StackRadar

CVE-2026-89511

High

Advisory

Published 11 Sept 2026In the index since 18 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
100
of 17,803 indexed, latest versions
Container images
111
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 100 of 17,803 indexed charts deploy, on 111 images.

Affected packageAffected versionsFixed inImages
linuxdeb5.4.0-62.70, 5.4.0-65.73, 5.4.0-67.75, 5.4.0-74.83+61 moreno fix listed111
OSV records
UBUNTU-CVE-2026-89511

Charts affected

100 by stars
ChartLatestAffected imagesRadar Score
milvusmilvus4.0.312 of 5See more

milvus milvus 4.0.31

2 of the 5 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
linux@5.4.0-91.102
no fix listed
milvusdb/milvus:v2.2.13a3a55e1c1497
linux@5.4.0-131.147
no fix listed

Open the chart page →

166,820
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
linux@6.8.0-88.89
no fix listed

Open the chart page →

70,047
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
linux@6.8.0-124.124
no fix listed

Open the chart page →

59,806
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
linux@5.4.0-131.147
no fix listed

Open the chart page →

82,549
bitbucketatlassian-data-centerVerified publisher2.0.151 of 1See more

bitbucket atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
atlassian/bitbucket:10.2.705933f2b1cfd
linux@6.8.0-139.139
no fix listed

Open the chart page →

28,156
stackstorm-hastackstormVerified publisher1.1.011 of 17See more

stackstorm-ha stackstorm 1.1.0

11 of the 17 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
linux@5.4.0-169.187
no fix listed
stackstorm/st2api:3.86f56d239d280
linux@5.4.0-169.187
no fix listed
stackstorm/st2auth:3.833ecfda16608
linux@5.4.0-169.187
no fix listed
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
linux@5.4.0-169.187
no fix listed
stackstorm/st2notifier:3.8f190a6212195
linux@5.4.0-169.187
no fix listed
stackstorm/st2rulesengine:3.8259503496ff9
linux@5.4.0-169.187
no fix listed
stackstorm/st2scheduler:3.8b1de2055c362
linux@5.4.0-169.187
no fix listed
stackstorm/st2sensorcontainer:3.8b1a338f64773
linux@5.4.0-169.187
no fix listed
stackstorm/st2stream:3.81c8904a3bf67
linux@5.4.0-169.187
no fix listed
stackstorm/st2timersengine:3.81bf35bfaf00c
linux@5.4.0-169.187
no fix listed
stackstorm/st2workflowengine:3.819fdfffdbba8
linux@5.4.0-169.187
no fix listed

Open the chart page →

690,249
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
linux@6.8.0-138.138
no fix listed

Open the chart page →

32,151
photoprismandrenarchyVerified publisher8.15.01 of 1See more

photoprism andrenarchy 8.15.0

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
photoprism/photoprism:260728958642220223
linux@7.0.0-28.28
no fix listed

Open the chart page →

37,025
bambooatlassian-data-centerVerified publisher2.0.151 of 2See more

bamboo atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
atlassian/bamboo:12.1.114af4bb6c8d46
linux@6.8.0-139.139
no fix listed

Open the chart page →

28,744
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
linux@5.4.0-62.70
no fix listed

Open the chart page →

127,498
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
linux@5.15.0-153.163
no fix listed

Open the chart page →

73,025
geonode-k8sgeonode-k8sVerified publisher2.0.01 of 10See more

geonode-k8s geonode-k8s 2.0.0

1 of the 10 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
linux@5.15.0-181.191
no fix listed

Open the chart page →

52,600
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
linux@5.4.0-156.173
no fix listed

Open the chart page →

64,571
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
linux@5.4.0-216.236
no fix listed

Open the chart page →

54,520
nominatimrobjuz6.4.21 of 4See more

nominatim robjuz 6.4.2

1 of the 4 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
mediagis/nominatim:5.3.27923a8e67197
linux@6.8.0-124.124
no fix listed

Open the chart page →

46,200
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
linux@5.4.0-81.91
no fix listed

Open the chart page →

96,081
sn-platformstreamnative1.11.441 of 9See more

sn-platform streamnative 1.11.44

1 of the 9 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
linux@5.4.0-182.202
no fix listed

Open the chart page →

67,666
open-elevationbeeinventor0.1.01 of 2See more

open-elevation beeinventor 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
openelevation/open-elevation:latest82fb21612e86
linux@5.4.0-80.90
no fix listed

Open the chart page →

85,286
powershelluniversaldigitalhubVerified publisher0.1.21 of 1See more

powershelluniversal digitalhub 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
ironmansoftware/universal:3.3.1-ubuntu-20.041943c73cce31
linux@5.4.0-125.141
no fix listed

Open the chart page →

72,845
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
linux@5.15.0-118.128
no fix listed

Open the chart page →

68,853
craftycontrollerdrewburr-labs-helm-chartsVerified publisher0.3.01 of 1See more

craftycontroller drewburr-labs-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
linux@6.8.0-134.134
no fix listed

Open the chart page →

38,780
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
linux@6.8.0-57.59
no fix listed

Open the chart page →

64,698
games-on-whalesgeek-cookbookVerified publisher1.8.21 of 7See more

games-on-whales geek-cookbook 1.8.2

1 of the 7 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
linux@5.4.0-81.91
no fix listed

Open the chart page →

106,894
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
linux@5.4.0-121.137
no fix listed

Open the chart page →

82,293
tdarrgeek-cookbookVerified publisher4.6.21 of 2See more

tdarr geek-cookbook 4.6.2

1 of the 2 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
haveagitgat/tdarr:2.00.181256348872ce
linux@5.4.0-109.123
no fix listed

Open the chart page →

99,240
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
linux@5.15.0-143.153
no fix listed

Open the chart page →

59,315
opennebulakvaps2.1.12 of 9See more

opennebula kvaps 2.1.1

2 of the 9 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
linux@5.4.0-80.90
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
linux@5.4.0-80.90
no fix listed

Open the chart page →

258,213
opsopsVerified publisher1.2.02 of 2See more

ops ops 1.2.0

2 of the 2 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
shaowenchen/ops-controller-manager:latest26da43bb5b66
linux@5.15.0-186.196
no fix listed
shaowenchen/ops-server:latest315444f703f4
linux@5.15.0-153.163
no fix listed

Open the chart page →

86,022
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
linux@6.8.0-136.136
no fix listed

Open the chart page →

51,893
napcatredish101Verified publisher0.1.31 of 1See more

napcat redish101 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
mlikiowa/napcat-docker:latest1336a777f9a4
linux@5.15.0-124.134
no fix listed

Open the chart page →

63,299
rstudio-pmrstudioVerified publisher0.20.51 of 1See more

rstudio-pm rstudio 0.20.5

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
posit/package-manager:2026.09.0-ubuntu-24.04527493ef621b
linux@6.8.0-139.139
no fix listed

Open the chart page →

28,031
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
linux@5.4.0-131.147
no fix listed
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
linux@5.4.0-131.147
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
linux@5.4.0-131.147
no fix listed

Open the chart page →

237,432
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
linux@5.4.0-74.83
no fix listed

Open the chart page →

98,121
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
linux@5.4.0-214.234
no fix listed

Open the chart page →

51,717
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
linux@5.4.0-67.75
no fix listed

Open the chart page →

99,481
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
linux@7.0.0-28.28
no fix listed

Open the chart page →

37,573
akto-regional-setupakto1.3.11 of 9See more

akto-regional-setup akto 1.3.1

1 of the 9 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
linux@7.0.0-29.29
no fix listed

Open the chart page →

35,613
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
linux@6.8.0-139.139
no fix listed

Open the chart page →

31,442
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
linux@6.8.0-94.96
no fix listed

Open the chart page →

53,616
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
linux@5.4.0-81.91
no fix listed

Open the chart page →

113,781
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
linux@5.15.0-91.101
no fix listed

Open the chart page →

83,638
videoaugmentationassist-iot-video-augmentation0.1.01 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
linux@5.4.0-144.161
no fix listed

Open the chart page →

72,862
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
linux@5.4.0-136.153
no fix listed

Open the chart page →

70,424
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
no fix listed

Open the chart page →

68,447
sippchetan-opensips0.1.01 of 1See more

sipp chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
chetangautamm/repo:sipp.v3e7f7049e1544
linux@5.4.0-65.73
no fix listed

Open the chart page →

86,680
datumcosmicrocks1.0.51 of 2See more

datum cosmicrocks 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
linux@6.8.0-90.91
no fix listed

Open the chart page →

53,250
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
linux@5.4.0-152.169
no fix listed

Open the chart page →

72,223
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
linux@5.15.0-52.58
no fix listed

Open the chart page →

111,395
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
linux@5.15.0-52.58
no fix listed

Open the chart page →

110,396
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-89511.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:main-localda995c129e2f
linux@6.8.0-138.138
no fix listed

Open the chart page →

47,013

Container images carrying it

111 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
linux@6.8.0-136.136
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
linux@5.4.0-121.137
no fix listed
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
linux@5.4.0-131.147
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
linux@5.4.0-131.147
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
linux@5.4.0-131.147
no fix listed
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
linux@5.4.0-200.220
no fix listed
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
linux@5.4.0-200.220
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
linux@6.8.0-139.139
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
linux@6.8.0-100.100
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
linux@6.8.0-134.134
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
linux@5.4.0-67.75
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.