StackRadar

CVE-2026-56208

High

Advisory

Published 19 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.6
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
254
of 17,781 indexed, latest versions
Container images
262
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 254 of 17,781 indexed charts deploy, on 262 images.

Affected packageAffected versionsFixed inImages
aomdeb1.0.0.errata1-3+deb11u1build0.20.04.1, 1.0.0.errata1-3build1, 3.1.0-0ubuntu1~20.04.sav0, 3.3.0-1+8 more3.6.0-1+deb12u3, 3.12.1-1+deb13u1262
OSV records
DEBIAN-CVE-2026-56208UBUNTU-CVE-2026-56208

Charts affected

254 by stars
ChartLatestAffected imagesRadar Score
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-56208.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
aom@3.6.0-1+deb12u2
3.6.0-1+deb12u3

Open the chart page →

9,117
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-56208.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
aom@3.3.0-1
no fix listed

Open the chart page →

14,100
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-56208.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
aom@3.6.0-1
3.6.0-1+deb12u3

Open the chart page →

7,673
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-56208.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
aom@3.3.0-1ubuntu0.1
no fix listed

Open the chart page →

7,849

Container images carrying it

262 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
aom@1.0.0.errata1-3build1
no fix listed
1
budibase/proxy:3.41.38d780b6ee602
aom@3.12.1-1
3.12.1-1+deb13u1
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
castopod/castopod:1.12.101fd37280cbb2
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
castopod/castopod:1.15.54e4f0440520f
aom@3.12.1-1
3.12.1-1+deb13u1
1
chocobozzz/peertube:v8.1.5052712130691
aom@3.12.1-1
3.12.1-1+deb13u1
1
ckulka/baikal:0.10.1-nginx434bdd162247
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
aom@3.6.0-1
3.6.0-1+deb12u3
1
dannielkil/book-frontend:latest937993927694
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
deconzcommunity/deconz:2.29.2062de2362641
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
aom@3.12.1-1
3.12.1-1+deb13u1
1
dragonflyoss/client:v0.1.82edf3e921f4e0
aom@3.6.0-1
3.6.0-1+deb12u3
1
emqx/ecp-ui:2.5.1e33e9816f147
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
felipecs8/app-db-connection-test:v129e06c9c6385
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
firefart/requesttracker:5.0.40d6249906d8c
aom@3.6.0-1
3.6.0-1+deb12u3
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
hazegoodlife/haaze:milksite8d4c63169e14
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
hecrom/myweatherangularclient:1.3.11bb0372939c19
aom@3.6.0-1
3.6.0-1+deb12u3
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
aom@3.6.0-1
3.6.0-1+deb12u3
1
instill/artifact-backend:b28766ac4a393e601ed
aom@3.12.1-1
3.12.1-1+deb13u1
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
aom@1.0.0.errata1-3build1
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
aom@3.6.0-1
3.6.0-1+deb12u3
1
itzg/bungeecord:latest1c59f9631f3b
aom@3.13.1-2
no fix listed
1
itzg/minecraft-server:2026.9.04e29d14082d9
aom@3.8.2-2ubuntu0.1
no fix listed
1
itzg/minecraft-server:latest8672e335dbef
aom@3.8.2-2ubuntu0.1
no fix listed
1
jaedb/iris:latest048cfbf58d57
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
jbtronics/part-db1:latest5db71f6db59d
aom@3.6.0-1+deb12u2
3.6.0-1+deb12u3
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
aom@3.6.0-1
3.6.0-1+deb12u3
1
jordan/icinga2:latestf75025fe8ea8
aom@3.6.0-1+deb12u2
3.6.0-1+deb12u3
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
aom@3.6.0-1+deb12u2
3.6.0-1+deb12u3
1
knspar/phronetis-operator:0.1.60c4f0543ee58
aom@3.6.0-1
3.6.0-1+deb12u3
1
kuzwolka/aws9:main1ad759b961b1
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
kuzwolka/aws9:news3e8880fbbb96
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
kuzwolka/aws9:blog4a7707410bf1
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
kuzwolka/aws9:shop84a9d9766345
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
laly9999/node-app:1dd0e503913e1
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
langflowai/langflow-frontend:latest54f67f1961fe
aom@3.6.0-1+deb12u2
3.6.0-1+deb12u3
1
langgenius/dify-api:0.6.11fca918260dd6
aom@3.6.0-1
3.6.0-1+deb12u3
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
aom@3.8.2-2ubuntu0.1
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
aom@3.8.2-2ubuntu0.1
no fix listed
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
aom@3.8.2-2ubuntu0.1
no fix listed
1
library/drupal:11.4.6-php8.5-apache-bookworm28f7931ecbcb
aom@3.6.0-1+deb12u2
3.6.0-1+deb12u3
1
library/nextcloud:31.0.6-apache588609d76b21
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
library/nginx:1.27.409369da6b103
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
library/nginx:1.291881968aff6f
aom@3.12.1-1
3.12.1-1+deb13u1
1
library/nginx:1.276784fb0834aa
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
library/nginx:1.25.167f9a4f10d14
aom@3.6.0-1
3.6.0-1+deb12u3
1
library/nginx:1.25.49ff236ed47fe
aom@3.6.0-1
3.6.0-1+deb12u3
1
library/nginx:1.27.3fb197595ebe7
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.