StackRadar

CVE-2026-73515

High

Advisory

Published 13 Aug 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
postgisdeb3.0.0+dfsg-6ubuntu4, 3.2.0+dfsg-1ubuntu1, 3.2.1+dfsg-1.pgdg22.04+1+b1, 3.2.3+dfsg-1.pgdg22.04+1+5 moreno fix listed10
OSV records
DEBIAN-CVE-2026-73515UBUNTU-CVE-2026-73515

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
nominatimrobjuz6.4.11 of 4See more

nominatim robjuz 6.4.1

1 of the 4 container images this version deploys carry CVE-2026-73515.

Container imageDigestPackageFixed in
mediagis/nominatim:5.3.27923a8e67197
postgis@3.4.2+dfsg-1ubuntu3
no fix listed

Open the chart page →

8,690
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-73515.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg16d7db8f1085a3
postgis@3.6.4+dfsg-2.pgdg22.04+1
no fix listed

Open the chart page →

12,930
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-73515.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
postgis@3.3.2+dfsg-1.pgdg22.04+1
no fix listed

Open the chart page →

32,501
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-73515.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
postgis@3.5.2+dfsg-1.pgdg22.04+1
no fix listed

Open the chart page →

20,900
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-73515.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
postgis@3.3.2+dfsg-1.pgdg22.04+1
no fix listed

Open the chart page →

24,917
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2026-73515.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
postgis@3.2.1+dfsg-1.pgdg22.04+1+b1
no fix listed

Open the chart page →

30,699
dawarichhelmforgeVerified publisher1.0.01 of 4See more

dawarich helmforge 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-73515.

Container imageDigestPackageFixed in
postgis/postgis:18-3.67e00e8c3539f
postgis@3.6.4+dfsg-2.pgdg13+1
no fix listed

Open the chart page →

4,742
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2026-73515.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
postgis@3.2.0+dfsg-1ubuntu1
no fix listed

Open the chart page →

14,290
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-73515.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
postgis@3.0.0+dfsg-6ubuntu4
no fix listed

Open the chart page →

22,658
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-73515.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
postgis@3.2.3+dfsg-1.pgdg22.04+1
no fix listed

Open the chart page →

13,459

Container images carrying it

10 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mediagis/nominatim:5.3.27923a8e67197
postgis@3.4.2+dfsg-1ubuntu3
no fix listed
1
mediagis/nominatim:3.7c15e941485ef
postgis@3.0.0+dfsg-6ubuntu4
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
postgis@3.2.0+dfsg-1ubuntu1
no fix listed
1
postgis/postgis:18-3.67e00e8c3539f
postgis@3.6.4+dfsg-2.pgdg13+1
no fix listed
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
postgis@3.3.2+dfsg-1.pgdg22.04+1
no fix listed
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
postgis@3.3.2+dfsg-1.pgdg22.04+1
no fix listed
1
timescale/timescaledb-ha:pg16d7db8f1085a3
postgis@3.6.4+dfsg-2.pgdg22.04+1
no fix listed
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
postgis@3.5.2+dfsg-1.pgdg22.04+1
no fix listed
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
postgis@3.2.1+dfsg-1.pgdg22.04+1+b1
no fix listed
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
postgis@3.2.3+dfsg-1.pgdg22.04+1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.