StackRadar

CVE-2026-91187

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,162
of 17,844 indexed, latest versions
Container images
1,073
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,162 of 17,844 indexed charts deploy, on 1,073 images.

Affected packageAffected versionsFixed inImages
dashdeb0.5.7-4ubuntu1, 0.5.8-2.1ubuntu2, 0.5.8-2.10, 0.5.10.2-6+3 moreno fix listed1,073
OSV records
UBUNTU-CVE-2026-91187
Trending
Rank 11 in indexed charts, since 25 Sept 2026. See the ranking →

Charts affected

1,162 by stars
ChartLatestAffected imagesRadar Score
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed

Open the chart page →

9,589
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
dash@0.5.10.2-6
no fix listed

Open the chart page →

6,651
wordpress-alpinewordpress-alpine1.5.181 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

1 of the 6 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
library/mariadb:12.3.2628f228f0fd5
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

4,402
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
library/mariadb:lts805c8e104bd5
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

4,866
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed

Open the chart page →

14,813
am-pattern-1wso22.6.0-72 of 6See more

am-pattern-1 wso2 2.6.0-7

2 of the 6 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
wso2/wso2am:2.6.0fbe0f4059b74
dash@0.5.10.2-6
no fix listed
wso2/wso2am-analytics-worker:2.6.005fa15b3d927
dash@0.5.8-2.10
no fix listed

Open the chart page →

32,045
ei-pattern-1wso26.6.0-33 of 6See more

ei-pattern-1 wso2 6.6.0-3

3 of the 6 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
wso2/wso2ei-analytics-dashboard:6.6.0526a1ccae902
dash@0.5.8-2.10
no fix listed
wso2/wso2ei-analytics-worker:6.6.021e6b03449ac
dash@0.5.8-2.10
no fix listed
wso2/wso2ei-integrator:6.6.0790cd8c3a5a2
dash@0.5.8-2.10
no fix listed

Open the chart page →

50,773
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

13,929
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

2,266
nightingalexxl-job-adminVerified publisher0.2.111 of 6See more

nightingale xxl-job-admin 0.2.11

1 of the 6 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

10,103
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
dash@0.5.8-2.10
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
dash@0.5.10.2-6
no fix listed

Open the chart page →

9,537
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed

Open the chart page →

8,360

Container images carrying it

1,073 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apachepulsar/pulsar:2.9.0d056c89b7131
dash@0.5.10.2-6
no fix listed
1
apache/ranger:2.7.076c176e8a0e4
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
apache/rocketmq:5.3.0434d8398f996
dash@0.5.12-6ubuntu5
no fix listed
1
apache/rocketmq-exporter:0.0.2c8fb51195444
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
apache/skywalking-oap-server:9.2.0133d35d2c263
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
dash@0.5.10.2-6
no fix listed
1
apache/skywalking-ui:9.2.0295f1dc87d98
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
apache/skywalking-ui:8.9.180530f0308a5
dash@0.5.10.2-6
no fix listed
1
apache/tika:latest-full80072bb73dd3
dash@0.5.12-12ubuntu3
no fix listed
1
apache/tika:3.3.1.090b7fa1dc018
dash@0.5.12-12ubuntu3
no fix listed
1
arilot/docker-bitcoind:0.17.127a4f7e0f9f1
dash@0.5.8-2.1ubuntu2
no fix listed
1
arunvelsriram/utils:latest655ad18fd8d6
dash@0.5.12-6ubuntu5
no fix listed
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
dash@0.5.10.2-6
no fix listed
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
dash@0.5.10.2-6
no fix listed
1
assistiot/location_processing:lateste9bae124095f
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
assistiot/open_api_backend:1.1.230812ba93555
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
dash@0.5.10.2-6
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
dash@0.5.10.2-6
no fix listed
1
atlassian/bamboo:12.1.119160c3bfb73b
dash@0.5.12-6ubuntu5
no fix listed
1
atlassian/bamboo-agent-base:12.1.1151c2d7274eef
dash@0.5.12-6ubuntu5
no fix listed
1
atlassian/bitbucket:10.2.705933f2b1cfd
dash@0.5.12-6ubuntu5
no fix listed
1
atlassian/confluence-server:7.10.03b9222ab32ef
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
atlassian/crowd:7.2.351e6d33676f6
dash@0.5.12-6ubuntu5
no fix listed
1
atlassian/crowd:5.2.2708162b8c094
dash@0.5.12-6ubuntu5
no fix listed
1
atlassian/jira-software:8.14.037bc46cbec1a
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
atlassian/jira-software:11.3.114046f4a668a4
dash@0.5.12-6ubuntu5
no fix listed
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
dash@0.5.10.2-6
no fix listed
1
bcgovimages/aries-cloudagent:py36-1.16-1_0.7.4faa2e2d21916
dash@0.5.8-2.10
no fix listed
1
beanbag/reviewboard:latest6b840f546e1c
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
dash@0.5.10.2-6
no fix listed
1
bicarus/mx-notifier:1.1.8bed688d16762
dash@0.5.10.2-6
no fix listed
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
dash@0.5.10.2-6
no fix listed
1
boxcutter/meshcmd:1.1.384e13f01bcab
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
dash@0.5.10.2-6
no fix listed
1
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
dash@0.5.12-6ubuntu5
no fix listed
1
camptocamp/mapserver:master5f9ddd0b9c5b
dash@0.5.12-12ubuntu3
no fix listed
1
camptocamp/mapserver:latest98e908c81ff8
dash@0.5.12-6ubuntu5
no fix listed
1
camunda/zeebe:8.4.5ab5abc09e407
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
castlemock/castlemock:latestb7f3f1527ba9
dash@0.5.12-6ubuntu5
no fix listed
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
dash@0.5.12-6ubuntu5
no fix listed
1
ceresdb/ceresdb-server:v1.0.053b2d0dbba1f
dash@0.5.10.2-6
no fix listed
1
chaerr/kridge:demo-operator-v0.1.266833deec017
dash@0.5.10.2-6
no fix listed
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
dash@0.5.7-4ubuntu1
no fix listed
1
chetangautamm/repo:sipp.v3e7f7049e1544
dash@0.5.10.2-6
no fix listed
1
cheveo/azp-agent:1.0.282240f890884
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
cheyang/distributed-tf:1.6.046cc34755493
dash@0.5.8-2.1ubuntu2
no fix listed
1
chriseaton/adventureworks:latest54c3384ce701
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
circleci/runner:launch-agent9bdc62f02162
dash@0.5.10.2-6
no fix listed
1
ciscolabs/msm-nc:0710202336d02faad958
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.