StackRadar

CVE-2026-56109

High

Advisory

Published 22 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.0
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
208
of 17,781 indexed, latest versions
Container images
189
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 208 of 17,781 indexed charts deploy, on 189 images.

Affected packageAffected versionsFixed inImages
alsa-libdeb1.0.27.2-3ubuntu7, 1.1.0-0ubuntu1, 1.1.3-5ubuntu0.2, 1.1.3-5ubuntu0.5+15 more1.2.6.1-1ubuntu1.2, 1.2.11-1ubuntu0.3, 1.2.15.3-1ubuntu1.1189
OSV records
DEBIAN-CVE-2026-56109UBUNTU-CVE-2026-56109
Also known as
USN-8538-1

Charts affected

208 by stars
ChartLatestAffected imagesRadar Score
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
alsa-lib@1.2.8-1+b1
no fix listed

Open the chart page →

9,616
openunison-operatortremolo3.0.301 of 1See more

openunison-operator tremolo 3.0.30

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3

Open the chart page →

2,126
orchestratremolo3.1.552 of 5See more

orchestra tremolo 3.1.55

2 of the 5 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3

Open the chart page →

7,637
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3

Open the chart page →

4,305
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed

Open the chart page →

28,605
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed

Open the chart page →

15,230
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2

Open the chart page →

14,100

Container images carrying it

189 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
photoprism/photoprism:260601650c6ad5a651
alsa-lib@1.2.15.3-1ubuntu1
1.2.15.3-1ubuntu1.1
1
photoprism/photoprism:251130db16ee6b1ba3
alsa-lib@1.2.14-1ubuntu1
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
alsa-lib@1.2.11-1build2
1.2.11-1ubuntu0.3
1
project2team4/react:latest3ff031a08887
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
resurfaceio/resurface:3.7.84d5cda2f64109
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
scrapinghub/splash:3.4.1a5f89bc84606
alsa-lib@1.1.3-5ubuntu0.2
no fix listed
1
seafileltd/seafile-mc:9.0.106693911bcc40
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
seafileltd/seafile-mc:10.0.170628f29c663
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
seafileltd/seafile-mc:9.0.97ac833196f60
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed
1
sismics/docs:v1.10f4b0ef019cf1
alsa-lib@1.1.3-5ubuntu0.5
no fix listed
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
alsa-lib@1.2.8-1+b1
no fix listed
1
snipe/snipe-it:v6.0.1455fb7636a98c
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
speckle/speckle-preview-service:2.26.3092384dba45d
alsa-lib@1.2.8-1+b1
no fix listed
1
speckle/speckle-preview-service:2.20.2-branch.testing4.134160-9fad4b21f897ca906ea
alsa-lib@1.2.8-1+b1
no fix listed
1
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
alsa-lib@1.2.8-1+b1
no fix listed
1
speckle/speckle-preview-service:2.23.14-branch.testing6.334655-b4e04ee6dee853ba74a
alsa-lib@1.2.8-1+b1
no fix listed
1
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
alsa-lib@1.2.8-1+b1
no fix listed
1
speckle/speckle-preview-service:2.17.14-branch.testing.72707.921a5f884fc39bca0c8
alsa-lib@1.2.8-1+b1
no fix listed
1
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
alsa-lib@1.2.8-1+b1
no fix listed
1
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
alsa-lib@1.2.8-1+b1
no fix listed
1
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
alsa-lib@1.2.8-1+b1
no fix listed
1
stashapp/stash:latest24dbd7607174
alsa-lib@1.2.2-2.1ubuntu2.3
no fix listed
1
statcan/ckan:2.93921305425b8
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
swimmwatch/cloakbrowser-mcp:1.13.0d48c705a58c8
alsa-lib@1.2.8-1+b1
no fix listed
1
sysnet4admin/colosseum-agg:logbc25b152d88e
alsa-lib@1.2.6.1-1ubuntu1.1
1.2.6.1-1ubuntu1.2
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
alsa-lib@1.1.0-0ubuntu1
no fix listed
1
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
alsa-lib@1.2.14-1
no fix listed
1
thingsboard/tb-postgres:latest2d17e4e36edc
alsa-lib@1.2.8-1+b1
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
alsa-lib@1.1.0-0ubuntu1
no fix listed
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
alsa-lib@1.2.14-1
no fix listed
1
trueosiris/vrising:latest9356f98ad561
alsa-lib@1.2.6.1-1ubuntu1.1
1.2.6.1-1ubuntu1.2
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
alsa-lib@1.1.3-5ubuntu0.6
no fix listed
1
voltha/voltha-onos:5.1.8e038acb950d3
alsa-lib@1.1.3-5ubuntu0.5
no fix listed
1
wavefronthq/proxy:9.2d1064d28f6eb
alsa-lib@1.1.3-5ubuntu0.5
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
alsa-lib@1.2.4-1.1
1.2.11-1ubuntu0.3
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
alsa-lib@1.2.14-1
no fix listed
1
ghcr.io/argonix-io/argonix-api:1.0.068e17a8aaa40
alsa-lib@1.2.14-1+deb13u1
no fix listed
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
alsa-lib@1.2.8-1+b1
no fix listed
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
alsa-lib@1.2.8-1+b1
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
alsa-lib@1.2.8-1+b1
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
alsa-lib@1.2.8-1+b1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.