StackRadar

CVE-2026-75904

Low

Advisory

Published 18 Aug 2026In the index since 6 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,787 indexed, latest versions
Container images
9
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 11 of 17,787 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
libmodplugdeb1:0.8.8.5-2, 1:0.8.9.0-2build1, 1:0.8.9.0-3, 1:0.8.9.0-3build1no fix listed9
OSV records
DEBIAN-CVE-2026-75904UBUNTU-CVE-2026-75904

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
smarter-demosmarterOfficialVerified publisher0.1.52 of 7See more

smarter-demo smarter 0.1.5

2 of the 7 container images this version deploys carry CVE-2026-75904.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
libmodplug@1:0.8.9.0-2build1
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libmodplug@1:0.8.9.0-2build1
no fix listed

Open the chart page →

45,832
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-75904.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libmodplug@1:0.8.8.5-2
no fix listed

Open the chart page →

77,758
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-75904.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
libmodplug@1:0.8.9.0-3
no fix listed

Open the chart page →

12,958
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-75904.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libmodplug@1:0.8.9.0-2build1
no fix listed

Open the chart page →

18,066
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-75904.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
libmodplug@1:0.8.9.0-3
no fix listed

Open the chart page →

10,716
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-75904.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
libmodplug@1:0.8.8.5-2
no fix listed

Open the chart page →

63,223
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-75904.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libmodplug@1:0.8.8.5-2
no fix listed

Open the chart page →

42,614
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-75904.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libmodplug@1:0.8.8.5-2
no fix listed

Open the chart page →

29,124
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-75904.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libmodplug@1:0.8.9.0-3build1
no fix listed

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-75904.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libmodplug@1:0.8.9.0-3build1
no fix listed

Open the chart page →

12,460
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-75904.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libmodplug@1:0.8.9.0-3
no fix listed

Open the chart page →

14,100

Container images carrying it

9 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
libmodplug@1:0.8.8.5-2
no fix listed
3
kurento/kurento-media-server:latest03c0d34d0828
libmodplug@1:0.8.9.0-3build1
no fix listed
2
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libmodplug@1:0.8.9.0-2build1
no fix listed
1
jaedb/iris:latest048cfbf58d57
libmodplug@1:0.8.9.0-3
no fix listed
1
livekit/ingress:v1.2.21ab01641b366
libmodplug@1:0.8.9.0-3
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libmodplug@1:0.8.8.5-2
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libmodplug@1:0.8.9.0-3
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
libmodplug@1:0.8.9.0-2build1
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libmodplug@1:0.8.9.0-2build1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.