StackRadar

CVE-2026-91187

Critical

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Critical
worst across findings
CVSS
9.3
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,255
of 17,879 indexed, latest versions
Container images
1,187
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,255 of 17,879 indexed charts deploy, on 1,187 images.

Affected packageAffected versionsFixed inImages
dashdeb0.5.7-4ubuntu1, 0.5.8-2.1ubuntu2, 0.5.8-2.10, 0.5.10.2-6+3 moreno fix listed1,187
OSV records
UBUNTU-CVE-2026-91187
Trending
Rank 1 in indexed charts, since 25 Sept 2026. See the ranking →

Charts affected

1,255 by stars
ChartLatestAffected imagesRadar Score
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

13,942
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

2,284
nightingalexxl-job-adminVerified publisher0.2.111 of 6See more

nightingale xxl-job-admin 0.2.11

1 of the 6 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

10,111
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
dash@0.5.8-2.10
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
dash@0.5.10.2-6
no fix listed

Open the chart page →

9,550
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed

Open the chart page →

8,389

Container images carrying it

1,187 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
dash@0.5.12-12ubuntu3
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.4_local5bda14f66e8e
dash@0.5.12-12ubuntu3
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
dash@0.5.12-6ubuntu5
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
dash@0.5.12-6ubuntu5
no fix listed
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
dash@0.5.12-12ubuntu3
no fix listed
1
public.ecr.aws/aktosecurity/akto-threat-detection:latesta728eb2eaf06
dash@0.5.12-12ubuntu3
no fix listed
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
dash@0.5.12-6ubuntu5
no fix listed
1
public.ecr.aws/datadog/cloudprem:v0.1.341cb9c5446621
dash@0.5.12-6ubuntu5
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
dash@0.5.12-6ubuntu5
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
dash@0.5.8-2.10
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
dash@0.5.10.2-6
no fix listed
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
quay.io/aerokube/keygen:1.0.1578934444f04
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
dash@0.5.12-12ubuntu3
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
quay.io/argoproj/argocd:v2.10.783c86003b781
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
dash@0.5.12-6ubuntu5
no fix listed
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
dash@0.5.12-6ubuntu5
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
dash@0.5.12-6ubuntu5
no fix listed
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
dash@0.5.12-6ubuntu5
no fix listed
1
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
dash@0.5.12-6ubuntu5
no fix listed
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
dash@0.5.12-6ubuntu5
no fix listed
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
dash@0.5.8-2.10
no fix listed
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
quay.io/go-skynet/local-ai:latest0632c21ddbe4
dash@0.5.12-6ubuntu5
no fix listed
1
quay.io/isindir/sops-secrets-operator:0.21.27bba7083dfa0
dash@0.5.12-12ubuntu3
no fix listed
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
dash@0.5.8-2.1ubuntu2
no fix listed
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
dash@0.5.12-6ubuntu5
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
dash@0.5.8-2.1ubuntu2
no fix listed
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
dash@0.5.12-12ubuntu3
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
dash@0.5.12-6ubuntu5
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
dash@0.5.12-12ubuntu3
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
dash@0.5.10.2-6
no fix listed
1

syft 1.42.1 · advisories as of 26 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.