StackRadar

CVE-2026-56391

Medium

Advisory

Published 24 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,483
of 17,790 indexed, latest versions
Container images
1,374
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,483 of 17,790 indexed charts deploy, on 1,374 images.

Affected packageAffected versionsFixed inImages
coreutilsdeb9.1-1, 9.7-3, 9.7-3+dhi3, 9.7-3+dhi4+2 more9.7-3+e4, 9.7-3ubuntu2.11,362
coreutils-fromdeb9.5-1ubuntu2+0.0.0~ubuntu259.7-3ubuntu2.173
OSV records
DEBIAN-CVE-2026-56391UBUNTU-CVE-2026-56391ECHO-3699-27c7-123e
Also known as
USN-8697-1

Charts affected

1,483 by stars
ChartLatestAffected imagesRadar Score
snappasssnappassVerified publisher0.4.32 of 3See more

snappass snappass 0.4.3

2 of the 3 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
coreutils@9.7-3
no fix listed
valkey/valkey:8.1.61f84517eca8e
coreutils@9.7-3
no fix listed

Open the chart page →

3,040
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
coreutils@9.7-3
no fix listed

Open the chart page →

14,550
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
coreutils@9.7-3
no fix listed

Open the chart page →

2,330
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
coreutils@9.7-3
no fix listed

Open the chart page →

7,204
postgresql-ha-chartsoldevelo-postgresql-ha-chart16.3.42 of 2See more

postgresql-ha-chart soldevelo-postgresql-ha-chart 16.3.4

2 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
soldevelo/pgpool:4.6.3-debian-12-r0044d16a65129
coreutils@9.1-1
no fix listed
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
coreutils@9.1-1
no fix listed

Open the chart page →

4,604
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
coreutils@9.1-1
no fix listed

Open the chart page →

5,699
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
coreutils@9.1-1
no fix listed

Open the chart page →

10,450
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
graphprotocol/graph-node:v0.37.0f4452cdedd68
coreutils@9.1-1
no fix listed

Open the chart page →

4,694
stornxstornxVerified publisher1.1.11 of 9See more

stornx stornx 1.1.1

1 of the 9 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
alazidis/stornx:1.1.1602d4f7f090c
coreutils@9.1-1
no fix listed

Open the chart page →

11,735
supabasesupabse0.8.04 of 11See more

supabase supabse 0.8.0

4 of the 11 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
supabase/edge-runtime:v1.74.02781daf92394
coreutils@9.1-1
no fix listed
supabase/postgres-meta:v0.96.6a84cc713585e
coreutils@9.1-1
no fix listed
supabase/realtime:v2.102.3aa1c92c0cf32
coreutils@9.1-1
no fix listed
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
coreutils@9.1-1
no fix listed

Open the chart page →

18,327
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
coreutils@9.7-3
no fix listed

Open the chart page →

3,263
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
coreutils@9.7-3
no fix listed

Open the chart page →

1,849
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
coreutils@9.7-3
no fix listed

Open the chart page →

1,849
teamcity-serverteamcity-server3.3.51 of 2See more

teamcity-server teamcity-server 3.3.5

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/haproxy:3.2de601ccc9a79
coreutils@9.7-3
no fix listed

Open the chart page →

846
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
coreutils@9.7-3+dhi3
no fix listed

Open the chart page →

2,563
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
coreutils@9.1-1
no fix listed

Open the chart page →

9,119
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
coreutils@9.1-1
no fix listed

Open the chart page →

9,119
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
coreutils@9.7-3
no fix listed

Open the chart page →

13,017
typemilltypemill-helm-chart2.2.02 of 2See more

typemill typemill-helm-chart 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
kixote/typemilldigest-pinned4e9dff179519
coreutils@9.7-3
no fix listed
kixote/typemilldigest-pinned628f79a08cc7
coreutils@9.7-3
no fix listed

Open the chart page →

5,474
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
coreutils@9.1-1
no fix listed

Open the chart page →

12,672
taigaunxwaresVerified publisher2026.3.82 of 6See more

taiga unxwares 2026.3.8

2 of the 6 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
coreutils@9.7-3
no fix listed
taigaio/taiga-protected:latestfd4568a97a59
coreutils@9.7-3
no fix listed

Open the chart page →

9,193
varnish-cachevarnishVerified publisher1.1.11 of 1See more

varnish-cache varnish 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/varnish:7.5.04d0bb287d87b
coreutils@9.1-1
no fix listed

Open the chart page →

4,339
varnish-ingress-controllervarnish-ingress-controllerVerified publisher0.5.01 of 1See more

varnish-ingress-controller varnish-ingress-controller 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
mariusm/vingress:0.5.0b3db186c3d72
coreutils@9.7-3
no fix listed

Open the chart page →

2,318
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
coreutils@9.1-1
no fix listed

Open the chart page →

5,259
waldurwaldur-chartsVerified publisher8.1.22 of 3See more

waldur waldur-charts 8.1.2

2 of the 3 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
coreutils@9.7-3
no fix listed
opennode/waldur-mastermind:8.1.24c82b15d9042
coreutils@9.7-3
no fix listed

Open the chart page →

4,901
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
coreutils@9.7-3
no fix listed

Open the chart page →

7,764
wordpress-helmwordpress-helm0.2.91 of 4See more

wordpress-helm wordpress-helm 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
coreutils@9.7-3
no fix listed

Open the chart page →

8,320
workflows-aggregatorworkflows-aggregatorVerified publisher0.16.91 of 1See more

workflows-aggregator workflows-aggregator 0.16.9

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

1,358
workflows-sinkworkflows-sinkVerified publisher0.16.31 of 1See more

workflows-sink workflows-sink 0.16.3

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
coreutils@9.1-1
no fix listed

Open the chart page →

1,414
yugawareyugabyteVerified publisher2026.1.11 of 3See more

yugaware yugabyte 2026.1.1

1 of the 3 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/postgres:14.22eba8ddbdd837
coreutils@9.7-3
no fix listed

Open the chart page →

2,640
zcash-stackzcashVerified publisher0.4.51 of 2See more

zcash-stack zcash 0.4.5

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
electriccoinco/lightwalletd:v0.5.42ae3a551e111
coreutils@9.7-3
no fix listed

Open the chart page →

2,919
changedetection-iozekker6Verified publisher1.99.01 of 1See more

changedetection-io zekker6 1.99.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.47bb6963b730d
coreutils@9.1-1
no fix listed

Open the chart page →

2,612
crowdsec-web-uizekker6Verified publisher0.51.01 of 1See more

crowdsec-web-ui zekker6 0.51.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
coreutils@9.7-3
no fix listed

Open the chart page →

1,433
mikochizer0tonin1.11.01 of 1See more

mikochi zer0tonin 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
zer0tonin/mikochi:1.11.009872bae1554
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

995
backendzymtraceOfficialVerified publisher26.9.11 of 6See more

backend zymtrace 26.9.1

1 of the 6 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/postgres:17.4304ab8135187
coreutils@9.1-1
no fix listed

Open the chart page →

10,432
abstract-nodeabstract-nodeVerified publisher0.1.491 of 2See more

abstract-node abstract-node 0.1.49

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
matterlabs/external-node:9734bf2-17870579939295dadc06bdf3b
coreutils@9.1-1
no fix listed

Open the chart page →

4,577
jenkinsaditisingh-jenkins1.0.01 of 1See more

jenkins aditisingh-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
coreutils@9.7-3
no fix listed

Open the chart page →

2,498
gotenbergadnoctemVerified publisher0.5.01 of 1See more

gotenberg adnoctem 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.37.0f29984bd1e22
coreutils@9.7-3
no fix listed

Open the chart page →

5,877
lhciadnoctemVerified publisher0.1.01 of 1See more

lhci adnoctem 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
coreutils@9.1-1
no fix listed

Open the chart page →

1,270
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
coreutils@9.1-1
no fix listed

Open the chart page →

3,838
outlineadnoctemVerified publisher0.1.21 of 1See more

outline adnoctem 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
outlinewiki/outline:1.10.1832051f039b4
coreutils@9.7-3
no fix listed

Open the chart page →

1,238
uptime-kumaadnoctemVerified publisher0.4.11 of 1See more

uptime-kuma adnoctem 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
coreutils@9.1-1
no fix listed

Open the chart page →

30,326
ahnlich-dbahnlich-dbVerified publisher0.1.11 of 1See more

ahnlich-db ahnlich-db 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
ghcr.io/deven96/ahnlich-db:latest45d8b5aab491
coreutils@9.7-3
no fix listed

Open the chart page →

1,609
airbyte-keycloakairbyteVerified publisher0.1.21 of 2See more

airbyte-keycloak airbyte 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
coreutils@9.7-3
no fix listed

Open the chart page →

1,649
pod-sweeperairbyteVerified publisher1.5.11 of 1See more

pod-sweeper airbyte 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
airbyte/pod-sweeper:1.5.198d2c39d512e
coreutils@9.1-1
no fix listed

Open the chart page →

4,956
airbyteairbyte-v2Verified publisher2.3.01 of 10See more

airbyte airbyte-v2 2.3.0

1 of the 10 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
airbyte/manifest-server:7.28.2deec511b51c3
coreutils@9.1-1
no fix listed

Open the chart page →

11,776
akto-ai-guardrails-v2akto0.3.04 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

4 of the 6 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
aktosecurity/akto-agent-guard-anonymizer:1.1.4d4b100cbdc47
coreutils@9.7-3
no fix listed
aktosecurity/akto-agent-guard-embedder:1.1.4dbc566b2376c
coreutils@9.7-3
no fix listed
aktosecurity/akto-agent-guard-worker:1.1.4666eaffd5362
coreutils@9.7-3
no fix listed
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1

Open the chart page →

9,505
akto-central-setupakto1.1.102 of 5See more

akto-central-setup akto 1.1.10

2 of the 5 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1
library/eclipse-temurin:211f79c73404fb
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1

Open the chart page →

5,118
akto-hybrid-redactakto1.44.61 of 5See more

akto-hybrid-redact akto 1.44.6

1 of the 5 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.4_local5bda14f66e8e
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1

Open the chart page →

4,098
akto-mini-runtimeakto0.7.222 of 3See more

akto-mini-runtime akto 0.7.22

2 of the 3 container images this version deploys carry CVE-2026-56391.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8be3ed26f746
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
public.ecr.aws/aktosecurity/redis:latestV8.6.2832d7785830f
coreutils@9.7-3
no fix listed

Open the chart page →

2,826

Container images carrying it

1,374 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/wi_stefan/consent-manager:0.0.656399619568b
coreutils@9.1-1
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
coreutils@9.1-1
no fix listed
1
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
coreutils@9.1-1
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
coreutils@9.1-1
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
coreutils@9.7-3ubuntu2
coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu25
9.7-3ubuntu2.1
9.7-3ubuntu2.1
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
coreutils@9.1-1
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
coreutils@9.7-3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
coreutils@9.7-3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
coreutils@9.1-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
coreutils@9.1-1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
coreutils@9.7-3
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
coreutils@9.1-1
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
coreutils@9.1-1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
coreutils@9.1-1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
coreutils@9.1-1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
coreutils@9.1-1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
coreutils@9.7-3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
coreutils@9.1-1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
coreutils@9.1-1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
coreutils@9.1-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
coreutils@9.1-1
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.