StackRadar

CVE-2026-89158

Medium

Advisory

Published 11 Sept 2026In the index since 12 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,244
of 17,821 indexed, latest versions
Container images
2,255
deployed by those charts
Fix available
1 of 2
affected packages

CVE-2026-89158 affecting package nmap 7.95-5

Carried by container images the latest versions of 2,244 of 17,821 indexed charts deploy, on 2,255 images.

Affected packageAffected versionsFixed inImages
pcre2deb10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+10 more10.42-1+deb12u1, 10.46-1~deb13u22,254
nmaprpm7.95-4.azl3no fix listed1
OSV records
DEBIAN-CVE-2026-89158UBUNTU-CVE-2026-89158AZL-101751
Trending
Rank 16 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

2,244 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,255 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
pcre2@10.39-3build1
no fix listed
2
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
pcre2@10.42-1
10.42-1+deb12u1
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
pcre2@10.42-1
10.42-1+deb12u1
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
pcre2@10.34-7ubuntu0.1
no fix listed
2
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2:latestb53a854bd7c1
pcre2@10.42-4ubuntu2.1
no fix listed
2
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
pcre2@10.42-4ubuntu2.1
no fix listed
2
quay.io/cilium/cilium-envoy:v1.37.6-1789133542-cbec91f666af0bf742da986d43832932dbb26b82af7382699576
pcre2@10.42-4ubuntu2.1
no fix listed
2
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
pcre2@10.42-1
10.42-1+deb12u1
2
1dev/server:11.9.0cd5b12fe5471
pcre2@10.42-4ubuntu2.1
no fix listed
1
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
pcre2@10.42-1
10.42-1+deb12u1
1
5200710/hadoop:3.2.3-java8092d3088a5fb
pcre2@10.34-7ubuntu0.1
no fix listed
1
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
aboogie/login_test_backend:new9c41a4483ac8
pcre2@10.42-1
10.42-1+deb12u1
1
actualbudget/actual-server:25.3.158fecd9088b7
pcre2@10.42-1
10.42-1+deb12u1
1
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
pcre2@10.42-4ubuntu2
no fix listed
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
pcre2@10.42-4ubuntu2
no fix listed
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
pcre2@10.34-7
no fix listed
1
agentarea/agentarea-api:latest9e15e16fa758
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
agentarea/agentarea-mcp-runner:latestd3c209a5d531
pcre2@10.42-1
10.42-1+deb12u1
1
agentarea/agentarea-worker:latest1e5cb68ee77a
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
pcre2@10.39-3ubuntu0.1
no fix listed
1
aibrix/metadata-service:v0.7.063fb81a64377
pcre2@10.42-1
10.42-1+deb12u1
1
airbyte/manifest-server:7.28.2deec511b51c3
pcre2@10.42-1
10.42-1+deb12u1
1
airbyte/pod-sweeper:1.5.198d2c39d512e
pcre2@10.42-1
10.42-1+deb12u1
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
pcre2@10.34-7
no fix listed
1
akaunting/akaunting:3.0.1552811b36ec3a
pcre2@10.42-1
10.42-1+deb12u1
1
akeyless/base:latest759e4289fae8
pcre2@10.42-4ubuntu2.1
no fix listed
1
akeyless/gateway:5.4.0d4768a9b089c
pcre2@10.42-4ubuntu2.1
no fix listed
1
aktosecurity/akto-agent-guard-anonymizer:1.1.4d4b100cbdc47
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
aktosecurity/akto-agent-guard-embedder:1.1.4dbc566b2376c
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
aktosecurity/akto-agent-guard-worker:1.1.4666eaffd5362
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
pcre2@10.42-4ubuntu2.1
no fix listed
1
aktosecurity/akto-threat-detection-backend:latest15ebb75b94dc
pcre2@10.46-1build1
no fix listed
1
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
pcre2@10.46-1build1
no fix listed
1
aktosecurity/data-ingestion-service213aded7adc5
pcre2@10.42-4ubuntu2.1
no fix listed
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
pcre2@10.46-1build1
no fix listed
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
pcre2@10.46-1build1
no fix listed
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
pcre2@10.46-1build1
no fix listed
1
alazidis/stornx:1.1.1602d4f7f090c
pcre2@10.42-1
10.42-1+deb12u1
1
allegroai/clearml:2.0.0-613713ae38f7daf
pcre2@10.42-1
10.42-1+deb12u1
1
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
pcre2@10.39-3ubuntu0.1
no fix listed
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
pcre2@10.42-4ubuntu2.1
no fix listed
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
pcre2@10.42-4ubuntu2
no fix listed
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
pcre2@10.39-3ubuntu0.1
no fix listed
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
pcre2@10.39-3ubuntu0.1
no fix listed
1
anguda/ant-media:2.5c435285fc241
pcre2@10.34-7ubuntu0.1
no fix listed
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
pcre2@10.42-1
10.42-1+deb12u1
1
antiantiops/vscode-browser-docker:1.138.0d1182e8090a7
pcre2@10.42-4ubuntu2.1
no fix listed
1
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
pcre2@10.42-4ubuntu2.1
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.