StackRadar

CVE-2026-87766

High

Advisory

Published 10 Sept 2026In the index since 11 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
6
of 17,781 indexed, latest versions
Container images
6
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 6 of 17,781 indexed charts deploy, on 6 images.

Affected packageAffected versionsFixed inImages
bubblewrapdeb0.4.0-1ubuntu4.1, 0.6.1-1, 0.6.1-1ubuntu0.1, 0.11.1-1ubuntu0.1no fix listed6
OSV records
UBUNTU-CVE-2026-87766

Charts affected

6 by stars
ChartLatestAffected imagesRadar Score
penpotpenpotOfficialVerified publisher1.9.01 of 4See more

penpot penpot 1.9.0

1 of the 4 container images this version deploys carry CVE-2026-87766.

Container imageDigestPackageFixed in
penpotapp/exporter:2.17.272a8061e8806
bubblewrap@0.11.1-1ubuntu0.1
no fix listed

Open the chart page →

4,314
photoprismandrenarchyVerified publisher8.15.01 of 1See more

photoprism andrenarchy 8.15.0

1 of the 1 container images this version deploys carry CVE-2026-87766.

Container imageDigestPackageFixed in
photoprism/photoprism:260728958642220223
bubblewrap@0.11.1-1ubuntu0.1
no fix listed

Open the chart page →

8,825
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-87766.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
bubblewrap@0.4.0-1ubuntu4.1
no fix listed

Open the chart page →

64,489
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-87766.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
bubblewrap@0.6.1-1
no fix listed

Open the chart page →

10,716
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-87766.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
bubblewrap@0.6.1-1ubuntu0.1
no fix listed

Open the chart page →

7,295
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-87766.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
bubblewrap@0.11.1-1ubuntu0.1
no fix listed

Open the chart page →

10,348

Container images carrying it

6 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
bubblewrap@0.4.0-1ubuntu4.1
no fix listed
1
livekit/ingress:v1.2.21ab01641b366
bubblewrap@0.6.1-1
no fix listed
1
penpotapp/exporter:2.17.272a8061e8806
bubblewrap@0.11.1-1ubuntu0.1
no fix listed
1
photoprism/photoprism:260601650c6ad5a651
bubblewrap@0.11.1-1ubuntu0.1
no fix listed
1
photoprism/photoprism:260728958642220223
bubblewrap@0.11.1-1ubuntu0.1
no fix listed
1
trueosiris/vrising:latest9356f98ad561
bubblewrap@0.6.1-1ubuntu0.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.