StackRadar

CVE-2026-89158

Medium

Advisory

Published 11 Sept 2026In the index since 12 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,244
of 17,821 indexed, latest versions
Container images
2,255
deployed by those charts
Fix available
1 of 2
affected packages

CVE-2026-89158 affecting package nmap 7.95-5

Carried by container images the latest versions of 2,244 of 17,821 indexed charts deploy, on 2,255 images.

Affected packageAffected versionsFixed inImages
pcre2deb10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+10 more10.42-1+deb12u1, 10.46-1~deb13u22,254
nmaprpm7.95-4.azl3no fix listed1
OSV records
DEBIAN-CVE-2026-89158UBUNTU-CVE-2026-89158AZL-101751
Trending
Rank 16 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

2,244 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,255 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/redis:7:7.4:7.4.1171da9275c5f3
pcre2@10.42-1
10.42-1+deb12u1
4
mastercloudapps/planner:v1.2340a950b311b2
pcre2@10.39-3ubuntu0.1
no fix listed
4
opea/llm-tgi:1.00c25aab3f106
pcre2@10.42-1
10.42-1+deb12u1
4
shashkist/flask-contacts-app:latest581de1fd6084
pcre2@10.42-1
10.42-1+deb12u1
4
valkey/valkey:9.0.2930b41430fb7
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
4
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
pcre2@10.39-3ubuntu0.1
no fix listed
4
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
pcre2@10.46-1build1
no fix listed
4
apache/apisix:3.18.0-ubuntu9ee5df1611f9
pcre2@10.42-4ubuntu2.1
no fix listed
3
apache/superset:6.1.0:latest16b50bbef664
pcre2@10.42-1
10.42-1+deb12u1
3
bitnamilegacy/etcd:latest99b408c15272
pcre2@10.42-1
10.42-1+deb12u1
3
bitnamilegacy/kubectl:latestcd354d5b2556
pcre2@10.42-1
10.42-1+deb12u1
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
pcre2@10.42-1
10.42-1+deb12u1
3
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
pcre2@10.42-1
10.42-1+deb12u1
3
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
pcre2@10.42-1
10.42-1+deb12u1
3
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
pcre2@10.42-1
10.42-1+deb12u1
3
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
pcre2@10.42-1
10.42-1+deb12u1
3
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
pcre2@10.42-1
10.42-1+deb12u1
3
ciscolabs/rtsp-client:latesta7b60ec88285
pcre2@10.34-7
no fix listed
3
ciscolabs/rtsp-server:latestb59fc10bb821
pcre2@10.34-7
no fix listed
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
pcre2@10.34-7
no fix listed
3
codeurjc/planner:v1.0800cf520c245
pcre2@10.39-3ubuntu0.1
no fix listed
3
dgraph/dgraph:v21.12.03b55ea83fffe
pcre2@10.34-7
no fix listed
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
pcre2@10.42-1
10.42-1+deb12u1
3
emberstack/kubernetes-reflector:10.0.6551dbd5880929
pcre2@10.42-4ubuntu2.1
no fix listed
3
envoyproxy/envoy:v1.31.02bf7f042e396
pcre2@10.39-3ubuntu0.1
no fix listed
3
gchq/hdfs:3.3.35ec58edbb2db
pcre2@10.42-4ubuntu2
no fix listed
3
guacamole/guacamole:1.6.0f344085e618b
pcre2@10.42-4ubuntu2.1
no fix listed
3
jacobalberty/unifi:v10.0.162896c0ab82d33
pcre2@10.34-7ubuntu0.1
no fix listed
3
library/memcached:1.6:1.6.4575c93cc91e76
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
3
library/nginx:1.25:1.25.5a484819eb602
pcre2@10.42-1
10.42-1+deb12u1
3
library/postgres:14156f0b253fd6
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
3
library/ubuntu:24.04008173c23f95
pcre2@10.42-4ubuntu2.1
no fix listed
3
library/wordpress:7.1.0-apache:latest5a93c470ae82
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
3
linuxserver/plex:1.43.4:latest1f6f97d76e7b
pcre2@10.46-1build1
no fix listed
3
mcp/grafana:latest9362bcf6aa0e
pcre2@10.42-1
10.42-1+deb12u1
3
meshery/meshery:stable-latest44b64ee128fb
pcre2@10.42-1
10.42-1+deb12u1
3
opencsghq/postgres:15.19b98600564e07
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
3
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
pcre2@10.39-3ubuntu0.1
no fix listed
3
openebs/node-disk-operator:2.1.06afe2123c457
pcre2@10.39-3ubuntu0.1
no fix listed
3
selenium/hub:3.141.5902f251d48d5f
pcre2@10.34-7
no fix listed
3
sigp/lighthouse:latest-amd6450f66cfebb6d
pcre2@10.39-3ubuntu0.1
no fix listed
3
vaultwarden/server:1.37.1ebdfe70701c6
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
3
xenondb/percona:5.7.330e26872a2b67
pcre2@10.34-7
no fix listed
3
ghcr.io/api7/adc:0.27.1f65f53dd9668
pcre2@10.42-1
10.42-1+deb12u1
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
pcre2@10.42-1
10.42-1+deb12u1
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
pcre2@10.42-1
10.42-1+deb12u1
3
ghcr.io/dgtlmoon/changedetection.io:0.60.7:latest096dae27b5d6
pcre2@10.42-1
10.42-1+deb12u1
3
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
pcre2@10.42-1
10.42-1+deb12u1
3
ghcr.io/flaresolverr/flaresolverr:latest:v3.5.2c80ae007ce2c
pcre2@10.42-1
10.42-1+deb12u1
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
pcre2@10.42-1
10.42-1+deb12u1
3

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.