StackRadar

CVE-2026-89157

High

Advisory

Published 11 Sept 2026In the index since 12 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,302
of 17,805 indexed, latest versions
Container images
2,233
deployed by those charts
Fix available
1 of 2
affected packages

CVE-2026-89157 affecting package nmap 7.95-5

Carried by container images the latest versions of 2,302 of 17,805 indexed charts deploy, on 2,233 images.

Affected packageAffected versionsFixed inImages
pcre2deb10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+10 more10.42-1+deb12u1, 10.46-1~deb13u22,232
nmaprpm7.95-4.azl3no fix listed1
OSV records
DEBIAN-CVE-2026-89157UBUNTU-CVE-2026-89157AZL-101748
Trending
Rank 3 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

2,302 by stars
ChartLatestAffected imagesRadar Score
clickhousezloi-space1.2.01 of 3See more

clickhouse zloi-space 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
yandex/clickhouse-server:21.3.204eccfffb01d7
pcre2@10.34-7
no fix listed

Open the chart page →

9,296
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-89157.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

7,964

Container images carrying it

2,233 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/astriaorg/auctioneer:pr-18391386b7b5e555
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/astriaorg/conductor:1.1.01f97d131b1d1
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/astriaorg/evm-bridge-withdrawer:1.0.29c88e1aff357
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/astriaorg/hermes:0.5.04f33a0a9f75e
pcre2@10.42-4ubuntu2
no fix listed
1
ghcr.io/astriaorg/sequencer:latest44f82ee0b24c
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/astriaorg/sequencer-relayer:latest5f6c74993f08
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/atuinsh/atuin:18.12.0e953fa9e36ef
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/backstage/backstage:latest792e262ea504
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
ghcr.io/base/node-reth:v1.1.18eb6e492fe3c
pcre2@10.42-4ubuntu2.1
no fix listed
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
pcre2@10.39-3ubuntu0.1
no fix listed
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
pcre2@10.39-3ubuntu0.1
no fix listed
1
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/blockscout/smart-contract-verifier:main9a43f0cc5797
pcre2@10.42-4ubuntu2.1
no fix listed
1
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
pcre2@10.34-7ubuntu0.1
no fix listed
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
pcre2@10.42-4ubuntu2.1
no fix listed
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
pcre2@10.42-4ubuntu2.1
no fix listed
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pcre2@10.42-4ubuntu2.1
no fix listed
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/camptocamp/pgbouncer:latest19dc5663cac4
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
pcre2@10.39-3ubuntu0.1
no fix listed
1
ghcr.io/caninehq/canine:latesta058034ca006
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.7.211cdbbc479b3
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.48a8ec8d4c9ea
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.0e7f9e8f1d565
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/chroma-core/chroma:1.5.3cfd193653bd6
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/cjmalloy/jasper-ui:v1.3.623246dc2160efe
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
ghcr.io/cleanuparr/cleanuparr:2.10.68136c3beda7a
pcre2@10.42-4ubuntu2.1
no fix listed
1
ghcr.io/cohdi/composable-dra-driver:v0.2.28c05f7366981
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/containeroo/filesystem-exporter:v1.5.2a66121e16d4e
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/cosanet/cosanet:1.0.098cb5d9fa215
pcre2@10.45-1
10.46-1~deb13u2
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
pcre2@10.42-4ubuntu2.1
no fix listed
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/ctfd/ctfd:3.8.2870e396fddf8
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/dakera-ai/dakera:0.11.101af610992a416
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
ghcr.io/dakera-ai/dakera-mcp:0.10.11a3d48418b14a
pcre2@10.42-1
10.42-1+deb12u1
1
ghcr.io/damap-org/damap-backend:5.0.0f3d0c7d35498
pcre2@10.42-4ubuntu2.1
no fix listed
1
ghcr.io/damap-org/damap-frontend:5.0.1609f48af4efc
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
ghcr.io/danielgines/brightdata-exporter:0.2.176920d17cf6ff
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.