StackRadar

CVE-2026-90802

Medium

Advisory

Published 14 Sept 2026In the index since 15 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
169
of 17,787 indexed, latest versions
Container images
157
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 169 of 17,787 indexed charts deploy, on 157 images.

Affected packageAffected versionsFixed inImages
binutilsdeb2.40-2, 2.44-3no fix listed157
OSV records
DEBIAN-CVE-2026-90802
Trending
Rank 49 in indexed charts, since 15 Sept 2026. See the ranking →

Charts affected

169 by stars
ChartLatestAffected imagesRadar Score
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
binutils@2.40-2
no fix listed

Open the chart page →

8,158
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
binutils@2.40-2
no fix listed

Open the chart page →

5,482
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
binutils@2.40-2
no fix listed

Open the chart page →

7,740
kyoorubxkubeVerified publisher0.1.102 of 9See more

kyoo rubxkube 0.1.10

2 of the 9 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
binutils@2.40-2
no fix listed
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
binutils@2.40-2
no fix listed

Open the chart page →

30,234
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
binutils@2.44-3
no fix listed

Open the chart page →

7,126
supabasesupabse0.8.01 of 11See more

supabase supabse 0.8.0

1 of the 11 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
binutils@2.40-2
no fix listed

Open the chart page →

18,075
typemilltypemill-helm-chart2.2.02 of 2See more

typemill typemill-helm-chart 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
kixote/typemilldigest-pinned4e9dff179519
binutils@2.44-3
no fix listed
kixote/typemilldigest-pinned628f79a08cc7
binutils@2.44-3
no fix listed

Open the chart page →

5,338
varnish-ingress-controllervarnish-ingress-controllerVerified publisher0.5.01 of 1See more

varnish-ingress-controller varnish-ingress-controller 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
mariusm/vingress:0.5.0b3db186c3d72
binutils@2.44-3
no fix listed

Open the chart page →

2,251
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
binutils@2.44-3
no fix listed

Open the chart page →

7,696
zcash-stackzcashVerified publisher0.4.51 of 2See more

zcash-stack zcash 0.4.5

1 of the 2 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
electriccoinco/lightwalletd:v0.5.42ae3a551e111
binutils@2.44-3
no fix listed

Open the chart page →

2,835
esphomealekcVerified publisher2.8.11 of 1See more

esphome alekc 2.8.1

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
esphome/esphome:2026.8.285abea33854b
binutils@2.44-3
no fix listed

Open the chart page →

3,112
anchore-admission-controlleranchore-charts0.8.51See more

anchore-admission-controller anchore-charts 0.8.5

1 container image this version deploys carries CVE-2026-90802.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
binutils@2.40-2
no fix listed

Open the chart page →

mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
binutils@2.40-2
no fix listed

Open the chart page →

7,239
speech-to-phraseandrenarchyVerified publisher1.3.01 of 1See more

speech-to-phrase andrenarchy 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
binutils@2.40-2
no fix listed

Open the chart page →

3,991
ddosifyanteonVerified publisher1.7.52 of 13See more

ddosify anteon 1.7.5

2 of the 13 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
binutils@2.40-2
no fix listed
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
binutils@2.40-2
no fix listed

Open the chart page →

25,669
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
binutils@2.44-3
no fix listed

Open the chart page →

7,489
arlas-aiasarlas-stackVerified publisher28.8.01 of 22See more

arlas-aias arlas-stack 28.8.0

1 of the 22 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
binutils@2.40-2
no fix listed

Open the chart page →

40,238
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
binutils@2.40-2
no fix listed

Open the chart page →

10,145
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
binutils@2.40-2
no fix listed
sysnet4admin/colosseum-prm:log5802bfcd7fed
binutils@2.40-2
no fix listed

Open the chart page →

26,996
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
binutils@2.40-2
no fix listed

Open the chart page →

14,352
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
binutils@2.40-2
no fix listed

Open the chart page →

5,778
polrchristianhuthVerified publisher4.3.01 of 2See more

polr christianhuth 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
binutils@2.40-2
no fix listed

Open the chart page →

5,904
kamaji-etcdclastixVerified publisher0.17.01 of 4See more

kamaji-etcd clastix 0.17.0

1 of the 4 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
cfssl/cfssl:latestc9018c2ddf0b
binutils@2.40-2
no fix listed

Open the chart page →

11,995
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
binutils@2.40-2
no fix listed

Open the chart page →

8,009
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
binutils@2.40-2
no fix listed

Open the chart page →

14,559
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
binutils@2.40-2
no fix listed

Open the chart page →

16,604
db-connection-testdb-connection-testVerified publisher0.1.01 of 1See more

db-connection-test db-connection-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
felipecs8/app-db-connection-test:v129e06c9c6385
binutils@2.40-2
no fix listed

Open the chart page →

10,090
devtron-enterprisedevtron48.0.02 of 28See more

devtron-enterprise devtron 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
binutils@2.40-2
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
binutils@2.40-2
no fix listed

Open the chart page →

68,240
devtron-enterprisedevtron-labs48.0.02 of 28See more

devtron-enterprise devtron-labs 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
binutils@2.40-2
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
binutils@2.40-2
no fix listed

Open the chart page →

68,240
devtron-operatordevtron-labs0.23.31 of 11See more

devtron-operator devtron-labs 0.23.3

1 of the 11 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
binutils@2.40-2
no fix listed

Open the chart page →

32,902
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
binutils@2.40-2
no fix listed

Open the chart page →

7,141
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
binutils@2.44-3
no fix listed

Open the chart page →

13,391
esphomeegebackVerified publisher2.0.251 of 1See more

esphome egeback 2.0.25

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
esphome/esphome:2026.7.44866347cb5b4
binutils@2.44-3
no fix listed

Open the chart page →

3,121
wordpresseoc-chartsVerified publisher0.14.41 of 1See more

wordpress eoc-charts 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
library/wordpress:6.8.3-apache30bff39330d1
binutils@2.44-3
no fix listed

Open the chart page →

7,233
matomoeosc-lot-1Verified publisher0.2.01 of 1See more

matomo eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
library/matomo:5.1.2-apache2415789e1602
binutils@2.40-2
no fix listed

Open the chart page →

5,290
beeport-uiethersphereVerified publisher0.76.21 of 3See more

beeport-ui ethersphere 0.76.2

1 of the 3 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
binutils@2.40-2
no fix listed

Open the chart page →

7,368
multichain-uiethersphereVerified publisher0.73.11 of 3See more

multichain-ui ethersphere 0.73.1

1 of the 3 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
binutils@2.40-2
no fix listed

Open the chart page →

7,368
static-siteethersphereVerified publisher0.73.11 of 2See more

static-site ethersphere 0.73.1

1 of the 2 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
library/node:latestf5d1cc40abc1
binutils@2.44-3
no fix listed

Open the chart page →

6,851
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
binutils@2.44-3
no fix listed

Open the chart page →

5,039
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
binutils@2.44-3
no fix listed
fireflyiii/data-importer:version-2.2.3ab52bf932546
binutils@2.44-3
no fix listed

Open the chart page →

10,260
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
binutils@2.44-3
no fix listed

Open the chart page →

4,829
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
binutils@2.44-3
no fix listed

Open the chart page →

5,704
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
binutils@2.40-2
no fix listed

Open the chart page →

64,489
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
binutils@2.44-3
no fix listed

Open the chart page →

5,704
esphomegabe565Verified publisher0.15.01 of 1See more

esphome gabe565 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:latest000c5ee5ee96
binutils@2.44-3
no fix listed

Open the chart page →

3,112
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
binutils@2.40-2
no fix listed

Open the chart page →

9,077
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
binutils@2.40-2
no fix listed

Open the chart page →

12,958
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
binutils@2.44-3
no fix listed

Open the chart page →

8,923
glpiglpi-chart0.1.12 of 3See more

glpi glpi-chart 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
binutils@2.44-3
no fix listed
vdiogov/glpi-conteiner:latest6945f84f0058
binutils@2.40-2
no fix listed

Open the chart page →

12,170
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-90802.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
binutils@2.40-2
no fix listed

Open the chart page →

49,025

Container images carrying it

157 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/phpmyadmin:5.2.3-apache:latest3a8a8d6b5289
binutils@2.44-3
no fix listed
7
library/wordpress:7.1.0-apache:latest5a93c470ae82
binutils@2.44-3
no fix listed
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
binutils@2.40-2
no fix listed
6
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
binutils@2.40-2
no fix listed
4
library/node:ltsbe23f54a88d3
binutils@2.40-2
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
binutils@2.40-2
no fix listed
3
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
binutils@2.40-2
no fix listed
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
binutils@2.44-3
no fix listed
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
binutils@2.44-3
no fix listed
2
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
binutils@2.44-3
no fix listed
2
library/phpmyadmin:5.2.16e75aa8f767c
binutils@2.40-2
no fix listed
2
library/python:3.7eedf63967cdb
binutils@2.40-2
no fix listed
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
binutils@2.44-3
no fix listed
2
localstack/localstack-pro:latest4aef81c53168
binutils@2.44-3
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
binutils@2.40-2
no fix listed
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
binutils@2.40-2
no fix listed
2
uffizzi/controller:latest0344805f267b
binutils@2.40-2
no fix listed
2
vdiogov/glpi-conteiner:latest6945f84f0058
binutils@2.40-2
no fix listed
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
binutils@2.40-2
no fix listed
2
aboogie/login_test_backend:new9c41a4483ac8
binutils@2.40-2
no fix listed
1
akaunting/akaunting:3.0.1552811b36ec3a
binutils@2.40-2
no fix listed
1
allegroai/clearml:2.0.0-613713ae38f7daf
binutils@2.40-2
no fix listed
1
aristidetm/basic-notebook:3.6.5469dbc951224
binutils@2.40-2
no fix listed
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
binutils@2.40-2
no fix listed
1
baserow/backend:1.31.1e0b3c8130b91
binutils@2.40-2
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
binutils@2.40-2
no fix listed
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
binutils@2.44-3
no fix listed
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
binutils@2.44-3
no fix listed
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
binutils@2.40-2
no fix listed
1
bmeares/meerschaum:2.8.48e9c5bacaa82
binutils@2.40-2
no fix listed
1
bnjbvr/kresus:0.22.137e216b182c8
binutils@2.40-2
no fix listed
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
binutils@2.40-2
no fix listed
1
castopod/castopod:1.12.101fd37280cbb2
binutils@2.40-2
no fix listed
1
castopod/castopod:1.15.54e4f0440520f
binutils@2.44-3
no fix listed
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
binutils@2.44-3
no fix listed
1
chocobozzz/peertube:v8.1.5052712130691
binutils@2.44-3
no fix listed
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
binutils@2.44-3
no fix listed
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
binutils@2.40-2
no fix listed
1
ddosify/selfhosted_backend:3.2.93c11e3182652
binutils@2.40-2
no fix listed
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
binutils@2.40-2
no fix listed
1
deconzcommunity/deconz:2.29.2062de2362641
binutils@2.40-2
no fix listed
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
binutils@2.44-3
no fix listed
1
dolibarr/dolibarr:24.0.069ec52e3b7ef
binutils@2.40-2
no fix listed
1
dolibarr/dolibarr:22.0.47ad88fc9b13c
binutils@2.40-2
no fix listed
1
domainmod/domainmod:4.23.04017bfe4c597
binutils@2.40-2
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
binutils@2.40-2
no fix listed
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
binutils@2.44-3
no fix listed
1
electriccoinco/lightwalletd:v0.5.42ae3a551e111
binutils@2.44-3
no fix listed
1
esphome/esphome:2026.7.44866347cb5b4
binutils@2.44-3
no fix listed
1
esphome/esphome:2026.8.285abea33854b
binutils@2.44-3
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.