StackRadar

CVE-2026-6476

High

Advisory

Published 14 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
123
of 17,781 indexed, latest versions
Container images
105
deployed by those charts
Fix available
6 of 10
affected packages

PostgreSQL pg_createsubscriber allows SQL injection via subscription name

Carried by container images the latest versions of 123 of 17,781 indexed charts deploy, on 105 images.

Affected packageAffected versionsFixed inImages
postgresql-17deb17.5-1, 17.5-1.pgdg130+1, 17.6-0+deb13u1, 17.6-1build1+5 more17.10-0+deb13u1, 17.10-0ubuntu0.25.10.130
postgresql-12deb12.7-0ubuntu0.20.04.1, 12.8-0ubuntu0.20.04.1, 12.9-0ubuntu0.20.04.1, 12.11-0ubuntu0.20.04.1+2 moreno fix listed17
postgresql-14deb14.3-1.pgdg22.04+1, 14.4-0ubuntu0.22.04.1, 14.5-0ubuntu0.22.04.1, 14.6-1.pgdg22.04+1+5 more14.23-0ubuntu0.22.04.113
postgresql18apk18.1-r0, 18.2-r0, 18.3-r018.4-r011
postgresql17apk17.2-r0, 17.4-r0, 17.5-r0, 17.6-r0+2 more17.10-r010
postgresqlbitnami17.2.0-1, 17.2.0-4, 17.4.0-9, 17.5.0-9+4 more17.10.08
postgresql-10deb10.6-0ubuntu0.18.04.1, 10.10-0ubuntu0.18.04.1, 10.12-0ubuntu0.18.04.1, 10.14-0ubuntu0.18.04.1+1 moreno fix listed6
postgresql-16deb16.2-1ubuntu4, 16.6-0ubuntu0.24.04.1, 16.9-0ubuntu0.24.04.1, 16.10-0ubuntu0.24.04.1+1 more16.14-0ubuntu0.24.04.16
postgresql-9.5deb9.5.10-0ubuntu0.16.04, 9.5.14-0ubuntu0.16.04no fix listed3
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
OSV records
ALPINE-CVE-2026-6476BIT-postgresql-2026-6476DEBIAN-CVE-2026-6476UBUNTU-CVE-2026-6476
Also known as
USN-8294-1

Charts affected

123 by stars
ChartLatestAffected imagesRadar Score
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
postgresql-10@10.12-0ubuntu0.18.04.1
no fix listed

Open the chart page →

41,044
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1

Open the chart page →

3,854
vaultwardenpascaliskeVerified publisher2.0.01 of 1See more

vaultwarden pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1

Open the chart page →

3,408
planectlplanectlVerified publisher0.7.01 of 10See more

planectl planectl 0.7.0

1 of the 10 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
17.10.0

Open the chart page →

25,934
rdfoxrdfox-helm-chart0.1.22 of 2See more

rdfox rdfox-helm-chart 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
oxfordsemantic/rdfox:5.6db17910eb855
postgresql-12@12.9-0ubuntu0.20.04.1
no fix listed
oxfordsemantic/rdfox-init:5.6baf570ff968d
postgresql-12@12.9-0ubuntu0.20.04.1
no fix listed

Open the chart page →

12,802
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
postgresql@17.5.0-11
17.10.0

Open the chart page →

15,591
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
postgresql17@17.7-r0
17.10-r0

Open the chart page →

4,499
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
postgresql@17.2.0-1
17.10.0

Open the chart page →

7,413
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1

Open the chart page →

9,534
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1

Open the chart page →

9,755
pev2schichtelVerified publisher0.3.01 of 1See more

pev2 schichtel 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
dalibo/explain.dalibo.com:2.20.12a0b749c2f7f
postgresql18@18.2-r0
18.4-r0

Open the chart page →

1,178
teamspeak3schichtelVerified publisher1.0.21 of 1See more

teamspeak3 schichtel 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
library/teamspeak:3.13.74d3fa1c0db9a
postgresql18@18.3-r0
18.4-r0

Open the chart page →

774
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
postgresql-12@12.11-0ubuntu0.20.04.1
no fix listed

Open the chart page →

30,687
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
postgresql-16@16.10-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
postgresql-16@16.10-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1

Open the chart page →

12,460
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
postgresql-12@12.12-0ubuntu0.20.04.1
no fix listed

Open the chart page →

12,655
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
postgresql-12@12.19-0ubuntu0.20.04.1
no fix listed

Open the chart page →

10,006
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
17.10.0

Open the chart page →

5,535
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
postgresql-16@16.2-1ubuntu4
16.14-0ubuntu0.24.04.1

Open the chart page →

45,239
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
postgresql-14@14.11-1.pgdg22.04+1
14.23-0ubuntu0.22.04.1

Open the chart page →

13,459
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
postgresql17@17.5-r0
17.10-r0

Open the chart page →

14,983
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-6476.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
17.10.0

Open the chart page →

7,624

Container images carrying it

105 by charts deploying them

A fixed version is listed for 6 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.