StackRadar

CVE-2026-89158

Medium

Advisory

Published 11 Sept 2026In the index since 12 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,244
of 17,821 indexed, latest versions
Container images
2,255
deployed by those charts
Fix available
1 of 2
affected packages

CVE-2026-89158 affecting package nmap 7.95-5

Carried by container images the latest versions of 2,244 of 17,821 indexed charts deploy, on 2,255 images.

Affected packageAffected versionsFixed inImages
pcre2deb10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+10 more10.42-1+deb12u1, 10.46-1~deb13u22,254
nmaprpm7.95-4.azl3no fix listed1
OSV records
DEBIAN-CVE-2026-89158UBUNTU-CVE-2026-89158AZL-101751
Trending
Rank 16 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

2,244 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,255 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
gotson/komga:1.26.36c2a967bbe9a
pcre2@10.46-1build1
no fix listed
2
gradiant/ueransim:3.2.6015b30d5fa0f
pcre2@10.39-3ubuntu0.1
no fix listed
2
grafana/alloy:v1.8.17790f6f7fbd8
pcre2@10.42-4ubuntu2.1
no fix listed
2
grafana/alloy:v1.12.2f94b1c82957a
pcre2@10.42-4ubuntu2.1
no fix listed
2
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
pcre2@10.42-1
10.42-1+deb12u1
2
homebridge/homebridge:latest77c685a40911
pcre2@10.42-4ubuntu2.1
no fix listed
2
honestica/kube-iptables-tailer:master-91a393242fb939
pcre2@10.34-7
no fix listed
2
hookiesolutions/webhookie:latest0629694246ba
pcre2@10.34-7
no fix listed
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
pcre2@10.34-7
no fix listed
2
ilum/api:6.7.3624fd09528c8
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
ilum/marquez:0.54.06e1d709d41f8
pcre2@10.42-1
10.42-1+deb12u1
2
infisical/infisical:latest:v0.165.602082bf13163
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
interlayhq/interbtc:latesta66d0e35e70f
pcre2@10.34-7ubuntu0.1
no fix listed
2
interlayhq/interbtc-clients:vault-masterc3e311de67da
pcre2@10.34-7
no fix listed
2
iomesh/node-disk-exporter:1.8.0f03148764f38
pcre2@10.34-7
no fix listed
2
istio/proxyv2:1.18.0757d28c24100
pcre2@10.39-3ubuntu0.1
no fix listed
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
pcre2@10.42-1
10.42-1+deb12u1
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
pcre2@10.42-1
10.42-1+deb12u1
2
kurento/kurento-media-server:latest03c0d34d0828
pcre2@10.42-4ubuntu2.1
no fix listed
2
langgenius/dify-sandbox:0.2.009b7e8705673
pcre2@10.42-1
10.42-1+deb12u1
2
library/cassandra:4.1.37cbcec0086ac
pcre2@10.39-3ubuntu0.1
no fix listed
2
library/elasticsearch:7.17.35e6ac15bf6a5
pcre2@10.34-7
no fix listed
2
library/elasticsearch:8.19.1289729a95066a
pcre2@10.42-4ubuntu2.1
no fix listed
2
library/ghost:6.64.0a31d03f1f629
pcre2@10.42-1
10.42-1+deb12u1
2
library/influxdb:2.7b8d940ca9376
pcre2@10.42-1
10.42-1+deb12u1
2
library/kong:3.9:latest2a8cf3b110cd
pcre2@10.42-4ubuntu2.1
no fix listed
2
library/mariadb:10.8.30abf60f81588
pcre2@10.39-3build1
no fix listed
2
library/mariadb:10.10334b315c10e5
pcre2@10.39-3ubuntu0.1
no fix listed
2
library/mariadb:12.0.2:12.0-noble607835cd628b
pcre2@10.42-4ubuntu2.1
no fix listed
2
library/mariadb:11.4611a2fcc5fa7
pcre2@10.42-4ubuntu2.1
no fix listed
2
library/mariadb:10.692e50059ea0a
pcre2@10.39-3ubuntu0.1
no fix listed
2
library/mariadb:11.3.2e101f9db3191
pcre2@10.39-3ubuntu0.1
no fix listed
2
library/mongo:8.0.20098862b1339f
pcre2@10.42-4ubuntu2.1
no fix listed
2
library/mongo:5.041108d183e97
pcre2@10.34-7ubuntu0.1
no fix listed
2
library/mongo:7b096b4cb9269
pcre2@10.39-3ubuntu0.1
no fix listed
2
library/nginx:latest6e23479198b9
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
library/nginx:1.27.098f8ec75657d
pcre2@10.42-1
10.42-1+deb12u1
2
library/nginx:1.29.49dd288848f44
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
library/phpmyadmin:5.2.16e75aa8f767c
pcre2@10.42-1
10.42-1+deb12u1
2
library/postgres:17-bookworm051f7b7b3abd
pcre2@10.42-1
10.42-1+deb12u1
2
library/postgres:16.109f23e02d766
pcre2@10.42-1
10.42-1+deb12u1
2
library/postgres:18.11090bc3a8ccf
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
library/postgres:16.24aea012537ed
pcre2@10.42-1
10.42-1+deb12u1
2
library/postgres:18.06f3e42ad37de
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
library/postgres:159b1d34adbce1
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
library/postgres:16.4e62fbf9d3e2b
pcre2@10.42-1
10.42-1+deb12u1
2
library/python:3.14-slim:3-slimcad9a2c87176
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.