StackRadar

CVE-2026-6638

High

Advisory

Published 14 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
146
of 17,781 indexed, latest versions
Container images
123
deployed by those charts
Fix available
8 of 12
affected packages

PostgreSQL REFRESH PUBLICATION allows SQL injection via table name

Carried by container images the latest versions of 146 of 17,781 indexed charts deploy, on 123 images.

Affected packageAffected versionsFixed inImages
postgresql-17deb17.5-1, 17.5-1.pgdg130+1, 17.6-0+deb13u1, 17.6-1build1+5 more17.10-0+deb13u1, 17.10-0ubuntu0.25.10.130
postgresqlbitnami16.1.0-14, 16.1.0-34, 16.2.0-2, 16.2.0-4+15 more16.14.020
postgresql18apk18.1-r0, 18.2-r0, 18.3-r018.4-r011
postgresql17apk17.2-r0, 17.4-r0, 17.5-r0, 17.6-r0+2 more17.10-r010
PostgreSQLbitnami16.0.0, 16.1.0, 16.1.0-34, 16.2.0-2+3 more16.14.07
postgresql16apk16.3-r0, 16.9-r016.14-r05
postgresql-12deb12.7-0ubuntu0.20.04.1, 12.8-0ubuntu0.20.04.1, 12.9-0ubuntu0.20.04.1, 12.11-0ubuntu0.20.04.1+2 moreno fix listed17
postgresql-14deb14.3-1.pgdg22.04+1, 14.4-0ubuntu0.22.04.1, 14.5-0ubuntu0.22.04.1, 14.6-1.pgdg22.04+1+5 more14.23-0ubuntu0.22.04.113
postgresql-10deb10.6-0ubuntu0.18.04.1, 10.10-0ubuntu0.18.04.1, 10.12-0ubuntu0.18.04.1, 10.14-0ubuntu0.18.04.1+1 moreno fix listed6
postgresql-16deb16.2-1ubuntu4, 16.6-0ubuntu0.24.04.1, 16.9-0ubuntu0.24.04.1, 16.10-0ubuntu0.24.04.1+1 more16.14-0ubuntu0.24.04.16
postgresql-9.5deb9.5.10-0ubuntu0.16.04, 9.5.14-0ubuntu0.16.04no fix listed3
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
OSV records
ALPINE-CVE-2026-6638BIT-postgresql-2026-6638DEBIAN-CVE-2026-6638UBUNTU-CVE-2026-6638
Also known as
USN-8294-1

Charts affected

146 by stars
ChartLatestAffected imagesRadar Score
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1

Open the chart page →

4,568
kestra-starterkestraOfficialVerified publisher2.0.11 of 5See more

kestra-starter kestra 2.0.1

1 of the 5 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
library/postgres:17.5aadf2c0696f5
postgresql-17@17.5-1.pgdg130+1
17.10-0+deb13u1

Open the chart page →

5,455
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r5cf63048c9209
postgresql@17.2.0-4
16.14.0

Open the chart page →

12,062
proxysqlklicktippVerified publisher1.3.01 of 1See more

proxysql klicktipp 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
proxysql/proxysql:3.0.8947a7abad45b
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1

Open the chart page →

2,520
visual-regression-trackerkokuwa5.1.01 of 4See more

visual-regression-tracker kokuwa 5.1.0

1 of the 4 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r15fdc6979dbc53
postgresql@16.3.0-12
16.14.0

Open the chart page →

9,098
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1

Open the chart page →

9,620
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
postgresql-12@12.9-0ubuntu0.20.04.1
no fix listed

Open the chart page →

17,779
novosgamarcusrepo0.1.11 of 2See more

novosga marcusrepo 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
novosga/novosga:latest34b9acbe6e51
postgresql18@18.3-r0
18.4-r0

Open the chart page →

3,706
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1

Open the chart page →

11,950
vaultwardenmt1905027.3.41 of 3See more

vaultwarden mt190502 7.3.4

1 of the 3 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
vaultwarden/server:1.35.443498a94b22f
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1

Open the chart page →

4,710
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
postgresql-14@14.5-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1

Open the chart page →

12,791
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
postgresql-14@14.5-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1

Open the chart page →

12,791
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.03ba6e6f11388
postgresql@16.4.0-20
16.14.0

Open the chart page →

15,369
jupyterhub-metricsncsaVerified publisher1.3.01 of 5See more

jupyterhub-metrics ncsa 1.3.0

1 of the 5 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0dcb8c731bb1b
postgresql17@17.8-r0
17.10-r0

Open the chart page →

4,132
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
postgresql-12@12.12-0ubuntu0.20.04.1
no fix listed

Open the chart page →

22,658
firecrawlobeoneVerified publisher3.0.11 of 5See more

firecrawl obeone 3.0.1

1 of the 5 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
postgresql-17@17.9-1.pgdg13+1
17.10-0+deb13u1

Open the chart page →

9,995
comacopencord1.0.02 of 9See more

comac opencord 1.0.0

2 of the 9 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed

Open the chart page →

88,546
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed

Open the chart page →

26,211
freeradiusopencord1.0.41 of 1See more

freeradius opencord 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
postgresql-10@10.12-0ubuntu0.18.04.1
no fix listed

Open the chart page →

15,702
sebaopencord1.0.01 of 17See more

seba opencord 1.0.0

1 of the 17 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
tpdock/freeradius:2.2.93da600c95a49
postgresql-9.5@9.5.10-0ubuntu0.16.04
no fix listed

Open the chart page →

93,855
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
postgresql-10@10.12-0ubuntu0.18.04.1
no fix listed

Open the chart page →

41,044
hiveopstty0.1.81 of 4See more

hive opstty 0.1.8

1 of the 4 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
postgresql@16.6.0-1
16.14.0

Open the chart page →

4,523
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1

Open the chart page →

3,854
vaultwardenpascaliskeVerified publisher2.0.01 of 1See more

vaultwarden pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1

Open the chart page →

3,408
planectlplanectlVerified publisher0.7.01 of 10See more

planectl planectl 0.7.0

1 of the 10 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
16.14.0

Open the chart page →

25,934
polyaxonpolyaxon2.16.41 of 5See more

polyaxon polyaxon 2.16.4

1 of the 5 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1102e2f47a405e
postgresql@16.4.0-10
16.14.0

Open the chart page →

13,741
rdfoxrdfox-helm-chart0.1.22 of 2See more

rdfox rdfox-helm-chart 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
oxfordsemantic/rdfox:5.6db17910eb855
postgresql-12@12.9-0ubuntu0.20.04.1
no fix listed
oxfordsemantic/rdfox-init:5.6baf570ff968d
postgresql-12@12.9-0ubuntu0.20.04.1
no fix listed

Open the chart page →

12,802
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
postgresql@17.5.0-11
16.14.0

Open the chart page →

15,591
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
postgresql17@17.7-r0
17.10-r0

Open the chart page →

4,499
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
postgresql@17.2.0-1
16.14.0

Open the chart page →

7,413
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1

Open the chart page →

9,534
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1

Open the chart page →

9,755
pev2schichtelVerified publisher0.3.01 of 1See more

pev2 schichtel 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
dalibo/explain.dalibo.com:2.20.12a0b749c2f7f
postgresql18@18.2-r0
18.4-r0

Open the chart page →

1,178
teamspeak3schichtelVerified publisher1.0.21 of 1See more

teamspeak3 schichtel 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
library/teamspeak:3.13.74d3fa1c0db9a
postgresql18@18.3-r0
18.4-r0

Open the chart page →

774
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
postgresql-12@12.11-0ubuntu0.20.04.1
no fix listed

Open the chart page →

30,687
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
postgresql-16@16.10-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
postgresql-16@16.10-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1

Open the chart page →

12,460
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
postgresql-12@12.12-0ubuntu0.20.04.1
no fix listed

Open the chart page →

12,655
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
postgresql-12@12.19-0ubuntu0.20.04.1
no fix listed

Open the chart page →

10,006
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
16.14.0

Open the chart page →

5,535
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
postgresql-16@16.2-1ubuntu4
16.14-0ubuntu0.24.04.1

Open the chart page →

45,239
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
postgresql-14@14.11-1.pgdg22.04+1
14.23-0ubuntu0.22.04.1

Open the chart page →

13,459
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
postgresql17@17.5-r0
17.10-r0

Open the chart page →

14,983
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
16.14.0

Open the chart page →

7,624
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-6638.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
postgresql@16.6.0-1
16.14.0

Open the chart page →

11,577

Container images carrying it

123 by charts deploying them

A fixed version is listed for 8 of the 12 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
postgresql17@17.2-r0
17.10-r0
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
postgresql-17@17.7-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
postgresql-17@17.9-1.pgdg13+1
17.10-0+deb13u1
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
postgresql18@18.2-r0
18.4-r0
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
postgresql-17@17.6-2.pgdg13+1
17.10-0+deb13u1
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
postgresql-12@12.7-0ubuntu0.20.04.1
no fix listed
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
postgresql17@17.4-r0
17.10-r0
1
ghcr.io/monicahq/monica-next:main8be69156acbb
postgresql-17@17.5-1
17.10-0+deb13u1
1
ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0dcb8c731bb1b
postgresql17@17.8-r0
17.10-r0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
postgresql-17@17.6-0+deb13u1
17.10-0+deb13u1
1
ghcr.io/wyrihaximusnet/redirect:randombf5983d754d7
postgresql16@16.3-r0
16.14-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.