StackRadar

CVE-2026-88806

High

Advisory

Published 21 Sept 2026In the index since 23 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
10th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
778
of 17,832 indexed, latest versions
Container images
682
deployed by those charts
Fix available
1 of 2
affected packages

libX11-6-1.8.13-2.1 on GA media

Carried by container images the latest versions of 778 of 17,832 indexed charts deploy, on 682 images.

Affected packageAffected versionsFixed inImages
libx11deb2:1.6.2-1ubuntu2, 2:1.6.2-1ubuntu2.1, 2:1.6.3-1ubuntu2, 2:1.6.3-1ubuntu2.1+17 moreno fix listed681
libX11rpm1.6.5-lp152.5.9.11.8.13-2.11
OSV records
DEBIAN-CVE-2026-88806UBUNTU-CVE-2026-88806openSUSE-SU-2026:11833-1
Trending
Rank 10 in indexed charts, since 23 Sept 2026. See the ranking →

Charts affected

778 by stars
ChartLatestAffected imagesRadar Score
workerot-container-kit0.1.01 of 1See more

worker ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,623
lens-metric-proxyowan-charts0.1.01 of 1See more

lens-metric-proxy owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:stable0aa2d81d65bc
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,623
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
libx11@2:1.7.5-1ubuntu0.3
no fix listed

Open the chart page →

3,746
k3p2p-avs0.1.51 of 2See more

k3 p2p-avs 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
libx11@2:1.7.5-1ubuntu0.3
no fix listed

Open the chart page →

2,415
mishtip2p-avs0.1.01 of 2See more

mishti p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
libx11@2:1.7.5-1ubuntu0.3
no fix listed

Open the chart page →

4,130
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

12,627
ungatep2p-avs0.1.03 of 3See more

ungate p2p-avs 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
libx11@2:1.8.4-2+deb12u2
no fix listed
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
libx11@2:1.8.4-2+deb12u2
no fix listed
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
libx11@2:1.7.5-1ubuntu0.3
no fix listed

Open the chart page →

28,063
minecraftpaul1365972-mc3.0.11 of 1See more

minecraft paul1365972-mc 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
itzg/minecraft-server:latest77280d10744f
libx11@2:1.8.7-1build1
no fix listed

Open the chart page →

4,217
examplepauls-helm-charts0.1.21 of 1See more

example pauls-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,999
kubeconpauls-helm-charts0.1.01 of 1See more

kubecon pauls-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,999
matomopetbattle11.0.11 of 2See more

matomo petbattle 11.0.1

1 of the 2 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

11,362
dummy-servicephanVerified publisher0.3.41 of 1See more

dummy-service phan 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
phan2410/dummy-service:0.0.89c6ed6de26ca
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

5,956
falcon-asgi-serverphanVerified publisher0.1.01 of 1See more

falcon-asgi-server phan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
phan2410/falcon-asgi-server:0.1.04a86d138832d
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

8,438
phronetisphronetis0.1.271 of 2See more

phronetis phronetis 0.1.27

1 of the 2 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
knspar/phronetis-operator:0.1.60c4f0543ee58
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

16,621
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
libx11@2:1.6.9-2ubuntu1.2
no fix listed

Open the chart page →

90,244
subgraph-oraclepinaxVerified publisher0.0.11 of 1See more

subgraph-oracle pinax 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

11,609
pingdom-operatorpingdom-operator0.0.201 of 1See more

pingdom-operator pingdom-operator 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

12,197
web-chartpjw-ktcloudlab0.1.01 of 1See more

web-chart pjw-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,623
planectlplanectlVerified publisher0.7.02 of 10See more

planectl planectl 0.7.0

2 of the 10 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/node:208f693eaa7e0a
libx11@2:1.8.4-2+deb12u2
no fix listed
quay.io/argoproj/argocd:v2.14.115fc69e31c755
libx11@2:1.8.7-1build1
no fix listed

Open the chart page →

26,700
k8s-oidc-discovery-providerpnnl-miscscripts0.1.21 of 2See more

k8s-oidc-discovery-provider pnnl-miscscripts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:1.29.49dd288848f44
libx11@2:1.8.12-1
no fix listed

Open the chart page →

4,432
nginx-apppnnl-miscscripts0.1.21 of 1See more

nginx-app pnnl-miscscripts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,999
pixiecore-simpleconfigpnnl-miscscripts0.1.51 of 1See more

pixiecore-simpleconfig pnnl-miscscripts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:stable0aa2d81d65bc
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,623
pod-birdspod-birds0.1.01 of 1See more

pod-birds pod-birds 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
teknas09/bird-pod:latest12a1fa85c4aa
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

13,201
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libx11@2:1.6.9-2ubuntu1.2
no fix listed

Open the chart page →

77,574
libretimepodzone-chartsVerified publisher0.4.12 of 9See more

libretime podzone-charts 0.4.1

2 of the 9 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libx11@2:1.8.12-1
no fix listed
ghcr.io/libretime/icecast:latest4bee94ce480c
libx11@2:1.8.12-1
no fix listed

Open the chart page →

11,335
wp-chartprojet-devops0.1.01 of 2See more

wp-chart projet-devops 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/wordpress:latest8746e7e072e3
libx11@2:1.8.12-1
no fix listed

Open the chart page →

4,583
web-chartpsb-ktcloudlab0.1.01 of 1See more

web-chart psb-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,623
web-chartpsg-ktcloudlab0.1.01 of 1See more

web-chart psg-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,623
nginx-chartpshs-nginx0.1.01 of 1See more

nginx-chart pshs-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,623
apppvillaverdeVerified publisher0.2.61 of 1See more

app pvillaverde 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:1.31a53fc6c27208
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,902
game-serverpvillaverdeVerified publisher1.0.61 of 1See more

game-server pvillaverde 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
ghcr.io/itzg/minecraft-server:latest46919d151d39
libx11@2:1.8.7-1build1
no fix listed

Open the chart page →

4,359
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
libx11@2:1.8.4-2
no fix listed

Open the chart page →

14,827
mychartpythonweb0.1.01 of 1See more

mychart pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

12,840
mypythonpythonweb0.1.01 of 1See more

mypython pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

12,840
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

8,096
nginx-chartrabsnginx0.1.01 of 1See more

nginx-chart rabsnginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:1.276784fb0834aa
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

4,575
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
libx11@2:1.6.9-2ubuntu1.2
no fix listed

Open the chart page →

15,686
my-nginx-apprepo-for-helm-nginx-app0.1.01 of 1See more

my-nginx-app repo-for-helm-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,999
redminerestic-pvc-backupVerified publisher0.2.61 of 1See more

redmine restic-pvc-backup 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
libx11@2:1.8.12-1
no fix listed

Open the chart page →

4,455
esphomeretsamedocVerified publisher2026.2.51 of 1See more

esphome retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
esphome/esphome:2024.3.09ab8cc88b28c
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

7,550
juicepassproxyretsamedocVerified publisher2026.2.41 of 1See more

juicepassproxy retsamedoc 2026.2.4

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

4,002
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

7,284
revwallet-apirevwallet0.7.121 of 1See more

revwallet-api revwallet 0.7.12

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
arthurjguerra18/revwallet:v0.7.12f540af20b307
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

6,024
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

15,978
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latest7e2ef5261764
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

6,576
reviewboardrock8sVerified publisher0.0.11 of 3See more

reviewboard rock8s 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libx11@2:1.8.12-1
no fix listed

Open the chart page →

5,879
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

9,825
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
libx11@2:1.7.5-1
no fix listed

Open the chart page →

13,259
devtron-enterpriseromholdings48.0.02 of 28See more

devtron-enterprise romholdings 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
libx11@2:1.8.7-1build1
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

70,037
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88806.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
libx11@2:1.7.5-1ubuntu0.3
no fix listed

Open the chart page →

7,916

Container images carrying it

682 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
libx11@2:1.8.4-2+deb12u2
no fix listed
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
libx11@2:1.8.4-2+deb12u2
no fix listed
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
libx11@2:1.8.4-2+deb12u2
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
libx11@2:1.8.4-2+deb12u2
no fix listed
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
libx11@2:1.8.4-2+deb12u2
no fix listed
1
ghcr.io/zammad/zammad:7.1.3-0017305162d81325
libx11@2:1.8.12-1
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
libx11@2:1.8.4-2+deb12u2
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
libx11@2:1.8.4-2+deb12u2
no fix listed
1
mcr.microsoft.com/playwright/mcp:v0.0.43e101b832b34d
libx11@2:1.8.4-2+deb12u2
no fix listed
1
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
libx11@2:1.8.4-2+deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
libx11@2:1.8.4-2+deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
libx11@2:1.8.4-2+deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
libx11@2:1.8.4-2+deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
libx11@2:1.8.4-2+deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
libx11@2:1.8.4-2+deb12u2
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
libx11@2:1.8.4-2+deb12u2
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libx11@2:1.6.9-2ubuntu1.2
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
libx11@2:1.8.4-2+deb12u2
no fix listed
1
quay.io/aerokube/keygen:1.0.1578934444f04
libx11@2:1.7.5-1ubuntu0.3
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
libx11@2:1.7.5-1
no fix listed
1
quay.io/argoproj/argocd:v2.10.783c86003b781
libx11@2:1.7.5-1ubuntu0.3
no fix listed
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
libx11@2:1.8.7-1build1
no fix listed
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
libx11@2:1.8.7-1build1
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
libx11@2:1.7.5-1ubuntu0.3
no fix listed
1
quay.io/go-skynet/local-ai:latest0632c21ddbe4
libx11@2:1.8.7-1build1
no fix listed
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
libx11@2:1.8.4-2+deb12u2
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libx11@2:1.6.3-1ubuntu2.1
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libx11@2:1.8.4-2+deb12u1
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
libx11@2:1.8.7-1build1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
libx11@2:1.8.12-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
libx11@2:1.8.4-2+deb12u2
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
libx11@2:1.8.4-2+deb12u2
no fix listed
1

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.