StackRadar

CVE-2026-89162

Low

Advisory

Published 11 Sept 2026In the index since 12 Sept 2026
Severity
Low
worst across findings
CVSS
2.9
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,654
of 17,790 indexed, latest versions
Container images
1,382
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,654 of 17,790 indexed charts deploy, on 1,382 images.

Affected packageAffected versionsFixed inImages
pcre2deb10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+9 more10.46-1~deb13u21,382
OSV records
DEBIAN-CVE-2026-89162UBUNTU-CVE-2026-89162
Trending
Rank 8 in indexed charts, since 12 Sept 2026. See the ranking →

Charts affected

1,654 by stars
ChartLatestAffected imagesRadar Score
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89162.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,839
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-89162.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pcre2@10.46-1~deb13u1
10.46-1~deb13u2

Open the chart page →

1,839
clickhousezloi-space1.2.01 of 3See more

clickhouse zloi-space 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-89162.

Container imageDigestPackageFixed in
yandex/clickhouse-server:21.3.204eccfffb01d7
pcre2@10.34-7
no fix listed

Open the chart page →

9,250
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-89162.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pcre2@10.39-3ubuntu0.1
no fix listed

Open the chart page →

7,916

Container images carrying it

1,382 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
pcre2@10.42-4ubuntu2
no fix listed
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
pcre2@10.34-7
no fix listed
1
agentarea/agentarea-api:latest9e15e16fa758
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
agentarea/agentarea-worker:latest1e5cb68ee77a
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
pcre2@10.39-3ubuntu0.1
no fix listed
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
pcre2@10.34-7
no fix listed
1
akeyless/base:latest759e4289fae8
pcre2@10.42-4ubuntu2.1
no fix listed
1
akeyless/gateway:5.3.13d2e7dce5eb9
pcre2@10.42-4ubuntu2.1
no fix listed
1
aktosecurity/akto-agent-guard-anonymizer:1.1.4d4b100cbdc47
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
aktosecurity/akto-agent-guard-embedder:1.1.4dbc566b2376c
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
aktosecurity/akto-agent-guard-worker:1.1.4666eaffd5362
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
pcre2@10.42-4ubuntu2.1
no fix listed
1
aktosecurity/akto-threat-detection-backend:latest15ebb75b94dc
pcre2@10.46-1build1
no fix listed
1
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
pcre2@10.46-1build1
no fix listed
1
aktosecurity/data-ingestion-service213aded7adc5
pcre2@10.42-4ubuntu2.1
no fix listed
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
pcre2@10.46-1build1
no fix listed
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
pcre2@10.46-1build1
no fix listed
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
pcre2@10.46-1build1
no fix listed
1
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
pcre2@10.39-3ubuntu0.1
no fix listed
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
pcre2@10.42-4ubuntu2.1
no fix listed
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
pcre2@10.42-4ubuntu2
no fix listed
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
pcre2@10.39-3ubuntu0.1
no fix listed
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
pcre2@10.39-3ubuntu0.1
no fix listed
1
anguda/ant-media:2.5c435285fc241
pcre2@10.34-7ubuntu0.1
no fix listed
1
antiantiops/vscode-browser-docker:1.137.0eeff80a99d92
pcre2@10.42-4ubuntu2.1
no fix listed
1
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
pcre2@10.42-4ubuntu2.1
no fix listed
1
antrea/antrea-controller-ubuntu:v2.7.0f1373d39217c
pcre2@10.42-4ubuntu2.1
no fix listed
1
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
pcre2@10.46-1~deb13u1
10.46-1~deb13u2
1
antrea/flow-aggregator:v2.7.0065193e7572f
pcre2@10.42-4ubuntu2.1
no fix listed
1
apache/activemq-artemis:2.44.00305c26f19ed
pcre2@10.42-4ubuntu2.1
no fix listed
1
apache/activemq-artemis:2.37.0bae523439ee3
pcre2@10.42-4ubuntu2
no fix listed
1
apache/apisix:3.16.0-ubuntu5e47692cac00
pcre2@10.42-4ubuntu2.1
no fix listed
1
apache/camel-k:2.11.0d173e7efe258
pcre2@10.46-1build1
no fix listed
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
pcre2@10.39-3ubuntu0.1
no fix listed
1
apache/hertzbeat:1.8.075d48a62748f
pcre2@10.42-4ubuntu2.1
no fix listed
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
pcre2@10.42-4ubuntu2.1
no fix listed
1
apache/iotdb:0.13.3-nodeafa47bf1692a
pcre2@10.34-7ubuntu0.1
no fix listed
1
apache/nifi-registry:1.27.063b8e3e40742
pcre2@10.39-3ubuntu0.1
no fix listed
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
pcre2@10.39-3ubuntu0.1
no fix listed
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
pcre2@10.34-7
no fix listed
1
apachepulsar/pulsar:3.0.79c9947de139d
pcre2@10.39-3ubuntu0.1
no fix listed
1
apachepulsar/pulsar:2.9.0d056c89b7131
pcre2@10.34-7
no fix listed
1
apachepulsar/pulsar:2.8.2d538416d5afe
pcre2@10.34-7
no fix listed
1
apache/ranger:2.7.076c176e8a0e4
pcre2@10.39-3ubuntu0.1
no fix listed
1
apache/rocketmq:5.3.0434d8398f996
pcre2@10.42-4ubuntu2
no fix listed
1
apache/rocketmq-exporter:0.0.2c8fb51195444
pcre2@10.39-3ubuntu0.1
no fix listed
1
apache/skywalking-oap-server:9.2.0133d35d2c263
pcre2@10.39-3build1
no fix listed
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
pcre2@10.34-7
no fix listed
1
apache/skywalking-ui:9.2.0295f1dc87d98
pcre2@10.39-3build1
no fix listed
1
apache/skywalking-ui:8.9.180530f0308a5
pcre2@10.34-7
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.