StackRadar

CVE-2026-64135

Medium

Advisory

Published 20 Jul 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,803 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 10 of 17,803 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
linuxdeb5.15.0-124.134, 5.15.0-143.153, 5.15.0-153.163, 5.15.0-181.191+4 more5.15.0-186.196, 6.8.0-139.13910
OSV records
UBUNTU-CVE-2026-64135
Also known as
USN-8575-1, USN-8729-1

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-64135.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
linux@6.8.0-88.89
6.8.0-139.139

Open the chart page →

19,654
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2026-64135.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
linux@6.8.0-124.124
6.8.0-139.139

Open the chart page →

22,306
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2026-64135.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
linux@5.15.0-153.163
5.15.0-186.196

Open the chart page →

27,465
geonode-k8sgeonode-k8sVerified publisher2.0.01 of 10See more

geonode-k8s geonode-k8s 2.0.0

1 of the 10 container images this version deploys carry CVE-2026-64135.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
linux@5.15.0-181.191
5.15.0-186.196

Open the chart page →

14,147
nominatimrobjuz6.4.21 of 4See more

nominatim robjuz 6.4.2

1 of the 4 container images this version deploys carry CVE-2026-64135.

Container imageDigestPackageFixed in
mediagis/nominatim:5.3.27923a8e67197
linux@6.8.0-124.124
6.8.0-139.139

Open the chart page →

8,826
craftycontrollerdrewburr-labs-helm-chartsVerified publisher0.3.01 of 1See more

craftycontroller drewburr-labs-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-64135.

Container imageDigestPackageFixed in
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
linux@6.8.0-134.134
6.8.0-139.139

Open the chart page →

3,823
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-64135.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
linux@6.8.0-57.59
6.8.0-139.139

Open the chart page →

5,813
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-64135.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
linux@5.15.0-143.153
5.15.0-186.196

Open the chart page →

12,553
opsopsVerified publisher1.2.01 of 2See more

ops ops 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-64135.

Container imageDigestPackageFixed in
shaowenchen/ops-server:latest315444f703f4
linux@5.15.0-153.163
5.15.0-186.196

Open the chart page →

9,214
napcatredish101Verified publisher0.1.31 of 1See more

napcat redish101 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-64135.

Container imageDigestPackageFixed in
mlikiowa/napcat-docker:latest1336a777f9a4
linux@5.15.0-124.134
5.15.0-186.196

Open the chart page →

7,519

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
datamate/seafile-professional:11.0.202dd66b722464
linux@5.15.0-153.163
5.15.0-186.196
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
linux@5.15.0-181.191
5.15.0-186.196
1
gethue/hue:latest7d5c1b9f8a79
linux@5.15.0-143.153
5.15.0-186.196
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
linux@6.8.0-124.124
6.8.0-139.139
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
linux@6.8.0-88.89
6.8.0-139.139
1
mediagis/nominatim:5.3.27923a8e67197
linux@6.8.0-124.124
6.8.0-139.139
1
mlikiowa/napcat-docker:latest1336a777f9a4
linux@5.15.0-124.134
5.15.0-186.196
1
shaowenchen/ops-server:latest315444f703f4
linux@5.15.0-153.163
5.15.0-186.196
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
linux@6.8.0-57.59
6.8.0-139.139
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
linux@6.8.0-134.134
6.8.0-139.139
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.