StackRadar

CVE-2026-89156

Medium

Advisory

Published 11 Sept 2026In the index since 12 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,283
of 17,803 indexed, latest versions
Container images
2,220
deployed by those charts
Fix available
1 of 2
affected packages

CVE-2026-89156 affecting package nmap 7.95-5

Carried by container images the latest versions of 2,283 of 17,803 indexed charts deploy, on 2,220 images.

Affected packageAffected versionsFixed inImages
pcre2deb10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+10 more10.42-1+deb12u1, 10.46-1~deb13u22,219
nmaprpm7.95-4.azl3no fix listed1
OSV records
DEBIAN-CVE-2026-89156UBUNTU-CVE-2026-89156AZL-101754
Trending
Rank 7 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

2,283 by stars
ChartLatestAffected imagesRadar Score
faasnetfaasnet0.0.41 of 5See more

faasnet faasnet 0.0.4

1 of the 5 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
pcre2@10.42-4ubuntu2.1
no fix listed

Open the chart page →

7,730
capsizefairwinds-incubator0.2.01 of 1See more

capsize fairwinds-incubator 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/python:3-slimcad9a2c87176
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

854
datadog-apmfairwinds-incubator2.0.01 of 1See more

datadog-apm fairwinds-incubator 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
pcre2@10.42-4ubuntu2.1
no fix listed

Open the chart page →

2,882
yelbfairwinds-incubator0.1.11 of 5See more

yelb fairwinds-incubator 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

5,151
event-generatorfalcosecurity0.4.01 of 1See more

event-generator falcosecurity 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
falcosecurity/event-generator:latest932956d86c99
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

3,832
farm-observabilityfarm-observabilityOfficialVerified publisher0.27.22 of 18See more

farm-observability farm-observability 0.27.2

2 of the 18 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
grafana/alloy:v1.16.384b76d56c594
pcre2@10.42-4ubuntu2.1
no fix listed
grafana/alloy:v1.12.2f94b1c82957a
pcre2@10.42-4ubuntu2.1
no fix listed

Open the chart page →

13,583
jenkinsfatihtepe-jenkins1.0.01 of 1See more

jenkins fatihtepe-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

2,517
quickstartfeatureformVerified publisher0.1.12 of 3See more

quickstart featureform 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
library/redis:latest298e5b3bc566
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

3,639
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
pcre2@10.39-3build1
no fix listed

Open the chart page →

13,529
rospoferama0.4.31 of 1See more

rospo ferama 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

6,229
vipienferama0.2.81 of 1See more

vipien ferama 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
pcre2@10.34-7
no fix listed

Open the chart page →

7,536
ferriscompanyferriscompany0.1.01 of 1See more

ferriscompany ferriscompany 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

10,840
fibfibonacci-cluster-appsVerified publisher1.0.03 of 5See more

fib fibonacci-cluster-apps 1.0.0

3 of the 5 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
pcre2@10.42-1
10.42-1+deb12u1
golenski/fibonacci-task-manager:2.0.03a2b36df247b
pcre2@10.42-1
10.42-1+deb12u1
golenski/fibonacci-worker:2.0.0954caf4aaf6a
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

17,045
infrafibonacci-cluster-infraVerified publisher1.0.03 of 4See more

infra fibonacci-cluster-infra 1.0.0

3 of the 4 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.37.0bae523439ee3
pcre2@10.42-4ubuntu2
no fix listed
library/postgres:16.4e62fbf9d3e2b
pcre2@10.42-1
10.42-1+deb12u1
library/redis:7.4.1bb142a9c18ac
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

12,617
fineractfineract-openshift0.1.12 of 4See more

fineract fineract-openshift 0.1.1

2 of the 4 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/mariadb:11.4611a2fcc5fa7
pcre2@10.42-4ubuntu2.1
no fix listed
library/nginx:latest05b8cb60c354
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

7,889
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

5,241
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
fireflyiii/data-importer:version-2.2.3ab52bf932546
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

10,664
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

5,031
flask-contactsfirst-idror-chart1.0.12 of 3See more

flask-contacts first-idror-chart 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
shashkist/flask-contacts-app:latest581de1fd6084
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

5,860
business-api-ecosystemfiware1.1.02 of 4See more

business-api-ecosystem fiware 1.1.0

2 of the 4 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
pcre2@10.34-7ubuntu0.1
no fix listed
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

108,383
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

1,907
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

1,549
apm-hubflanksourceVerified publisher0.0.472 of 2See more

apm-hub flanksource 0.0.47

2 of the 2 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
flanksource/apm-hub:v0.0.471dacc3195bf9
pcre2@10.39-3ubuntu0.1
no fix listed
library/postgres:14156f0b253fd6
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

6,198
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
pcre2@10.42-4ubuntu2.1
no fix listed

Open the chart page →

5,534
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

4,702
flanksource-uiflanksourceVerified publisher1.4.3181 of 1See more

flanksource-ui flanksource 1.4.318

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.318891f21df54fb
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

2,607
mission-controlflanksourceVerified publisher0.1.3382 of 8See more

mission-control flanksource 0.1.338

2 of the 8 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
pcre2@10.42-1
10.42-1+deb12u1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

9,006
mission-control-ai-assistantflanksourceVerified publisher1.0.121 of 1See more

mission-control-ai-assistant flanksource 1.0.12

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/flanksource/mission-control-ai-assistant:1.0.1229a635cbeeb5
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

1,340
flask-contactsflask-contacts-generic1.0.12 of 3See more

flask-contacts flask-contacts-generic 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
shashkist/flask-contacts-app:latest581de1fd6084
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

5,860
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

4,115
flinkflink0.5.11 of 1See more

flink flink 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/flink:1.14.6-scala_2.122461f02672b3
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

5,707
fluentd-aggregatorfluentd-aggregatorOfficialVerified publisher1.0.01 of 2See more

fluentd-aggregator fluentd-aggregator 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,795
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

3,567
dump1090fnzv0.2.81 of 1See more

dump1090 fnzv 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
fnzv/dump1090:latestb3079b95c336
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

4,141
fr24feederfnzv0.1.21 of 1See more

fr24feeder fnzv 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest917e53402d51
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

2,480
mod-z3950folio-org0.1.31 of 1See more

mod-z3950 folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
folioci/mod-z3950:latest2493041ce880
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

2,591
ledgerformance1.2.01 of 1See more

ledger formance 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

4,672
ff-testfrankframework0.7.61 of 2See more

ff-test frankframework 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/postgres:17-bookworm051f7b7b3abd
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

1,796
frank2examplefrankframework0.7.41 of 2See more

frank2example frankframework 0.7.4

1 of the 2 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/postgres:17-bookworm051f7b7b3abd
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

1,796
passboltg0dscookie0.5.21 of 2See more

passbolt g0dscookie 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/mariadb:10.79a48ac9f196f
pcre2@10.34-7ubuntu0.1
no fix listed

Open the chart page →

8,008
changedetection-iogabe565Verified publisher0.12.01 of 2See more

changedetection-io gabe565 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:latestecacd9fd0c66
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

2,649
esphomegabe565Verified publisher0.15.01 of 1See more

esphome gabe565 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:latest000c5ee5ee96
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

3,216
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

13,300
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

6,475
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
pcre2@10.34-7
no fix listed

Open the chart page →

6,007
accumulogaffer2.2.12 of 4See more

accumulo gaffer 2.2.1

2 of the 4 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
pcre2@10.42-4ubuntu2
no fix listed
gchq/hdfs:3.3.35ec58edbb2db
pcre2@10.42-4ubuntu2
no fix listed

Open the chart page →

17,092
gaffer-road-trafficgaffer2.2.11 of 8See more

gaffer-road-traffic gaffer 2.2.1

1 of the 8 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
pcre2@10.42-4ubuntu2
no fix listed

Open the chart page →

9,442
garge-apigargeVerified publisher0.1.551 of 1See more

garge-api garge 0.1.55

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
sondresjo/garge-api:v2.12.6f41e452800ff
pcre2@10.42-4ubuntu2.1
no fix listed

Open the chart page →

1,089
garge-appgargeVerified publisher0.1.471 of 1See more

garge-app garge 0.1.47

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
sondresjo/garge-app:v1.20.70382ebf9dfc8
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

1,883
garge-operatorgargeVerified publisher0.1.341 of 1See more

garge-operator garge 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
sondresjo/garge-operator:v1.9.416cb6643dae6
pcre2@10.42-4ubuntu2.1
no fix listed

Open the chart page →

703

Container images carrying it

2,220 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
pcre2@10.46-1build1
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
pcre2@10.42-1
10.42-1+deb12u1
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
pcre2@10.42-1
10.42-1+deb12u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
pcre2@10.42-1
10.42-1+deb12u1
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
pcre2@10.34-7
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
pcre2@10.42-1
10.42-1+deb12u1
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.