StackRadar

CVE-2026-89157

Medium

Advisory

Published 11 Sept 2026In the index since 12 Sept 2026
Severity
Medium
worst across findings
CVSS
5.7
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,267
of 17,803 indexed, latest versions
Container images
2,197
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,267 of 17,803 indexed charts deploy, on 2,197 images.

Affected packageAffected versionsFixed inImages
pcre2deb10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+10 more10.42-1+deb12u1, 10.46-1~deb13u22,197
OSV records
DEBIAN-CVE-2026-89157UBUNTU-CVE-2026-89157
Trending
Rank 4 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

2,267 by stars
ChartLatestAffected imagesRadar Score
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

2,500
rediswiremindVerified publisher23.0.61 of 1See more

redis wiremind 23.0.6

1 of the 1 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/redis:8.4.0-debian-12-r31f0f7ddc4370
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

2,143
wordpress-alpinewordpress-alpine1.5.182 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

2 of the 6 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
library/mariadb:12.3.2628f228f0fd5
pcre2@10.42-4ubuntu2.1
no fix listed
library/memcached:1.6.45dc561d52bb8a
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

4,080
Wordpresswordpress-mariadb1.0.22 of 2See more

Wordpress wordpress-mariadb 1.0.2

2 of the 2 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
library/mariadb:ltsdd9b303aed4f
pcre2@10.42-4ubuntu2.1
no fix listed
library/wordpress:latest5a93c470ae82
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

5,713
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

14,218
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

11,622
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

7,714
xkopsxkops0.1.04 of 5See more

xkops xkops 0.1.0

4 of the 5 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
pcre2@10.42-1
10.42-1+deb12u1
hamzaarshad10/querypodpy:1.7154f38e8668e
pcre2@10.42-1
10.42-1+deb12u1
library/mongo:latest5211c51171f5
pcre2@10.42-4ubuntu2.1
no fix listed
murtazashah46/helmfile:latest4d11726cf803
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

13,813
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
pcre2@10.42-4ubuntu2
no fix listed

Open the chart page →

2,152
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,861
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,311
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,861
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

2,692
changedetection-iozekker6Verified publisher1.101.01See more

changedetection-io zekker6 1.101.0

1 container image this version deploys carries CVE-2026-89157.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.6eb4a9f718801
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,861
clickhousezloi-space1.2.01 of 3See more

clickhouse zloi-space 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
yandex/clickhouse-server:21.3.204eccfffb01d7
pcre2@10.34-7
no fix listed

Open the chart page →

9,272
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

7,936

Container images carrying it

2,197 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
lumenvox/cloud-assure-identity:2.0.0147854a3c916
pcre2@10.34-7
no fix listed
1
lumenvox/cloud-audit:2.0.079428add7f38
pcre2@10.34-7
no fix listed
1
lumenvox/cloud-binary-storage:2.0.053decadc102d
pcre2@10.34-7
no fix listed
1
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
pcre2@10.34-7
no fix listed
1
lumenvox/cloud-deployment:2.0.0ea8110886d38
pcre2@10.34-7
no fix listed
1
lumenvox/cloud-engine-resource:2.0.0e2e5abe27abc
pcre2@10.34-7
no fix listed
1
lumenvox/cloud-management-api:2.0.0b9a23345eabd
pcre2@10.34-7
no fix listed
1
lumenvox/cloud-reporting:2.0.07a9ffdc2178a
pcre2@10.34-7
no fix listed
1
lumenvox/cloud-reporting-api:2.0.0dbbaf5462ad6
pcre2@10.34-7
no fix listed
1
lumenvox/cloud-transaction:2.0.08b74f9d3ba09
pcre2@10.34-7
no fix listed
1
lumenvox/cloud-voice-verifier:2.0.014170ad34903
pcre2@10.34-7
no fix listed
1
machines/filestash:latest0b8fc005e52e
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
makemake1337/blutgang:latest8a55174fc830
pcre2@10.42-1
10.42-1+deb12u1
1
makeplane/plane-mcp-server:v0.3.071b7252adef0
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
makersquad/harp-proxy:0.8.1a40dd258c527
pcre2@10.42-1
10.42-1+deb12u1
1
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
pcre2@10.34-7ubuntu0.1
no fix listed
1
maponyacharles/sceptreai:mlflow-0.1.1242d418654ebd
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
maponyacharles/sceptreai:api-0.1.127b37b092130a
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
maptiler/server:4.8.07e206140057b
pcre2@10.34-7ubuntu0.1
no fix listed
1
marcoimme/oidcmock:latestb6035c0721a8
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
mariusm/vingress:0.5.0b3db186c3d72
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
martinhelmich/typo3:12.4c83a4f3fd7ae
pcre2@10.42-1
10.42-1+deb12u1
1
mathesar/mathesar:0.12.0091757cb01fe
pcre2@10.42-1
10.42-1+deb12u1
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
pcre2@10.42-1
10.42-1+deb12u1
1
matterlabs/external-node:9734bf2-17870579939295dadc06bdf3b
pcre2@10.42-1
10.42-1+deb12u1
1
matterlabs/external-node:v24.0.06cbfea4c694a
pcre2@10.42-1
10.42-1+deb12u1
1
mautic/mautic:7-apacheeb8cc73d97e1
pcre2@10.42-1
10.42-1+deb12u1
1
mawad98/backstage-pyactions:demo99422c56a274
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
mbround18/valheim:3.1.070bd4da591cd
pcre2@10.39-3ubuntu0.1
no fix listed
1
mediagis/nominatim:5.3.27923a8e67197
pcre2@10.42-4ubuntu2.1
no fix listed
1
mediagis/nominatim:3.7c15e941485ef
pcre2@10.34-7
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
pcre2@10.39-3ubuntu0.1
no fix listed
1
memgraph/mcp-memgraph:0.1.13ecdf7faea3f7
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
merlos/zookeeper:3.9.3a38fc7e09ed7
pcre2@10.42-1
10.42-1+deb12u1
1
middlewareeng/middleware:0.3.1747d880812f1
pcre2@10.42-1
10.42-1+deb12u1
1
milvusdb/etcd:3.5.25-r1fededb2f2d63
pcre2@10.39-3ubuntu0.1
no fix listed
1
milvusdb/milvus:v2.2.13a3a55e1c1497
pcre2@10.34-7
no fix listed
1
mindsdb/mindsdb:latest163011c09299
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
pcre2@10.34-7
no fix listed
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
pcre2@10.42-1
10.42-1+deb12u1
1
miqm/session-scaler:0.1.0c5c211717d9b
pcre2@10.42-1
10.42-1+deb12u1
1
mlikiowa/napcat-docker:latest1336a777f9a4
pcre2@10.39-3ubuntu0.1
no fix listed
1
mockserver/mockserver:mockserver-8.0.0b8426e0b3c80
pcre2@10.42-1
10.42-1+deb12u1
1
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
pcre2@10.42-1
10.42-1+deb12u1
1
moreillon/api-proxy:latestd7d4a5463525
pcre2@10.42-1
10.42-1+deb12u1
1
moreillon/camera-viewer:lateste418cc694bd5
pcre2@10.42-1
10.42-1+deb12u1
1
moreillon/food-manager:lateste8fd856e593d
pcre2@10.42-1
10.42-1+deb12u1
1
moreillon/group-manager:latest3caa8f710ee0
pcre2@10.42-1
10.42-1+deb12u1
1
moreillon/group-manager-front:latest5f0a38498271
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
moreillon/user-manager-front:v5.1.06597e6b98d21
pcre2@10.42-1
10.42-1+deb12u1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.