StackRadar

CVE-2026-64833

High

Advisory

Published 22 Jul 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
70
of 17,781 indexed, latest versions
Container images
63
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 70 of 17,781 indexed charts deploy, on 63 images.

Affected packageAffected versionsFixed inImages
ffmpegdeb7:2.8.11-0ubuntu0.16.04.1, 7:2.8.15-0ubuntu0.16.04.1, 7:3.4.6-0ubuntu0.18.04.1, 7:3.4.8-0ubuntu0.2+13 more7:2.8.17-0ubuntu0.1+esm17, 7:3.4.11-0ubuntu0.1+esm15, 7:4.2.7-0ubuntu0.1+esm16, 7:4.4.2-0ubuntu0.22.04.1+esm15+2 more63
OSV records
DEBIAN-CVE-2026-64833UBUNTU-CVE-2026-64833
Also known as
USN-8716-1, USN-8716-2

Charts affected

70 by stars
ChartLatestAffected imagesRadar Score
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
ffmpeg@7:5.1.8-0+deb12u1
no fix listed

Open the chart page →

7,081
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
ffmpeg@7:4.4.2-0ubuntu0.22.04.1
7:4.4.2-0ubuntu0.22.04.1+esm15

Open the chart page →

10,716
cameramedia-streaming-meshVerified publisher0.2.52 of 3See more

camera media-streaming-mesh 0.2.5

2 of the 3 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
ciscolabs/rtsp-server:latestb59fc10bb821
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16

Open the chart page →

18,608
msm-rtspmedia-streaming-meshVerified publisher0.0.22 of 2See more

msm-rtsp media-streaming-mesh 0.0.2

2 of the 2 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
ciscolabs/rtsp-server:latestb59fc10bb821
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16

Open the chart page →

18,608
rtspmedia-streaming-meshVerified publisher0.0.142 of 2See more

rtsp media-streaming-mesh 0.0.14

2 of the 2 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
ciscolabs/rtsp-server:latestb59fc10bb821
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16

Open the chart page →

18,608
filestashmt1905024.0.01 of 1See more

filestash mt190502 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
machines/filestash:latest0b8fc005e52e
ffmpeg@7:7.1.5-0+deb13u1
no fix listed

Open the chart page →

3,499
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
ffmpeg@7:7.1.3-0+deb13u1
no fix listed

Open the chart page →

11,950
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
ffmpeg@7:3.4.6-0ubuntu0.18.04.1
7:3.4.11-0ubuntu0.1+esm15

Open the chart page →

27,633
paperless-ngxoli-the-devVerified publisher1.1.11 of 1See more

paperless-ngx oli-the-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
ffmpeg@7:7.1.5-0+deb13u1
no fix listed

Open the chart page →

4,626
cdn-remoteopencord0.2.42 of 3See more

cdn-remote opencord 0.2.4

2 of the 3 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
ffmpeg@7:3.4.6-0ubuntu0.18.04.1
7:3.4.11-0ubuntu0.1+esm15
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
ffmpeg@7:2.8.15-0ubuntu0.16.04.1
7:2.8.17-0ubuntu0.1+esm17

Open the chart page →

63,223
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
ffmpeg@7:2.8.15-0ubuntu0.16.04.1
7:2.8.17-0ubuntu0.1+esm17

Open the chart page →

42,614
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
ffmpeg@7:2.8.15-0ubuntu0.16.04.1
7:2.8.17-0ubuntu0.1+esm17

Open the chart page →

29,124
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
ffmpeg@7:7.1.2-0+deb13u1
no fix listed

Open the chart page →

10,605
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
ffmpeg@7:6.1.1-3ubuntu5
7:6.1.1-3ubuntu5+esm13

Open the chart page →

6,207
nadekobotryuunosukeds30.1.21 of 2See more

nadekobot ryuunosukeds3 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
ffmpeg@7:4.4.2-0ubuntu0.22.04.1
7:4.4.2-0ubuntu0.22.04.1+esm15

Open the chart page →

8,619
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
ffmpeg@7:8.0.1-3ubuntu2
7:8.0.1-3ubuntu2+esm4

Open the chart page →

10,348
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
ffmpeg@7:6.1.1-3ubuntu5
7:6.1.1-3ubuntu5+esm13

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
ffmpeg@7:6.1.1-3ubuntu5
7:6.1.1-3ubuntu5+esm13

Open the chart page →

12,460
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
ffmpeg@7:5.1.6-0+deb12u1
no fix listed

Open the chart page →

9,616
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ffmpeg@7:4.4.2-0ubuntu0.22.04.1
7:4.4.2-0ubuntu0.22.04.1+esm15

Open the chart page →

14,100

Container images carrying it

63 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
ffmpeg@7:5.1.9-0+deb12u1
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
ffmpeg@7:7.1.5-0+deb13u1
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
ffmpeg@7:5.1.8-0+deb12u1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
ffmpeg@7:5.1.6-0+deb12u1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
ffmpeg@7:7.1.3-0+deb13u1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
ffmpeg@7:7.1.2-0+deb13u1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
ffmpeg@7:7.1.2-0+deb13u1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
ffmpeg@7:5.1.4-0+deb12u1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
ffmpeg@7:7.1.3-0+deb13u1
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
ffmpeg@7:6.1.1-3ubuntu5
7:6.1.1-3ubuntu5+esm13
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
ffmpeg@7:6.1.1-3ubuntu5
7:6.1.1-3ubuntu5+esm13
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.