StackRadar

CVE-2026-89156

Medium

Advisory

Published 11 Sept 2026In the index since 12 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,270
of 17,813 indexed, latest versions
Container images
2,246
deployed by those charts
Fix available
1 of 2
affected packages

CVE-2026-89156 affecting package nmap 7.95-5

Carried by container images the latest versions of 2,270 of 17,813 indexed charts deploy, on 2,246 images.

Affected packageAffected versionsFixed inImages
pcre2deb10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+10 more10.42-1+deb12u1, 10.46-1~deb13u22,245
nmaprpm7.95-4.azl3no fix listed1
OSV records
DEBIAN-CVE-2026-89156UBUNTU-CVE-2026-89156AZL-101754
Trending
Rank 14 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

2,270 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,246 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
prodrigestivill/postgres-backup-local:latestf70742ebe42b
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
project2team4/react:latest3ff031a08887
pcre2@10.34-7
no fix listed
1
prom/cloudwatch-exporter:v0.16.071c2e988af06
pcre2@10.42-4ubuntu2
no fix listed
1
promzeus/redis-sentinel-gateway:v182f6d56e280b
pcre2@10.42-1
10.42-1+deb12u1
1
prowlercloud/prowler-api:5.31.14f252d579be2
pcre2@10.42-1
10.42-1+deb12u1
1
proxysql/proxysql:3.0.8947a7abad45b
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
proxysql/proxysql:2.7.3a4d6c35c2949
pcre2@10.42-1
10.42-1+deb12u1
1
pschichtel/mindustry-server:v145.1b543e9c2d371
pcre2@10.39-3ubuntu0.1
no fix listed
1
psorab/elibrary:latest53b68896c4ce
pcre2@10.34-7ubuntu0.1
no fix listed
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
pcre2@10.34-7
no fix listed
1
qdrant/qdrant:v1.7.45f2a56b95266
pcre2@10.42-1
10.42-1+deb12u1
1
qdrant/qdrant:v1.4.166ee661d5241
pcre2@10.42-1
10.42-1+deb12u1
1
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
qonstrukt/php:8.4-v8-apache089af7925aa1
pcre2@10.42-4ubuntu2.1
no fix listed
1
quickwit/quickwit:v0.8.1d29332bdadcc
pcre2@10.42-1
10.42-1+deb12u1
1
qumine/minecraft-server:v0.1.15c0b650d51132
pcre2@10.39-3ubuntu0.1
no fix listed
1
qxip/qryn:3.2.3977acc9c7a9fd
pcre2@10.42-1
10.42-1+deb12u1
1
rabeh/apibootspring:1.0941007b6946e
pcre2@10.39-3ubuntu0.1
no fix listed
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
pcre2@10.42-4ubuntu2.1
no fix listed
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
pcre2@10.42-4ubuntu2.1
no fix listed
1
razorbladex401/dayz:latest6a4d79248e7d
pcre2@10.39-3ubuntu0.1
no fix listed
1
readysettech/sqp:latest588f3507280e
pcre2@10.42-4ubuntu2.1
no fix listed
1
readysettech/sqp-duckdb:latest67a83203ce60
pcre2@10.42-4ubuntu2.1
no fix listed
1
reallibrephotos/librephotos-proxy:1.0.398a13dabbadc
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
redash/redash:25.8.000d813437db5
pcre2@10.42-1
10.42-1+deb12u1
1
redash/redash:26.3.0c5c9148f5c38
pcre2@10.42-1
10.42-1+deb12u1
1
redimp/otterwiki:2778bf30da3da
pcre2@10.42-1
10.42-1+deb12u1
1
redis/redis-stack-server:6.2.6-v251a58f32d412
pcre2@10.34-7ubuntu0.1
no fix listed
1
redis/redis-stack-server:latest798ab84d9f26
pcre2@10.39-3ubuntu0.1
no fix listed
1
redis/redis-stack-server:7.4.0-v0887cf87cc744
pcre2@10.39-3ubuntu0.1
no fix listed
1
redpandadata/redpanda:latest468bd13a9f2b
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
resurfaceio/resurface:3.7.84d5cda2f64109
pcre2@10.39-3ubuntu0.1
no fix listed
1
rezachalak/bzen-mongo:1.0.034f694325191
pcre2@10.34-7ubuntu0.1
no fix listed
1
rhasspy/wyoming-openwakeword:2.1.052cb1168731a
pcre2@10.42-1
10.42-1+deb12u1
1
rhasspy/wyoming-piper:2.3.169b7f797ae3a
pcre2@10.42-1
10.42-1+deb12u1
1
rhasspy/wyoming-piper:2.5.27d39aafac409
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
pcre2@10.42-1
10.42-1+deb12u1
1
rhasspy/wyoming-whisper:3.5.0308b7959a925
pcre2@10.42-1
10.42-1+deb12u1
1
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
pcre2@10.34-7
no fix listed
1
rnwood/smtp4dev:3.6.1912304153668
pcre2@10.42-1
10.42-1+deb12u1
1
robotshop/rs-mongodb:latest119b545823cd
pcre2@10.34-7
no fix listed
1
robustadev/krr:v1.30.0b8d782e568c7
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
rocketadmin/rocketadmin:1.17.710955ef540b9
pcre2@10.42-1
10.42-1+deb12u1
1
rocketchat/freeswitch:stablecfba5c20a5cc
pcre2@10.42-1
10.42-1+deb12u1
1
rotationalio/beacon:0.2.0f8d8b694515a
pcre2@10.46-1~deb13u1+dhi1
10.46-1~deb13u2
1
rotationalio/endeavor:1.3.0ac566baddc06
pcre2@10.42-1
10.42-1+deb12u1
1
rotationalio/genoa:1.2.03ab583519215
pcre2@10.42-1
10.42-1+deb12u1
1
rotationalio/geoping:1.3.034bcb6fc3cb7
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
rotationalio/honu:0.5.069fd30c2e31c
pcre2@10.42-1
10.42-1+deb12u1
1
rotationalio/rotational-api:1.3.0f1a2d05d8fff
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.