StackRadar

CVE-2026-56109

High

Advisory

Published 22 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.0
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
208
of 17,781 indexed, latest versions
Container images
189
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 208 of 17,781 indexed charts deploy, on 189 images.

Affected packageAffected versionsFixed inImages
alsa-libdeb1.0.27.2-3ubuntu7, 1.1.0-0ubuntu1, 1.1.3-5ubuntu0.2, 1.1.3-5ubuntu0.5+15 more1.2.6.1-1ubuntu1.2, 1.2.11-1ubuntu0.3, 1.2.15.3-1ubuntu1.1189
OSV records
DEBIAN-CVE-2026-56109UBUNTU-CVE-2026-56109
Also known as
USN-8538-1

Charts affected

208 by stars
ChartLatestAffected imagesRadar Score
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
alsa-lib@1.2.8-1+b1
no fix listed

Open the chart page →

9,616
openunison-operatortremolo3.0.301 of 1See more

openunison-operator tremolo 3.0.30

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3

Open the chart page →

2,126
orchestratremolo3.1.552 of 5See more

orchestra tremolo 3.1.55

2 of the 5 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3

Open the chart page →

7,637
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3

Open the chart page →

4,305
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed

Open the chart page →

28,605
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed

Open the chart page →

15,230
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2

Open the chart page →

14,100

Container images carrying it

189 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
chocobozzz/peertube:v8.1.5052712130691
alsa-lib@1.2.14-1
no fix listed
1
codedesignplus/ms-emails-grpc:lateste336012bc781
alsa-lib@1.2.8-1+b1
no fix listed
1
codedesignplus/ms-emails-rest:latestac84661c605e
alsa-lib@1.2.8-1+b1
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
alsa-lib@1.2.14-1
no fix listed
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
alsa-lib@1.1.3-5ubuntu0.5
no fix listed
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
alsa-lib@1.1.3-5ubuntu0.5
no fix listed
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
gotenberg/gotenberg:8.30206a6c708fc6
alsa-lib@1.2.14-1
no fix listed
1
gotenberg/gotenberg:8.3467097317623a
alsa-lib@1.2.14-1
no fix listed
1
gotenberg/gotenberg:8-chromiuma40f92d7419a
alsa-lib@1.2.14-1
no fix listed
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
alsa-lib@1.1.0-0ubuntu1
no fix listed
1
instill/artifact-backend:b28766ac4a393e601ed
alsa-lib@1.2.14-1
no fix listed
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
ispras/svacer:11-2-042aa9fa9f189
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
alsa-lib@1.1.3-5ubuntu0.6
no fix listed
1
jaedb/iris:latest048cfbf58d57
alsa-lib@1.2.8-1+b1
no fix listed
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
alsa-lib@1.2.2-2.1ubuntu2.3
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
alsa-lib@1.2.8-1+b1
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
alsa-lib@1.2.8-1+b1
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
alsa-lib@1.2.11-1ubuntu0.1
1.2.11-1ubuntu0.3
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
alsa-lib@1.1.3-5ubuntu0.5
no fix listed
1
linuxserver/unifi-controller:8.0.240ae315a3a456
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
linuxserver/unifi-controller:7.3.83ab105cc50322
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
livekit/ingress:v1.2.21ab01641b366
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
longhornio/longhorn-manager:v1.2.3dca34321452c
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
louislam/uptime-kuma:2.5.33e24e96c89ef
alsa-lib@1.2.8-1+b1
no fix listed
1
louislam/uptime-kuma:2.0.24c364ef96aad
alsa-lib@1.2.8-1+b1
no fix listed
1
louislam/uptime-kuma:2.4.091e963bfda56
alsa-lib@1.2.8-1+b1
no fix listed
1
machines/filestash:latest0b8fc005e52e
alsa-lib@1.2.14-1
no fix listed
1
mbround18/valheim:3.1.070bd4da591cd
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
merlos/zookeeper:3.9.3a38fc7e09ed7
alsa-lib@1.2.8-1+b1
no fix listed
1
mlikiowa/napcat-docker:latest1336a777f9a4
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
alsa-lib@1.2.14-1
no fix listed
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
alsa-lib@1.1.3-5ubuntu0.2
no fix listed
1
oneuptime/probe:release6b2d98713711
alsa-lib@1.2.8-1+b1
no fix listed
1
onosproject/onos:2.2.144914a8d4b3f
alsa-lib@1.1.3-5ubuntu0.2
no fix listed
1
onyxdotapp/onyx-backend:latest473fdffe4e67
alsa-lib@1.2.14-1
no fix listed
1
opea/speecht5:1.0249afad3d268
alsa-lib@1.2.8-1+b1
no fix listed
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
alsa-lib@1.2.8-1+b1
no fix listed
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
alsa-lib@1.2.14-1
no fix listed
1
openhab/openhab:5.2.1bfd4a60e90da
alsa-lib@1.2.14-1
no fix listed
1
openkm/openkm-ce:6.3.113bc465a7461b
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
opsmx11/issuegen:v2.1.05c50ca123d88
alsa-lib@1.0.27.2-3ubuntu7
no fix listed
1
payara/server-full:7.2026.2-jdk2531f1253f0cf8
alsa-lib@1.2.6.1-1ubuntu1.1
1.2.6.1-1ubuntu1.2
1
penpotapp/exporter:2.2.15c835ffd87ab
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
photoprism/photoprism:220629-jammy2954334adbda
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.