StackRadar

CVE-2026-89156

Medium

Advisory

Published 11 Sept 2026In the index since 12 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,283
of 17,803 indexed, latest versions
Container images
2,220
deployed by those charts
Fix available
1 of 2
affected packages

CVE-2026-89156 affecting package nmap 7.95-5

Carried by container images the latest versions of 2,283 of 17,803 indexed charts deploy, on 2,220 images.

Affected packageAffected versionsFixed inImages
pcre2deb10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+10 more10.42-1+deb12u1, 10.46-1~deb13u22,219
nmaprpm7.95-4.azl3no fix listed1
OSV records
DEBIAN-CVE-2026-89156UBUNTU-CVE-2026-89156AZL-101754
Trending
Rank 7 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

2,283 by stars
ChartLatestAffected imagesRadar Score
databend-metakubesphere-stable0.7.31 of 1See more

databend-meta kubesphere-stable 0.7.3

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
datafuselabs/databend-meta:v1.2.279ba877ee6cb4d
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

2,864
databend-querykubesphere-stable0.8.31 of 1See more

databend-query kubesphere-stable 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
datafuselabs/databend-query:v1.2.279a936843b85b4
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

2,864
deepflowkubesphere-stable6.2.6062 of 8See more

deepflow kubesphere-stable 6.2.606

2 of the 8 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
pcre2@10.34-7
no fix listed
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

18,476
iomeshkubesphere-stable1.1.04 of 25See more

iomesh kubesphere-stable 1.1.0

4 of the 25 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
iomesh/csi-driver:v2.7.25d3f9bf9240b
pcre2@10.39-3ubuntu0.1
no fix listed
iomesh/node-disk-exporter:1.8.0f03148764f38
pcre2@10.34-7
no fix listed
iomesh/node-disk-manager:1.8.0002c4b92fd34
pcre2@10.34-7
no fix listed
iomesh/node-disk-operator:1.8.0f6c76380db34
pcre2@10.34-7
no fix listed

Open the chart page →

49,027
IOMeshkubesphere-stable1.2.04 of 25See more

IOMesh kubesphere-stable 1.2.0

4 of the 25 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
iomesh/csi-driver:v2.8.01a151f602451
pcre2@10.39-3ubuntu0.1
no fix listed
iomesh/node-disk-exporter:1.8.0f03148764f38
pcre2@10.34-7
no fix listed
iomesh/node-disk-manager:1.8.0-2292ad270082e
pcre2@10.42-4ubuntu2
no fix listed
iomesh/node-disk-operator:1.8.0-1de4aa40684ad
pcre2@10.42-4ubuntu2
no fix listed

Open the chart page →

46,717
pulsarkubesphere-stable2.7.131 of 3See more

pulsar kubesphere-stable 2.7.13

1 of the 3 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
pcre2@10.34-7
no fix listed

Open the chart page →

86,937
mysqlkubesphere-testVerified publisher1.0.21 of 3See more

mysql kubesphere-test 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
pcre2@10.34-7
no fix listed

Open the chart page →

7,397
xenondbkubesphere-testVerified publisher1.0.01 of 3See more

xenondb kubesphere-test 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
pcre2@10.34-7
no fix listed

Open the chart page →

7,397
kubevoipkubevoipOfficialVerified publisher0.6.81 of 1See more

kubevoip kubevoip 0.6.8

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/kubevoip/kubevoip:v0.6.841c603a93642
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,123
kube-wordpress-mysqlkube-wordpress-mysql0.1.01 of 2See more

kube-wordpress-mysql kube-wordpress-mysql 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/wordpress:php8.1-apachef73396626d2f
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

8,816
penpotkubitodevVerified publisher1.2.12 of 5See more

penpot kubitodev 1.2.1

2 of the 5 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
pcre2@10.39-3ubuntu0.1
no fix listed
penpotapp/exporter:2.2.15c835ffd87ab
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

17,037
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.43 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

3 of the 9 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
grafana/alloy:v1.5.101a63f4e032c
pcre2@10.42-4ubuntu2
no fix listed
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

20,515
ctrlmeshkusionstackVerified publisher0.2.01 of 1See more

ctrlmesh kusionstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
pcre2@10.34-7ubuntu0.1
no fix listed

Open the chart page →

3,481
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

59,153
sample-operatorkusionstackVerified publisher0.1.21 of 1See more

sample-operator kusionstack 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
chaerr/kridge:demo-operator-v0.1.266833deec017
pcre2@10.34-7ubuntu0.1
no fix listed

Open the chart page →

2,515
fstyr-ddp-keycloak-application-platform-configkvalitetsitVerified publisher0.1.131 of 1See more

fstyr-ddp-keycloak-application-platform-config kvalitetsit 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
pcre2@10.42-4ubuntu2
no fix listed

Open the chart page →

3,163
keycloak-application-platform-configkvalitetsitVerified publisher0.0.291 of 1See more

keycloak-application-platform-config kvalitetsit 0.0.29

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
pcre2@10.42-4ubuntu2
no fix listed

Open the chart page →

3,393
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

7,852
nginx-chartkyb-nginx0.1.01 of 1See more

nginx-chart kyb-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,879
pageslatif-pages1.0.01 of 3See more

pages latif-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pcre2@10.34-7
no fix listed

Open the chart page →

20,261
pageslavanya-pages1.0.01 of 3See more

pages lavanya-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pcre2@10.34-7
no fix listed

Open the chart page →

20,261
homebridgelbenicio-communityVerified publisher0.1.151 of 1See more

homebridge lbenicio-community 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
pcre2@10.42-4ubuntu2.1
no fix listed

Open the chart page →

29,715
kubernetes-dashboardlbenicio-communityVerified publisher7.14.91 of 5See more

kubernetes-dashboard lbenicio-community 7.14.9

1 of the 5 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/kong:3.92a8cf3b110cd
pcre2@10.42-4ubuntu2.1
no fix listed

Open the chart page →

2,322
smtplbenicio-communityVerified publisher0.1.31 of 1See more

smtp lbenicio-community 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,372
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

33,731
jenkinsleechistest2.7.11 of 2See more

jenkins leechistest 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

4,464
kinesaliteleprechaun-charts0.1.21 of 1See more

kinesalite leprechaun-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
instructure/kinesalite:latest34400d82f28f
pcre2@10.34-7ubuntu0.1
no fix listed

Open the chart page →

4,287
owntracks-exporterleprechaun-charts0.1.111 of 1See more

owntracks-exporter leprechaun-charts 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

4,086
vaultwardenleprechaun-charts0.1.281 of 1See more

vaultwarden leprechaun-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.1ebdfe70701c6
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

2,076
jackettlib42Verified publisher1.1.01 of 1See more

jackett lib42 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
lib42/jackett:latesta55596cda383
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

4,668
libredb-studiolibredb-studio-oci0.1.641 of 1See more

libredb-studio libredb-studio-oci 0.1.64

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.16.0fa925884368a
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,182
librenmslibrenms10.1.11 of 5See more

librenms librenms 10.1.1

1 of the 5 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

3,169
kube-iptables-tailerlifen0.2.31 of 1See more

kube-iptables-tailer lifen 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
pcre2@10.34-7
no fix listed

Open the chart page →

4,472
lightlyticslightlytics0.1.212 of 2See more

lightlytics lightlytics 0.1.21

2 of the 2 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
pcre2@10.42-1
10.42-1+deb12u1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

5,439
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

38,429
weblinzhengen0.1.71 of 1See more

web linzhengen 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,879
listmonklistmonk-chartVerified publisher2.0.11 of 2See more

listmonk listmonk-chart 2.0.1

1 of the 2 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

3,128
pocketbase-halitesql0.0.31 of 1See more

pocketbase-ha litesql 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/litesql/pocketbase-ha:latestc5b28608958b
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,164
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

10,821
pagesliviu884422-pages1.0.01 of 3See more

pages liviu884422-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pcre2@10.34-7
no fix listed

Open the chart page →

20,261
web-chartljw-ktcloudlab0.1.01 of 1See more

web-chart ljw-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,879
llmarinerllmariner1.53.11 of 21See more

llmariner llmariner 1.53.1

1 of the 21 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

12,177
jellyfinlmatfyVerified publisher0.1.31 of 1See more

jellyfin lmatfy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11aefb67e6a7ff
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

2,658
mt-mcp-grafanaloafoe0.10.01 of 2See more

mt-mcp-grafana loafoe 0.10.0

1 of the 2 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
grafana/mcp-grafana:0.14.042f541f22063
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

1,981
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
locustio/locust:2.24.151d866285170
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

7,570
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

33,731
vnode-runtimeloftVerified publisher0.3.31 of 1See more

vnode-runtime loft 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

2,536
nightingalelogic3579Verified publisher0.3.13 of 6See more

nightingale logic3579 0.3.1

3 of the 6 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
pcre2@10.42-4ubuntu2.1
no fix listed
flashcatcloud/nightingale:8.5.1421acb36181b
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
library/redis:6.2143f7bfc2358
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

9,147
rocketmq-exporterlogic3579Verified publisher0.0.21 of 1See more

rocketmq-exporter logic3579 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
apache/rocketmq-exporter:0.0.2c8fb51195444
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

6,680
login-test-backendlogin-test-backend0.1.01 of 2See more

login-test-backend login-test-backend 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-89156.

Container imageDigestPackageFixed in
aboogie/login_test_backend:new9c41a4483ac8
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

6,591

Container images carrying it

2,220 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
pcre2@10.46-1build1
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
pcre2@10.42-1
10.42-1+deb12u1
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
pcre2@10.42-1
10.42-1+deb12u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
pcre2@10.42-1
10.42-1+deb12u1
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
pcre2@10.34-7
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
pcre2@10.42-1
10.42-1+deb12u1
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
pcre2@10.42-1
10.42-1+deb12u1
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.