.48.0-202609055ac71fd8dd1e
libsoup3@3.4.4-5ubuntu0.7
no fix listed
1
selenium/node-firefox:4.48.0-2026090574a5c1c90f95
libsoup3@3.4.4-5ubuntu0.7
no fix listed
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
libsoup2.4@2.70.0-1
2.70.0-1ubuntu0.5+esm2
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libsoup2.4@2.52.2-1ubuntu0.2
2.52.2-1ubuntu0.3+esm6
1
trueosiris/vrising:latest9356f98ad561
libsoup2.4@2.74.2-3ubuntu0.6
2.74.2-3ubuntu0.7
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libsoup2.4@2.74.2-3
libsoup3@3.0.7-0ubuntu1
2.74.2-3ubuntu0.7
no fix listed
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
libsoup2.4@2.72.0-2
2.74.3-6ubuntu1.7
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.