StackRadar

CVE-2026-61627

Medium

Advisory

Published 14 Jul 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
56
of 17,781 indexed, latest versions
Container images
53
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 56 of 17,781 indexed charts deploy, on 53 images.

Affected packageAffected versionsFixed inImages
libassdeb0.13.1-1, 1:0.14.0-1, 1:0.14.0-2, 1:0.15.2-1+4 more1:0.17.1-1+deb12u1, 1:0.17.3-1+deb13u153
OSV records
UBUNTU-CVE-2026-61627DEBIAN-CVE-2026-61627

Charts affected

56 by stars
ChartLatestAffected imagesRadar Score
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-61627.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
libass@1:0.17.4-2
no fix listed

Open the chart page →

10,348
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-61627.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libass@1:0.17.1-2build1
no fix listed

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-61627.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libass@1:0.17.1-2build1
no fix listed

Open the chart page →

12,460
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-61627.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
libass@1:0.17.1-1
1:0.17.1-1+deb12u1

Open the chart page →

9,616
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-61627.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
libass@1:0.15.2-1
no fix listed

Open the chart page →

9,347
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-61627.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libass@1:0.15.2-1
no fix listed

Open the chart page →

14,100

Container images carrying it

53 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ciscolabs/rtsp-client:latesta7b60ec88285
libass@1:0.14.0-2
no fix listed
3
ciscolabs/rtsp-server:latestb59fc10bb821
libass@1:0.14.0-2
no fix listed
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
libass@0.13.1-1
no fix listed
3
kurento/kurento-media-server:latest03c0d34d0828
libass@1:0.17.1-2build1
no fix listed
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libass@1:0.14.0-2
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
libass@1:0.17.1-1
1:0.17.1-1+deb12u1
2
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libass@1:0.14.0-2
no fix listed
1
archivebox/archivebox:0.7.41a5a37331091
libass@1:0.17.1-1
1:0.17.1-1+deb12u1
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
libass@1:0.14.0-2
no fix listed
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libass@1:0.14.0-2
no fix listed
1
castopod/castopod:1.12.101fd37280cbb2
libass@1:0.17.1-1
1:0.17.1-1+deb12u1
1
castopod/castopod:1.15.54e4f0440520f
libass@1:0.17.3-1+b1
1:0.17.3-1+deb13u1
1
chocobozzz/peertube:v8.1.5052712130691
libass@1:0.17.3-1+b1
1:0.17.3-1+deb13u1
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
libass@1:0.14.0-1
no fix listed
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libass@1:0.14.0-1
no fix listed
1
haveagitgat/tdarr:2.00.181256348872ce
libass@1:0.14.0-2
no fix listed
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
libass@1:0.14.0-2
no fix listed
1
instill/artifact-backend:b28766ac4a393e601ed
libass@1:0.17.3-1+b1
1:0.17.3-1+deb13u1
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libass@1:0.14.0-2
no fix listed
1
jaedb/iris:latest048cfbf58d57
libass@1:0.17.1-1
1:0.17.1-1+deb12u1
1
josh5/unmanic:0.2.64d49c4816260
libass@1:0.15.2-1
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
libass@1:0.17.1-1
1:0.17.1-1+deb12u1
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
libass@1:0.17.1-2build1
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
libass@1:0.17.1-2build1
no fix listed
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
libass@1:0.17.1-2build1
no fix listed
1
linuxserver/jellyfin:10.7.72427dde159a2
libass@1:0.14.0-2
no fix listed
1
livekit/ingress:v1.2.21ab01641b366
libass@1:0.15.2-1
no fix listed
1
mlikiowa/napcat-docker:latest1336a777f9a4
libass@1:0.15.2-1
no fix listed
1
opea/speecht5:1.0249afad3d268
libass@1:0.17.1-1
1:0.17.1-1+deb12u1
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
libass@1:0.17.1-1
1:0.17.1-1+deb12u1
1
photoprism/photoprism:220629-jammy2954334adbda
libass@1:0.15.2-1
no fix listed
1
photoprism/photoprism:260601650c6ad5a651
libass@1:0.17.4-2
no fix listed
1
photoprism/photoprism:260728958642220223
libass@1:0.17.4-2
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
libass@1:0.17.1-2build1
no fix listed
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
libass@1:0.15.2-1
no fix listed
1
scrapinghub/splash:3.4.1a5f89bc84606
libass@1:0.14.0-1
no fix listed
1
sismics/docs:v1.10f4b0ef019cf1
libass@1:0.14.0-1
no fix listed
1
stashapp/stash:latest24dbd7607174
libass@1:0.14.0-2
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libass@0.13.1-1
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libass@1:0.15.2-1
no fix listed
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libass@1:0.15.2-1
no fix listed
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
libass@1:0.17.1-1
1:0.17.1-1+deb12u1
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libass@1:0.14.0-2
no fix listed
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
libass@1:0.14.0-2
no fix listed
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libass@1:0.14.0-2
no fix listed
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
libass@1:0.17.1-1
1:0.17.1-1+deb12u1
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
libass@1:0.14.0-1
no fix listed
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
libass@1:0.17.1-1
1:0.17.1-1+deb12u1
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
libass@1:0.17.1-1
1:0.17.1-1+deb12u1
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
libass@1:0.17.1-1
1:0.17.1-1+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.