StackRadar

CVE-2026-55199

High

Advisory

Published 17 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
128
of 17,781 indexed, latest versions
Container images
112
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 128 of 17,781 indexed charts deploy, on 112 images.

Affected packageAffected versionsFixed inImages
libssh2deb1.11.0-4.1build2, 1.11.1-1, 1.11.1-1+e1, 1.11.1-1build1+2 more1.11.0-4.1ubuntu0.24.04.2, 1.11.1-1+deb13u1, 1.11.1-1+e4, 1.11.1-1ubuntu0.25.10.2+1 more103
libssh2apk1.11.1-r0, 1.11.1-r11.11.1-r2, 1.11.1-r39
OSV records
ALPINE-CVE-2026-55199DEBIAN-CVE-2026-55199UBUNTU-CVE-2026-55199ECHO-3e02-3a01-4ae3
Also known as
USN-8486-1

Charts affected

128 by stars
ChartLatestAffected imagesRadar Score
vaultwardenmt1905027.3.41 of 3See more

vaultwarden mt190502 7.3.4

1 of the 3 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
vaultwarden/server:1.35.443498a94b22f
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

4,710
core-keeper-dedicatednerkho-helm-charts0.1.11 of 1See more

core-keeper-dedicated nerkho-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
escaping/core-keeper-dedicated:latest87fa79255962
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

3,891
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

3,843
f5-waf-policy-controllernginxVerified publisher5.15.01 of 4See more

f5-waf-policy-controller nginx 5.15.0

1 of the 4 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
curlimages/curl:8.20.0b3f1fb2a51d9
libssh2@1.11.1-r1
1.11.1-r3

Open the chart page →

418
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
libssh2@1.11.1-r0
1.11.1-r2

Open the chart page →

4,749
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

3,854
vaultwardenpascaliskeVerified publisher2.0.01 of 1See more

vaultwarden pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

3,408
k8s-oidc-discovery-providerpnnl-miscscripts0.1.22 of 2See more

k8s-oidc-discovery-provider pnnl-miscscripts 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
curlimages/curl:8.17.0935d9100e9ba
libssh2@1.11.1-r0
1.11.1-r2
library/nginx:1.29.49dd288848f44
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

4,260
management-portalradar-baseVerified publisher1.7.01 of 1See more

management-portal radar-base 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
libssh2@1.11.1-1build2
1.11.1-1ubuntu0.26.04.2

Open the chart page →

3,182
radar-hydraradar-baseVerified publisher0.3.41 of 2See more

radar-hydra radar-base 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
curlimages/curl:8.15.04026b29997dc
libssh2@1.11.1-r0
1.11.1-r2

Open the chart page →

2,177
vsl-rpcrss30.3.41 of 4See more

vsl-rpc rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
quay.io/curl/curl:8.16.0b17b13321678
libssh2@1.11.1-r0
1.11.1-r2

Open the chart page →

4,610
vsl-sequencerrss30.3.41 of 4See more

vsl-sequencer rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
quay.io/curl/curl:8.16.0b17b13321678
libssh2@1.11.1-r0
1.11.1-r2

Open the chart page →

4,610
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

10,605
jellyfinrubxkubeVerified publisher1.3.11 of 1See more

jellyfin rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

2,604
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

9,534
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

9,755
factorioschichtelVerified publisher0.1.11 of 1See more

factorio schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
factoriotools/factorio:2.0.67-rootlessf7909f7361d6
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

2,971
s3-backupschichtelVerified publisher0.10.01 of 1See more

s3-backup schichtel 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

2,343
wordpressschichtelVerified publisher0.10.102 of 2See more

wordpress schichtel 0.10.10

2 of the 2 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
library/wordpress:6.9.4-fpmad4a8bae2eb4
libssh2@1.11.1-1
1.11.1-1+deb13u1
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

8,184
jellyfinschoolguys-helmcharts0.4.21 of 1See more

jellyfin schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.81694ff069f0c
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

3,001
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
libssh2@1.11.1-1ubuntu0.26.04.1
1.11.1-1ubuntu0.26.04.2

Open the chart page →

10,348
ctlogsigstoreVerified publisher0.2.681 of 4See more

ctlog sigstore 0.2.68

1 of the 4 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
curlimages/curl:8.17.0935d9100e9ba
libssh2@1.11.1-r0
1.11.1-r2

Open the chart page →

2,728
slothsloth0.16.01 of 2See more

sloth sloth 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

3,962
bootzookasoftwaremillVerified publisher0.2.11 of 2See more

bootzooka softwaremill 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
softwaremill/bootzooka:latest845b5e8f8056
libssh2@1.11.1-1build2
1.11.1-1ubuntu0.26.04.2

Open the chart page →

3,003
squadsquadVerified publisher0.1.111 of 1See more

squad squad 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
cm2network/squad:latest8cba47f53df5
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

2,487
jellyfinsudo-kraken-jellyfinVerified publisher2.1.31 of 1See more

jellyfin sudo-kraken-jellyfin 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.6333b64771663
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

3,389
app-startersynkubeVerified publisher1.4.11 of 1See more

app-starter synkube 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

3,240
wallarm-gatewaywallarmVerified publisher0.4.01 of 1See more

wallarm-gateway wallarm 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-55199.

Container imageDigestPackageFixed in
wallarm/gateway-controller:0.4.09c6ed23e2f0e
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

2,018

Container images carrying it

112 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
libssh2@1.11.1-1build2
1.11.1-1ubuntu0.26.04.2
1
ghcr.io/reitermarkus/7d2d:main39953b387b61
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
libssh2@1.11.1-1+e1
1.11.1-1+e4
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
libssh2@1.11.1-1
1.11.1-1+deb13u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.