StackRadar

CVE-2026-6476

High

Advisory

Published 14 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
123
of 17,781 indexed, latest versions
Container images
105
deployed by those charts
Fix available
6 of 10
affected packages

PostgreSQL pg_createsubscriber allows SQL injection via subscription name

Carried by container images the latest versions of 123 of 17,781 indexed charts deploy, on 105 images.

Affected packageAffected versionsFixed inImages
postgresql-17deb17.5-1, 17.5-1.pgdg130+1, 17.6-0+deb13u1, 17.6-1build1+5 more17.10-0+deb13u1, 17.10-0ubuntu0.25.10.130
postgresql-12deb12.7-0ubuntu0.20.04.1, 12.8-0ubuntu0.20.04.1, 12.9-0ubuntu0.20.04.1, 12.11-0ubuntu0.20.04.1+2 moreno fix listed17
postgresql-14deb14.3-1.pgdg22.04+1, 14.4-0ubuntu0.22.04.1, 14.5-0ubuntu0.22.04.1, 14.6-1.pgdg22.04+1+5 more14.23-0ubuntu0.22.04.113
postgresql18apk18.1-r0, 18.2-r0, 18.3-r018.4-r011
postgresql17apk17.2-r0, 17.4-r0, 17.5-r0, 17.6-r0+2 more17.10-r010
postgresqlbitnami17.2.0-1, 17.2.0-4, 17.4.0-9, 17.5.0-9+4 more17.10.08
postgresql-10deb10.6-0ubuntu0.18.04.1, 10.10-0ubuntu0.18.04.1, 10.12-0ubuntu0.18.04.1, 10.14-0ubuntu0.18.04.1+1 moreno fix listed6
postgresql-16deb16.2-1ubuntu4, 16.6-0ubuntu0.24.04.1, 16.9-0ubuntu0.24.04.1, 16.10-0ubuntu0.24.04.1+1 more16.14-0ubuntu0.24.04.16
postgresql-9.5deb9.5.10-0ubuntu0.16.04, 9.5.14-0ubuntu0.16.04no fix listed3
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
OSV records
ALPINE-CVE-2026-6476BIT-postgresql-2026-6476DEBIAN-CVE-2026-6476UBUNTU-CVE-2026-6476
Also known as
USN-8294-1

Charts affected

123 by stars
ChartLatestAffected imagesRadar Score
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
postgresql-14@14.18-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1

Open the chart page →

6,172
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
postgresql-10@10.10-0ubuntu0.18.04.1
no fix listed

Open the chart page →

24,335
private-action-runnerdatadogVerified publisher1.28.11 of 1See more

private-action-runner datadog 1.28.1

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
gcr.io/datadoghq/private-action-runner:v1.21.05f5918f843a4
postgresql-16@16.13-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1

Open the chart page →

2,125
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
postgresql-14@14.5-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1

Open the chart page →

30,031
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
postgresql-14@14.5-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1

Open the chart page →

29,033
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
postgresql@17.5.0-9
17.10.0

Open the chart page →

4,046
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
postgresql-14@14.6-1.pgdg22.04+1
14.23-0ubuntu0.22.04.1

Open the chart page →

24,917
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
postgresql-14@14.3-1.pgdg22.04+1
14.23-0ubuntu0.22.04.1

Open the chart page →

30,699
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1

Open the chart page →

13,391
rommernail-romm1.0.11 of 1See more

romm ernail-romm 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
rommapp/romm:4.4.1b909e95d1aab
postgresql17@17.7-r0
17.10-r0

Open the chart page →

2,896
fairwinds-insightsfairwinds-stableVerified publisher10.1.101 of 13See more

fairwinds-insights fairwinds-stable 10.1.10

1 of the 13 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
alpine/psql:18.339824ef2b7fc
postgresql18@18.3-r0
18.4-r0

Open the chart page →

3,797
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1

Open the chart page →

5,039
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1
fireflyiii/data-importer:version-2.2.3ab52bf932546
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1

Open the chart page →

10,260
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1

Open the chart page →

4,829
borgmaticgabe565Verified publisher0.10.11 of 1See more

borgmatic gabe565 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
postgresql17@17.2-r0
17.10-r0

Open the chart page →

2,438
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
postgresql-12@12.12-0ubuntu0.20.04.1
no fix listed

Open the chart page →

27,949
octoboxhalkeye0.1.11 of 1See more

octobox halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
octoboxio/octobox:latestd909041c46eb
postgresql18@18.1-r0
18.4-r0

Open the chart page →

3,255
hatchet-hahatchetOfficialVerified publisher0.18.01 of 8See more

hatchet-ha hatchet 0.18.0

1 of the 8 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
17.10.0

Open the chart page →

7,344
hatchet-stackhatchetOfficialVerified publisher0.18.01 of 8See more

hatchet-stack hatchet 0.18.0

1 of the 8 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
17.10.0

Open the chart page →

7,344
castopodhelmforgeVerified publisher1.2.71 of 3See more

castopod helmforge 1.2.7

1 of the 3 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
castopod/castopod:1.15.54e4f0440520f
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1

Open the chart page →

9,342
chiefonboardinghelmforgeVerified publisher1.1.141 of 3See more

chiefonboarding helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1

Open the chart page →

10,849
openaevhelm-openbasVerified publisher2.0.51 of 7See more

openaev helm-openbas 2.0.5

1 of the 7 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
17.10.0

Open the chart page →

7,437
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
17.10.0

Open the chart page →

25,017
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
postgresql-14@14.10-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1

Open the chart page →

14,290
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
postgresql-16@16.9-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1

Open the chart page →

8,967
plausible-analyticsimioVerified publisher0.4.21 of 5See more

plausible-analytics imio 0.4.2

1 of the 5 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
postgresql@17.6.0-0
17.10.0

Open the chart page →

10,418
daveit-at-mOfficialVerified publisher0.2.152 of 11See more

dave it-at-m 0.2.15

2 of the 11 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
postgresql@17.5.0-14
17.10.0
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
postgresql@17.6.0-0
17.10.0

Open the chart page →

15,089
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
postgresql-16@16.2-1ubuntu4
16.14-0ubuntu0.24.04.1

Open the chart page →

45,239
ja-shortenerja-shortenerVerified publisher0.1.01 of 2See more

ja-shortener ja-shortener 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
cr0hn/ja-shortener:v0.1.414482d0bc4a1
postgresql17@17.5-r0
17.10-r0

Open the chart page →

2,089
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1

Open the chart page →

9,103
vaultwardenk8s-home-lab-repo6.2.31 of 1See more

vaultwarden k8s-home-lab-repo 6.2.3

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
vaultwarden/server:1.35.79a8eec71f4a5
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1

Open the chart page →

2,854
librephotosk8sonlabVerified publisher1.1.61 of 7See more

librephotos k8sonlab 1.1.6

1 of the 7 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
postgresql@17.5.0-14
17.10.0

Open the chart page →

14,801
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1

Open the chart page →

4,568
kestra-starterkestraOfficialVerified publisher2.0.11 of 5See more

kestra-starter kestra 2.0.1

1 of the 5 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
library/postgres:17.5aadf2c0696f5
postgresql-17@17.5-1.pgdg130+1
17.10-0+deb13u1

Open the chart page →

5,455
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r5cf63048c9209
postgresql@17.2.0-4
17.10.0

Open the chart page →

12,062
proxysqlklicktippVerified publisher1.3.01 of 1See more

proxysql klicktipp 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
proxysql/proxysql:3.0.8947a7abad45b
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1

Open the chart page →

2,520
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1

Open the chart page →

9,620
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
postgresql-12@12.9-0ubuntu0.20.04.1
no fix listed

Open the chart page →

17,779
novosgamarcusrepo0.1.11 of 2See more

novosga marcusrepo 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
novosga/novosga:latest34b9acbe6e51
postgresql18@18.3-r0
18.4-r0

Open the chart page →

3,706
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1

Open the chart page →

11,950
vaultwardenmt1905027.3.41 of 3See more

vaultwarden mt190502 7.3.4

1 of the 3 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
vaultwarden/server:1.35.443498a94b22f
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1

Open the chart page →

4,710
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
postgresql-14@14.5-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1

Open the chart page →

12,791
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
postgresql-14@14.5-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1

Open the chart page →

12,791
jupyterhub-metricsncsaVerified publisher1.3.01 of 5See more

jupyterhub-metrics ncsa 1.3.0

1 of the 5 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0dcb8c731bb1b
postgresql17@17.8-r0
17.10-r0

Open the chart page →

4,132
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
postgresql-12@12.12-0ubuntu0.20.04.1
no fix listed

Open the chart page →

22,658
firecrawlobeoneVerified publisher3.0.11 of 5See more

firecrawl obeone 3.0.1

1 of the 5 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
postgresql-17@17.9-1.pgdg13+1
17.10-0+deb13u1

Open the chart page →

9,995
comacopencord1.0.02 of 9See more

comac opencord 1.0.0

2 of the 9 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed

Open the chart page →

88,546
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed

Open the chart page →

26,211
freeradiusopencord1.0.41 of 1See more

freeradius opencord 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
postgresql-10@10.12-0ubuntu0.18.04.1
no fix listed

Open the chart page →

15,702
sebaopencord1.0.01 of 17See more

seba opencord 1.0.0

1 of the 17 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
tpdock/freeradius:2.2.93da600c95a49
postgresql-9.5@9.5.10-0ubuntu0.16.04
no fix listed

Open the chart page →

93,855

Container images carrying it

105 by charts deploying them

A fixed version is listed for 6 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
opendatacube/pipelines:wofs-1.225d810e8504b8
postgresql-10@10.6-0ubuntu0.18.04.1
no fix listed
1
opendatacube/restcube:latest91870111837c
postgresql-10@10.10-0ubuntu0.18.04.1
no fix listed
1
opendatacube/wms:latest1b90cdf68831
postgresql-10@10.10-0ubuntu0.18.04.1
no fix listed
1
opendatacube/wps:latest80df355a660b
postgresql-14@14.18-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1
1
openelevation/open-elevation:latest82fb21612e86
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
openkm/openkm-ce:6.3.113bc465a7461b
postgresql-12@12.12-0ubuntu0.20.04.1
no fix listed
1
owncloud/server:10.15.051d9b74fc2a8
postgresql-12@12.19-0ubuntu0.20.04.1
no fix listed
1
oxfordsemantic/rdfox:5.6db17910eb855
postgresql-12@12.9-0ubuntu0.20.04.1
no fix listed
1
oxfordsemantic/rdfox-init:5.6baf570ff968d
postgresql-12@12.9-0ubuntu0.20.04.1
no fix listed
1
photoprism/photoprism:251130db16ee6b1ba3
postgresql-17@17.6-1build1
17.10-0ubuntu0.25.10.1
1
proxysql/proxysql:3.0.8947a7abad45b
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
postgresql-12@12.12-0ubuntu0.20.04.1
no fix listed
1
resurfaceio/resurface:3.7.84d5cda2f64109
postgresql-14@14.17-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1
1
rommapp/romm:4.4.1b909e95d1aab
postgresql17@17.7-r0
17.10-r0
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
postgresql-12@12.11-0ubuntu0.20.04.1
no fix listed
1
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
postgresql-17@17.7-0+deb13u1
17.10-0+deb13u1
1
statcan/ckan:2.93921305425b8
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
postgresql17@17.5-r0
17.10-r0
1
temporalio/admin-tools:1.28cfde8170c92f
postgresql18@18.2-r0
18.4-r0
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
postgresql-14@14.7-1.pgdg22.04+1
14.23-0ubuntu0.22.04.1
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
postgresql-14@14.6-1.pgdg22.04+1
14.23-0ubuntu0.22.04.1
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
postgresql-14@14.3-1.pgdg22.04+1
14.23-0ubuntu0.22.04.1
1
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1
1
tpdock/freeradius:2.2.93da600c95a49
postgresql-9.5@9.5.10-0ubuntu0.16.04
no fix listed
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
postgresql-14@14.11-1.pgdg22.04+1
14.23-0ubuntu0.22.04.1
1
vabene1111/recipes:2.3.50f8d061895e9
postgresql17@17.7-r0
17.10-r0
1
vaultwarden/server:1.35.443498a94b22f
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1
1
vaultwarden/server:1.35.79a8eec71f4a5
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
postgresql-12@12.8-0ubuntu0.20.04.1
no fix listed
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
postgresql-14@14.5-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
postgresql-12@12.8-0ubuntu0.20.04.1
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
postgresql-14@14.5-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1
1
gcr.io/datadoghq/private-action-runner:v1.21.05f5918f843a4
postgresql-16@16.13-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1
1
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
postgresql17@17.2-r0
17.10-r0
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
postgresql-17@17.7-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
postgresql-17@17.9-1.pgdg13+1
17.10-0+deb13u1
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
postgresql18@18.2-r0
18.4-r0
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
postgresql-17@17.6-2.pgdg13+1
17.10-0+deb13u1
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
postgresql17@17.4-r0
17.10-r0
1
ghcr.io/monicahq/monica-next:main8be69156acbb
postgresql-17@17.5-1
17.10-0+deb13u1
1
ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0dcb8c731bb1b
postgresql17@17.8-r0
17.10-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.