StackRadar

CVE-2026-56109

High

Advisory

Published 22 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.0
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
208
of 17,781 indexed, latest versions
Container images
189
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 208 of 17,781 indexed charts deploy, on 189 images.

Affected packageAffected versionsFixed inImages
alsa-libdeb1.0.27.2-3ubuntu7, 1.1.0-0ubuntu1, 1.1.3-5ubuntu0.2, 1.1.3-5ubuntu0.5+15 more1.2.6.1-1ubuntu1.2, 1.2.11-1ubuntu0.3, 1.2.15.3-1ubuntu1.1189
OSV records
DEBIAN-CVE-2026-56109UBUNTU-CVE-2026-56109
Also known as
USN-8538-1

Charts affected

208 by stars
ChartLatestAffected imagesRadar Score
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
alsa-lib@1.2.8-1+b1
no fix listed

Open the chart page →

9,616
openunison-operatortremolo3.0.301 of 1See more

openunison-operator tremolo 3.0.30

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3

Open the chart page →

2,126
orchestratremolo3.1.552 of 5See more

orchestra tremolo 3.1.55

2 of the 5 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3

Open the chart page →

7,637
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3

Open the chart page →

4,305
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed

Open the chart page →

28,605
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed

Open the chart page →

15,230
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2

Open the chart page →

14,100

Container images carrying it

189 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
alsa-lib@1.2.8-1+b1
no fix listed
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
alsa-lib@1.2.8-1+b1
no fix listed
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
alsa-lib@1.2.8-1+b1
no fix listed
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
alsa-lib@1.2.8-1+b1
no fix listed
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
alsa-lib@1.2.11-1build2
1.2.11-1ubuntu0.3
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
alsa-lib@1.2.11-1build2
1.2.11-1ubuntu0.3
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
alsa-lib@1.2.8-1+b1
no fix listed
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
alsa-lib@1.2.8-1+b1
no fix listed
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
alsa-lib@1.1.3-5ubuntu0.6
no fix listed
1
ghcr.io/lloesche/valheim-server:latest20fde516ce31
alsa-lib@1.2.14-1
no fix listed
1
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
alsa-lib@1.2.14-1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
alsa-lib@1.2.14-1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
alsa-lib@1.2.14-1
no fix listed
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
alsa-lib@1.2.8-1+b1
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
alsa-lib@1.2.8-1+b1
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
alsa-lib@1.2.14-1
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
alsa-lib@1.2.8-1+b1
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
alsa-lib@1.2.8-1+b1
no fix listed
1
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
ghcr.io/steadybit/agent:2.4.52bc7b260e44e
alsa-lib@1.2.14-1
no fix listed
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
alsa-lib@1.2.8-1+b1
no fix listed
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
alsa-lib@1.2.8-1+b1
no fix listed
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
alsa-lib@1.2.8-1+b1
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
alsa-lib@1.1.0-0ubuntu1
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.