StackRadar

CVE-2026-90016

High

Advisory

Published 17 Sept 2026In the index since 18 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.003
23rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
135
of 17,813 indexed, latest versions
Container images
144
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 135 of 17,813 indexed charts deploy, on 144 images.

Affected packageAffected versionsFixed inImages
linuxdeb4.15.0-38.41, 4.15.0-46.49, 4.15.0-50.54, 4.15.0-74.84+82 moreno fix listed144
OSV records
UBUNTU-CVE-2026-90016

Charts affected

135 by stars
ChartLatestAffected imagesRadar Score
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
linux@6.8.0-139.139
no fix listed

Open the chart page →

36,090
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
linux@6.8.0-94.96
no fix listed

Open the chart page →

58,281
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
linux@5.4.0-81.91
no fix listed

Open the chart page →

118,407
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
linux@5.15.0-91.101
no fix listed

Open the chart page →

88,283
videoaugmentationassist-iot-video-augmentation0.1.01 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
linux@5.4.0-144.161
no fix listed

Open the chart page →

77,506
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
linux@5.4.0-136.153
no fix listed

Open the chart page →

74,990
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
linux@4.15.0-144.148
no fix listed

Open the chart page →

87,471
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
no fix listed

Open the chart page →

73,325
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
linux@4.15.0-213.224
no fix listed

Open the chart page →

66,909
sippchetan-opensips0.1.01 of 1See more

sipp chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
chetangautamm/repo:sipp.v3e7f7049e1544
linux@5.4.0-65.73
no fix listed

Open the chart page →

91,273
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
cloudve/janis-terminal:latestaf56e77ca587
linux@4.15.0-106.107
no fix listed

Open the chart page →

81,044
datumcosmicrocks1.0.51 of 2See more

datum cosmicrocks 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
linux@6.8.0-90.91
no fix listed

Open the chart page →

57,910
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
linux@4.15.0-50.54
no fix listed

Open the chart page →

98,082
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
linux@4.15.0-117.118
no fix listed

Open the chart page →

85,159
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
linux@4.15.0-46.49
no fix listed

Open the chart page →

93,130
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
linux@4.15.0-50.54
no fix listed

Open the chart page →

94,689
eg-edge-stackdatawire0.0.11 of 7See more

eg-edge-stack datawire 0.0.1

1 of the 7 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
linux@4.15.0-112.113
no fix listed

Open the chart page →

82,304
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
linux@5.4.0-152.169
no fix listed

Open the chart page →

76,789
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
linux@5.15.0-52.58
no fix listed

Open the chart page →

116,089
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
linux@5.15.0-52.58
no fix listed

Open the chart page →

115,089
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:main-localda995c129e2f
linux@6.8.0-138.138
no fix listed

Open the chart page →

51,732
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
linux@6.8.0-38.38
no fix listed

Open the chart page →

92,708
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
linux@5.4.0-135.152
no fix listed

Open the chart page →

92,653
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
linux@5.4.0-144.161
no fix listed

Open the chart page →

72,876
nethermindethersphereVerified publisher0.2.11 of 1See more

nethermind ethersphere 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
nethermind/nethermind:1.14.615517708c3b6
linux@5.15.0-53.59
no fix listed

Open the chart page →

89,028
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
linux@5.4.0-216.236
no fix listed

Open the chart page →

113,143
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
linux@5.4.0-89.100
no fix listed

Open the chart page →

87,575
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
linux@5.4.0-80.90
no fix listed

Open the chart page →

100,981
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
linux@6.8.0-39.39
no fix listed

Open the chart page →

83,510
hawk-envoy-pluginhawk0.1.01 of 4See more

hawk-envoy-plugin hawk 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
kong/httpbin:latesta6ac46531193
linux@5.15.0-130.140
no fix listed

Open the chart page →

66,018
heliconehelicone0.1.421 of 14See more

helicone helicone 0.1.42

1 of the 14 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
linux@5.4.0-200.220
no fix listed

Open the chart page →

77,057
7dtdhelm-7dtd0.1.01 of 1See more

7dtd helm-7dtd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
vinanrra/7dtd-server:v0.4.4f9534490bd2b
linux@4.15.0-204.215
no fix listed

Open the chart page →

67,072
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
linux@5.4.0-189.209
no fix listed

Open the chart page →

73,884
komgahelmforgeVerified publisher1.4.151 of 1See more

komga helmforge 1.4.15

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
linux@7.0.0-29.29
no fix listed

Open the chart page →

34,743
httpbin2022httpbin2022Verified publisher0.1.11 of 1See more

httpbin2022 httpbin2022 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
mshanley80/httpbin2022:latest5b189a70c0fb
linux@5.4.0-135.152
no fix listed

Open the chart page →

76,124
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:1.2.0e4770285aaf7
linux@5.4.0-89.100
no fix listed

Open the chart page →

113,426
gmaintelVerified publisher0.1.01 of 1See more

gma intel 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
linux@5.4.0-131.147
no fix listed

Open the chart page →

76,149
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
linux@5.4.0-120.136
no fix listed

Open the chart page →

89,173
map5gintelVerified publisher1.0.01 of 1See more

map5g intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
linux@5.4.0-131.147
no fix listed

Open the chart page →

76,149
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization-streaming:3.01a89327e499b
linux@5.4.0-122.138
no fix listed

Open the chart page →

81,916
homebridgejespernohrVerified publisher0.2.01 of 1See more

homebridge jespernohr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
linux@6.8.0-138.138
no fix listed

Open the chart page →

34,371
valheim-serverk8s-chartsVerified publisher1.3.01 of 1See more

valheim-server k8s-charts 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
mbround18/valheim:3.1.070bd4da591cd
linux@5.15.0-133.144
no fix listed

Open the chart page →

61,974
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
no fix listed

Open the chart page →

67,567
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
linux@5.4.0-136.153
no fix listed

Open the chart page →

83,618
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.21.08a4d7e9308de
linux@4.15.0-204.215
no fix listed

Open the chart page →

68,898
kovi-appkovi-charts0.8.11 of 1See more

kovi-app kovi-charts 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
kennethreitz/httpbin:latest599fe5e50731
linux@4.15.0-38.41
no fix listed

Open the chart page →

85,956
kubernetes-netskope-publisherkubernetes-netskope-publisherVerified publisher1.5.01 of 2See more

kubernetes-netskope-publisher kubernetes-netskope-publisher 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
netskopeprivateaccess/publisher_u22:latest93e2fd164a93
linux@5.15.0-186.196
no fix listed

Open the chart page →

39,912
pulsarkubesphere-stable2.7.131 of 3See more

pulsar kubesphere-stable 2.7.13

1 of the 3 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
linux@5.4.0-77.86
no fix listed

Open the chart page →

91,524
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
linux@5.15.0-130.140
no fix listed

Open the chart page →

63,775
homebridgelbenicio-communityVerified publisher0.1.151 of 1See more

homebridge lbenicio-community 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-90016.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
linux@6.8.0-138.138
no fix listed

Open the chart page →

34,371

Container images carrying it

144 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
socialmediamacroscope/image_crawler:0.1.2f508216be63c
linux@4.15.0-210.221
no fix listed
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
linux@5.4.0-117.132
no fix listed
1
stackstorm/st2actionrunner:3.888235ba70cad
linux@5.4.0-169.187
no fix listed
1
stackstorm/st2api:3.86f56d239d280
linux@5.4.0-169.187
no fix listed
1
stackstorm/st2auth:3.833ecfda16608
linux@5.4.0-169.187
no fix listed
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
linux@5.4.0-169.187
no fix listed
1
stackstorm/st2notifier:3.8f190a6212195
linux@5.4.0-169.187
no fix listed
1
stackstorm/st2rulesengine:3.8259503496ff9
linux@5.4.0-169.187
no fix listed
1
stackstorm/st2scheduler:3.8b1de2055c362
linux@5.4.0-169.187
no fix listed
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
linux@5.4.0-169.187
no fix listed
1
stackstorm/st2stream:3.81c8904a3bf67
linux@5.4.0-169.187
no fix listed
1
stackstorm/st2timersengine:3.81bf35bfaf00c
linux@5.4.0-169.187
no fix listed
1
stackstorm/st2workflowengine:3.819fdfffdbba8
linux@5.4.0-169.187
no fix listed
1
statcan/ckan:2.93921305425b8
linux@5.4.0-74.83
no fix listed
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
linux@5.4.0-77.86
no fix listed
1
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
linux@5.15.0-92.102
no fix listed
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
linux@5.4.0-176.196
no fix listed
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
linux@5.15.0-134.145
no fix listed
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
linux@4.15.0-204.215
no fix listed
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
linux@5.4.0-144.161
no fix listed
1
xeladock/mysql_dns:latest4baf531453f1
linux@5.15.0-25.25
no fix listed
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
linux@4.15.0-88.88
no fix listed
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
linux@6.8.0-90.91
no fix listed
1
ghcr.io/guydavis/machinaris:test50a71a30f18e
linux@6.8.0-139.139
no fix listed
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
linux@5.4.0-110.124
no fix listed
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
linux@5.4.0-214.234
no fix listed
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
linux@5.4.0-80.90
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
linux@5.4.0-80.90
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
linux@6.8.0-57.59
no fix listed
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
linux@6.8.0-136.136
no fix listed
1
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
linux@6.8.0-136.136
no fix listed
1
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
linux@6.8.0-136.136
no fix listed
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
linux@6.8.0-136.136
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
linux@5.4.0-121.137
no fix listed
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
linux@5.4.0-131.147
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
linux@5.4.0-131.147
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
linux@5.4.0-131.147
no fix listed
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
linux@5.4.0-200.220
no fix listed
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
linux@5.4.0-200.220
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
linux@6.8.0-139.139
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
linux@6.8.0-100.100
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
linux@4.15.0-191.202
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
linux@6.8.0-139.139
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
linux@5.4.0-67.75
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.