StackRadar

CVE-2026-6476

High

Advisory

Published 14 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
123
of 17,781 indexed, latest versions
Container images
105
deployed by those charts
Fix available
6 of 10
affected packages

PostgreSQL pg_createsubscriber allows SQL injection via subscription name

Carried by container images the latest versions of 123 of 17,781 indexed charts deploy, on 105 images.

Affected packageAffected versionsFixed inImages
postgresql-17deb17.5-1, 17.5-1.pgdg130+1, 17.6-0+deb13u1, 17.6-1build1+5 more17.10-0+deb13u1, 17.10-0ubuntu0.25.10.130
postgresql-12deb12.7-0ubuntu0.20.04.1, 12.8-0ubuntu0.20.04.1, 12.9-0ubuntu0.20.04.1, 12.11-0ubuntu0.20.04.1+2 moreno fix listed17
postgresql-14deb14.3-1.pgdg22.04+1, 14.4-0ubuntu0.22.04.1, 14.5-0ubuntu0.22.04.1, 14.6-1.pgdg22.04+1+5 more14.23-0ubuntu0.22.04.113
postgresql18apk18.1-r0, 18.2-r0, 18.3-r018.4-r011
postgresql17apk17.2-r0, 17.4-r0, 17.5-r0, 17.6-r0+2 more17.10-r010
postgresqlbitnami17.2.0-1, 17.2.0-4, 17.4.0-9, 17.5.0-9+4 more17.10.08
postgresql-10deb10.6-0ubuntu0.18.04.1, 10.10-0ubuntu0.18.04.1, 10.12-0ubuntu0.18.04.1, 10.14-0ubuntu0.18.04.1+1 moreno fix listed6
postgresql-16deb16.2-1ubuntu4, 16.6-0ubuntu0.24.04.1, 16.9-0ubuntu0.24.04.1, 16.10-0ubuntu0.24.04.1+1 more16.14-0ubuntu0.24.04.16
postgresql-9.5deb9.5.10-0ubuntu0.16.04, 9.5.14-0ubuntu0.16.04no fix listed3
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
OSV records
ALPINE-CVE-2026-6476BIT-postgresql-2026-6476DEBIAN-CVE-2026-6476UBUNTU-CVE-2026-6476
Also known as
USN-8294-1

Charts affected

123 by stars
ChartLatestAffected imagesRadar Score
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1

Open the chart page →

5,366
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
postgresql-14@14.4-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1

Open the chart page →

9,145
weblateweblateOfficialVerified publisher0.5.361 of 3See more

weblate weblate 0.5.36

1 of the 3 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
postgresql@17.5.0-14
17.10.0

Open the chart page →

6,699
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
grafana/oncall:v1.16.5499851658393
postgresql17@17.6-r0
17.10-r0

Open the chart page →

16,251
zabbixcetic3.1.32 of 5See more

zabbix cetic 3.1.3

2 of the 5 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
postgresql-14@14.5-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
postgresql-14@14.5-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1

Open the chart page →

33,725
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
postgresql-17@17.5-1
17.10-0+deb13u1

Open the chart page →

5,634
paperless-ngxpaperless-ngxVerified publisher0.3.221 of 3See more

paperless-ngx paperless-ngx 0.3.22

1 of the 3 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
17.10.0

Open the chart page →

8,489
zabbix-serveraekondratievVerified publisher1.0.62 of 4See more

zabbix-server aekondratiev 1.0.6

2 of the 4 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
postgresql-12@12.8-0ubuntu0.20.04.1
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
postgresql-12@12.8-0ubuntu0.20.04.1
no fix listed

Open the chart page →

30,668
convoyconvoyVerified publisher3.7.131 of 3See more

convoy convoy 3.7.13

1 of the 3 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
17.10.0

Open the chart page →

5,896
coturnjaconiVerified publisher1.0.51 of 1See more

coturn jaconi 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
coturn/coturn:4.10.0-r1f4c2af06c3c5
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1

Open the chart page →

2,901
headwind-mdmchristianhuthVerified publisher5.10.11 of 2See more

headwind-mdm christianhuth 5.10.1

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
17.10.0

Open the chart page →

5,870
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1

Open the chart page →

9,316
healthchecksgabe565Verified publisher0.17.01 of 1See more

healthchecks gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
postgresql17@17.4-r0
17.10-r0

Open the chart page →

2,286
coreinstill-aiOfficialVerified publisher0.1.751 of 15See more

core instill-ai 0.1.75

1 of the 15 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.28cfde8170c92f
postgresql18@18.2-r0
18.4-r0

Open the chart page →

30,816
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
postgresql18@18.2-r0
18.4-r0

Open the chart page →

4,634
nebraskanebraska3.0.01 of 2See more

nebraska nebraska 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.042a8200d3597
postgresql@17.5.0-14
17.10.0

Open the chart page →

4,060
freeradiusstartechnicaVerified publisher1.2.01 of 1See more

freeradius startechnica 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.2.8af6fd34a5b78
postgresql-14@14.18-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1

Open the chart page →

5,751
huginnutkuozdemirVerified publisher2.2.11 of 4See more

huginn utkuozdemir 2.2.1

1 of the 4 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
postgresql-10@10.15-0ubuntu0.18.04.1
no fix listed

Open the chart page →

18,137
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.01 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1

Open the chart page →

12,037
open-elevationbeeinventor0.1.01 of 2See more

open-elevation beeinventor 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
openelevation/open-elevation:latest82fb21612e86
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed

Open the chart page →

13,145
cert-vaultcert-vaultOfficialVerified publisher2.12.01 of 7See more

cert-vault cert-vault 2.12.0

1 of the 7 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.4.0-debian-12-r11fb3806e823c2
postgresql@17.4.0-9
17.10.0

Open the chart page →

15,863
cosmotech-copilot-apicosmotech-apiVerified publisher0.1.11 of 1See more

cosmotech-copilot-api cosmotech-api 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
postgresql-17@17.7-0+deb13u1
17.10-0+deb13u1

Open the chart page →

11,205
datacube-explorerdatacube-charts0.5.321 of 1See more

datacube-explorer datacube-charts 0.5.32

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
opendatacube/explorer:latest120457ffcd69
postgresql-16@16.10-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1

Open the chart page →

4,854
dbrepodbrepo1.13.31 of 25See more

dbrepo dbrepo 1.13.3

1 of the 25 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
postgresql@17.6.0-0
17.10.0

Open the chart page →

52,635
domain-lockerdomain-locker0.2.81 of 3See more

domain-locker domain-locker 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
lissy93/domain-locker:latestd3c95edc0a8b
postgresql18@18.3-r0
18.4-r0

Open the chart page →

1,882
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
postgresql-17@17.6-2.pgdg13+1
17.10-0+deb13u1

Open the chart page →

15,712
iris-webappiris-webapp0.2.41 of 2See more

iris-webapp iris-webapp 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1

Open the chart page →

11,764
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed

Open the chart page →

113,791
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
postgresql-17@17.6-1build1
17.10-0ubuntu0.25.10.1

Open the chart page →

11,103
paperless-ngxpaperlessVerified publisher0.4.01 of 3See more

paperless-ngx paperless 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresqldigest-pinned926356130b77
postgresql@17.6.0-2
17.10.0

Open the chart page →

8,489
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
postgresql-14@14.17-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1

Open the chart page →

7,432
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
postgresql-17@17.7-0+deb13u1
17.10-0+deb13u1

Open the chart page →

7,126
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed

Open the chart page →

24,930
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1

Open the chart page →

12,907
linkstackadnoctemVerified publisher0.4.01 of 1See more

linkstack adnoctem 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
linkstackorg/linkstack:latest1c8b05399ee4
postgresql17@17.8-r0
17.10-r0

Open the chart page →

2,092
antigenic-docuseal-helm-chartantigenic-docuseal-helm-chartVerified publisher0.2.01 of 1See more

antigenic-docuseal-helm-chart antigenic-docuseal-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
docuseal/docuseal:2.4.17493fd7f6728
postgresql18@18.3-r0
18.4-r0

Open the chart page →

2,766
appwriteappwrite-helmVerified publisher1.3.21 of 8See more

appwrite appwrite-helm 1.3.2

1 of the 8 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
postgresql18@18.2-r0
18.4-r0

Open the chart page →

9,847
arlas-aiasarlas-stackVerified publisher28.8.01 of 22See more

arlas-aias arlas-stack 28.8.0

1 of the 22 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
postgresql@17.6.0-0
17.10.0

Open the chart page →

40,238
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
postgresql-14@14.7-1.pgdg22.04+1
14.23-0ubuntu0.22.04.1

Open the chart page →

32,501
blackduck-alertblackduck8.4.01 of 4See more

blackduck-alert blackduck 8.4.0

1 of the 4 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
postgresql18@18.3-r0
18.4-r0

Open the chart page →

4,292
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
galaxy/galaxy-stable:v18.018e577a626dfd
postgresql-9.3@9.3.22-0ubuntu0.14.04
no fix listed

Open the chart page →

70,895
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
postgresql@17.5.0-14
17.10.0

Open the chart page →

13,220
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
opencsghq/psql:latest57def8e77d0f
postgresql17@17.2-r0
17.10-r0

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
opencsghq/psql:latest57def8e77d0f
postgresql17@17.2-r0
17.10-r0

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
opencsghq/psql:latest57def8e77d0f
postgresql17@17.2-r0
17.10-r0

Open the chart page →

6,632
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
postgresql-10@10.10-0ubuntu0.18.04.1
no fix listed

Open the chart page →

27,728
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
postgresql-10@10.14-0ubuntu0.18.04.1
no fix listed

Open the chart page →

18,863
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
postgresql-16@16.6-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
postgresql-16@16.6-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1

Open the chart page →

5,974
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
postgresql-10@10.6-0ubuntu0.18.04.1
no fix listed

Open the chart page →

22,405

Container images carrying it

105 by charts deploying them

A fixed version is listed for 6 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.