StackRadar

CVE-2026-6575

Medium

Advisory

Published 14 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
57
of 17,781 indexed, latest versions
Container images
58
deployed by those charts
Fix available
4 of 8
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 57 of 17,781 indexed charts deploy, on 58 images.

Affected packageAffected versionsFixed inImages
postgresql-12deb12.7-0ubuntu0.20.04.1, 12.8-0ubuntu0.20.04.1, 12.9-0ubuntu0.20.04.1, 12.11-0ubuntu0.20.04.1+2 moreno fix listed17
postgresql-14deb14.3-1.pgdg22.04+1, 14.4-0ubuntu0.22.04.1, 14.5-0ubuntu0.22.04.1, 14.6-1.pgdg22.04+1+5 more14.23-0ubuntu0.22.04.113
postgresql18apk18.1-r0, 18.2-r0, 18.3-r018.4-r011
postgresql-10deb10.6-0ubuntu0.18.04.1, 10.10-0ubuntu0.18.04.1, 10.12-0ubuntu0.18.04.1, 10.14-0ubuntu0.18.04.1+1 moreno fix listed6
postgresql-16deb16.2-1ubuntu4, 16.6-0ubuntu0.24.04.1, 16.9-0ubuntu0.24.04.1, 16.10-0ubuntu0.24.04.1+1 more16.14-0ubuntu0.24.04.16
postgresql-9.5deb9.5.10-0ubuntu0.16.04, 9.5.14-0ubuntu0.16.04no fix listed3
postgresql-17deb17.6-1build117.10-0ubuntu0.25.10.11
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
OSV records
ALPINE-CVE-2026-6575UBUNTU-CVE-2026-6575
Also known as
USN-8294-1

Charts affected

57 by stars
ChartLatestAffected imagesRadar Score
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-6575.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
postgresql-12@12.11-0ubuntu0.20.04.1
no fix listed

Open the chart page →

30,687
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6575.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
postgresql-16@16.10-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6575.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
postgresql-16@16.10-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1

Open the chart page →

12,460
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-6575.

Container imageDigestPackageFixed in
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
postgresql-12@12.12-0ubuntu0.20.04.1
no fix listed

Open the chart page →

12,655
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-6575.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
postgresql-12@12.19-0ubuntu0.20.04.1
no fix listed

Open the chart page →

10,006
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-6575.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
postgresql-16@16.2-1ubuntu4
16.14-0ubuntu0.24.04.1

Open the chart page →

45,239
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-6575.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
postgresql-14@14.11-1.pgdg22.04+1
14.23-0ubuntu0.22.04.1

Open the chart page →

13,459

Container images carrying it

58 by charts deploying them

A fixed version is listed for 4 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
postgresql-14@14.5-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1
1
gcr.io/datadoghq/private-action-runner:v1.21.05f5918f843a4
postgresql-16@16.13-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
postgresql18@18.2-r0
18.4-r0
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.