StackRadar

CVE-2026-89160

Low

Advisory

Published 11 Sept 2026In the index since 12 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,255
of 17,792 indexed, latest versions
Container images
2,185
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,255 of 17,792 indexed charts deploy, on 2,185 images.

Affected packageAffected versionsFixed inImages
pcre2deb10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+10 more10.42-1+deb12u1, 10.46-1~deb13u22,185
OSV records
DEBIAN-CVE-2026-89160UBUNTU-CVE-2026-89160
Trending
Rank 5 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

2,255 by stars
ChartLatestAffected imagesRadar Score
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-89160.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

2,684
changedetection-iozekker6Verified publisher1.99.01 of 1See more

changedetection-io zekker6 1.99.0

1 of the 1 container images this version deploys carry CVE-2026-89160.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.47bb6963b730d
pcre2@10.42-1
10.42-1+deb12u1

Open the chart page →

2,612
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-89160.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,849
clickhousezloi-space1.2.01 of 3See more

clickhouse zloi-space 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-89160.

Container imageDigestPackageFixed in
yandex/clickhouse-server:21.3.204eccfffb01d7
pcre2@10.34-7
no fix listed

Open the chart page →

9,256
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-89160.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

7,929

Container images carrying it

2,185 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
falcosecurity/event-generator:latest932956d86c99
pcre2@10.42-1
10.42-1+deb12u1
1
falcosecurity/falco-driver-loader:0.44.17df783d5269a
pcre2@10.42-1
10.42-1+deb12u1
1
federid/webhook:0.1.0fbfb7c6510a7
pcre2@10.42-1
10.42-1+deb12u1
1
felipecs8/app-db-connection-test:v129e06c9c6385
pcre2@10.42-1
10.42-1+deb12u1
1
firefart/requesttracker:5.0.40d6249906d8c
pcre2@10.42-1
10.42-1+deb12u1
1
fireflyiii/core:version-6.6.6ae69fdd95cde
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
pcre2@10.34-7ubuntu0.1
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
pcre2@10.42-1
10.42-1+deb12u1
1
flanksource/apm-hub:v0.0.471dacc3195bf9
pcre2@10.39-3ubuntu0.1
no fix listed
1
flanksource/batch-runner:v1.0.44689687a7cf95
pcre2@10.42-4ubuntu2.1
no fix listed
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
pcre2@10.42-1
10.42-1+deb12u1
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
pcre2@10.42-1
10.42-1+deb12u1
1
flashcatcloud/categraf:latest42e6ab16472e
pcre2@10.42-4ubuntu2.1
no fix listed
1
flashcatcloud/nightingale:8.5.1421acb36181b
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
fluent/fluent-bit:4.0-debuge76397ef3983
pcre2@10.42-1
10.42-1+deb12u1
1
fluent/fluentd-kubernetes-daemonset:v1.19.3-debian-elasticsearch7-1.1de9cf5f1127a
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
fluent/fluentd-kubernetes-daemonset:v1-debian-graylogfda93f768f98
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
flyway/flyway:9.1545b5d7cdc75a
pcre2@10.34-7ubuntu0.1
no fix listed
1
fnzv/dump1090:latestb3079b95c336
pcre2@10.39-3ubuntu0.1
no fix listed
1
folioci/mod-z3950:latest2493041ce880
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
fosrl/pangolin:latest83a55f933b4d
pcre2@10.42-1
10.42-1+deb12u1
1
frankescobar/allure-docker-service:latestdc171ec796d5
pcre2@10.42-4ubuntu2.1
no fix listed
1
freedom98/flask:k3.0d7ce1533f297
pcre2@10.42-1
10.42-1+deb12u1
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
pcre2@10.39-3ubuntu0.1
no fix listed
1
galaxy/cloudman-server:lateste5c265fe9fcd
pcre2@10.34-7
no fix listed
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pcre2@10.42-1
10.42-1+deb12u1
1
galexrt/extended-ceph-exporter:v1.8.05373078a3a08
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
gchq/accumulo:2.0.1c460bb587d6d
pcre2@10.42-4ubuntu2
no fix listed
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
pcre2@10.39-3ubuntu0.1
no fix listed
1
geopython/pycsw:3.0.0-beta284662ea6b78b
pcre2@10.42-1
10.42-1+deb12u1
1
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
pcre2@10.34-7
no fix listed
1
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
pcre2@10.46-1build1
no fix listed
1
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
pcre2@10.46-1build1
no fix listed
1
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
pcre2@10.46-1build1
no fix listed
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
pcre2@10.34-7
no fix listed
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
pcre2@10.34-7
no fix listed
1
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
pcre2@10.46-1build1
no fix listed
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
pcre2@10.34-7
no fix listed
1
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
pcre2@10.46-1build1
no fix listed
1
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
pcre2@10.46-1build1
no fix listed
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
pcre2@10.34-7
no fix listed
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
pcre2@10.34-7
no fix listed
1
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
pcre2@10.46-1build1
no fix listed
1
gethue/hue:4.11.011b649636e68
pcre2@10.34-7ubuntu0.1
no fix listed
1
gethue/hue:latest7d5c1b9f8a79
pcre2@10.39-3ubuntu0.1
no fix listed
1
getsentry/relay:24.10.0ba7bf9163219
pcre2@10.42-1
10.42-1+deb12u1
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
pcre2@10.42-1
10.42-1+deb12u1
1
ghusta/postgres-world-db:latest879d0919fdcc
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
pcre2@10.34-7
no fix listed
1
glasskube/operator:0.12.2be5133100d63
pcre2@10.39-3ubuntu0.1
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.