StackRadar

CVE-2026-89699

High

Advisory

Published 11 Sept 2026In the index since 18 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
170
of 17,803 indexed, latest versions
Container images
172
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 170 of 17,803 indexed charts deploy, on 172 images.

Affected packageAffected versionsFixed inImages
linuxdeb3.13.0-46.77, 3.13.0-126.175, 3.13.0-149.199, 3.13.0-170.220+96 moreno fix listed172
OSV records
UBUNTU-CVE-2026-89699

Charts affected

170 by stars
ChartLatestAffected imagesRadar Score
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
linux@7.0.0-28.28
no fix listed

Open the chart page →

37,573
akto-regional-setupakto1.3.11 of 9See more

akto-regional-setup akto 1.3.1

1 of the 9 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
linux@7.0.0-29.29
no fix listed

Open the chart page →

35,613
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
linux@6.8.0-139.139
no fix listed

Open the chart page →

31,442
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
linux@6.8.0-94.96
no fix listed

Open the chart page →

53,616
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
linux@5.4.0-81.91
no fix listed

Open the chart page →

113,781
dltkvassist-iot-data-integrity-verification0.2.02 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
linux@4.4.0-128.154
no fix listed
hyperledger/fabric-couchdb:0.4.15f6c724592abf
linux@4.4.0-143.169
no fix listed

Open the chart page →

185,703
dltflassist-iot-dlt-based-fl0.2.02 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
linux@4.4.0-128.154
no fix listed
hyperledger/fabric-couchdb:0.4.15f6c724592abf
linux@4.4.0-143.169
no fix listed

Open the chart page →

185,703
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
linux@5.15.0-91.101
no fix listed

Open the chart page →

83,638
videoaugmentationassist-iot-video-augmentation0.1.01 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
linux@5.4.0-144.161
no fix listed

Open the chart page →

72,862
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
linux@5.4.0-136.153
no fix listed

Open the chart page →

70,424
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
linux@4.15.0-144.148
no fix listed

Open the chart page →

83,011
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
no fix listed

Open the chart page →

68,447
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
linux@4.15.0-213.224
no fix listed

Open the chart page →

62,428
opensipschetan-opensips0.1.01 of 1See more

opensips chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
chetangautamm/repo:Opensips_Buildb4b94155ff5a
linux@3.13.0-170.220
no fix listed

Open the chart page →

74,602
sippchetan-opensips0.1.01 of 1See more

sipp chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
chetangautamm/repo:sipp.v3e7f7049e1544
linux@5.4.0-65.73
no fix listed

Open the chart page →

86,680
distributed-tensorflowcloudnativeapp0.1.11 of 1See more

distributed-tensorflow cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
cheyang/distributed-tf:1.6.046cc34755493
linux@4.4.0-116.140
no fix listed

Open the chart page →

91,485
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
linux@4.4.0-104.127
no fix listed

Open the chart page →

83,114
guestbookcloudnativeapp0.2.01 of 3See more

guestbook cloudnativeapp 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
resouer/redis-slave:v2e2f198b49ba7
linux@3.13.0-46.77
no fix listed

Open the chart page →

87,728
hlf-couchdbcloudnativeapp1.0.61 of 1See more

hlf-couchdb cloudnativeapp 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
hyperledger/fabric-couchdb:0.4.10c65891b6c237
linux@4.4.0-128.154
no fix listed

Open the chart page →

88,450
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
linux@4.4.0-112.135
no fix listed

Open the chart page →

133,332
galaxy-stablecloudve2.0.02 of 5See more

galaxy-stable cloudve 2.0.0

2 of the 5 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
linux@3.13.0-149.199
no fix listed
galaxy/galaxy-stable:v18.018e577a626dfd
linux@3.13.0-149.199
no fix listed

Open the chart page →

163,336
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
cloudve/janis-terminal:latestaf56e77ca587
linux@4.15.0-106.107
no fix listed

Open the chart page →

76,586
datumcosmicrocks1.0.51 of 2See more

datum cosmicrocks 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
linux@6.8.0-90.91
no fix listed

Open the chart page →

53,250
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
linux@4.15.0-50.54
no fix listed

Open the chart page →

93,624
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
linux@4.15.0-117.118
no fix listed

Open the chart page →

80,703
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
linux@4.15.0-46.49
no fix listed

Open the chart page →

88,672
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
linux@4.15.0-50.54
no fix listed

Open the chart page →

90,231
eg-edge-stackdatawire0.0.11 of 7See more

eg-edge-stack datawire 0.0.1

1 of the 7 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
linux@4.15.0-112.113
no fix listed

Open the chart page →

77,853
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
linux@5.4.0-152.169
no fix listed

Open the chart page →

72,223
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
linux@5.15.0-52.58
no fix listed

Open the chart page →

111,395
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
linux@5.15.0-52.58
no fix listed

Open the chart page →

110,396
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:main-localda995c129e2f
linux@6.8.0-138.138
no fix listed

Open the chart page →

47,013
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
linux@6.8.0-38.38
no fix listed

Open the chart page →

87,945
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
linux@5.4.0-135.152
no fix listed

Open the chart page →

88,064
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
linux@5.4.0-144.161
no fix listed

Open the chart page →

68,313
nethermindethersphereVerified publisher0.2.11 of 1See more

nethermind ethersphere 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
nethermind/nethermind:1.14.615517708c3b6
linux@5.15.0-53.59
no fix listed

Open the chart page →

84,388
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
linux@5.4.0-216.236
no fix listed

Open the chart page →

108,383
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
linux@5.4.0-89.100
no fix listed

Open the chart page →

82,980
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
linux@5.4.0-80.90
no fix listed

Open the chart page →

96,390
knativegitlabVerified publisher0.10.03 of 10See more

knative gitlab 0.10.0

3 of the 10 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
istio/node-agent-k8s:1.2.9268ab879ea51
linux@4.4.0-150.176
no fix listed
istio/pilot:1.2.9c09319753454
linux@4.4.0-150.176
no fix listed
istio/proxyv2:1.2.90c78be035e98
linux@4.4.0-150.176
no fix listed

Open the chart page →

193,711
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
linux@6.8.0-39.39
no fix listed

Open the chart page →

78,760
hawk-envoy-pluginhawk0.1.01 of 4See more

hawk-envoy-plugin hawk 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
kong/httpbin:latesta6ac46531193
linux@5.15.0-130.140
no fix listed

Open the chart page →

61,394
heliconehelicone0.1.421 of 14See more

helicone helicone 0.1.42

1 of the 14 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
linux@5.4.0-200.220
no fix listed

Open the chart page →

72,363
7dtdhelm-7dtd0.1.01 of 1See more

7dtd helm-7dtd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
vinanrra/7dtd-server:v0.4.4f9534490bd2b
linux@4.15.0-204.215
no fix listed

Open the chart page →

62,635
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
linux@5.4.0-189.209
no fix listed

Open the chart page →

69,307
komgahelmforgeVerified publisher1.4.151 of 1See more

komga helmforge 1.4.15

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
linux@7.0.0-29.29
no fix listed

Open the chart page →

29,969
httpbin2022httpbin2022Verified publisher0.1.11 of 1See more

httpbin2022 httpbin2022 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
mshanley80/httpbin2022:latest5b189a70c0fb
linux@5.4.0-135.152
no fix listed

Open the chart page →

71,556
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
ibmcom/microclimate-theia:lateste17bdccc5030
linux@4.4.0-104.127
no fix listed

Open the chart page →

113,436
ibm-swift-sampleibm-charts1.1.21 of 1See more

ibm-swift-sample ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
ibmcom/icp-swift-sample:latestb5d8c6714dbc
linux@4.4.0-124.148
no fix listed

Open the chart page →

79,865
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2026-89699.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:1.2.0e4770285aaf7
linux@5.4.0-89.100
no fix listed

Open the chart page →

108,761

Container images carrying it

172 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
linux@4.4.0-150.176
no fix listed
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
linux@6.8.0-90.91
no fix listed
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
linux@5.4.0-110.124
no fix listed
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
linux@5.4.0-214.234
no fix listed
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
linux@5.4.0-80.90
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
linux@5.4.0-80.90
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
linux@6.8.0-57.59
no fix listed
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
linux@6.8.0-136.136
no fix listed
1
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
linux@6.8.0-136.136
no fix listed
1
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
linux@6.8.0-136.136
no fix listed
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
linux@6.8.0-136.136
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
linux@5.4.0-121.137
no fix listed
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
linux@5.4.0-131.147
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
linux@5.4.0-131.147
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
linux@5.4.0-131.147
no fix listed
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
linux@5.4.0-200.220
no fix listed
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
linux@5.4.0-200.220
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
linux@6.8.0-139.139
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
linux@6.8.0-100.100
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
linux@4.15.0-191.202
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
linux@6.8.0-134.134
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
linux@5.4.0-67.75
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.