StackRadar

CVE-2026-76163

High

Advisory

Published 16 Sept 2026In the index since 17 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
23
of 17,792 indexed, latest versions
Container images
25
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 23 of 17,792 indexed charts deploy, on 25 images.

Affected packageAffected versionsFixed inImages
bind9deb1:9.18.19-1~deb12u1, 1:9.18.24-1, 1:9.18.33-1~deb12u2, 1:9.18.41-1~deb12u1+8 moreno fix listed25
OSV records
DEBIAN-CVE-2026-76163

Charts affected

23 by stars
ChartLatestAffected imagesRadar Score
jupyterhubjupyterhubOfficialVerified publisher4.4.22 of 7See more

jupyterhub jupyterhub 4.4.2

2 of the 7 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
bind9@1:9.18.49-1~deb12u2
no fix listed
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
bind9@1:9.18.49-1~deb12u2
no fix listed

Open the chart page →

8,146
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
bind9@1:9.20.15-1~deb13u1
no fix listed

Open the chart page →

5,593
dragonflydragonflyVerified publisher1.8.51 of 3See more

dragonfly dragonfly 1.8.5

1 of the 3 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.59fe2a1d6206f
bind9@1:9.18.49-1~deb12u2
no fix listed

Open the chart page →

4,083
oneuptimeoneuptimeOfficialVerified publisher13.0.61 of 7See more

oneuptime oneuptime 13.0.6

1 of the 7 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
oneuptime/probe:releasec5ef060a0bf3
bind9@1:9.18.49-1~deb12u2
no fix listed

Open the chart page →

11,633
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
budibase/proxy:3.41.38d780b6ee602
bind9@1:9.20.23-1~deb13u1
no fix listed

Open the chart page →

10,981
coturnjaconiVerified publisher1.0.51 of 1See more

coturn jaconi 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
coturn/coturn:4.10.0-r1f4c2af06c3c5
bind9@1:9.20.21-1~deb13u1
no fix listed

Open the chart page →

3,035
defectdojodefectdojo1.9.521 of 4See more

defectdojo defectdojo 1.9.52

1 of the 4 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
defectdojo/defectdojo-django:3.3.100c597abdbb535
bind9@1:9.20.26-1~deb13u1
no fix listed

Open the chart page →

2,591
carbone-eecarboneOfficialVerified publisher1.0.61 of 1See more

carbone-ee carbone 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
carbone/carbone-ee:full-5.11.0518172cbad49
bind9@1:9.20.26-1~deb13u1
no fix listed

Open the chart page →

1,755
dragonfly-stackdragonflyVerified publisher0.1.21 of 7See more

dragonfly-stack dragonfly 0.1.2

1 of the 7 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
dragonflyoss/client:v0.1.82edf3e921f4e0
bind9@1:9.18.24-1
no fix listed

Open the chart page →

18,593
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
bind9@1:9.18.41-1~deb12u1
no fix listed

Open the chart page →

7,909
arbitrumchronicleVerified publisher0.3.41 of 1See more

arbitrum chronicle 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
bind9@1:9.18.33-1~deb12u2
no fix listed

Open the chart page →

7,125
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
bind9@1:9.18.33-1~deb12u2
no fix listed

Open the chart page →

14,740
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
bind9@1:9.20.11-4
no fix listed

Open the chart page →

5,304
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
bind9@1:9.18.24-1
no fix listed

Open the chart page →

9,364
rospoferama0.4.31 of 1See more

rospo ferama 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
bind9@1:9.18.19-1~deb12u1
no fix listed

Open the chart page →

6,157
fr24feederfnzv0.1.21 of 1See more

fr24feeder fnzv 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest917e53402d51
bind9@1:9.20.26-1~deb13u1
no fix listed

Open the chart page →

2,407
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
bind9@1:9.18.49-1~deb12u1
no fix listed

Open the chart page →

9,335
helixhelix1.4.31 of 2See more

helix helix 1.4.3

1 of the 2 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
bind9@1:9.18.47-1~deb12u1
no fix listed

Open the chart page →

5,696
jupyterhubhelmforgeVerified publisher1.0.61 of 3See more

jupyterhub helmforge 1.0.6

1 of the 3 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
bind9@1:9.18.47-1~deb12u1
no fix listed

Open the chart page →

5,471
node-debug-dashboardnode-debug-dashboardVerified publisher0.3.21 of 1See more

node-debug-dashboard node-debug-dashboard 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
bind9@1:9.18.49-1~deb12u1
no fix listed

Open the chart page →

6,977
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
bind9@1:9.20.23-1~deb13u1
no fix listed

Open the chart page →

4,408
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
bind9@1:9.18.33-1~deb12u2
no fix listed

Open the chart page →

6,951
steadybit-agentsteadybit3.1.1632 of 6See more

steadybit-agent steadybit 3.1.163

2 of the 6 container images this version deploys carry CVE-2026-76163.

Container imageDigestPackageFixed in
ghcr.io/steadybit/extension-container:v1.8.0dd31d4713ef6
bind9@1:9.20.26-1~deb13u1
no fix listed
ghcr.io/steadybit/extension-host:v1.8.0a198ac7bc8c1
bind9@1:9.20.26-1~deb13u1
no fix listed

Open the chart page →

4,566

Container images carrying it

25 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
bind9@1:9.18.33-1~deb12u2
no fix listed
1
boky/postfix:5.1.0aafc77238423
bind9@1:9.20.15-1~deb13u1
no fix listed
1
budibase/proxy:3.41.38d780b6ee602
bind9@1:9.20.23-1~deb13u1
no fix listed
1
carbone/carbone-ee:full-5.11.0518172cbad49
bind9@1:9.20.26-1~deb13u1
no fix listed
1
coturn/coturn:4.10.0-r1f4c2af06c3c5
bind9@1:9.20.21-1~deb13u1
no fix listed
1
defectdojo/defectdojo-django:3.3.100c597abdbb535
bind9@1:9.20.26-1~deb13u1
no fix listed
1
dragonflyoss/client:v1.5.59fe2a1d6206f
bind9@1:9.18.49-1~deb12u2
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
bind9@1:9.18.24-1
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
bind9@1:9.18.41-1~deb12u1
no fix listed
1
ixsystems/truecommand:3.2.019c218455cd2
bind9@1:9.20.11-4
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
bind9@1:9.18.49-1~deb12u1
no fix listed
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
bind9@1:9.18.33-1~deb12u2
no fix listed
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
bind9@1:9.18.24-1
no fix listed
1
oneuptime/probe:releasec5ef060a0bf3
bind9@1:9.18.49-1~deb12u2
no fix listed
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
bind9@1:9.18.33-1~deb12u2
no fix listed
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
bind9@1:9.18.19-1~deb12u1
no fix listed
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
bind9@1:9.20.23-1~deb13u1
no fix listed
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
bind9@1:9.18.49-1~deb12u1
no fix listed
1
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest917e53402d51
bind9@1:9.20.26-1~deb13u1
no fix listed
1
ghcr.io/steadybit/extension-container:v1.8.0dd31d4713ef6
bind9@1:9.20.26-1~deb13u1
no fix listed
1
ghcr.io/steadybit/extension-host:v1.8.0a198ac7bc8c1
bind9@1:9.20.26-1~deb13u1
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
bind9@1:9.18.49-1~deb12u2
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
bind9@1:9.18.47-1~deb12u1
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
bind9@1:9.18.47-1~deb12u1
no fix listed
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
bind9@1:9.18.49-1~deb12u2
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.