StackRadar

CVE-2026-88647

Critical

Advisory

Published 8 Oct 2026In the index since 10 Oct 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,344
of 18,090 indexed, latest versions
Container images
1,235
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,344 of 18,090 indexed charts deploy, on 1,235 images.

Affected packageAffected versionsFixed inImages
gnutls28deb3.7.9-2, 3.7.9-2+deb12u1, 3.7.9-2+deb12u2, 3.7.9-2+deb12u3+12 moreno fix listed1,235
OSV records
DEBIAN-CVE-2026-88647ECHO-4d78-972f-d59f
Trending
Rank 15 in indexed charts, since 10 Oct 2026. See the ranking →

Charts affected

1,344 by stars
ChartLatestAffected imagesRadar Score
postgresappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

postgresapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
library/postgres:latest74935e722416
gnutls28@3.8.9-3+deb13u4
no fix listed

Open the chart page →

1,802
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
library/postgres:latestfc973eb97c9f
gnutls28@3.8.9-3+deb13u4
no fix listed

Open the chart page →

9,736
voting-app-envvoting-example-with-env0.0.32 of 6See more

voting-app-env voting-example-with-env 0.0.3

2 of the 6 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
kerolosayman308/voting-app-env:examplevotingapp_vote29d99802f2d7
gnutls28@3.8.9-3+deb13u2
no fix listed
kerolosayman308/voting-app-env:examplevotingapp_result6e92e5a231fa
gnutls28@3.7.9-2+deb12u4
no fix listed

Open the chart page →

8,258
aih-scannerwallarmVerified publisher2.9.01 of 2See more

aih-scanner wallarm 2.9.0

1 of the 2 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.9.0b39795d50e83
gnutls28@3.8.9-3+deb13u4
no fix listed

Open the chart page →

3,792
api-gatewaywallarmVerified publisher0.2.01 of 1See more

api-gateway wallarm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
wallarm/api-gateway:0.2.0a3d4d2f780e8
gnutls28@3.7.9-2+deb12u5
no fix listed

Open the chart page →

2,587
wallarm-gatewaywallarmVerified publisher0.4.01 of 1See more

wallarm-gateway wallarm 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
wallarm/gateway-controller:0.4.09c6ed23e2f0e
gnutls28@3.8.9-3+deb13u4
no fix listed

Open the chart page →

2,362
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
gnutls28@3.7.9-2+deb12u4
no fix listed

Open the chart page →

6,509
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
gnutls28@3.7.9-2+deb12u2
no fix listed

Open the chart page →

7,767
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
gnutls28@3.7.9-2
no fix listed

Open the chart page →

11,133
jenkinswebencryptor1.9.181 of 1See more

jenkins webencryptor 1.9.18

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
gnutls28@3.8.9-3+deb13u4
no fix listed

Open the chart page →

2,129
welcome-apiwelcome-api7.0.01 of 1See more

welcome-api welcome-api 7.0.0

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
lucassandin/welcome-api:latest04551c5d5881
gnutls28@3.7.9-2+deb12u2
no fix listed

Open the chart page →

3,401
welcome-elos-webappwelcome-elos-webappVerified publisher2.0.01 of 1See more

welcome-elos-webapp welcome-elos-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
pococze/python-hello-elos:2.0.07a1aab425e51
gnutls28@3.7.9-2+deb12u3
no fix listed

Open the chart page →

2,976
apisixwener2.18.01 of 3See more

apisix wener 2.18.0

1 of the 3 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
gnutls28@3.7.9-2+deb12u4
no fix listed

Open the chart page →

3,650
apisix-ingress-controllerwener1.4.01 of 2See more

apisix-ingress-controller wener 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
gnutls28@3.7.9-2+deb12u7
no fix listed

Open the chart page →

2,334
giteawener12.7.03 of 4See more

gitea wener 12.7.0

3 of the 4 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
gnutls28@3.7.9-2+deb12u5
no fix listed
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
gnutls28@3.7.9-2+deb12u5
no fix listed
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
gnutls28@3.7.9-2+deb12u5
no fix listed

Open the chart page →

10,495
juicefs-csi-driverwener0.33.01 of 5See more

juicefs-csi-driver wener 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
gnutls28@3.7.9-2+deb12u4
no fix listed

Open the chart page →

12,261
mesherywener1.0.701 of 1See more

meshery wener 1.0.70

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest44b64ee128fb
gnutls28@3.7.9-2+deb12u7
no fix listed

Open the chart page →

2,027
apisixwenerme2.18.01 of 3See more

apisix wenerme 2.18.0

1 of the 3 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
gnutls28@3.7.9-2+deb12u4
no fix listed

Open the chart page →

3,650
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
gnutls28@3.7.9-2+deb12u7
no fix listed

Open the chart page →

2,334
giteawenerme12.7.03 of 4See more

gitea wenerme 12.7.0

3 of the 4 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
gnutls28@3.7.9-2+deb12u5
no fix listed
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
gnutls28@3.7.9-2+deb12u5
no fix listed
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
gnutls28@3.7.9-2+deb12u5
no fix listed

Open the chart page →

10,495
juicefs-csi-driverwenerme0.33.01 of 5See more

juicefs-csi-driver wenerme 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
gnutls28@3.7.9-2+deb12u4
no fix listed

Open the chart page →

12,261
mesherywenerme1.0.701 of 1See more

meshery wenerme 1.0.70

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest44b64ee128fb
gnutls28@3.7.9-2+deb12u7
no fix listed

Open the chart page →

2,027
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.7.45f2a56b95266
gnutls28@3.7.9-2+deb12u1
no fix listed

Open the chart page →

17,084
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
library/postgres:1874935e722416
gnutls28@3.8.9-3+deb13u4
no fix listed

Open the chart page →

4,419
keycloakwiremindVerified publisher25.3.12 of 2See more

keycloak wiremind 25.3.1

2 of the 2 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
gnutls28@3.7.9-2+deb12u5
no fix listed
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
gnutls28@3.7.9-2+deb12u5
no fix listed

Open the chart page →

8,863
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
gnutls28@3.7.9-2+deb12u1
no fix listed

Open the chart page →

5,944
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
gnutls28@3.7.9-2+deb12u5
no fix listed

Open the chart page →

3,237
rediswiremindVerified publisher23.0.61 of 1See more

redis wiremind 23.0.6

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/redis:8.4.0-debian-12-r31f0f7ddc4370
gnutls28@3.7.9-2+deb12u5
no fix listed

Open the chart page →

2,700
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
library/wordpress:latestf32ffa85064d
gnutls28@3.8.9-3+deb13u4
no fix listed

Open the chart page →

5,823
wordpresswordpress-ng1.0.111 of 2See more

wordpress wordpress-ng 1.0.11

1 of the 2 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
cloudtooling/wordpress:7.1.3fb4863035a05
gnutls28@3.7.9-2+deb12u7
no fix listed

Open the chart page →

4,890
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
gnutls28@3.7.9-2+deb12u3
no fix listed

Open the chart page →

12,178
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
gnutls28@3.7.9-2+deb12u2
no fix listed

Open the chart page →

8,831
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
gnutls28@3.7.9-2+deb12u3
no fix listed
hamzaarshad10/querypodpy:1.7154f38e8668e
gnutls28@3.7.9-2+deb12u3
no fix listed
murtazashah46/helmfile:latest4d11726cf803
gnutls28@3.7.9-2+deb12u3
no fix listed

Open the chart page →

15,702
cloudeye-exporterxxl-job-adminVerified publisher0.1.21 of 1See more

cloudeye-exporter xxl-job-admin 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
dellnoantechnp/cloudeye-exporter:v2.0.316873356c882d
gnutls28@3.7.9-2+deb12u6
no fix listed

Open the chart page →

3,565
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.0.0-beta.11ea1b0aaabe09
gnutls28@3.7.9-2+deb12u4
no fix listed
library/redis:6.2e7b96daa9a18
gnutls28@3.7.9-2+deb12u7
no fix listed

Open the chart page →

12,694
pgcatxxl-job-adminVerified publisher0.3.31 of 1See more

pgcat xxl-job-admin 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
gnutls28@3.7.9-2+deb12u3
no fix listed

Open the chart page →

3,466
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
library/nginx:latestf9ea18bfa4fa
gnutls28@3.8.9-3+deb13u4
no fix listed

Open the chart page →

1,747
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
library/nginx:stable9bf97bd7714f
gnutls28@3.8.9-3+deb13u4
no fix listed

Open the chart page →

1,747
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
gnutls28@3.7.9-2+deb12u2
no fix listed

Open the chart page →

2,940
jenkinszanise-jenkins-helm-chart0.1.01 of 1See more

jenkins zanise-jenkins-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsa660310e39ad
gnutls28@3.8.9-3+deb13u4
no fix listed

Open the chart page →

2,129
changedetection-iozekker6Verified publisher1.103.01 of 1See more

changedetection-io zekker6 1.103.0

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.834df3680db1c
gnutls28@3.7.9-2+deb12u7
no fix listed

Open the chart page →

3,005
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
library/nginx:latestf9ea18bfa4fa
gnutls28@3.8.9-3+deb13u4
no fix listed

Open the chart page →

1,747
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
gnutls28@3.7.9-2+deb12u7
no fix listed

Open the chart page →

5,139
zimagizimagi2.7.171 of 6See more

zimagi zimagi 2.7.17

1 of the 6 container images this version deploys carry CVE-2026-88647.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.15.331407c0e8e32
gnutls28@3.7.9-2+deb12u5
no fix listed

Open the chart page →

2,175

Container images carrying it

1,235 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/nginx:1.27.098f8ec75657d
gnutls28@3.7.9-2+deb12u3
no fix listed
2
library/nginx:1.29.49dd288848f44
gnutls28@3.8.9-3+deb13u1
no fix listed
2
library/nginx:stableb972f831f200
gnutls28@3.8.9-3+deb13u4
no fix listed
2
library/node:lts64af3819f927
gnutls28@3.7.9-2+deb12u7
no fix listed
2
library/phpmyadmin:5.2.16e75aa8f767c
gnutls28@3.7.9-2+deb12u3
no fix listed
2
library/postgres:16.109f23e02d766
gnutls28@3.7.9-2+deb12u1
no fix listed
2
library/postgres:18.11090bc3a8ccf
gnutls28@3.8.9-3+deb13u1
no fix listed
2
library/postgres:17-bookworm3645570cccdf
gnutls28@3.7.9-2+deb12u7
no fix listed
2
library/postgres:16.24aea012537ed
gnutls28@3.7.9-2+deb12u2
no fix listed
2
library/postgres:18.06f3e42ad37de
gnutls28@3.8.9-3
no fix listed
2
library/postgres:17.5aadf2c0696f5
gnutls28@3.8.9-3
no fix listed
2
library/postgres:14c2427de38f99
gnutls28@3.8.9-3+deb13u4
no fix listed
2
library/postgres:17c6222b54873a
gnutls28@3.8.9-3+deb13u4
no fix listed
2
library/postgres:16ca0bd484cb98
gnutls28@3.8.9-3+deb13u4
no fix listed
2
library/postgres:16.4e62fbf9d3e2b
gnutls28@3.7.9-2+deb12u3
no fix listed
2
library/python:3.7eedf63967cdb
gnutls28@3.7.9-2
no fix listed
2
library/redis:7.2.3a7cee7c8178f
gnutls28@3.7.9-2+deb12u1
no fix listed
2
library/redis:6:6.2a9c881672688
gnutls28@3.7.9-2+deb12u7
no fix listed
2
library/redis:6.2c1cc41c5583b
gnutls28@3.7.9-2+deb12u7
no fix listed
2
library/redis:7:7.4:7.4.11c6eabf748fc7
gnutls28@3.7.9-2+deb12u7
no fix listed
2
library/redis:8.2.2f0957bcaa75f
gnutls28@3.7.9-2+deb12u5
no fix listed
2
library/redmine:6.1.3-trixief474a901faec
gnutls28@3.8.9-3+deb13u4
no fix listed
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
gnutls28@3.8.9-3
no fix listed
2
library/wordpress:7.1.2-apache:lateste04cf657f248
gnutls28@3.8.9-3+deb13u4
no fix listed
2
library/wordpress:latestf32ffa85064d
gnutls28@3.8.9-3+deb13u4
no fix listed
2
localstack/localstack-pro:latest801a3dff7f6a
gnutls28@3.8.9-3+deb13u4
no fix listed
2
locustio/locust:2.32.2a0d4b88e42c1
gnutls28@3.7.9-2+deb12u3
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
gnutls28@3.7.9-2+deb12u6
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
gnutls28@3.7.9-2+deb12u6
no fix listed
2
louislam/uptime-kuma:2.5.5c74379ac4509
gnutls28@3.7.9-2+deb12u6
no fix listed
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
gnutls28@3.7.9-2+deb12u3
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
gnutls28@3.7.9-2
no fix listed
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
gnutls28@3.7.9-2
no fix listed
2
nginxinc/nginx-unprivileged:stabled715f7a85cdf
gnutls28@3.8.9-3+deb13u4
no fix listed
2
nousresearch/hermes-agent:v2026.9.24fca358f12efd
gnutls28@3.8.9-3+deb13u4
no fix listed
2
obolnetwork/charon:v1.10.0278c7e2897b6
gnutls28@3.8.9-3+deb13u2
no fix listed
2
opea/embedding-tei:1.05c9639de61c1
gnutls28@3.7.9-2+deb12u3
no fix listed
2
opea/reranking-tei:1.0e48613afb191
gnutls28@3.7.9-2+deb12u3
no fix listed
2
opea/retriever-redis:1.0eb746b263705
gnutls28@3.7.9-2+deb12u3
no fix listed
2
openbas/caldera-server:5.1.0a277796d9724
gnutls28@3.7.9-2+deb12u2
no fix listed
2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
gnutls28@3.7.9-2+deb12u4
no fix listed
2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
gnutls28@3.7.9-2+deb12u4
no fix listed
2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
gnutls28@3.7.9-2+deb12u4
no fix listed
2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
gnutls28@3.7.9-2+deb12u4
no fix listed
2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
gnutls28@3.7.9-2+deb12u4
no fix listed
2
opencsghq/label-studio:v2.5.047e22aa71870
gnutls28@3.8.9-3+deb13u4
no fix listed
2
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
gnutls28@3.7.9-2+deb12u5
no fix listed
2
patrikx3/p3x-redis-ui:latestf19eb45b0694
gnutls28@3.7.9-2+deb12u7
no fix listed
2
pgvector/pgvector:pg167b822b0aac60
gnutls28@3.7.9-2+deb12u7
no fix listed
2
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
gnutls28@3.8.9-3+deb13u4
no fix listed
2

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.