StackRadar

CVE-2026-61626

Medium

Advisory

Published 14 Jul 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
40
of 17,781 indexed, latest versions
Container images
38
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 40 of 17,781 indexed charts deploy, on 38 images.

Affected packageAffected versionsFixed inImages
libassdeb0.13.1-1, 1:0.14.0-1, 1:0.14.0-2, 1:0.15.2-1+2 moreno fix listed38
OSV records
UBUNTU-CVE-2026-61626

Charts affected

40 by stars
ChartLatestAffected imagesRadar Score
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
libass@1:0.17.1-2build1
no fix listed

Open the chart page →

19,391
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
libass@1:0.17.1-2build1
no fix listed

Open the chart page →

22,002
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
libass@1:0.14.0-2
no fix listed

Open the chart page →

7,880
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libass@1:0.15.2-1
no fix listed

Open the chart page →

4,244
photoprismandrenarchyVerified publisher8.15.01 of 1See more

photoprism andrenarchy 8.15.0

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
photoprism/photoprism:260728958642220223
libass@1:0.17.4-2
no fix listed

Open the chart page →

8,825
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestd78cd113b2bc
libass@1:0.17.1-2build1
no fix listed

Open the chart page →

3,997
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libass@1:0.14.0-2
no fix listed

Open the chart page →

24,488
bazarrgeek-cookbookVerified publisher10.6.21 of 1See more

bazarr geek-cookbook 10.6.2

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
libass@1:0.14.0-2
no fix listed

Open the chart page →

17,377
games-on-whalesgeek-cookbookVerified publisher1.8.21 of 7See more

games-on-whales geek-cookbook 1.8.2

1 of the 7 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libass@1:0.14.0-2
no fix listed

Open the chart page →

35,305
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
libass@1:0.14.0-2
no fix listed

Open the chart page →

15,856
tdarrgeek-cookbookVerified publisher4.6.21 of 2See more

tdarr geek-cookbook 4.6.2

1 of the 2 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
haveagitgat/tdarr:2.00.181256348872ce
libass@1:0.14.0-2
no fix listed

Open the chart page →

31,000
napcatredish101Verified publisher0.1.31 of 1See more

napcat redish101 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
mlikiowa/napcat-docker:latest1336a777f9a4
libass@1:0.15.2-1
no fix listed

Open the chart page →

7,405
smarter-demosmarterOfficialVerified publisher0.1.52 of 7See more

smarter-demo smarter 0.1.5

2 of the 7 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
libass@1:0.14.0-2
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libass@1:0.14.0-2
no fix listed

Open the chart page →

45,832
tdarrvhdirkVerified publisher5.0.52 of 2See more

tdarr vhdirk 5.0.5

2 of the 2 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
libass@1:0.14.0-2
no fix listed
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libass@1:0.14.0-2
no fix listed

Open the chart page →

26,657
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libass@1:0.14.0-2
no fix listed

Open the chart page →

42,126
videoaugmentationassist-iot-video-augmentation0.1.01 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
libass@1:0.14.0-2
no fix listed

Open the chart page →

13,913
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libass@0.13.1-1
no fix listed

Open the chart page →

77,758
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:main-localda995c129e2f
libass@1:0.17.1-2build1
no fix listed

Open the chart page →

19,224
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
libass@1:0.17.1-2build1
no fix listed

Open the chart page →

16,954
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libass@1:0.14.0-2
no fix listed

Open the chart page →

18,230
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
libass@1:0.14.0-1
no fix listed

Open the chart page →

19,215
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
libass@1:0.15.2-1
no fix listed

Open the chart page →

19,503
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
libass@1:0.14.0-1
no fix listed

Open the chart page →

26,944
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libass@1:0.14.0-2
no fix listed

Open the chart page →

17,929
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libass@1:0.14.0-2
no fix listed

Open the chart page →

18,066
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
libass@1:0.15.2-1
no fix listed

Open the chart page →

10,716
elastictranscoderluiscajl0.46.02 of 4See more

elastictranscoder luiscajl 0.46.0

2 of the 4 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
elastictranscoder/transcoder:627e21dcb4a0327029e6
libass@1:0.14.0-1
no fix listed
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libass@1:0.14.0-1
no fix listed

Open the chart page →

58,160
cameramedia-streaming-meshVerified publisher0.2.52 of 3See more

camera media-streaming-mesh 0.2.5

2 of the 3 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
libass@1:0.14.0-2
no fix listed
ciscolabs/rtsp-server:latestb59fc10bb821
libass@1:0.14.0-2
no fix listed

Open the chart page →

18,608
msm-rtspmedia-streaming-meshVerified publisher0.0.22 of 2See more

msm-rtsp media-streaming-mesh 0.0.2

2 of the 2 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
libass@1:0.14.0-2
no fix listed
ciscolabs/rtsp-server:latestb59fc10bb821
libass@1:0.14.0-2
no fix listed

Open the chart page →

18,608
rtspmedia-streaming-meshVerified publisher0.0.142 of 2See more

rtsp media-streaming-mesh 0.0.14

2 of the 2 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
libass@1:0.14.0-2
no fix listed
ciscolabs/rtsp-server:latestb59fc10bb821
libass@1:0.14.0-2
no fix listed

Open the chart page →

18,608
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
libass@1:0.14.0-1
no fix listed

Open the chart page →

27,633
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
libass@0.13.1-1
no fix listed

Open the chart page →

63,223
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libass@0.13.1-1
no fix listed

Open the chart page →

42,614
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libass@0.13.1-1
no fix listed

Open the chart page →

29,124
nadekobotryuunosukeds30.1.21 of 2See more

nadekobot ryuunosukeds3 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
libass@1:0.15.2-1
no fix listed

Open the chart page →

8,619
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
libass@1:0.17.4-2
no fix listed

Open the chart page →

10,348
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libass@1:0.17.1-2build1
no fix listed

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libass@1:0.17.1-2build1
no fix listed

Open the chart page →

12,460
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
libass@1:0.15.2-1
no fix listed

Open the chart page →

9,347
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-61626.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libass@1:0.15.2-1
no fix listed

Open the chart page →

14,100

Container images carrying it

38 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ciscolabs/rtsp-client:latesta7b60ec88285
libass@1:0.14.0-2
no fix listed
3
ciscolabs/rtsp-server:latestb59fc10bb821
libass@1:0.14.0-2
no fix listed
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
libass@0.13.1-1
no fix listed
3
kurento/kurento-media-server:latest03c0d34d0828
libass@1:0.17.1-2build1
no fix listed
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libass@1:0.14.0-2
no fix listed
2
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libass@1:0.14.0-2
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
libass@1:0.14.0-2
no fix listed
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libass@1:0.14.0-2
no fix listed
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
libass@1:0.14.0-1
no fix listed
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libass@1:0.14.0-1
no fix listed
1
haveagitgat/tdarr:2.00.181256348872ce
libass@1:0.14.0-2
no fix listed
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
libass@1:0.14.0-2
no fix listed
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libass@1:0.14.0-2
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
libass@1:0.15.2-1
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
libass@1:0.17.1-2build1
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
libass@1:0.17.1-2build1
no fix listed
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
libass@1:0.17.1-2build1
no fix listed
1
linuxserver/jellyfin:10.7.72427dde159a2
libass@1:0.14.0-2
no fix listed
1
livekit/ingress:v1.2.21ab01641b366
libass@1:0.15.2-1
no fix listed
1
mlikiowa/napcat-docker:latest1336a777f9a4
libass@1:0.15.2-1
no fix listed
1
photoprism/photoprism:220629-jammy2954334adbda
libass@1:0.15.2-1
no fix listed
1
photoprism/photoprism:260601650c6ad5a651
libass@1:0.17.4-2
no fix listed
1
photoprism/photoprism:260728958642220223
libass@1:0.17.4-2
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
libass@1:0.17.1-2build1
no fix listed
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
libass@1:0.15.2-1
no fix listed
1
scrapinghub/splash:3.4.1a5f89bc84606
libass@1:0.14.0-1
no fix listed
1
sismics/docs:v1.10f4b0ef019cf1
libass@1:0.14.0-1
no fix listed
1
stashapp/stash:latest24dbd7607174
libass@1:0.14.0-2
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libass@0.13.1-1
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libass@1:0.15.2-1
no fix listed
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libass@1:0.15.2-1
no fix listed
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libass@1:0.14.0-2
no fix listed
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
libass@1:0.14.0-2
no fix listed
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libass@1:0.14.0-2
no fix listed
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
libass@1:0.14.0-1
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
libass@1:0.14.0-2
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libass@1:0.14.0-2
no fix listed
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
libass@1:0.17.1-2build1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.