StackRadar

CVE-2026-91187

Critical

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Critical
worst across findings
CVSS
9.3
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,255
of 17,879 indexed, latest versions
Container images
1,187
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,255 of 17,879 indexed charts deploy, on 1,187 images.

Affected packageAffected versionsFixed inImages
dashdeb0.5.7-4ubuntu1, 0.5.8-2.1ubuntu2, 0.5.8-2.10, 0.5.10.2-6+3 moreno fix listed1,187
OSV records
UBUNTU-CVE-2026-91187
Trending
Rank 1 in indexed charts, since 25 Sept 2026. See the ranking →

Charts affected

1,255 by stars
ChartLatestAffected imagesRadar Score
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

13,942
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

2,284
nightingalexxl-job-adminVerified publisher0.2.111 of 6See more

nightingale xxl-job-admin 0.2.11

1 of the 6 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

10,111
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
dash@0.5.8-2.10
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
dash@0.5.10.2-6
no fix listed

Open the chart page →

9,550
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed

Open the chart page →

8,389

Container images carrying it

1,187 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
boxcutter/meshcmd:1.1.384e13f01bcab
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
dash@0.5.10.2-6
no fix listed
1
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
dash@0.5.12-6ubuntu5
no fix listed
1
camptocamp/mapserver:master5f9ddd0b9c5b
dash@0.5.12-12ubuntu3
no fix listed
1
camptocamp/mapserver:latest98e908c81ff8
dash@0.5.12-6ubuntu5
no fix listed
1
camunda/zeebe:8.4.5ab5abc09e407
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
castlemock/castlemock:latestb7f3f1527ba9
dash@0.5.12-6ubuntu5
no fix listed
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
dash@0.5.12-6ubuntu5
no fix listed
1
ceresdb/ceresdb-server:v1.0.053b2d0dbba1f
dash@0.5.10.2-6
no fix listed
1
chaerr/kridge:demo-operator-v0.1.266833deec017
dash@0.5.10.2-6
no fix listed
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
dash@0.5.7-4ubuntu1
no fix listed
1
chetangautamm/repo:sipp.v3e7f7049e1544
dash@0.5.10.2-6
no fix listed
1
cheveo/azp-agent:1.0.282240f890884
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
cheyang/distributed-tf:1.6.046cc34755493
dash@0.5.8-2.1ubuntu2
no fix listed
1
chriseaton/adventureworks:latest54c3384ce701
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
circleci/runner:launch-agent9bdc62f02162
dash@0.5.10.2-6
no fix listed
1
ciscolabs/msm-nc:0710202336d02faad958
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
citizenstig/httpbin:latestb81c818ccb86
dash@0.5.8-2.1ubuntu2
no fix listed
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
clickhouse/clickhouse-server:24.81ffa82edee00
dash@0.5.10.2-6
no fix listed
1
clickhouse/clickhouse-server:24.4.12e6587b81a26
dash@0.5.10.2-6
no fix listed
1
clickhouse/clickhouse-server:latest42acb460c63b
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
clickhouse/clickhouse-server:23.8512bb8a21483
dash@0.5.10.2-6
no fix listed
1
clickhouse/clickhouse-server:26.3810861a2e2d0
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
clickhouse/clickhouse-server:26.584d05b9c205e
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
clickhouse/clickhouse-server:25.3.2.398745843b17f9
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
clickhouse/clickhouse-server:26.3.1092098d3b31dd
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
clickhouse/clickhouse-server:24.12.6a65ca89ddbe8
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
clickhouse/clickhouse-server:latesta73b5c0fb6f8
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
clickhouse/clickhouse-server:25.3.14.14b627d7a9bc0e
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
clickhouse/clickhouse-server:26.8.3d73903d1b61d
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
clickhouse/clickhouse-server:26.7fe3b5cd5c231
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
cloudve/janis-terminal:latestaf56e77ca587
dash@0.5.8-2.10
no fix listed
1
cloudve/ttyd:latestd79c1c5881c0
dash@0.5.8-2.10
no fix listed
1
consensys/teku:latest6bfef491dc27
dash@0.5.12-6ubuntu5
no fix listed
1
consensys/teku:25.4.1bf6ecd2ea716
dash@0.5.12-6ubuntu5
no fix listed
1
consensys/web3signer:latestf146a51a1ba3
dash@0.5.12-12ubuntu3
no fix listed
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
cortezaproject/corteza:2024.9.08eb7a26605c9
dash@0.5.10.2-6
no fix listed
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
dash@0.5.10.2-6
no fix listed
1
cradlepoint/pgbouncer:1.0.18f5720b0cd03
dash@0.5.8-2.10
no fix listed
1
cribl/cribl:3.0.2762747cb6796
dash@0.5.8-2.10
no fix listed
1
curtismager20/mcp-orchestrator:3.9.189ba6fda586b2
dash@0.5.12-6ubuntu5
no fix listed
1
cyverse/irods-csi-driver:v0.12.0aa69d105b292
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
daedalusproject/base_kubectl:latest6f72b5119eda
dash@0.5.10.2-6
no fix listed
1
darthsim/imgproxy:v3.30.13b709e4a0e5e
dash@0.5.12-6ubuntu5
no fix listed
1

syft 1.42.1 · advisories as of 26 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.