StackRadar

CVE-2026-56288

Medium

Advisory

Published 9 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
379
of 17,787 indexed, latest versions
Container images
377
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 379 of 17,787 indexed charts deploy, on 377 images.

Affected packageAffected versionsFixed inImages
patchdeb2.7.1-4ubuntu1, 2.7.1-4ubuntu2.3, 2.7.1-4ubuntu2.4, 2.7.5-1+10 moreno fix listed377
OSV records
DEBIAN-CVE-2026-56288UBUNTU-CVE-2026-56288

Charts affected

379 by stars
ChartLatestAffected imagesRadar Score
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
patch@2.7.5-1
no fix listed

Open the chart page →

77,798
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
cloudve/janis-terminal:latestaf56e77ca587
patch@2.7.6-2ubuntu1.1
no fix listed

Open the chart page →

14,285
chowdacluster-deploy0.2.01 of 1See more

chowda cluster-deploy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/chowda:main86ab9effd1a5
patch@2.8-2
no fix listed

Open the chart page →

1,801
pbcore-utilcluster-deploy0.0.11 of 1See more

pbcore-util cluster-deploy 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
patch@2.7.6-7
no fix listed

Open the chart page →

8,806
opencloudcommunity-opencloud3.0.01 of 11See more

opencloud community-opencloud 3.0.0

1 of the 11 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
apache/tika:latest-full80072bb73dd3
patch@2.8-2build1
no fix listed

Open the chart page →

3,850
cortezacorteza1.1.01 of 3See more

corteza corteza 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
patch@2.7.6-7
no fix listed

Open the chart page →

8,251
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
patch@2.7.6-7
no fix listed

Open the chart page →

14,587
cspconsolecspconsole1.3.111 of 5See more

cspconsole cspconsole 1.3.11

1 of the 5 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
cspconsole/csp-control-center:1.0.1046dda4a31bd6
patch@2.7.6-7
no fix listed

Open the chart page →

11,891
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
patch@2.7.6-7
no fix listed

Open the chart page →

16,632
damap-chartdamapVerified publisher0.3.01 of 5See more

damap-chart damap 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8f29984bd1e22
patch@2.8-2
no fix listed

Open the chart page →

13,859
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
patch@2.7.6-7
no fix listed

Open the chart page →

4,914
deploy-elibrarydeploy-elibrary-helm0.1.01 of 1See more

deploy-elibrary deploy-elibrary-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
psorab/elibrary:latest53b68896c4ce
patch@2.7.6-6
no fix listed

Open the chart page →

7,259
deploy-elibrarydeploy-elibrary-oo0.1.01 of 1See more

deploy-elibrary deploy-elibrary-oo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
jedi132000/nextapp:latestdc2a81e92f23
patch@2.7.6-6
no fix listed

Open the chart page →

8,154
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
patch@2.7.6-6
no fix listed

Open the chart page →

14,910
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
patch@2.7.6-7build2
no fix listed

Open the chart page →

30,150
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
patch@2.7.6-7build2
no fix listed

Open the chart page →

29,151
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
patch@2.7.6-7
no fix listed

Open the chart page →

9,152
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
patch@2.7.6-7build2
no fix listed

Open the chart page →

12,999
devtron-enterprisedevtron48.0.02 of 28See more

devtron-enterprise devtron 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
patch@2.7.6-7build3
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
patch@2.7.6-7
no fix listed

Open the chart page →

66,542
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
patch@2.7.6-7
no fix listed

Open the chart page →

9,152
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
patch@2.7.6-7build2
no fix listed

Open the chart page →

12,999
devtron-enterprisedevtron-labs48.0.02 of 28See more

devtron-enterprise devtron-labs 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
patch@2.7.6-7build3
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
patch@2.7.6-7
no fix listed

Open the chart page →

66,542
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:main-localda995c129e2f
patch@2.7.6-7build3
no fix listed

Open the chart page →

19,063
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
patch@2.7.6-7
no fix listed

Open the chart page →

7,167
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
patch@2.7.6-7build3
no fix listed

Open the chart page →

17,053
webtreesdjjudas21Verified publisher3.0.01 of 1See more

webtrees djjudas21 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
patch@2.8-2
no fix listed

Open the chart page →

5,885
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
patch@2.7.6-7
no fix listed

Open the chart page →

13,031
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
patch@2.8-2
no fix listed

Open the chart page →

13,422
deploy-elibraryeducative-helm-bookapp0.5.01 of 1See more

deploy-elibrary educative-helm-bookapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
patch@2.7.6-6
no fix listed

Open the chart page →

5,150
esphomeegebackVerified publisher2.0.251 of 1See more

esphome egeback 2.0.25

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
esphome/esphome:2026.7.44866347cb5b4
patch@2.8-2
no fix listed

Open the chart page →

3,153
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
patch@2.7.6-6
no fix listed

Open the chart page →

25,239
wordpresseoc-chartsVerified publisher0.14.41 of 1See more

wordpress eoc-charts 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
library/wordpress:6.8.3-apache30bff39330d1
patch@2.8-2
no fix listed

Open the chart page →

7,265
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
patch@2.7.6-6
no fix listed

Open the chart page →

9,383
matomoeosc-lot-1Verified publisher0.2.01 of 1See more

matomo eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
library/matomo:5.1.2-apache2415789e1602
patch@2.7.6-7
no fix listed

Open the chart page →

5,316
espocrmespocrmVerified publisher1.0.11 of 2See more

espocrm espocrm 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
espocrm/espocrm:9.3.101b5a24504ed9
patch@2.8-2
no fix listed

Open the chart page →

6,475
beeport-uiethersphereVerified publisher0.76.21 of 3See more

beeport-ui ethersphere 0.76.2

1 of the 3 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
patch@2.7.6-7
no fix listed

Open the chart page →

7,406
multichain-uiethersphereVerified publisher0.73.11 of 3See more

multichain-ui ethersphere 0.73.1

1 of the 3 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
patch@2.7.6-7
no fix listed

Open the chart page →

7,406
static-siteethersphereVerified publisher0.73.11 of 2See more

static-site ethersphere 0.73.1

1 of the 2 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
library/node:latestf5d1cc40abc1
patch@2.8-2
no fix listed

Open the chart page →

6,894
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
patch@2.7.6-7build2
no fix listed

Open the chart page →

13,491
ferriscompanyferriscompany0.1.01 of 1See more

ferriscompany ferriscompany 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
patch@2.7.6-7
no fix listed

Open the chart page →

10,119
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
patch@2.8-2
no fix listed

Open the chart page →

5,038
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
patch@2.8-2
no fix listed
fireflyiii/data-importer:version-2.2.3ab52bf932546
patch@2.8-2
no fix listed

Open the chart page →

10,258
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
patch@2.8-2
no fix listed

Open the chart page →

4,828
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
patch@2.8-2
no fix listed

Open the chart page →

5,624
business-api-ecosystemfiware1.1.02 of 4See more

business-api-ecosystem fiware 1.1.0

2 of the 4 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
patch@2.7.6-6
no fix listed
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
patch@2.7.6-7
no fix listed

Open the chart page →

64,192
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
patch@2.8-2
no fix listed

Open the chart page →

5,624
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
patch@2.7.6-7
no fix listed

Open the chart page →

3,384
esphomegabe565Verified publisher0.15.01 of 1See more

esphome gabe565 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:latest000c5ee5ee96
patch@2.8-2
no fix listed

Open the chart page →

3,143
duplicatigeek-cookbookVerified publisher5.4.21 of 1See more

duplicati geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/duplicati:latesta792931146b4
patch@2.7.6-7build3
no fix listed

Open the chart page →

1,764
lancachegeek-cookbookVerified publisher0.6.21 of 1See more

lancache geek-cookbook 0.6.2

1 of the 1 container images this version deploys carry CVE-2026-56288.

Container imageDigestPackageFixed in
lancachenet/monolithic:latest37f28b362c93
patch@2.7.6-7build3
no fix listed

Open the chart page →

1,270

Container images carrying it

377 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
oomk8s/readiness-check:2.0.2875814cc853d
patch@2.7.5-1ubuntu0.16.04.1
no fix listed
11
library/phpmyadmin:5.2.3-apache:latest3a8a8d6b5289
patch@2.8-2
no fix listed
7
library/wordpress:7.1.0-apache:latest5a93c470ae82
patch@2.8-2
no fix listed
6
oomk8s/readiness-check:2.0.07daa08b81954
patch@2.7.5-1
no fix listed
6
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
patch@2.7.5-1ubuntu0.16.04.1
no fix listed
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
patch@2.7.5-1ubuntu0.16.04.1
no fix listed
4
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
patch@2.7.6-7build2
no fix listed
4
library/node:ltsbe23f54a88d3
patch@2.7.6-7
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
patch@2.7.6-7
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
patch@2.7.6-7build2
no fix listed
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
patch@2.7.6-7build3
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
patch@2.7.6-7
no fix listed
3
apache/tika:2.9.2.1-fullae0b86d3c4d0
patch@2.7.6-7build3
no fix listed
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
patch@2.8-2
no fix listed
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
patch@2.8-2
no fix listed
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
patch@2.7.6-7
no fix listed
2
gotenberg/gotenberg:8.36.087c16b9f3642
patch@2.8-2
no fix listed
2
gotenberg/gotenberg:8:8.37.0f29984bd1e22
patch@2.8-2
no fix listed
2
homebridge/homebridge:latest77c685a40911
patch@2.7.6-7build3
no fix listed
2
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
patch@2.8-2
no fix listed
2
library/phpmyadmin:5.2.16e75aa8f767c
patch@2.7.6-7
no fix listed
2
library/python:3.7eedf63967cdb
patch@2.7.6-7
no fix listed
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
patch@2.8-2
no fix listed
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
patch@2.7.6-6
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
patch@2.7.6-7
no fix listed
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
patch@2.7.5-1ubuntu0.16.04.1
no fix listed
2
polyaxon/polyaxon-agent:2.16.4eca6952b20e6
patch@2.8-2
no fix listed
2
polyaxon/polyaxon-cli:2.16.4024ff3fa775e
patch@2.8-2
no fix listed
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
patch@2.7.6-7
no fix listed
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
patch@2.7.6-6
no fix listed
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
patch@2.7.6-6
no fix listed
2
vdiogov/glpi-conteiner:latest6945f84f0058
patch@2.7.6-7
no fix listed
2
wurstmeister/zookeeper:latest7a7fd44a7210
patch@2.7.1-4ubuntu1
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
patch@2.7.6-7build3
no fix listed
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
patch@2.7.6-7build2
no fix listed
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
patch@2.7.6-7
no fix listed
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
patch@2.7.6-7build3
no fix listed
2
1dev/server:11.9.0cd5b12fe5471
patch@2.7.6-7build3
no fix listed
1
a10networks/acos-prometheus-exporter:latest8dc58d434d71
patch@2.7.6-2ubuntu1.1
no fix listed
1
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
patch@2.8-2
no fix listed
1
adamzammit/limesurvey:7.1.0f48962e1528c
patch@2.8-2
no fix listed
1
airbyte/manifest-server:7.23.73b3a670af168
patch@2.7.6-7
no fix listed
1
akaunting/akaunting:3.0.1552811b36ec3a
patch@2.7.6-7
no fix listed
1
allegroai/clearml:2.0.0-613713ae38f7daf
patch@2.7.6-7
no fix listed
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
patch@2.7.6-2ubuntu1.1
no fix listed
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
patch@2.7.6-7build3
no fix listed
1
antiantiops/vscode-browser-docker:1.137.0eeff80a99d92
patch@2.7.6-7build3
no fix listed
1
apachepulsar/pulsar:2.9.0d056c89b7131
patch@2.7.6-6
no fix listed
1
apachepulsar/pulsar:2.8.2d538416d5afe
patch@2.7.6-6
no fix listed
1
apache/superset:4.0.1ab9467fd712c
patch@2.7.6-7
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.