StackRadar

CVE-2026-66035

High

Advisory

Published 24 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
454
of 17,781 indexed, latest versions
Container images
292
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 454 of 17,781 indexed charts deploy, on 292 images.

Affected packageAffected versionsFixed inImages
libssh2deb1.5.0-2ubuntu0.1, 1.8.0-2.1build1, 1.10.0-3, 1.11.0-4.1build2+9 more1.11.0-4.1ubuntu0.24.04.4, 1.11.1-1+deb13u2, 1.11.1-1+e5, 1.11.1-1ubuntu0.26.04.4292
OSV records
DEBIAN-CVE-2026-66035UBUNTU-CVE-2026-66035ECHO-a13b-3527-8590
Also known as
USN-8722-1

Charts affected

454 by stars
ChartLatestAffected imagesRadar Score
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-66035.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2

Open the chart page →

5,560
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-66035.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2

Open the chart page →

1,827
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-66035.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2

Open the chart page →

1,827
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-66035.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2

Open the chart page →

1,827

Container images carrying it

292 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
phpmyadmin/phpmyadmin:5.2.342a200db07b4
libssh2@1.11.1-1
1.11.1-1+deb13u2
1
pockost/matomo:5.13.07f5d293cbe4e
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
polyaxon/polyaxon-api:2.16.42b55c3265a90
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
polyaxon/polyaxon-streams:2.16.4c186bd9834c0
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
postgis/postgis:18-3.67e00e8c3539f
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
powerdns/pdns-recursor-54:5.4.533aadc74a8d6
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
prefecthq/prefect:3.8.5-python3.110018d02259bc
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
pretix/standalone:2026.7.05df3b7aa852e
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
prodrigestivill/postgres-backup-local:latestf70742ebe42b
libssh2@1.11.1-1
1.11.1-1+deb13u2
1
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
reallibrephotos/librephotos-proxy:1.0.398a13dabbadc
libssh2@1.11.1-1
1.11.1-1+deb13u2
1
redpandadata/redpanda:latest468bd13a9f2b
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
libssh2@1.10.0-3
no fix listed
1
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
libssh2@1.10.0-3
no fix listed
1
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
libssh2@1.10.0-3
no fix listed
1
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
libssh2@1.11.0-4.1build2
1.11.0-4.1ubuntu0.24.04.4
1
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
libssh2@1.11.0-4.1build2
1.11.0-4.1ubuntu0.24.04.4
1
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
libssh2@1.11.0-4.1build2
1.11.0-4.1ubuntu0.24.04.4
1
scholtz2/aramid-conduit:v1.9.0-stable3a3b3d3277d2
libssh2@1.11.1-1ubuntu0.26.04.1
1.11.1-1ubuntu0.26.04.4
1
scholtz2/aramid-indexer:v3.9.0-stable6770214bc881
libssh2@1.11.1-1ubuntu0.26.04.1
1.11.1-1ubuntu0.26.04.4
1
serversideup/php:8.5-fpm-nginx8f8c2f010ac5
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
sissbruecker/linkding:1.46.20c0a9a04c7eb
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
softwaremill/bootzooka:latest845b5e8f8056
libssh2@1.11.1-1build2
1.11.1-1ubuntu0.26.04.4
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libssh2@1.8.0-2.1build1
no fix listed
1
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
libssh2@1.11.1-1
1.11.1-1+deb13u2
1
sslhep/servicex_app:v1.8.51d12f943cec5
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
stalwartlabs/stalwart:v0.16.1425001929f36a
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
stalwartlabs/stalwart:v0.16.2074ca4f7f6885
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
stalwartlabs/stalwart:v0.16.2193c574e52249
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
supabase/logflare:latest49bfe526f1b4
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
supabase/realtime:latestd3aa0c86c7b3
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
tautulli/tautulli:latest670e68dd9efc
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
tchiotludo/akhq:0.28.0c2824dc2ae44
libssh2@1.11.1-1ubuntu0.26.04.3
1.11.1-1ubuntu0.26.04.4
1
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
libssh2@1.11.1-1
1.11.1-1+deb13u2
1
thijsvanloef/palworld-server-docker:v2.5.0b4ac9ee22483
libssh2@1.11.1-1
1.11.1-1+deb13u2
1
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
thingsboard/tbmq-node:2.4.070661025dba5
libssh2@1.11.1-1+deb13u1
1.11.1-1+deb13u2
1
timescale/timescaledb-ha:pg16d7db8f1085a3
libssh2@1.10.0-3
no fix listed
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
libssh2@1.10.0-3
no fix listed
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
libssh2@1.11.1-1
1.11.1-1+deb13u2
1
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
libssh2@1.11.1-1
1.11.1-1+deb13u2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.