StackRadar

CVE-2026-56391

Medium

Advisory

Published 24 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,483
of 17,792 indexed, latest versions
Container images
1,368
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,483 of 17,792 indexed charts deploy, on 1,368 images.

Affected packageAffected versionsFixed inImages
coreutilsdeb9.1-1, 9.7-3, 9.7-3+dhi3, 9.7-3+dhi4+2 more9.7-3+e4, 9.7-3ubuntu2.11,356
coreutils-fromdeb9.5-1ubuntu2+0.0.0~ubuntu259.7-3ubuntu2.172
OSV records
DEBIAN-CVE-2026-56391UBUNTU-CVE-2026-56391ECHO-3699-27c7-123e
Also known as
USN-8697-1

Charts affected

1,483 by stars
ChartLatestAffected imagesRadar Score
openaevhelm-openbasVerified publisher2.0.52 of 7See more

openaev helm-openbas 2.0.5

2 of the 7 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
coreutils@9.1-1
no fix listed
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
coreutils@9.1-1
no fix listed

Open the chart page →

7,564
openbashelm-openbasVerified publisher1.8.143 of 7See more

openbas helm-openbas 1.8.14

3 of the 7 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
coreutils@9.1-1
no fix listed
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
coreutils@9.1-1
no fix listed
openbas/caldera-server:5.1.0a277796d9724
coreutils@9.1-1
no fix listed

Open the chart page →

25,217
steampipehelm-steampipeVerified publisher2.4.11 of 1See more

steampipe helm-steampipe 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
coreutils@9.1-1
no fix listed

Open the chart page →

3,159
my-nginxhelmtaiwo0.1.01 of 1See more

my-nginx helmtaiwo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
coreutils@9.7-3
no fix listed

Open the chart page →

1,861
samplehelmapphelmtraining3.0.01 of 1See more

samplehelmapp helmtraining 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
praravind1801/helmimages:3.0.0f29d637b9ce1
coreutils@9.1-1
no fix listed

Open the chart page →

6,013
home-ha-mockhome-ha-mockVerified publisher2.0.51 of 1See more

home-ha-mock home-ha-mock 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
coreutils@9.1-1
no fix listed

Open the chart page →

3,069
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
coreutils@9.1-1
no fix listed

Open the chart page →

16,444
home-security-demohome-security-demoVerified publisher2.0.121 of 3See more

home-security-demo home-security-demo 2.0.12

1 of the 3 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
coreutils@9.1-1
no fix listed

Open the chart page →

3,152
paperlesshpVerified publisher0.1.23 of 5See more

paperless hp 0.1.2

3 of the 5 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
apache/tika:3.3.1.090b7fa1dc018
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1
gotenberg/gotenberg:8.3467097317623a
coreutils@9.7-3
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
coreutils@9.7-3
no fix listed

Open the chart page →

27,104
jenkinshuangchengwu-helm-chart0.1.01 of 2See more

jenkins huangchengwu-helm-chart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

749
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
coreutils@9.1-1
no fix listed

Open the chart page →

3,439
add-crismuxhydraVerified publisher0.9.31 of 1See more

add-crismux hydra 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
coreutils@9.1-1
no fix listed

Open the chart page →

1,307
hydrahydraVerified publisher0.9.52 of 2See more

hydra hydra 0.9.5

2 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
coreutils@9.1-1
no fix listed
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
coreutils@9.1-1
no fix listed

Open the chart page →

9,061
isolated-vmhydraVerified publisher0.9.41 of 1See more

isolated-vm hydra 0.9.4

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
coreutils@9.1-1
no fix listed

Open the chart page →

7,754
remove-crismuxhydraVerified publisher0.9.31 of 1See more

remove-crismux hydra 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
coreutils@9.1-1
no fix listed

Open the chart page →

1,307
nginx-charthyomin-nginx0.1.01 of 1See more

nginx-chart hyomin-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
coreutils@9.7-3
no fix listed

Open the chart page →

1,861
nginx-charthyun-nginx0.1.01 of 1See more

nginx-chart hyun-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
coreutils@9.7-3
no fix listed

Open the chart page →

1,861
iam-eks-user-mapperiam-eks-user-mapper1.6.01 of 1See more

iam-eks-user-mapper iam-eks-user-mapper 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/qovery/iam-eks-user-mapper:mainc41e3efc6097
coreutils@9.7-3
no fix listed

Open the chart page →

1,681
ibexaibexaVerified publisher3.11.11 of 10See more

ibexa ibexa 3.11.1

1 of the 10 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
boky/postfix:4.4.0f3f247fd4252
coreutils@9.1-1
no fix listed

Open the chart page →

6,050
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
coreutils@9.7-3
no fix listed

Open the chart page →

57,842
ibm-ucv-prodibm-helm5.2.62 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

2 of the 16 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
bitnamilegacy/nginx:1.27.1934d1acd5ca8
coreutils@9.1-1
no fix listed
bitnamilegacy/rabbitmq:4.1.2fac502149c40
coreutils@9.1-1
no fix listed

Open the chart page →

12,184
icegateicegateVerified publisher0.1.13 of 3See more

icegate icegate 0.1.1

3 of the 3 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/icegatetech/icegate-ingest:0.1.1bae3c441894a
coreutils@9.1-1
no fix listed
ghcr.io/icegatetech/icegate-maintain:0.1.193e85b2b76ee
coreutils@9.1-1
no fix listed
ghcr.io/icegatetech/icegate-query:0.1.17542b4e7fff2
coreutils@9.1-1
no fix listed

Open the chart page →

4,575
codex-poolericoretechVerified publisher0.8.71 of 1See more

codex-pooler icoretech 0.8.7

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/icoretech/codex-pooler:0.7.81bebc7e4a770
coreutils@9.7-3
no fix listed

Open the chart page →

836
metamcpicoretechVerified publisher0.3.101 of 2See more

metamcp icoretech 0.3.10

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
coreutils@9.7-3
no fix listed

Open the chart page →

1,667
multicaicoretechVerified publisher0.4.431 of 5See more

multica icoretech 0.4.43

1 of the 5 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
pgvector/pgvector:pg17cf134a767f47
coreutils@9.1-1
no fix listed

Open the chart page →

2,612
nextjsicoretechVerified publisher1.2.01 of 1See more

nextjs icoretech 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
coreutils@9.7-3
no fix listed

Open the chart page →

1,861
tolgeeicoretechVerified publisher0.49.01 of 3See more

tolgee icoretech 0.49.0

1 of the 3 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/postgres:18.369e8582b781c
coreutils@9.7-3
no fix listed

Open the chart page →

2,769
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
coreutils@9.7-3
no fix listed

Open the chart page →

2,203
ilum-hive-metastoreilumVerified publisher1.2.01 of 2See more

ilum-hive-metastore ilum 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
coreutils@9.1-1
no fix listed

Open the chart page →

3,616
ilum-marquezilumVerified publisher6.7.02 of 3See more

ilum-marquez ilum 6.7.0

2 of the 3 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
coreutils@9.1-1
no fix listed
ilum/marquez:0.54.06e1d709d41f8
coreutils@9.1-1
no fix listed

Open the chart page →

6,332
ilum-streamlitilumVerified publisher0.1.01 of 1See more

ilum-streamlit ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ilum/streamlit-example:1.0.0ce5dcdeb22ba
coreutils@9.7-3
no fix listed

Open the chart page →

2,773
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
coreutils@9.1-1
no fix listed

Open the chart page →

11,888
web-chartimcherry57780.1.01 of 1See more

web-chart imcherry5778 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
coreutils@9.7-3
no fix listed

Open the chart page →

1,861
onechartimioVerified publisher0.76.01 of 1See more

onechart imio 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
coreutils@9.7-3
no fix listed

Open the chart page →

1,861
plausible-analyticsimioVerified publisher0.4.23 of 5See more

plausible-analytics imio 0.4.2

3 of the 5 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
bitnamilegacy/clickhouse:24.12.3-debian-12-r13cf6544f6c6c
coreutils@9.1-1
no fix listed
bitnamilegacy/clickhouse:24.12.4c7e70bf1d3fb
coreutils@9.1-1
no fix listed
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
coreutils@9.1-1
no fix listed

Open the chart page →

10,558
smtp4devimioVerified publisher0.1.11 of 1See more

smtp4dev imio 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
rnwood/smtp4dev:3.6.1912304153668
coreutils@9.1-1
no fix listed

Open the chart page →

3,223
pgcatimprowisedVerified publisher0.1.01 of 1See more

pgcat improwised 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
coreutils@9.1-1
no fix listed

Open the chart page →

3,805
proxysqlimprowisedVerified publisher1.0.01 of 1See more

proxysql improwised 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
improwised/proxysql:master-6b26e59-171765063828940522e8b7
coreutils@9.1-1
no fix listed

Open the chart page →

3,517
impulseimpulse1.0.161 of 1See more

impulse impulse 1.0.16

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/eslupmi/impulse:v3.7.03ded1b7ebca0
coreutils@9.7-3
no fix listed

Open the chart page →

1,378
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
coreutils@9.7-3
no fix listed

Open the chart page →

3,055
influxdb-enterpriseinfluxdata0.2.12 of 2See more

influxdb-enterprise influxdata 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/influxdb:1.12.3-meta8812029260b5
coreutils@9.1-1
no fix listed
library/influxdb:1.12.3-datab0f9fc41ed79
coreutils@9.1-1
no fix listed

Open the chart page →

5,988
influxdbinfluxdb20.1.01 of 1See more

influxdb influxdb2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/influxdb:latestf75e48af0598
coreutils@9.1-1
no fix listed

Open the chart page →

2,362
ai-stackinfracloud-chartsVerified publisher0.6.01 of 3See more

ai-stack infracloud-charts 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/chroma-core/chroma:1.5.91e0b73a187a2
coreutils@9.7-3
no fix listed

Open the chart page →

1,298
chromadbinfracloud-chartsVerified publisher0.3.01 of 1See more

chromadb infracloud-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/chroma-core/chroma:1.5.91e0b73a187a2
coreutils@9.7-3
no fix listed

Open the chart page →

1,298
guardrails-usvcinfracloud-chartsVerified publisher1.0.11 of 1See more

guardrails-usvc infracloud-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
opea/guardrails-tgi:latestf68bec6a1271
coreutils@9.1-1
no fix listed

Open the chart page →

5,100
erigoninfradao0.0.51 of 2See more

erigon infradao 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
testinprod/op-erigon:latest0a125bd77a2d
coreutils@9.1-1
no fix listed

Open the chart page →

2,905
op-stackinfradao0.0.11 of 1See more

op-stack infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
coreutils@9.7-3
no fix listed

Open the chart page →

1,861
intelowlintelowl-helm6.6.1-01-06-20262 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

2 of the 5 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
coreutils@9.1-1
no fix listed
library/redis:8.6.34d25e2fe601f
coreutils@9.7-3
no fix listed

Open the chart page →

17,978
inventreeinventreeOfficialVerified publisher0.4.282 of 2See more

inventree inventree 0.4.28

2 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
inventree/inventree:1.5.4a946ec09da3e
coreutils@9.7-3
no fix listed
library/nginx:stabled5792f71a949
coreutils@9.7-3
no fix listed

Open the chart page →

5,881
daveit-at-mOfficialVerified publisher0.2.153 of 11See more

dave it-at-m 0.2.15

3 of the 11 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
coreutils@9.1-1
no fix listed
bitnamilegacy/postgresql:latest42a8200d3597
coreutils@9.1-1
no fix listed
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
coreutils@9.1-1
no fix listed

Open the chart page →

15,320

Container images carrying it

1,368 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
coreutils@9.7-3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
coreutils@9.7-3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
coreutils@9.1-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
coreutils@9.1-1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
coreutils@9.7-3
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
coreutils@9.1-1
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
coreutils@9.1-1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
coreutils@9.1-1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
coreutils@9.1-1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
coreutils@9.1-1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
coreutils@9.7-3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
coreutils@9.1-1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
coreutils@9.1-1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
coreutils@9.1-1
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.