StackRadar

CVE-2026-88372

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
60
of 17,844 indexed, latest versions
Container images
61
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 60 of 17,844 indexed charts deploy, on 61 images.

Affected packageAffected versionsFixed inImages
libsndfiledeb1.0.25-7ubuntu2.2, 1.0.25-10ubuntu0.16.04.1, 1.0.25-10ubuntu0.16.04.2, 1.0.28-4+12 moreno fix listed61
OSV records
UBUNTU-CVE-2026-88372

Charts affected

60 by stars
ChartLatestAffected imagesRadar Score
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-88372.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libsndfile@1.0.25-10ubuntu0.16.04.1
no fix listed

Open the chart page →

43,804
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-88372.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libsndfile@1.0.25-10ubuntu0.16.04.1
no fix listed

Open the chart page →

30,117
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-88372.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
libsndfile@1.0.25-7ubuntu2.2
no fix listed

Open the chart page →

26,716
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88372.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
libsndfile@1.0.28-7ubuntu0.1
no fix listed

Open the chart page →

16,075
nadekobotryuunosukeds30.1.21 of 2See more

nadekobot ryuunosukeds3 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-88372.

Container imageDigestPackageFixed in
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
libsndfile@1.0.31-2ubuntu0.2
no fix listed

Open the chart page →

8,919
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88372.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
libsndfile@1.0.31-2ubuntu0.2
no fix listed

Open the chart page →

7,872
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-88372.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
libsndfile@1.2.2-4
no fix listed

Open the chart page →

57,124
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-88372.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libsndfile@1.2.2-1ubuntu5.24.04.1
no fix listed

Open the chart page →

13,480
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-88372.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libsndfile@1.2.2-1ubuntu5.24.04.1
no fix listed

Open the chart page →

13,480
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-88372.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libsndfile@1.0.31-2ubuntu0.1
no fix listed

Open the chart page →

14,813

Container images carrying it

61 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/linuxserver/booksonic:version-1.2677efca1065d
libsndfile@1.0.28-4ubuntu0.18.04.2
no fix listed
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
libsndfile@1.0.28-4ubuntu0.18.04.2
no fix listed
1
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
libsndfile@1.0.28-4ubuntu0.18.04.2
no fix listed
1
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
libsndfile@1.0.28-4ubuntu0.18.04.2
no fix listed
1
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
libsndfile@1.0.28-4ubuntu0.18.04.2
no fix listed
1
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
libsndfile@1.0.28-4ubuntu0.18.04.2
no fix listed
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
libsndfile@1.0.28-7ubuntu0.1
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
libsndfile@1.0.28-7ubuntu0.1
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libsndfile@1.0.28-7ubuntu0.1
no fix listed
1
quay.io/go-skynet/local-ai:latest0632c21ddbe4
libsndfile@1.2.2-1ubuntu5.24.04.1
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libsndfile@1.0.25-10ubuntu0.16.04.2
no fix listed
1

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.