StackRadar

CVE-2026-56289

Medium

Advisory

Published 9 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
376
of 17,781 indexed, latest versions
Container images
374
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 376 of 17,781 indexed charts deploy, on 374 images.

Affected packageAffected versionsFixed inImages
patchdeb2.7.1-4ubuntu1, 2.7.1-4ubuntu2.3, 2.7.1-4ubuntu2.4, 2.7.5-1+10 moreno fix listed374
OSV records
DEBIAN-CVE-2026-56289UBUNTU-CVE-2026-56289

Charts affected

376 by stars
ChartLatestAffected imagesRadar Score
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
cloudve/janis-terminal:latestaf56e77ca587
patch@2.7.6-2ubuntu1.1
no fix listed

Open the chart page →

14,270
chowdacluster-deploy0.2.01 of 1See more

chowda cluster-deploy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/chowda:main86ab9effd1a5
patch@2.8-2
no fix listed

Open the chart page →

1,834
pbcore-utilcluster-deploy0.0.11 of 1See more

pbcore-util cluster-deploy 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
patch@2.7.6-7
no fix listed

Open the chart page →

9,128
opencloudcommunity-opencloud3.0.01 of 11See more

opencloud community-opencloud 3.0.0

1 of the 11 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
apache/tika:latest-full80072bb73dd3
patch@2.8-2build1
no fix listed

Open the chart page →

3,773
cortezacorteza1.0.121 of 3See more

corteza corteza 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
patch@2.7.6-7
no fix listed

Open the chart page →

8,368
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
patch@2.7.6-7
no fix listed

Open the chart page →

14,559
cspconsolecspconsole1.3.111 of 5See more

cspconsole cspconsole 1.3.11

1 of the 5 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
cspconsole/csp-control-center:1.0.1046dda4a31bd6
patch@2.7.6-7
no fix listed

Open the chart page →

12,274
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
patch@2.7.6-7
no fix listed

Open the chart page →

16,604
damap-chartdamapVerified publisher0.3.01 of 5See more

damap-chart damap 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8f29984bd1e22
patch@2.8-2
no fix listed

Open the chart page →

13,936
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
patch@2.7.6-7
no fix listed

Open the chart page →

5,062
deploy-elibrarydeploy-elibrary-helm0.1.01 of 1See more

deploy-elibrary deploy-elibrary-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
psorab/elibrary:latest53b68896c4ce
patch@2.7.6-6
no fix listed

Open the chart page →

7,212
deploy-elibrarydeploy-elibrary-oo0.1.01 of 1See more

deploy-elibrary deploy-elibrary-oo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
jedi132000/nextapp:latestdc2a81e92f23
patch@2.7.6-6
no fix listed

Open the chart page →

8,106
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
patch@2.7.6-6
no fix listed

Open the chart page →

14,856
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
patch@2.7.6-7build2
no fix listed

Open the chart page →

30,031
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
patch@2.7.6-7build2
no fix listed

Open the chart page →

29,033
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
patch@2.7.6-7
no fix listed

Open the chart page →

9,607
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
patch@2.7.6-7build2
no fix listed

Open the chart page →

12,949
devtron-enterprisedevtron48.0.02 of 28See more

devtron-enterprise devtron 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
patch@2.7.6-7build3
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
patch@2.7.6-7
no fix listed

Open the chart page →

68,240
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
patch@2.7.6-7
no fix listed

Open the chart page →

9,607
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
patch@2.7.6-7build2
no fix listed

Open the chart page →

12,949
devtron-enterprisedevtron-labs48.0.02 of 28See more

devtron-enterprise devtron-labs 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
patch@2.7.6-7build3
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
patch@2.7.6-7
no fix listed

Open the chart page →

68,240
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:main-localda995c129e2f
patch@2.7.6-7build3
no fix listed

Open the chart page →

19,224
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
patch@2.7.6-7
no fix listed

Open the chart page →

7,141
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
patch@2.7.6-7build3
no fix listed

Open the chart page →

16,954
webtreesdjjudas21Verified publisher3.0.01 of 1See more

webtrees djjudas21 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
patch@2.8-2
no fix listed

Open the chart page →

5,966
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
patch@2.7.6-7
no fix listed

Open the chart page →

14,627
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
patch@2.8-2
no fix listed

Open the chart page →

13,391
deploy-elibraryeducative-helm-bookapp0.5.01 of 1See more

deploy-elibrary educative-helm-bookapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
patch@2.7.6-6
no fix listed

Open the chart page →

5,112
esphomeegebackVerified publisher2.0.251 of 1See more

esphome egeback 2.0.25

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
esphome/esphome:2026.7.44866347cb5b4
patch@2.8-2
no fix listed

Open the chart page →

3,121
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
patch@2.7.6-6
no fix listed

Open the chart page →

25,122
wordpresseoc-chartsVerified publisher0.14.41 of 1See more

wordpress eoc-charts 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
library/wordpress:6.8.3-apache30bff39330d1
patch@2.8-2
no fix listed

Open the chart page →

7,233
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
patch@2.7.6-6
no fix listed

Open the chart page →

9,334
matomoeosc-lot-1Verified publisher0.2.01 of 1See more

matomo eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
library/matomo:5.1.2-apache2415789e1602
patch@2.7.6-7
no fix listed

Open the chart page →

5,290
espocrmespocrmVerified publisher1.0.11 of 2See more

espocrm espocrm 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
espocrm/espocrm:9.3.101b5a24504ed9
patch@2.8-2
no fix listed

Open the chart page →

6,431
beeport-uiethersphereVerified publisher0.76.21 of 3See more

beeport-ui ethersphere 0.76.2

1 of the 3 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
patch@2.7.6-7
no fix listed

Open the chart page →

7,368
multichain-uiethersphereVerified publisher0.73.11 of 3See more

multichain-ui ethersphere 0.73.1

1 of the 3 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
patch@2.7.6-7
no fix listed

Open the chart page →

7,368
static-siteethersphereVerified publisher0.73.11 of 2See more

static-site ethersphere 0.73.1

1 of the 2 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
library/node:latestf5d1cc40abc1
patch@2.8-2
no fix listed

Open the chart page →

6,851
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
patch@2.7.6-7build2
no fix listed

Open the chart page →

13,450
ferriscompanyferriscompany0.1.01 of 1See more

ferriscompany ferriscompany 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
patch@2.7.6-7
no fix listed

Open the chart page →

10,741
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
patch@2.8-2
no fix listed

Open the chart page →

5,039
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
patch@2.8-2
no fix listed
fireflyiii/data-importer:version-2.2.3ab52bf932546
patch@2.8-2
no fix listed

Open the chart page →

10,260
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
patch@2.8-2
no fix listed

Open the chart page →

4,829
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
patch@2.8-2
no fix listed

Open the chart page →

5,704
business-api-ecosystemfiware1.1.02 of 4See more

business-api-ecosystem fiware 1.1.0

2 of the 4 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
patch@2.7.6-6
no fix listed
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
patch@2.7.6-7
no fix listed

Open the chart page →

64,489
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
patch@2.8-2
no fix listed

Open the chart page →

5,704
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
patch@2.7.6-7
no fix listed

Open the chart page →

3,463
esphomegabe565Verified publisher0.15.01 of 1See more

esphome gabe565 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:latest000c5ee5ee96
patch@2.8-2
no fix listed

Open the chart page →

3,112
duplicatigeek-cookbookVerified publisher5.4.21 of 1See more

duplicati geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/duplicati:latesta792931146b4
patch@2.7.6-7build3
no fix listed

Open the chart page →

1,716
lancachegeek-cookbookVerified publisher0.6.21 of 1See more

lancache geek-cookbook 0.6.2

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
lancachenet/monolithic:latest37f28b362c93
patch@2.7.6-7build3
no fix listed

Open the chart page →

1,222
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56289.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
patch@2.7.6-7
no fix listed

Open the chart page →

12,958

Container images carrying it

374 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
fireflyiii/core:version-6.6.6ae69fdd95cde
patch@2.8-2
no fix listed
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
patch@2.7.6-6
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
patch@2.7.6-7
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
patch@2.7.6-7
no fix listed
1
flyway/flyway:9.1545b5d7cdc75a
patch@2.7.6-6
no fix listed
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
patch@2.7.6-7build2
no fix listed
1
gethue/hue:4.11.011b649636e68
patch@2.7.6-6
no fix listed
1
gethue/hue:4.10.05702b2c37ff9
patch@2.7.6-2ubuntu1.1
no fix listed
1
gethue/hue:latest7d5c1b9f8a79
patch@2.7.6-7build2
no fix listed
1
glpi/glpi:latest4b681082a79e
patch@2.8-2
no fix listed
1
gotenberg/gotenberg:8.30206a6c708fc6
patch@2.8-2
no fix listed
1
gotenberg/gotenberg:8.3467097317623a
patch@2.8-2
no fix listed
1
gulacedia/web-dvwa-new:v367b467d961ca
patch@2.7.6-7
no fix listed
1
haugene/transmission-openvpn:4.0059216cfae4b
patch@2.7.6-6
no fix listed
1
haveagitgat/tdarr:2.00.181256348872ce
patch@2.7.6-6
no fix listed
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
patch@2.7.6-6
no fix listed
1
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
patch@2.7.6-6
no fix listed
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
patch@2.7.6-7
no fix listed
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
patch@2.7.6-7
no fix listed
1
hmediade/printserver-init:latest7f005eb6c718
patch@2.7.6-7build2
no fix listed
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
patch@2.7.6-2ubuntu1.1
no fix listed
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
patch@2.7.5-1ubuntu0.16.04.1
no fix listed
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
patch@2.7.5-1ubuntu0.16.04.1
no fix listed
1
ibmcom/microclimate-theia:lateste17bdccc5030
patch@2.7.5-1
no fix listed
1
inseefrlab/shelly:cloudshell31f04ca7436b
patch@2.7.6-7build2
no fix listed
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
patch@2.7.6-6
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
patch@2.7.6-7
no fix listed
1
itzg/minecraft-server:2026.9.04e29d14082d9
patch@2.7.6-7build3
no fix listed
1
itzg/minecraft-server:latest8672e335dbef
patch@2.7.6-7build3
no fix listed
1
jaedb/iris:latest048cfbf58d57
patch@2.7.6-7
no fix listed
1
jedi132000/nextapp:latestdc2a81e92f23
patch@2.7.6-6
no fix listed
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
patch@2.7.6-6
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
patch@2.7.6-6
no fix listed
1
kennethreitz/httpbin:latest599fe5e50731
patch@2.7.6-2ubuntu1
no fix listed
1
kimai/kimai2:2.65.06dfc63199654
patch@2.7.6-7
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
patch@2.8-2
no fix listed
1
kixote/typemill4e9dff179519
patch@2.8-2
no fix listed
1
kixote/typemill628f79a08cc7
patch@2.8-2
no fix listed
1
knspar/phronetis-operator:0.1.60c4f0543ee58
patch@2.7.6-7
no fix listed
1
kong/httpbin:latesta6ac46531193
patch@2.7.6-7build2
no fix listed
1
kusionstack/kusion:v0.14.0126c8f0b0976
patch@2.7.6-7build2
no fix listed
1
laly9999/node-app:1dd0e503913e1
patch@2.7.6-7
no fix listed
1
lancachenet/monolithic:latest37f28b362c93
patch@2.7.6-7build3
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
patch@2.7.6-7build3
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
patch@2.7.6-7build3
no fix listed
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
patch@2.7.6-7build3
no fix listed
1
library/drupal:11.4.6-php8.5-apache-bookworm28f7931ecbcb
patch@2.7.6-7
no fix listed
1
library/matomo:5.1.2-apache2415789e1602
patch@2.7.6-7
no fix listed
1
library/matomo:5.13.0-apache8e6bdd396496
patch@2.8-2
no fix listed
1
library/nextcloud:31.0.6-apache588609d76b21
patch@2.7.6-7
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.