StackRadar

CVE-2026-89158

Medium

Advisory

Published 11 Sept 2026In the index since 12 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,255
of 17,792 indexed, latest versions
Container images
2,185
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,255 of 17,792 indexed charts deploy, on 2,185 images.

Affected packageAffected versionsFixed inImages
pcre2deb10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+10 more10.42-1+deb12u1, 10.46-1~deb13u22,185
OSV records
DEBIAN-CVE-2026-89158UBUNTU-CVE-2026-89158
Trending
Rank 1 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

2,255 by stars
ChartLatestAffected imagesRadar Score
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-89158.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

2,684
changedetection-iozekker6Verified publisher1.99.01 of 1See more

changedetection-io zekker6 1.99.0

1 of the 1 container images this version deploys carry CVE-2026-89158.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.47bb6963b730d
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

2,612
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-89158.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,849
clickhousezloi-space1.2.01 of 3See more

clickhouse zloi-space 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-89158.

Container imageDigestPackageFixed in
yandex/clickhouse-server:21.3.204eccfffb01d7
pcre2@10.34-7
no fix listed

Open the chart page →

9,256
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-89158.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

7,929

Container images carrying it

2,185 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
sigp/lighthouse:v8.1.344aa773dcf27
pcre2@10.39-3ubuntu0.1
no fix listed
2
sigp/lighthouse:latest9a62bb870545
pcre2@10.39-3ubuntu0.1
no fix listed
2
sikalabs/hello-world-server:latest5f49bf889a64
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
pcre2@10.34-7ubuntu0.1
no fix listed
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
pcre2@10.42-1
10.42-1+deb12u1
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
pcre2@10.34-7ubuntu0.1
no fix listed
2
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
pcre2@10.39-3build1
no fix listed
2
taigaio/taiga-back:latest4beed8f62c9f
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
taigaio/taiga-protected:latestfd4568a97a59
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
technitium/dns-server:15.4.0df7d90ef0f7b
pcre2@10.42-4ubuntu2.1
no fix listed
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
pcre2@10.39-3ubuntu0.1
no fix listed
2
uffizzi/controller:latest0344805f267b
pcre2@10.42-1
10.42-1+deb12u1
2
valkey/valkey:83fbd2e3e4b6e
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
valkey/valkey:9.1.2475ee65cc75c
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
valkey/valkey:9.0.1546304417fea
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
valkey/valkey:8.1.481db6d39e1bb
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
valkey/valkey:9.1.08e8d64b405ce
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
vaultwarden/server:1.37.31587c45feaa4
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
vdiogov/glpi-conteiner:latest6945f84f0058
pcre2@10.42-1
10.42-1+deb12u1
2
wolveix/satisfactory-server:latest:v1.9.10e103700ae6ae
pcre2@10.39-3ubuntu0.1
no fix listed
2
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
pcre2@10.42-4ubuntu2
no fix listed
2
ghcr.io/api7/adc:0.27.1f65f53dd9668
pcre2@10.42-1
10.42-1+deb12u1
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
pcre2@10.39-3ubuntu0.1
no fix listed
2
ghcr.io/astriaorg/conductor:latest3ea8164b0eae
pcre2@10.42-1
10.42-1+deb12u1
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
pcre2@10.42-4ubuntu2.1
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
pcre2@10.42-4ubuntu2.1
no fix listed
2
ghcr.io/chroma-core/chroma:1.5.91e0b73a187a2
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
pcre2@10.40-1+ubuntu22.04.1+deb.sury.org+1
no fix listed
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
pcre2@10.39-3build1
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
pcre2@10.42-1
10.42-1+deb12u1
2
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
pcre2@10.42-1
10.42-1+deb12u1
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
pcre2@10.42-1
10.42-1+deb12u1
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
pcre2@10.34-7
no fix listed
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
pcre2@10.34-7
no fix listed
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
pcre2@10.34-7
no fix listed
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
pcre2@10.42-1
10.42-1+deb12u1
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
pcre2@10.42-1
10.42-1+deb12u1
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
pcre2@10.42-1
10.42-1+deb12u1
2
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
pcre2@10.42-4ubuntu2.1
no fix listed
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
pcre2@10.42-1
10.42-1+deb12u1
2
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
pcre2@10.42-1
10.42-1+deb12u1
2
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
pcre2@10.42-1
10.42-1+deb12u1
2
ghcr.io/openunison/openunison-kubernetes-operator:1.0.1392bd6c526c50
pcre2@10.42-4ubuntu2.1
no fix listed
2
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
pcre2@10.42-1
10.42-1+deb12u1
2
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
pcre2@10.42-1
10.42-1+deb12u1
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
pcre2@10.39-3build1
no fix listed
2
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
pcre2@10.42-1
10.42-1+deb12u1
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
pcre2@10.42-1
10.42-1+deb12u1
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
pcre2@10.34-7ubuntu0.1
no fix listed
2
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2:latestb53a854bd7c1
pcre2@10.42-4ubuntu2.1
no fix listed
2

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.