StackRadar

CVE-2026-89157

High

Advisory

Published 11 Sept 2026In the index since 12 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,270
of 17,813 indexed, latest versions
Container images
2,246
deployed by those charts
Fix available
1 of 2
affected packages

CVE-2026-89157 affecting package nmap 7.95-5

Carried by container images the latest versions of 2,270 of 17,813 indexed charts deploy, on 2,246 images.

Affected packageAffected versionsFixed inImages
pcre2deb10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+10 more10.42-1+deb12u1, 10.46-1~deb13u22,245
nmaprpm7.95-4.azl3no fix listed1
OSV records
DEBIAN-CVE-2026-89157UBUNTU-CVE-2026-89157AZL-101748
Trending
Rank 9 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

2,270 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,246 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/mongo:5.0.32-focal3b6c281e1c08
pcre2@10.34-7ubuntu0.1
no fix listed
1
library/mongo:7.0-jammy:7-jammy406a4fdca9fc
pcre2@10.39-3ubuntu0.1
no fix listed
1
library/mongo:5.0.14-focal50cae5081ab4
pcre2@10.34-7ubuntu0.1
no fix listed
1
library/mongo:6.0.12646902910d6a
pcre2@10.39-3ubuntu0.1
no fix listed
1
library/mongo:noble6ede2806c78e
pcre2@10.42-4ubuntu2.1
no fix listed
1
library/mongo:6.0.271a63fc2438e
pcre2@10.34-7ubuntu0.1
no fix listed
1
library/mongo:5.0.217c81758cb295
pcre2@10.34-7ubuntu0.1
no fix listed
1
library/mongo:8.3.981a1c8842a09
pcre2@10.42-4ubuntu2.1
no fix listed
1
library/mongo:7.0-jammy84c4a18b60a0
pcre2@10.39-3ubuntu0.1
no fix listed
1
library/mongo:7.0.28-jammy88785f6f665a
pcre2@10.39-3ubuntu0.1
no fix listed
1
library/mongo:7.09854f7139445
pcre2@10.39-3ubuntu0.1
no fix listed
1
library/mongo:7.0.12ae1cf99fa7bf
pcre2@10.39-3ubuntu0.1
no fix listed
1
library/mongo:7.0b6421fd6d1c5
pcre2@10.39-3ubuntu0.1
no fix listed
1
library/mongo:4.4.18d23ec07162ca
pcre2@10.34-7ubuntu0.1
no fix listed
1
library/mongo:8.0.11dca8d11fe467
pcre2@10.42-4ubuntu2.1
no fix listed
1
library/mysql:8.0-debian9382e4f6f7f0
pcre2@10.42-1
10.42-1+deb12u1
1
library/neo4j:2026.05.0-enterprise2caf944aa4a5
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/neo4j:2026.02.25ab4ab0358cf
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/neo4j:2026.05.06c162e2432f8
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/nextcloud:31.0.6-apache588609d76b21
pcre2@10.42-1
10.42-1+deb12u1
1
library/nextcloud:31.0.10-apacheb7faa1653c39
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/nginx:1.27.409369da6b103
pcre2@10.42-1
10.42-1+deb12u1
1
library/nginx:1.291881968aff6f
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/nginx:1.276784fb0834aa
pcre2@10.42-1
10.42-1+deb12u1
1
library/nginx:1.25.167f9a4f10d14
pcre2@10.42-1
10.42-1+deb12u1
1
library/nginx:1.25.49ff236ed47fe
pcre2@10.42-1
10.42-1+deb12u1
1
library/nginx:1.31a53fc6c27208
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/nginx:1.27.3fb197595ebe7
pcre2@10.42-1
10.42-1+deb12u1
1
library/node:22-bookworm-slim83f487e0a634
pcre2@10.42-1
10.42-1+deb12u1
1
library/node:208f693eaa7e0a
pcre2@10.42-1
10.42-1+deb12u1
1
library/node:latestf5d1cc40abc1
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/php:8.4-fpm59fa733c9af6
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/postgres:18.0073e7c8b84e2
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/postgres:17.4304ab8135187
pcre2@10.42-1
10.42-1+deb12u1
1
library/postgres:18.43a82e1f56c8f
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/postgres:16.11468e1f126ca5
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/postgres:16.6557fea37a744
pcre2@10.42-1
10.42-1+deb12u1
1
library/postgres:18.369e8582b781c
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/postgres:15.186eb0add3b77c
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/postgres:15.38775adb39f0d
pcre2@10.42-1
10.42-1+deb12u1
1
library/postgres:18.48ff36f3c6637
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/postgres:18.3a9abf4275f9e
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/postgres:17.5aadf2c0696f5
pcre2@10.45-1
10.46-1~deb13u2
1
library/postgres:13.12ced3ba927f4c
pcre2@10.42-1
10.42-1+deb12u1
1
library/postgres:15.18-bookworme8db9bd3e9e1
pcre2@10.42-1
10.42-1+deb12u1
1
library/postgres:14.22eba8ddbdd837
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/postgres:17.10ebba4f4de37f
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/postgres:17.5-bookwormfbcea1bd13b6
pcre2@10.42-1
10.42-1+deb12u1
1
library/python:3.1070c9cc675605
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
library/python:3.11-slim9534e5a8e315
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.