StackRadar

CVE-2026-63381

Medium

Advisory

Published 20 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.8
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
168
of 17,781 indexed, latest versions
Container images
183
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 168 of 17,781 indexed charts deploy, on 183 images.

Affected packageAffected versionsFixed inImages
libeventdeb2.1.8-stable-4build1, 2.1.11-stable-1, 2.1.12-stable-1, 2.1.12-stable-1build3+3 more2.1.8-stable-4ubuntu0.1~esm1, 2.1.11-stable-1ubuntu0.1~esm1, 2.1.12-stable-1ubuntu0.1, 2.1.12-stable-9ubuntu2.1+2 more183
OSV records
DEBIAN-CVE-2026-63381UBUNTU-CVE-2026-63381ECHO-b3a5-0d83-0d17
Also known as
USN-8710-1

Charts affected

168 by stars
ChartLatestAffected imagesRadar Score
pgbouncersinextraVerified publisher0.17.01 of 1See more

pgbouncer sinextra 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/pgbouncer:16.1518f1121ba0a4
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

1,915
yopasssky-sailVerified publisher1.3.11 of 2See more

yopass sky-sail 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
library/memcached:1.6.409ae868852d0b
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1

Open the chart page →

2,986
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libevent@2.1.11-stable-1
2.1.11-stable-1ubuntu0.1~esm1

Open the chart page →

30,687
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
sashafefler/spacecapybara_app:latestf96d7804c0ca
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

11,888
servicexssl-hep1.8.510 of 16See more

servicex ssl-hep 1.8.5

10 of the 16 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
library/python:3.1070c9cc675605
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex_app:v1.8.51d12f943cec5
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1

Open the chart page →

66,266
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

20,223
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

13,390
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

11,199
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

11,648
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

28,858
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

14,358
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
libevent@2.1.12-stable-1build3
2.1.12-stable-1ubuntu0.1

Open the chart page →

13,459
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
libevent@2.1.11-stable-1
2.1.11-stable-1ubuntu0.1~esm1

Open the chart page →

15,230
wordpress-alpinewordpress-alpine1.5.181 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

1 of the 6 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
library/memcached:1.6.45dc561d52bb8a
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1

Open the chart page →

3,990
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-63381.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libevent@2.1.12-stable-1build3
2.1.12-stable-1ubuntu0.1

Open the chart page →

14,100

Container images carrying it

183 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
libevent@2.1.12-stable-8
no fix listed
1
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
libevent@2.1.12-stable-8
no fix listed
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
libevent@2.1.11-stable-1
2.1.11-stable-1ubuntu0.1~esm1
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
libevent@2.1.12-stable-8
no fix listed
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
libevent@2.1.12-stable-8
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
libevent@2.1.12-stable-8
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
libevent@2.1.12-stable-8
no fix listed
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
libevent@2.1.12-stable-8
no fix listed
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
libevent@2.1.12-stable-8
no fix listed
1
ghcr.io/port-labs/port-agent:v0.8.12c92d1e223f5c
libevent@2.1.12-stable-10+b1
2.1.12-stable-10+e1
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
libevent@2.1.12-stable-8
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
libevent@2.1.12-stable-8
no fix listed
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
1
ghcr.io/sergelogvinov/pgbouncer:16.1518f1121ba0a4
libevent@2.1.12-stable-8
no fix listed
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
libevent@2.1.12-stable-8
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
libevent@2.1.12-stable-8
no fix listed
1
ghcr.io/zammad/zammad:7.1.3-0011e65123a43ecc
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
libevent@2.1.12-stable-8
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
libevent@2.1.12-stable-8
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
libevent@2.1.12-stable-8
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
libevent@2.1.12-stable-8
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
libevent@2.1.12-stable-8
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
libevent@2.1.12-stable-8
no fix listed
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
libevent@2.1.8-stable-4build1
2.1.8-stable-4ubuntu0.1~esm1
1
quay.io/opstree/memcached:1.6.38-alpine3.22cabbdfd2c3fe
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libevent@2.1.12-stable-8
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
libevent@2.1.12-stable-8
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
libevent@2.1.11-stable-1
2.1.11-stable-1ubuntu0.1~esm1
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
libevent@2.1.12-stable-8
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
libevent@2.1.12-stable-8
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.