StackRadar

CVE-2026-89157

High

Advisory

Published 11 Sept 2026In the index since 12 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,235
of 17,813 indexed, latest versions
Container images
2,194
deployed by those charts
Fix available
1 of 2
affected packages

CVE-2026-89157 affecting package nmap 7.95-5

Carried by container images the latest versions of 2,235 of 17,813 indexed charts deploy, on 2,194 images.

Affected packageAffected versionsFixed inImages
pcre2deb10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+10 more10.42-1+deb12u1, 10.46-1~deb13u22,193
nmaprpm7.95-4.azl3no fix listed1
OSV records
DEBIAN-CVE-2026-89157UBUNTU-CVE-2026-89157AZL-101748
Trending
Rank 9 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

2,235 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,194 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
pcre2@10.39-3ubuntu0.1
no fix listed
1
photoprism/photoprism:220629-jammy2954334adbda
pcre2@10.39-3build1
no fix listed
1
photoprism/photoprism:260601650c6ad5a651
pcre2@10.46-1build1
no fix listed
1
photoprism/photoprism:260728958642220223
pcre2@10.46-1build1
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
pcre2@10.42-4ubuntu2
no fix listed
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
pk910/powfaucet:v2-stable3dcae6a62896
pcre2@10.42-1
10.42-1+deb12u1
1
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
pcre2@10.42-4ubuntu2.1
no fix listed
1
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
pcre2@10.34-7
no fix listed
1
plexinc/pms-docker:1.43.3.10896-cb3ebc72d83a425ae9e13
pcre2@10.42-4ubuntu2.1
no fix listed
1
pockost/matomo:5.13.07f5d293cbe4e
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
pococze/python-hello-elos:2.0.07a1aab425e51
pcre2@10.42-1
10.42-1+deb12u1
1
polyaxon/polyaxon-api:2.17.0163707082036
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
polyaxon/polyaxon-streams:2.17.0a5fec70e757b
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
posit/package-manager:2026.09.0-ubuntu-24.04527493ef621b
pcre2@10.42-4ubuntu2.1
no fix listed
1
postgis/postgis:18-3.67e00e8c3539f
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
powerdns/pdns-recursor-54:5.4.533aadc74a8d6
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
praravind1801/helmimages:3.0.0f29d637b9ce1
pcre2@10.42-1
10.42-1+deb12u1
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
pcre2@10.42-1
10.42-1+deb12u1
1
prefecthq/prometheus-prefect-exporter:4.1.06e0e79cabdc2
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
pretix/standalone:2026.7.05df3b7aa852e
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
probely/farcaster-onprem-agent:v3741b34e8166f
pcre2@10.42-1
10.42-1+deb12u1
1
prodrigestivill/postgres-backup-local:latestf70742ebe42b
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
project2team4/react:latest3ff031a08887
pcre2@10.34-7
no fix listed
1
prom/cloudwatch-exporter:v0.16.071c2e988af06
pcre2@10.42-4ubuntu2
no fix listed
1
promzeus/redis-sentinel-gateway:v182f6d56e280b
pcre2@10.42-1
10.42-1+deb12u1
1
prowlercloud/prowler-api:5.31.14f252d579be2
pcre2@10.42-1
10.42-1+deb12u1
1
proxysql/proxysql:3.0.8947a7abad45b
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
proxysql/proxysql:2.7.3a4d6c35c2949
pcre2@10.42-1
10.42-1+deb12u1
1
pschichtel/mindustry-server:v145.1b543e9c2d371
pcre2@10.39-3ubuntu0.1
no fix listed
1
psorab/elibrary:latest53b68896c4ce
pcre2@10.34-7ubuntu0.1
no fix listed
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
pcre2@10.34-7
no fix listed
1
qdrant/qdrant:v1.7.45f2a56b95266
pcre2@10.42-1
10.42-1+deb12u1
1
qdrant/qdrant:v1.4.166ee661d5241
pcre2@10.42-1
10.42-1+deb12u1
1
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
qonstrukt/php:8.4-v8-apache089af7925aa1
pcre2@10.42-4ubuntu2.1
no fix listed
1
quickwit/quickwit:v0.8.1d29332bdadcc
pcre2@10.42-1
10.42-1+deb12u1
1
qumine/minecraft-server:v0.1.15c0b650d51132
pcre2@10.39-3ubuntu0.1
no fix listed
1
qxip/qryn:3.2.3977acc9c7a9fd
pcre2@10.42-1
10.42-1+deb12u1
1
rabeh/apibootspring:1.0941007b6946e
pcre2@10.39-3ubuntu0.1
no fix listed
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
pcre2@10.42-4ubuntu2.1
no fix listed
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
pcre2@10.42-4ubuntu2.1
no fix listed
1
razorbladex401/dayz:latest6a4d79248e7d
pcre2@10.39-3ubuntu0.1
no fix listed
1
readysettech/sqp:latest588f3507280e
pcre2@10.42-4ubuntu2.1
no fix listed
1
readysettech/sqp-duckdb:latest67a83203ce60
pcre2@10.42-4ubuntu2.1
no fix listed
1
reallibrephotos/librephotos-proxy:1.0.398a13dabbadc
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
redash/redash:25.8.000d813437db5
pcre2@10.42-1
10.42-1+deb12u1
1
redash/redash:26.3.0c5c9148f5c38
pcre2@10.42-1
10.42-1+deb12u1
1
redimp/otterwiki:2778bf30da3da
pcre2@10.42-1
10.42-1+deb12u1
1
redis/redis-stack-server:6.2.6-v251a58f32d412
pcre2@10.34-7ubuntu0.1
no fix listed
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.