StackRadar

CVE-2026-63385

Critical

Advisory

Published 20 Aug 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.2
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
171
of 17,781 indexed, latest versions
Container images
186
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 171 of 17,781 indexed charts deploy, on 186 images.

Affected packageAffected versionsFixed inImages
libeventdeb2.0.21-stable-1ubuntu1.14.04.1, 2.0.21-stable-2ubuntu0.16.04.1, 2.1.8-stable-4build1, 2.1.11-stable-1+5 more2.0.21-stable-1ubuntu1.14.04.2+esm1, 2.0.21-stable-2ubuntu0.16.04.1+esm1, 2.1.8-stable-4ubuntu0.1~esm1, 2.1.11-stable-1ubuntu0.1~esm1+4 more186
OSV records
DEBIAN-CVE-2026-63385UBUNTU-CVE-2026-63385ECHO-7ffd-12b3-6870
Also known as
USN-8710-1

Charts affected

171 by stars
ChartLatestAffected imagesRadar Score
safe-stacksafe-global0.1.02 of 9See more

safe-stack safe-global 0.1.0

2 of the 9 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
libevent@2.1.12-stable-8
no fix listed
safeglobal/safe-transaction-service:latest80db836cc5d5
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.02 of 6See more

safe-transaction-service safe-global 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
libevent@2.1.12-stable-8
no fix listed
safeglobal/safe-transaction-service:latest80db836cc5d5
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1

Open the chart page →

16,620
unboundschoolguys-helmcharts0.1.11 of 1See more

unbound schoolguys-helmcharts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
mvance/unbound:1.20.04bf67b567f39
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

3,103
pgbouncersinextraVerified publisher0.17.01 of 1See more

pgbouncer sinextra 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/pgbouncer:16.1518f1121ba0a4
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

1,915
yopasssky-sailVerified publisher1.3.11 of 2See more

yopass sky-sail 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
library/memcached:1.6.409ae868852d0b
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1

Open the chart page →

2,986
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libevent@2.1.11-stable-1
2.1.11-stable-1ubuntu0.1~esm1

Open the chart page →

30,687
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
sashafefler/spacecapybara_app:latestf96d7804c0ca
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

11,888
servicexssl-hep1.8.510 of 16See more

servicex ssl-hep 1.8.5

10 of the 16 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
library/python:3.1070c9cc675605
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex_app:v1.8.51d12f943cec5
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1

Open the chart page →

66,266
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

20,223
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

13,390
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

11,199
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

11,648
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

28,858
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libevent@2.1.12-stable-8
no fix listed

Open the chart page →

14,358
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
libevent@2.1.12-stable-1build3
2.1.12-stable-1ubuntu0.1

Open the chart page →

13,459
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
libevent@2.1.11-stable-1
2.1.11-stable-1ubuntu0.1~esm1

Open the chart page →

15,230
wordpress-alpinewordpress-alpine1.5.181 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

1 of the 6 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
library/memcached:1.6.45dc561d52bb8a
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1

Open the chart page →

3,990
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-63385.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libevent@2.1.12-stable-1build3
2.1.12-stable-1ubuntu0.1

Open the chart page →

14,100

Container images carrying it

186 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/memcached:1.6:1.6.4575c93cc91e76
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
5
library/node:ltsbe23f54a88d3
libevent@2.1.12-stable-8
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
libevent@2.1.12-stable-8
no fix listed
3
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
libevent@2.1.12-stable-8
no fix listed
2
library/python:3.7eedf63967cdb
libevent@2.1.12-stable-8
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
libevent@2.1.12-stable-8
no fix listed
2
polyaxon/polyaxon-agent:2.16.4eca6952b20e6
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
2
polyaxon/polyaxon-cli:2.16.4024ff3fa775e
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
libevent@2.1.12-stable-8
no fix listed
2
safeglobal/safe-transaction-service:latest80db836cc5d5
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
libevent@2.1.11-stable-1
2.1.11-stable-1ubuntu0.1~esm1
2
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
libevent@2.1.12-stable-9ubuntu2
2.1.12-stable-9ubuntu2.1
1
arilot/docker-bitcoind:0.17.127a4f7e0f9f1
libevent@2.0.21-stable-2ubuntu0.16.04.1
2.0.21-stable-2ubuntu0.16.04.1+esm1
1
aristidetm/basic-notebook:3.6.5469dbc951224
libevent@2.1.12-stable-8
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
libevent@2.1.12-stable-8
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
libevent@2.1.12-stable-8
no fix listed
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
libevent@2.1.12-stable-8
no fix listed
1
bitnamilegacy/memcached:1.6.24-debian-12-r01d80b6a96f00
libevent@2.1.12-stable-8
no fix listed
1
bitnamilegacy/memcached:1.6.29-debian-12-r4ff0e7239c17c
libevent@2.1.12-stable-8
no fix listed
1
bitnamilegacy/pgbouncer:1.23.192356da09704
libevent@2.1.12-stable-8
no fix listed
1
bitnami/memcached:1.6.38dd8f2cba9a5b
libevent@2.1.12-stable-8
no fix listed
1
bmeares/meerschaum:2.8.48e9c5bacaa82
libevent@2.1.12-stable-8
no fix listed
1
bnjbvr/kresus:0.22.137e216b182c8
libevent@2.1.12-stable-8
no fix listed
1
boky/postfix:5.1.0aafc77238423
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
1
boky/postfix:4.4.0f3f247fd4252
libevent@2.1.12-stable-8
no fix listed
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
libevent@2.1.12-stable-8
no fix listed
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
libevent@2.1.12-stable-1build3
2.1.12-stable-1ubuntu0.1
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
1
coturn/coturn:4.10.0-r1f4c2af06c3c5
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
1
cradlepoint/pgbouncer:1.0.18f5720b0cd03
libevent@2.1.8-stable-4build1
2.1.8-stable-4ubuntu0.1~esm1
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
libevent@2.1.12-stable-8
no fix listed
1
ddosify/selfhosted_backend:3.2.93c11e3182652
libevent@2.1.12-stable-8
no fix listed
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
libevent@2.1.12-stable-8
no fix listed
1
defectdojo/defectdojo-django:3.3.1b140a89a34e2
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
1
domainmod/domainmod:4.23.04017bfe4c597
libevent@2.1.12-stable-8
no fix listed
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
1
fireflyiii/core:version-6.6.6ae69fdd95cde
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
libevent@2.1.12-stable-8
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
libevent@2.1.12-stable-8
no fix listed
1
folioci/mod-z3950:latest2493041ce880
libevent@2.1.12-stable-10+b1
2.1.13-stable-1~deb13u1
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
libevent@2.1.12-stable-1build3
2.1.12-stable-1ubuntu0.1
1
haugene/transmission-openvpn:4.0059216cfae4b
libevent@2.1.11-stable-1
2.1.11-stable-1ubuntu0.1~esm1
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
libevent@2.1.12-stable-8
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
libevent@2.1.12-stable-8
no fix listed
1
itzg/minecraft-server:2026.9.04e29d14082d9
libevent@2.1.12-stable-9ubuntu2
2.1.12-stable-9ubuntu2.1
1
jbtronics/part-db1:latest5db71f6db59d
libevent@2.1.12-stable-8
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
libevent@2.1.12-stable-8
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.