StackRadar

CVE-2026-55200

High

Advisory

Published 17 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.3
base score, highest
EPSS
0.040
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
121
of 17,781 indexed, latest versions
Container images
105
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 121 of 17,781 indexed charts deploy, on 105 images.

Affected packageAffected versionsFixed inImages
libssh2deb1.11.1-1, 1.11.1-1+e1, 1.11.1-1build1, 1.11.1-1build2+1 more1.11.1-1+deb13u1, 1.11.1-1+e4, 1.11.1-1ubuntu0.25.10.2, 1.11.1-1ubuntu0.26.04.296
libssh2apk1.11.1-r0, 1.11.1-r11.11.1-r2, 1.11.1-r39
OSV records
ALPINE-CVE-2026-55200DEBIAN-CVE-2026-55200UBUNTU-CVE-2026-55200ECHO-81b6-9726-71c6
Also known as
USN-8486-1

Charts affected

121 by stars
ChartLatestAffected imagesRadar Score
k8s-oidc-discovery-providerpnnl-miscscripts0.1.22 of 2See more

k8s-oidc-discovery-provider pnnl-miscscripts 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
curlimages/curl:8.17.0935d9100e9ba
libssh2@1.11.1-r0
1.11.1-r2
library/nginx:1.29.49dd288848f44
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

4,260
management-portalradar-baseVerified publisher1.7.01 of 1See more

management-portal radar-base 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
libssh2@1.11.1-1build2
1.11.1-1ubuntu0.26.04.2

Open the chart page →

3,182
radar-hydraradar-baseVerified publisher0.3.41 of 2See more

radar-hydra radar-base 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
curlimages/curl:8.15.04026b29997dc
libssh2@1.11.1-r0
1.11.1-r2

Open the chart page →

2,177
vsl-rpcrss30.3.41 of 4See more

vsl-rpc rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
quay.io/curl/curl:8.16.0b17b13321678
libssh2@1.11.1-r0
1.11.1-r2

Open the chart page →

4,610
vsl-sequencerrss30.3.41 of 4See more

vsl-sequencer rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
quay.io/curl/curl:8.16.0b17b13321678
libssh2@1.11.1-r0
1.11.1-r2

Open the chart page →

4,610
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

10,605
jellyfinrubxkubeVerified publisher1.3.11 of 1See more

jellyfin rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

2,604
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

9,534
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

9,755
factorioschichtelVerified publisher0.1.11 of 1See more

factorio schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
factoriotools/factorio:2.0.67-rootlessf7909f7361d6
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

2,971
s3-backupschichtelVerified publisher0.10.01 of 1See more

s3-backup schichtel 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

2,343
wordpressschichtelVerified publisher0.10.102 of 2See more

wordpress schichtel 0.10.10

2 of the 2 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
library/wordpress:6.9.4-fpmad4a8bae2eb4
libssh2@1.11.1-1
1.11.1-1+deb13u1
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

8,184
jellyfinschoolguys-helmcharts0.4.21 of 1See more

jellyfin schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.81694ff069f0c
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

3,001
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
libssh2@1.11.1-1ubuntu0.26.04.1
1.11.1-1ubuntu0.26.04.2

Open the chart page →

10,348
ctlogsigstoreVerified publisher0.2.681 of 4See more

ctlog sigstore 0.2.68

1 of the 4 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
curlimages/curl:8.17.0935d9100e9ba
libssh2@1.11.1-r0
1.11.1-r2

Open the chart page →

2,728
slothsloth0.16.01 of 2See more

sloth sloth 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

3,962
bootzookasoftwaremillVerified publisher0.2.11 of 2See more

bootzooka softwaremill 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
softwaremill/bootzooka:latest845b5e8f8056
libssh2@1.11.1-1build2
1.11.1-1ubuntu0.26.04.2

Open the chart page →

3,003
squadsquadVerified publisher0.1.111 of 1See more

squad squad 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
cm2network/squad:latest8cba47f53df5
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

2,487
jellyfinsudo-kraken-jellyfinVerified publisher2.1.31 of 1See more

jellyfin sudo-kraken-jellyfin 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.6333b64771663
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

3,389
app-startersynkubeVerified publisher1.4.11 of 1See more

app-starter synkube 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

3,240
wallarm-gatewaywallarmVerified publisher0.4.01 of 1See more

wallarm-gateway wallarm 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-55200.

Container imageDigestPackageFixed in
wallarm/gateway-controller:0.4.09c6ed23e2f0e
libssh2@1.11.1-1
1.11.1-1+deb13u1

Open the chart page →

2,018

Container images carrying it

105 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
jellyfin/jellyfin:10.11:10.11.11:latestaefb67e6a7ff
libssh2@1.11.1-1
1.11.1-1+deb13u1
7
curlimages/curl:8.17.0935d9100e9ba
libssh2@1.11.1-r0
1.11.1-r2
6
curlimages/curl:8.18.0d94d07ba9e7d
libssh2@1.11.1-r1
1.11.1-r3
3
curlimages/curl:8.15.04026b29997dc
libssh2@1.11.1-r0
1.11.1-r2
2
curlimages/curl:8.20.0b3f1fb2a51d9
libssh2@1.11.1-r1
1.11.1-r3
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
libssh2@1.11.1-1
1.11.1-1+deb13u1
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
libssh2@1.11.1-1
1.11.1-1+deb13u1
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
libssh2@1.11.1-1
1.11.1-1+deb13u1
2
library/nginx:latest6e23479198b9
libssh2@1.11.1-1
1.11.1-1+deb13u1
2
library/nginx:1.29.49dd288848f44
libssh2@1.11.1-1
1.11.1-1+deb13u1
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
libssh2@1.11.1-1
1.11.1-1+deb13u1
2
quay.io/curl/curl:8.16.0b17b13321678
libssh2@1.11.1-r0
1.11.1-r2
2
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
boky/postfix:5.1.0aafc77238423
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
castopod/castopod:1.15.54e4f0440520f
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
chocobozzz/peertube:v8.1.5052712130691
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
cm2network/squad:latest8cba47f53df5
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
curlimages/curl:8.12.194e9e444bcba
libssh2@1.11.1-r0
1.11.1-r2
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
emqx/emqx:5.8.935b46f7aa7a0
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
escaping/core-keeper-dedicated:latest87fa79255962
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
esphome/esphome:2026.7.44866347cb5b4
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
esphome/esphome:2026.8.285abea33854b
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
espocrm/espocrm:9.3.101b5a24504ed9
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
factoriotools/factorio:2.0.67-rootlessf7909f7361d6
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
fireflyiii/core:version-6.6.6ae69fdd95cde
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
gotenberg/gotenberg:8.30206a6c708fc6
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
gotenberg/gotenberg:8.3467097317623a
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
helmforge/fastmcp-server:0.2.061f759a1421f
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
helmforge/fastmcp-server:0.11.2fcb7017327d6
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
hiboxsystems/marge-bot:0.16.0b59f01bc0418
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
instill/artifact-backend:b28766ac4a393e601ed
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
instill/model-backend:611f0f2e980125e5ba5
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
ixsystems/truecommand:3.2.019c218455cd2
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
jellyfin/jellyfin:10.11.81694ff069f0c
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
jellyfin/jellyfin:10.11.717285f9cce63
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
jellyfin/jellyfin:10.11.6333b64771663
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
library/nextcloud:31.0.10-apacheb7faa1653c39
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
library/nginx:1.291881968aff6f
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
library/python:3.9da5aee29682d
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
library/redmine:6.1.204ac44a2595b
libssh2@1.11.1-1
1.11.1-1+deb13u1
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
libssh2@1.11.1-1
1.11.1-1+deb13u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.