StackRadar

CVE-2026-90803

Medium

Advisory

Published 14 Sept 2026In the index since 15 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
235
of 17,787 indexed, latest versions
Container images
236
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 235 of 17,787 indexed charts deploy, on 236 images.

Affected packageAffected versionsFixed inImages
binutilsdeb2.40-2, 2.44-3no fix listed236
OSV records
DEBIAN-CVE-2026-90803
Trending
Rank 48 in indexed charts, since 15 Sept 2026. See the ranking →

Charts affected

235 by stars
ChartLatestAffected imagesRadar Score
devtron-enterprisedevtron48.0.02 of 28See more

devtron-enterprise devtron 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
binutils@2.40-2
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
binutils@2.40-2
no fix listed

Open the chart page →

66,542
devtron-enterprisedevtron-labs48.0.02 of 28See more

devtron-enterprise devtron-labs 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
binutils@2.40-2
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
binutils@2.40-2
no fix listed

Open the chart page →

66,542
devtron-operatordevtron-labs0.23.31 of 11See more

devtron-operator devtron-labs 0.23.3

1 of the 11 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
binutils@2.40-2
no fix listed

Open the chart page →

31,447
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
binutils@2.40-2
no fix listed

Open the chart page →

7,167
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
binutils@2.40-2
no fix listed

Open the chart page →

13,031
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
binutils@2.44-3
no fix listed

Open the chart page →

13,422
esphomeegebackVerified publisher2.0.251 of 1See more

esphome egeback 2.0.25

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
esphome/esphome:2026.7.44866347cb5b4
binutils@2.44-3
no fix listed

Open the chart page →

3,153
wordpresseoc-chartsVerified publisher0.14.41 of 1See more

wordpress eoc-charts 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
library/wordpress:6.8.3-apache30bff39330d1
binutils@2.44-3
no fix listed

Open the chart page →

7,265
matomoeosc-lot-1Verified publisher0.2.01 of 1See more

matomo eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
library/matomo:5.1.2-apache2415789e1602
binutils@2.40-2
no fix listed

Open the chart page →

5,316
espocrmespocrmVerified publisher1.0.11 of 2See more

espocrm espocrm 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
espocrm/espocrm:9.3.101b5a24504ed9
binutils@2.44-3
no fix listed

Open the chart page →

6,475
beeport-uiethersphereVerified publisher0.76.21 of 3See more

beeport-ui ethersphere 0.76.2

1 of the 3 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
binutils@2.40-2
no fix listed

Open the chart page →

7,406
multichain-uiethersphereVerified publisher0.73.11 of 3See more

multichain-ui ethersphere 0.73.1

1 of the 3 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
binutils@2.40-2
no fix listed

Open the chart page →

7,406
static-siteethersphereVerified publisher0.73.11 of 2See more

static-site ethersphere 0.73.1

1 of the 2 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
library/node:latestf5d1cc40abc1
binutils@2.44-3
no fix listed

Open the chart page →

6,894
ferriscompanyferriscompany0.1.01 of 1See more

ferriscompany ferriscompany 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
binutils@2.40-2
no fix listed

Open the chart page →

10,119
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
binutils@2.44-3
no fix listed

Open the chart page →

5,038
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
binutils@2.44-3
no fix listed
fireflyiii/data-importer:version-2.2.3ab52bf932546
binutils@2.44-3
no fix listed

Open the chart page →

10,258
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
binutils@2.44-3
no fix listed

Open the chart page →

4,828
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
binutils@2.44-3
no fix listed

Open the chart page →

5,624
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
binutils@2.40-2
no fix listed

Open the chart page →

64,192
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
binutils@2.44-3
no fix listed

Open the chart page →

5,624
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
binutils@2.40-2
no fix listed

Open the chart page →

3,384
esphomegabe565Verified publisher0.15.01 of 1See more

esphome gabe565 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:latest000c5ee5ee96
binutils@2.44-3
no fix listed

Open the chart page →

3,143
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
binutils@2.40-2
no fix listed

Open the chart page →

9,103
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
binutils@2.40-2
no fix listed

Open the chart page →

12,993
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
binutils@2.44-3
no fix listed

Open the chart page →

8,955
glpiglpi-chart0.1.12 of 3See more

glpi glpi-chart 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
binutils@2.44-3
no fix listed
vdiogov/glpi-conteiner:latest6945f84f0058
binutils@2.40-2
no fix listed

Open the chart page →

12,270
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
binutils@2.40-2
no fix listed

Open the chart page →

47,117
heliconehelicone0.1.421 of 14See more

helicone helicone 0.1.42

1 of the 14 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
binutils@2.40-2
no fix listed

Open the chart page →

23,472
castopodhelmforgeVerified publisher1.2.71 of 3See more

castopod helmforge 1.2.7

1 of the 3 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
castopod/castopod:1.15.54e4f0440520f
binutils@2.44-3
no fix listed

Open the chart page →

9,422
chiefonboardinghelmforgeVerified publisher1.1.141 of 3See more

chiefonboarding helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
binutils@2.44-3
no fix listed

Open the chart page →

10,898
discount-bandithelmforgeVerified publisher2.0.81 of 3See more

discount-bandit helmforge 2.0.8

1 of the 3 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
cybrarist/discount-bandit:v4.0.4e9e2447ac666
binutils@2.44-3
no fix listed

Open the chart page →

29,852
drupalhelmforgeVerified publisher1.2.131 of 2See more

drupal helmforge 1.2.13

1 of the 2 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
library/drupal:11.4.6-php8.5-apache-bookworm28f7931ecbcb
binutils@2.40-2
no fix listed

Open the chart page →

3,660
middlewarehelmforgeVerified publisher1.2.61 of 4See more

middleware helmforge 1.2.6

1 of the 4 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
binutils@2.40-2
no fix listed

Open the chart page →

9,704
moodlehelmforgeVerified publisher1.1.01 of 2See more

moodle helmforge 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
binutils@2.40-2
no fix listed

Open the chart page →

5,911
nextcloudhelmforgeVerified publisher1.0.01 of 3See more

nextcloud helmforge 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
library/nextcloud:34.0.4-apachede4ad9389386
binutils@2.44-3
no fix listed

Open the chart page →

7,041
phpmyadminhelmforgeVerified publisher2.0.11 of 1See more

phpmyadmin helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.342a200db07b4
binutils@2.44-3
no fix listed

Open the chart page →

4,741
myapphelmingapp0.1.01 of 1See more

myapp helmingapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
muhammedgamal/fp23:latest74b4cd69b6fa
binutils@2.40-2
no fix listed

Open the chart page →

11,441
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
binutils@2.40-2
no fix listed

Open the chart page →

25,099
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
binutils@2.40-2
no fix listed

Open the chart page →

11,838
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
binutils@2.40-2
no fix listed

Open the chart page →

16,558
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
binutils@2.40-2
no fix listed

Open the chart page →

10,816
jasperjasperVerified publisher1.0.2031 of 2See more

jasper jasper 1.0.203

1 of the 2 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
binutils@2.40-2
no fix listed

Open the chart page →

9,148
esphomejeffrescVerified publisher0.2.21 of 1See more

esphome jeffresc 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:2026.4.078a82d810709
binutils@2.40-2
no fix listed

Open the chart page →

5,066
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
binutils@2.40-2
no fix listed

Open the chart page →

22,665
shinsei-managerjtektVerified publisher0.2.04 of 8See more

shinsei-manager jtekt 0.2.0

4 of the 8 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
binutils@2.40-2
no fix listed
moreillon/group-manager:latest3caa8f710ee0
binutils@2.40-2
no fix listed
moreillon/user-manager:v5.0.2e1c9bfab5c16
binutils@2.40-2
no fix listed
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
binutils@2.40-2
no fix listed

Open the chart page →

59,560
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
binutils@2.40-2
no fix listed

Open the chart page →

16,626
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
kitware/cdash:v5.3.0d7767d9b9da4
binutils@2.44-3
no fix listed

Open the chart page →

12,131
rspamdklicktippVerified publisher1.6.01 of 1See more

rspamd klicktipp 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
rspamd/rspamd:4.1.4e870599c970d
binutils@2.44-3
no fix listed

Open the chart page →

1,788
kubeflowkromanow94-kubeflow0.5.12 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

2 of the 30 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
library/python:3.7eedf63967cdb
binutils@2.40-2
no fix listed
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
binutils@2.40-2
no fix listed

Open the chart page →

68,994
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-90803.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
binutils@2.44-3
no fix listed

Open the chart page →

9,652

Container images carrying it

236 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/phpmyadmin:5.2.3-apache:latest3a8a8d6b5289
binutils@2.44-3
no fix listed
7
library/wordpress:7.1.0-apache:latest5a93c470ae82
binutils@2.44-3
no fix listed
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
binutils@2.40-2
no fix listed
6
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
binutils@2.40-2
no fix listed
4
library/node:ltsbe23f54a88d3
binutils@2.40-2
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
binutils@2.40-2
no fix listed
3
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
binutils@2.40-2
no fix listed
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
binutils@2.44-3
no fix listed
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
binutils@2.44-3
no fix listed
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
binutils@2.40-2
no fix listed
2
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
binutils@2.44-3
no fix listed
2
library/phpmyadmin:5.2.16e75aa8f767c
binutils@2.40-2
no fix listed
2
library/python:3.7eedf63967cdb
binutils@2.40-2
no fix listed
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
binutils@2.44-3
no fix listed
2
localstack/localstack-pro:latest4aef81c53168
binutils@2.44-3
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
binutils@2.40-2
no fix listed
2
polyaxon/polyaxon-agent:2.16.4eca6952b20e6
binutils@2.44-3
no fix listed
2
polyaxon/polyaxon-cli:2.16.4024ff3fa775e
binutils@2.44-3
no fix listed
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
binutils@2.40-2
no fix listed
2
uffizzi/controller:latest0344805f267b
binutils@2.40-2
no fix listed
2
vdiogov/glpi-conteiner:latest6945f84f0058
binutils@2.40-2
no fix listed
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
binutils@2.40-2
no fix listed
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
binutils@2.40-2
no fix listed
2
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
binutils@2.44-3
no fix listed
1
aboogie/login_test_backend:new9c41a4483ac8
binutils@2.40-2
no fix listed
1
adamzammit/limesurvey:7.1.0f48962e1528c
binutils@2.44-3
no fix listed
1
akaunting/akaunting:3.0.1552811b36ec3a
binutils@2.40-2
no fix listed
1
allegroai/clearml:2.0.0-613713ae38f7daf
binutils@2.40-2
no fix listed
1
apache/superset:4.0.1ab9467fd712c
binutils@2.40-2
no fix listed
1
aristidetm/basic-notebook:3.6.5469dbc951224
binutils@2.40-2
no fix listed
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
binutils@2.40-2
no fix listed
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
binutils@2.40-2
no fix listed
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
binutils@2.40-2
no fix listed
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
binutils@2.40-2
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
binutils@2.40-2
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
binutils@2.40-2
no fix listed
1
baserow/backend:1.31.1e0b3c8130b91
binutils@2.40-2
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
binutils@2.40-2
no fix listed
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
binutils@2.44-3
no fix listed
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
binutils@2.44-3
no fix listed
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
binutils@2.40-2
no fix listed
1
bitnamilegacy/mysql:8.4.5-debian-12-r07089d796fc9b
binutils@2.40-2
no fix listed
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
binutils@2.40-2
no fix listed
1
bmeares/meerschaum:2.8.48e9c5bacaa82
binutils@2.40-2
no fix listed
1
bnjbvr/kresus:0.22.137e216b182c8
binutils@2.40-2
no fix listed
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
binutils@2.40-2
no fix listed
1
castopod/castopod:1.12.101fd37280cbb2
binutils@2.40-2
no fix listed
1
castopod/castopod:1.15.54e4f0440520f
binutils@2.44-3
no fix listed
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
binutils@2.44-3
no fix listed
1
chocobozzz/peertube:v8.1.5052712130691
binutils@2.44-3
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.