StackRadar

CVE-2026-66140

High

Advisory

Published 24 Jul 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
13
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 13 images.

Affected packageAffected versionsFixed inImages
exim4deb4.96-15+deb12u1, 4.96-15+deb12u2, 4.96-15+deb12u6, 4.96-15+deb12u10+2 more4.98.2-1+deb13u413
OSV records
DEBIAN-CVE-2026-66140

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-66140.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
exim4@4.98.2-1
4.98.2-1+deb13u4

Open the chart page →

2,244
part-dbpart-dbVerified publisher0.1.21 of 1See more

part-db part-db 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-66140.

Container imageDigestPackageFixed in
jbtronics/part-db1:latest5db71f6db59d
exim4@4.96-15+deb12u10
no fix listed

Open the chart page →

3,327
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-66140.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
exim4@4.98.2-1
4.98.2-1+deb13u4

Open the chart page →

7,126
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-66140.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
exim4@4.96-15+deb12u6
no fix listed

Open the chart page →

7,141
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-66140.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
exim4@4.98.2-1
4.98.2-1+deb13u4

Open the chart page →

5,039
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-66140.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
exim4@4.98.2-1
4.98.2-1+deb13u4
fireflyiii/data-importer:version-2.2.3ab52bf932546
exim4@4.98.2-1
4.98.2-1+deb13u4

Open the chart page →

10,260
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-66140.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
exim4@4.98.2-1
4.98.2-1+deb13u4

Open the chart page →

4,829
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-66140.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
exim4@4.96-15+deb12u10
no fix listed

Open the chart page →

64,489
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-66140.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
exim4@4.96-15+deb12u10
no fix listed

Open the chart page →

9,077
firefly-iiikubernetes-homelab-helm-chartsVerified publisher0.1.31 of 3See more

firefly-iii kubernetes-homelab-helm-charts 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-66140.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.6.6ae69fdd95cde
exim4@4.98.2-1+deb13u3
4.98.2-1+deb13u4

Open the chart page →

4,382
smilencsaVerified publisher1.1.04 of 23See more

smile ncsa 1.1.0

4 of the 23 container images this version deploys carry CVE-2026-66140.

Container imageDigestPackageFixed in
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
exim4@4.96-15+deb12u2
no fix listed
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
exim4@4.96-15+deb12u1
no fix listed
socialmediamacroscope/preprocessing:0.1.3ca863306314b
exim4@4.96-15+deb12u1
no fix listed
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
exim4@4.96-15+deb12u1
no fix listed

Open the chart page →

109,294

Container images carrying it

13 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
fireflyiii/core:version-6.5.9fe4ecec4c2ba
exim4@4.98.2-1
4.98.2-1+deb13u4
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
exim4@4.98.2-1
4.98.2-1+deb13u4
2
domainmod/domainmod:4.23.04017bfe4c597
exim4@4.96-15+deb12u6
no fix listed
1
fireflyiii/core:version-6.6.6ae69fdd95cde
exim4@4.98.2-1+deb13u3
4.98.2-1+deb13u4
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
exim4@4.96-15+deb12u10
no fix listed
1
jbtronics/part-db1:latest5db71f6db59d
exim4@4.96-15+deb12u10
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
exim4@4.96-15+deb12u10
no fix listed
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
exim4@4.96-15+deb12u2
no fix listed
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
exim4@4.96-15+deb12u1
no fix listed
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
exim4@4.96-15+deb12u1
no fix listed
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
exim4@4.96-15+deb12u1
no fix listed
1
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
exim4@4.98.2-1
4.98.2-1+deb13u4
1
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
exim4@4.98.2-1
4.98.2-1+deb13u4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.