StackRadar

CVE-2026-56209

High

Advisory

Published 19 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
254
of 17,781 indexed, latest versions
Container images
262
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 254 of 17,781 indexed charts deploy, on 262 images.

Affected packageAffected versionsFixed inImages
aomdeb1.0.0.errata1-3+deb11u1build0.20.04.1, 1.0.0.errata1-3build1, 3.1.0-0ubuntu1~20.04.sav0, 3.3.0-1+8 more3.6.0-1+deb12u3, 3.12.1-1+deb13u1262
OSV records
DEBIAN-CVE-2026-56209UBUNTU-CVE-2026-56209

Charts affected

254 by stars
ChartLatestAffected imagesRadar Score
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-56209.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
aom@3.6.0-1+deb12u2
3.6.0-1+deb12u3

Open the chart page →

9,117
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-56209.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
aom@3.3.0-1
no fix listed

Open the chart page →

14,100
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-56209.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
aom@3.6.0-1
3.6.0-1+deb12u3

Open the chart page →

7,673
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-56209.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
aom@3.3.0-1ubuntu0.1
no fix listed

Open the chart page →

7,849

Container images carrying it

262 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/node:208f693eaa7e0a
aom@3.6.0-1+deb12u2
3.6.0-1+deb12u3
1
library/python:3.8d41127070014
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
library/wordpress:6.4.3-apache8ae66efb09a2
aom@3.6.0-1
3.6.0-1+deb12u3
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
aom@3.12.1-1
3.12.1-1+deb13u1
1
library/wordpress:php8.1-apachef73396626d2f
aom@3.12.1-1
3.12.1-1+deb13u1
1
linuxserver/calibre-web:0.6.24241009026e6f
aom@3.8.2-2ubuntu0.1
no fix listed
1
livekit/ingress:v1.2.21ab01641b366
aom@3.3.0-1
no fix listed
1
logiqai/flash:v3.10.265b996bc7bdc
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
makersquad/harp-proxy:0.8.1a40dd258c527
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
martinhelmich/typo3:12.4c83a4f3fd7ae
aom@3.6.0-1+deb12u2
3.6.0-1+deb12u3
1
mathesar/mathesar:0.12.0091757cb01fe
aom@3.6.0-1+deb12u2
3.6.0-1+deb12u3
1
mautic/mautic:7-apacheeb8cc73d97e1
aom@3.6.0-1+deb12u2
3.6.0-1+deb12u3
1
mediagis/nominatim:5.3.27923a8e67197
aom@3.8.2-2ubuntu0.1
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
aom@3.3.0-1
no fix listed
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
mlikiowa/napcat-docker:latest1336a777f9a4
aom@3.3.0-1
no fix listed
1
moreillon/api-proxy:latestd7d4a5463525
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
moreillon/camera-viewer:lateste418cc694bd5
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
moreillon/food-manager:lateste8fd856e593d
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
moreillon/group-manager:latest3caa8f710ee0
aom@3.6.0-1+deb12u2
3.6.0-1+deb12u3
1
moreillon/group-manager-front:latest5f0a38498271
aom@3.12.1-1
3.12.1-1+deb13u1
1
moreillon/user-manager-front:v5.1.06597e6b98d21
aom@3.6.0-1
3.6.0-1+deb12u3
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
aom@3.6.0-1
3.6.0-1+deb12u3
1
muhammedgamal/fp23:latest74b4cd69b6fa
aom@3.6.0-1
3.6.0-1+deb12u3
1
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
aom@3.12.1-1
3.12.1-1+deb13u1
1
nirmalnaveen/supermario:latest8541a39162f3
aom@3.6.0-1
3.6.0-1+deb12u3
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
aom@3.12.1-1
3.12.1-1+deb13u1
1
opea/codegen-ui:1.02bee4eb66f3e
aom@3.6.0-1
3.6.0-1+deb12u3
1
opea/codetrans-ui:1.03ef121f34610
aom@3.6.0-1
3.6.0-1+deb12u3
1
opea/docsum-ui:1.07f854e9bffaf
aom@3.6.0-1
3.6.0-1+deb12u3
1
opea/speecht5:1.0249afad3d268
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
openbas/caldera-server:5.1.0a277796d9724
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
aom@3.6.0-1+deb12u2
3.6.0-1+deb12u3
1
openproject/hocuspocus:release-338001b288dc1359dfb5
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
owncloud/server:10.16.274c53d341076
aom@3.3.0-1ubuntu0.1
no fix listed
1
owncloud/server:10.16.3b3f9efdcd7f7
aom@3.3.0-1ubuntu0.1
no fix listed
1
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
aom@3.12.1-1
3.12.1-1+deb13u1
1
penpotapp/backend:2.2.147853d9bb9dd
aom@3.3.0-1
no fix listed
1
penpotapp/exporter:2.2.15c835ffd87ab
aom@3.3.0-1
no fix listed
1
penpotapp/exporter:2.17.272a8061e8806
aom@3.13.1-2
no fix listed
1
phan2410/dummy-service:0.0.89c6ed6de26ca
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
photoprism/photoprism:220629-jammy2954334adbda
aom@3.3.0-1
no fix listed
1
photoprism/photoprism:260601650c6ad5a651
aom@3.13.1-2
no fix listed
1
photoprism/photoprism:260728958642220223
aom@3.13.1-2
no fix listed
1
photoprism/photoprism:251130db16ee6b1ba3
aom@3.12.1-1
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
aom@3.8.2-2ubuntu0.1
no fix listed
1
pk910/powfaucet:v2-stable3dcae6a62896
aom@3.6.0-1+deb12u1
3.6.0-1+deb12u3
1
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
aom@3.8.2-2ubuntu0.1
no fix listed
1
posit/package-manager:2026.09.0-ubuntu-24.04527493ef621b
aom@3.8.2-2ubuntu0.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.