StackRadar

CVE-2026-56109

High

Advisory

Published 22 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.0
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
208
of 17,781 indexed, latest versions
Container images
189
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 208 of 17,781 indexed charts deploy, on 189 images.

Affected packageAffected versionsFixed inImages
alsa-libdeb1.0.27.2-3ubuntu7, 1.1.0-0ubuntu1, 1.1.3-5ubuntu0.2, 1.1.3-5ubuntu0.5+15 more1.2.6.1-1ubuntu1.2, 1.2.11-1ubuntu0.3, 1.2.15.3-1ubuntu1.1189
OSV records
DEBIAN-CVE-2026-56109UBUNTU-CVE-2026-56109
Also known as
USN-8538-1

Charts affected

208 by stars
ChartLatestAffected imagesRadar Score
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
alsa-lib@1.2.8-1+b1
no fix listed

Open the chart page →

9,616
openunison-operatortremolo3.0.301 of 1See more

openunison-operator tremolo 3.0.30

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3

Open the chart page →

2,126
orchestratremolo3.1.552 of 5See more

orchestra tremolo 3.1.55

2 of the 5 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3

Open the chart page →

7,637
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3

Open the chart page →

4,305
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed

Open the chart page →

28,605
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed

Open the chart page →

15,230
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-56109.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2

Open the chart page →

14,100

Container images carrying it

189 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
flaresolverr/flaresolverr:latest:v3.5.0139dfee1c6f8
alsa-lib@1.2.8-1+b1
no fix listed
5
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
alsa-lib@1.1.0-0ubuntu1
no fix listed
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
alsa-lib@1.1.0-0ubuntu1
no fix listed
4
ciscolabs/rtsp-client:latesta7b60ec88285
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
3
ciscolabs/rtsp-server:latestb59fc10bb821
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
3
jacobalberty/unifi:v10.0.162896c0ab82d33
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
alsa-lib@1.1.0-0ubuntu1
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
alsa-lib@1.2.8-1+b1
no fix listed
3
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
alsa-lib@1.2.8-1+b1
no fix listed
2
gotenberg/gotenberg:8.36.087c16b9f3642
alsa-lib@1.2.14-1
no fix listed
2
gotenberg/gotenberg:8:8.37.0f29984bd1e22
alsa-lib@1.2.14-1
no fix listed
2
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
alsa-lib@1.2.14-1
no fix listed
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
alsa-lib@1.2.14-1
no fix listed
2
hookiesolutions/webhookie:latest0629694246ba
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
2
kurento/kurento-media-server:latest03c0d34d0828
alsa-lib@1.2.11-1ubuntu0.1
1.2.11-1ubuntu0.3
2
louislam/uptime-kuma:2.5.4917318f9d7be
alsa-lib@1.2.8-1+b1
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
alsa-lib@1.2.8-1+b1
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
alsa-lib@1.2.8-1+b1
no fix listed
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
alsa-lib@1.2.8-1+b1
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
alsa-lib@1.2.11-1build2
1.2.11-1ubuntu0.3
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
alsa-lib@1.2.8-1+b1
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
alsa-lib@1.2.8-1+b1
no fix listed
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
alsa-lib@1.2.8-1+b1
no fix listed
2
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
alsa-lib@1.2.11-1ubuntu0.2
1.2.11-1ubuntu0.3
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
alsa-lib@1.2.8-1+b1
no fix listed
2
1dev/server:11.9.0cd5b12fe5471
alsa-lib@1.2.11-1build2
1.2.11-1ubuntu0.3
1
5200710/hadoop:3.2.3-java8092d3088a5fb
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
anguda/ant-media:2.5c435285fc241
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
apachepulsar/pulsar:3.0.79c9947de139d
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
apachepulsar/pulsar:2.9.0d056c89b7131
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
apachepulsar/pulsar:2.8.2d538416d5afe
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
apache/tika:2.9.0.092d055a84e9e
alsa-lib@1.2.6.1-1ubuntu1
1.2.6.1-1ubuntu1.2
1
archivebox/archivebox:0.7.41a5a37331091
alsa-lib@1.2.8-1+b1
no fix listed
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
alsa-lib@1.2.2-2.1ubuntu2.5
no fix listed
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
alsa-lib@1.2.8-1+b1
no fix listed
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
alsa-lib@1.2.8-1+b1
no fix listed
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
alsa-lib@1.2.2-2.1ubuntu2.4
no fix listed
1
budibase/database:2.1.0d90f656261c9
alsa-lib@1.2.8-1+b1
no fix listed
1
castopod/castopod:1.12.101fd37280cbb2
alsa-lib@1.2.8-1+b1
no fix listed
1
castopod/castopod:1.15.54e4f0440520f
alsa-lib@1.2.14-1
no fix listed
1
cheyang/distributed-tf:1.6.046cc34755493
alsa-lib@1.1.0-0ubuntu1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.