StackRadar

CVE-2026-89158

Medium

Advisory

Published 11 Sept 2026In the index since 12 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,244
of 17,821 indexed, latest versions
Container images
2,255
deployed by those charts
Fix available
1 of 2
affected packages

CVE-2026-89158 affecting package nmap 7.95-5

Carried by container images the latest versions of 2,244 of 17,821 indexed charts deploy, on 2,255 images.

Affected packageAffected versionsFixed inImages
pcre2deb10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+10 more10.42-1+deb12u1, 10.46-1~deb13u22,254
nmaprpm7.95-4.azl3no fix listed1
OSV records
DEBIAN-CVE-2026-89158UBUNTU-CVE-2026-89158AZL-101751
Trending
Rank 16 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

2,244 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,255 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
pcre2@10.42-1
10.42-1+deb12u1
3
ghcr.io/tremolosecurity/kube-oidc-proxy:1.0.13a89736c586ba
pcre2@10.42-4ubuntu2.1
no fix listed
3
quay.io/cilium/cilium:v1.20.22939231d0d3e
pcre2@10.46-1build1
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
pcre2@10.42-1
10.42-1+deb12u1
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
pcre2@10.39-3ubuntu0.1
no fix listed
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
pcre2@10.42-4ubuntu2
no fix listed
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
pcre2@10.42-4ubuntu2
no fix listed
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
pcre2@10.42-4ubuntu2
no fix listed
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
pcre2@10.42-4ubuntu2
no fix listed
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
pcre2@10.34-7
no fix listed
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
pcre2@10.42-4ubuntu2
no fix listed
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
pcre2@10.39-3ubuntu0.1
no fix listed
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
pcre2@10.42-4ubuntu2
no fix listed
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
pcre2@10.42-4ubuntu2
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
pcre2@10.42-1
10.42-1+deb12u1
3
actualbudget/actual-server:26.9.0552beab3dec8
pcre2@10.42-1
10.42-1+deb12u1
2
alazidis/kube-netlag:1.1.00e8c84152201
pcre2@10.42-4ubuntu2.1
no fix listed
2
apache/druid:37.0.00116fb802786
pcre2@10.42-1
10.42-1+deb12u1
2
apache/nifi-registry:1.26.07cdfd8deec92
pcre2@10.39-3ubuntu0.1
no fix listed
2
apache/rocketmq:5.4.0319cd8a81ed1
pcre2@10.42-4ubuntu2.1
no fix listed
2
apache/tika:2.9.0.092d055a84e9e
pcre2@10.39-3ubuntu0.1
no fix listed
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
pcre2@10.42-4ubuntu2
no fix listed
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
pcre2@10.42-1
10.42-1+deb12u1
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
pcre2@10.42-1
10.42-1+deb12u1
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
pcre2@10.42-1
10.42-1+deb12u1
2
bitnamilegacy/redis:latest5927ff3702df
pcre2@10.42-1
10.42-1+deb12u1
2
bitnami/minideb:latestab4d5b45116e
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
blockstack/stacks-core:3.2.0.0.0f79944317326
pcre2@10.42-1
10.42-1+deb12u1
2
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
pcre2@10.42-1
10.42-1+deb12u1
2
chromedp/headless-shell:148.0.7778.97313ed7255ae1
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
clickhouse/clickhouse-server:24.2ed9640bfff07
pcre2@10.34-7ubuntu0.1
no fix listed
2
cribl/cribl:4.20.0dddc9c0f2a52
pcre2@10.42-4ubuntu2.1
no fix listed
2
dagster/user-code-example:1.13.235a358fd3509f
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
datagrok/grok_connect:latestf5876d3aebb8
pcre2@10.39-3ubuntu0.1
no fix listed
2
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
pcre2@10.34-7
no fix listed
2
eqalpha/keydb:latest6537505c4235
pcre2@10.34-7ubuntu0.1
no fix listed
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
pcre2@10.34-7ubuntu0.1
no fix listed
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
flashcatcloud/categraf:latest42e6ab16472e
pcre2@10.42-4ubuntu2.1
no fix listed
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
pcre2@10.34-7
no fix listed
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
pcre2@10.34-7
no fix listed
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
pcre2@10.34-7
no fix listed
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
pcre2@10.34-7
no fix listed
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
pcre2@10.34-7
no fix listed
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
pcre2@10.34-7
no fix listed
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
pcre2@10.42-1
10.42-1+deb12u1
2
gotenberg/gotenberg:8.36.087c16b9f3642
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
gotenberg/gotenberg:8:8.37.0f29984bd1e22
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.