StackRadar

CVE-2026-64833

High

Advisory

Published 22 Jul 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
70
of 17,781 indexed, latest versions
Container images
63
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 70 of 17,781 indexed charts deploy, on 63 images.

Affected packageAffected versionsFixed inImages
ffmpegdeb7:2.8.11-0ubuntu0.16.04.1, 7:2.8.15-0ubuntu0.16.04.1, 7:3.4.6-0ubuntu0.18.04.1, 7:3.4.8-0ubuntu0.2+13 more7:2.8.17-0ubuntu0.1+esm17, 7:3.4.11-0ubuntu0.1+esm15, 7:4.2.7-0ubuntu0.1+esm16, 7:4.4.2-0ubuntu0.22.04.1+esm15+2 more63
OSV records
DEBIAN-CVE-2026-64833UBUNTU-CVE-2026-64833
Also known as
USN-8716-1, USN-8716-2

Charts affected

70 by stars
ChartLatestAffected imagesRadar Score
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
ffmpeg@7:5.1.8-0+deb12u1
no fix listed

Open the chart page →

7,081
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
ffmpeg@7:4.4.2-0ubuntu0.22.04.1
7:4.4.2-0ubuntu0.22.04.1+esm15

Open the chart page →

10,716
cameramedia-streaming-meshVerified publisher0.2.52 of 3See more

camera media-streaming-mesh 0.2.5

2 of the 3 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
ciscolabs/rtsp-server:latestb59fc10bb821
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16

Open the chart page →

18,608
msm-rtspmedia-streaming-meshVerified publisher0.0.22 of 2See more

msm-rtsp media-streaming-mesh 0.0.2

2 of the 2 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
ciscolabs/rtsp-server:latestb59fc10bb821
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16

Open the chart page →

18,608
rtspmedia-streaming-meshVerified publisher0.0.142 of 2See more

rtsp media-streaming-mesh 0.0.14

2 of the 2 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
ciscolabs/rtsp-server:latestb59fc10bb821
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16

Open the chart page →

18,608
filestashmt1905024.0.01 of 1See more

filestash mt190502 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
machines/filestash:latest0b8fc005e52e
ffmpeg@7:7.1.5-0+deb13u1
no fix listed

Open the chart page →

3,499
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
ffmpeg@7:7.1.3-0+deb13u1
no fix listed

Open the chart page →

11,950
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
ffmpeg@7:3.4.6-0ubuntu0.18.04.1
7:3.4.11-0ubuntu0.1+esm15

Open the chart page →

27,633
paperless-ngxoli-the-devVerified publisher1.1.11 of 1See more

paperless-ngx oli-the-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
ffmpeg@7:7.1.5-0+deb13u1
no fix listed

Open the chart page →

4,626
cdn-remoteopencord0.2.42 of 3See more

cdn-remote opencord 0.2.4

2 of the 3 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
ffmpeg@7:3.4.6-0ubuntu0.18.04.1
7:3.4.11-0ubuntu0.1+esm15
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
ffmpeg@7:2.8.15-0ubuntu0.16.04.1
7:2.8.17-0ubuntu0.1+esm17

Open the chart page →

63,223
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
ffmpeg@7:2.8.15-0ubuntu0.16.04.1
7:2.8.17-0ubuntu0.1+esm17

Open the chart page →

42,614
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
ffmpeg@7:2.8.15-0ubuntu0.16.04.1
7:2.8.17-0ubuntu0.1+esm17

Open the chart page →

29,124
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
ffmpeg@7:7.1.2-0+deb13u1
no fix listed

Open the chart page →

10,605
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
ffmpeg@7:6.1.1-3ubuntu5
7:6.1.1-3ubuntu5+esm13

Open the chart page →

6,207
nadekobotryuunosukeds30.1.21 of 2See more

nadekobot ryuunosukeds3 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
ffmpeg@7:4.4.2-0ubuntu0.22.04.1
7:4.4.2-0ubuntu0.22.04.1+esm15

Open the chart page →

8,619
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
ffmpeg@7:8.0.1-3ubuntu2
7:8.0.1-3ubuntu2+esm4

Open the chart page →

10,348
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
ffmpeg@7:6.1.1-3ubuntu5
7:6.1.1-3ubuntu5+esm13

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
ffmpeg@7:6.1.1-3ubuntu5
7:6.1.1-3ubuntu5+esm13

Open the chart page →

12,460
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
ffmpeg@7:5.1.6-0+deb12u1
no fix listed

Open the chart page →

9,616
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-64833.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ffmpeg@7:4.4.2-0ubuntu0.22.04.1
7:4.4.2-0ubuntu0.22.04.1+esm15

Open the chart page →

14,100

Container images carrying it

63 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
ffmpeg@7:7.1.5-0+deb13u1
no fix listed
7
ciscolabs/rtsp-client:latesta7b60ec88285
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
3
ciscolabs/rtsp-server:latestb59fc10bb821
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
ffmpeg@7:2.8.15-0ubuntu0.16.04.1
7:2.8.17-0ubuntu0.1+esm17
3
kurento/kurento-media-server:latest03c0d34d0828
ffmpeg@7:6.1.1-3ubuntu5
7:6.1.1-3ubuntu5+esm13
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
ffmpeg@7:4.2.4-1ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
ffmpeg@7:5.1.8-0+deb12u1
no fix listed
2
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
ffmpeg@7:4.4.2-0ubuntu0.22.04.1
7:4.4.2-0ubuntu0.22.04.1+esm15
1
archivebox/archivebox:0.7.41a5a37331091
ffmpeg@7:5.1.9-0+deb12u1
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
ffmpeg@7:4.2.4-1ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
1
castopod/castopod:1.12.101fd37280cbb2
ffmpeg@7:5.1.6-0+deb12u1
no fix listed
1
castopod/castopod:1.15.54e4f0440520f
ffmpeg@7:7.1.3-0+deb13u1
no fix listed
1
chocobozzz/peertube:v8.1.5052712130691
ffmpeg@7:7.1.4-0+deb13u1
no fix listed
1
instill/artifact-backend:b28766ac4a393e601ed
ffmpeg@7:7.1.3-0+deb13u1
no fix listed
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
ffmpeg@7:4.2.7-0ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
1
jaedb/iris:latest048cfbf58d57
ffmpeg@7:5.1.6-0+deb12u1
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
ffmpeg@7:5.1.4-0+deb12u1
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
ffmpeg@7:6.1.1-3ubuntu5
7:6.1.1-3ubuntu5+esm13
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
ffmpeg@7:6.1.1-3ubuntu5
7:6.1.1-3ubuntu5+esm13
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
ffmpeg@7:6.1.1-3ubuntu5
7:6.1.1-3ubuntu5+esm13
1
livekit/ingress:v1.2.21ab01641b366
ffmpeg@7:4.4.2-0ubuntu0.22.04.1
7:4.4.2-0ubuntu0.22.04.1+esm15
1
machines/filestash:latest0b8fc005e52e
ffmpeg@7:7.1.5-0+deb13u1
no fix listed
1
mlikiowa/napcat-docker:latest1336a777f9a4
ffmpeg@7:4.4.2-0ubuntu0.22.04.1
7:4.4.2-0ubuntu0.22.04.1+esm15
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
ffmpeg@7:7.1.5-0+deb13u1
no fix listed
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
ffmpeg@7:3.4.6-0ubuntu0.18.04.1
7:3.4.11-0ubuntu0.1+esm15
1
opea/speecht5:1.0249afad3d268
ffmpeg@7:5.1.6-0+deb12u1
no fix listed
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
ffmpeg@7:5.1.9-0+deb12u1
no fix listed
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
ffmpeg@7:7.1.5-0+deb13u1
no fix listed
1
photoprism/photoprism:220629-jammy2954334adbda
ffmpeg@7:4.4.2-0ubuntu0.22.04.1
7:4.4.2-0ubuntu0.22.04.1+esm15
1
photoprism/photoprism:260601650c6ad5a651
ffmpeg@7:8.0.1-3ubuntu2
7:8.0.1-3ubuntu2+esm4
1
photoprism/photoprism:260728958642220223
ffmpeg@7:8.0.1-3ubuntu2
7:8.0.1-3ubuntu2+esm4
1
photoprism/photoprism:240711-cefc6fd632ca74
ffmpeg@7:6.1.1-3ubuntu5
7:6.1.1-3ubuntu5+esm13
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
ffmpeg@7:4.4.2-0ubuntu0.22.04.1
7:4.4.2-0ubuntu0.22.04.1+esm15
1
scrapinghub/splash:3.4.1a5f89bc84606
ffmpeg@7:3.4.6-0ubuntu0.18.04.1
7:3.4.11-0ubuntu0.1+esm15
1
selenium/node-chrome:4.48.0-202609055ac71fd8dd1e
ffmpeg@7:6.1.1-3ubuntu5
7:6.1.1-3ubuntu5+esm13
1
selenium/node-firefox:4.48.0-2026090574a5c1c90f95
ffmpeg@7:6.1.1-3ubuntu5
7:6.1.1-3ubuntu5+esm13
1
sismics/docs:v1.10f4b0ef019cf1
ffmpeg@7:3.4.8-0ubuntu0.2
7:3.4.11-0ubuntu0.1+esm15
1
stashapp/stash:latest24dbd7607174
ffmpeg@7:4.2.4-1ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
ffmpeg@7:2.8.11-0ubuntu0.16.04.1
7:2.8.17-0ubuntu0.1+esm17
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ffmpeg@7:4.4.2-0ubuntu0.22.04.1
7:4.4.2-0ubuntu0.22.04.1+esm15
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
ffmpeg@7:5.1.9-0+deb12u1
no fix listed
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
ffmpeg@7:4.2.4-1ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
ffmpeg@7:4.2.4-1ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
ffmpeg@7:4.2.4-1ubuntu0.1
7:4.2.7-0ubuntu0.1+esm16
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
ffmpeg@7:5.1.9-0+deb12u1
no fix listed
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
ffmpeg@7:3.4.8-0ubuntu0.2
7:3.4.11-0ubuntu0.1+esm15
1
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
ffmpeg@7:7.1.5-0+deb13u1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
ffmpeg@7:7.1.5-0+deb13u1
no fix listed
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
ffmpeg@7:5.1.8-0+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.