StackRadar

CVE-2026-90215

Medium

Advisory

Published 18 Sept 2026In the index since 19 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
108
of 17,828 indexed, latest versions
Container images
99
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 108 of 17,828 indexed charts deploy, on 99 images.

Affected packageAffected versionsFixed inImages
linuxdeb3.13.0-46.77, 3.13.0-126.175, 3.13.0-149.199, 3.13.0-170.220+66 moreno fix listed99
OSV records
UBUNTU-CVE-2026-90215

Charts affected

108 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

99 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
oomk8s/readiness-check:2.0.2875814cc853d
linux@4.4.0-142.168
no fix listed
11
oomk8s/readiness-check:2.0.07daa08b81954
linux@4.4.0-116.140
no fix listed
6
istio/kubectl:1.5.10dbb7726d1bf0
linux@4.15.0-112.113
no fix listed
3
gotson/komga:1.26.36c2a967bbe9a
linux@7.0.0-29.29
no fix listed
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
linux@4.4.0-142.168
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
linux@6.8.0-60.63
no fix listed
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
linux@5.15.0-52.58
no fix listed
2
a10networks/acos-prometheus-exporter:latest8dc58d434d71
linux@4.15.0-101.102
no fix listed
1
aktosecurity/data-ingestion-service213aded7adc5
linux@6.8.0-94.96
no fix listed
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
linux@7.0.0-28.28
no fix listed
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
linux@7.0.0-29.29
no fix listed
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
linux@6.8.0-138.138
no fix listed
1
apachepulsar/pulsar:2.9.0d056c89b7131
linux@5.4.0-90.101
no fix listed
1
assistiot/open_api_backend:1.1.230812ba93555
linux@5.15.0-91.101
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
linux@5.4.0-144.161
no fix listed
1
atlassian/bamboo:12.1.114af4bb6c8d46
linux@6.8.0-139.139
no fix listed
1
atlassian/bitbucket:10.2.705933f2b1cfd
linux@6.8.0-139.139
no fix listed
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
linux@5.4.0-136.153
no fix listed
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
linux@3.13.0-170.220
no fix listed
1
chetangautamm/repo:sipp.v3e7f7049e1544
linux@5.4.0-65.73
no fix listed
1
cheyang/distributed-tf:1.6.046cc34755493
linux@4.4.0-116.140
no fix listed
1
cloudve/janis-terminal:latestaf56e77ca587
linux@4.15.0-106.107
no fix listed
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
linux@5.4.0-122.138
no fix listed
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
linux@4.4.0-104.127
no fix listed
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
linux@5.4.0-216.236
no fix listed
1
frankescobar/allure-docker-service:2.27.00815040339a9
linux@4.15.0-213.224
no fix listed
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
linux@4.15.0-204.215
no fix listed
1
galaxy/galaxy-init:v18.010267bad550e6
linux@3.13.0-149.199
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
linux@3.13.0-149.199
no fix listed
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
linux@4.15.0-117.118
no fix listed
1
gethue/hue:4.11.011b649636e68
linux@5.4.0-136.153
no fix listed
1
grpl/grapple-cli:0.2.127c00aafee6629
linux@6.8.0-39.39
no fix listed
1
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
linux@5.4.0-200.220
no fix listed
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
linux@4.4.0-128.154
no fix listed
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
linux@4.4.0-124.148
no fix listed
1
ibmcom/microclimate-theia:lateste17bdccc5030
linux@4.4.0-104.127
no fix listed
1
istio/node-agent-k8s:1.2.9268ab879ea51
linux@4.4.0-150.176
no fix listed
1
istio/pilot:1.10.0294ca55bd1cc
linux@4.15.0-143.147
no fix listed
1
istio/pilot:1.2.9c09319753454
linux@4.4.0-150.176
no fix listed
1
istio/proxyv2:1.2.90c78be035e98
linux@4.4.0-150.176
no fix listed
1
istio/proxyv2:1.10.088c6c693e67a
linux@4.15.0-143.147
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
linux@5.15.0-100.110
no fix listed
1
jupyterhub/k8s-hub:0.9.1ec78bdae0fed
linux@4.15.0-96.97
no fix listed
1
kennethreitz/httpbin:latest599fe5e50731
linux@4.15.0-38.41
no fix listed
1
kong/httpbin:latesta6ac46531193
linux@5.15.0-130.140
no fix listed
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
linux@6.8.0-138.138
no fix listed
1
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
linux@4.15.0-171.180
no fix listed
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
linux@5.4.0-100.113
no fix listed
1
mbround18/valheim:3.1.070bd4da591cd
linux@5.15.0-133.144
no fix listed
1
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
linux@5.4.0-117.132
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.