StackRadar

CVE-2026-91187

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,162
of 17,844 indexed, latest versions
Container images
1,073
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,162 of 17,844 indexed charts deploy, on 1,073 images.

Affected packageAffected versionsFixed inImages
dashdeb0.5.7-4ubuntu1, 0.5.8-2.1ubuntu2, 0.5.8-2.10, 0.5.10.2-6+3 moreno fix listed1,073
OSV records
UBUNTU-CVE-2026-91187
Trending
Rank 11 in indexed charts, since 25 Sept 2026. See the ranking →

Charts affected

1,162 by stars
ChartLatestAffected imagesRadar Score
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed

Open the chart page →

9,589
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
dash@0.5.10.2-6
no fix listed

Open the chart page →

6,651
wordpress-alpinewordpress-alpine1.5.181 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

1 of the 6 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
library/mariadb:12.3.2628f228f0fd5
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

4,402
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
library/mariadb:lts805c8e104bd5
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

4,866
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed

Open the chart page →

14,813
am-pattern-1wso22.6.0-72 of 6See more

am-pattern-1 wso2 2.6.0-7

2 of the 6 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
wso2/wso2am:2.6.0fbe0f4059b74
dash@0.5.10.2-6
no fix listed
wso2/wso2am-analytics-worker:2.6.005fa15b3d927
dash@0.5.8-2.10
no fix listed

Open the chart page →

32,045
ei-pattern-1wso26.6.0-33 of 6See more

ei-pattern-1 wso2 6.6.0-3

3 of the 6 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
wso2/wso2ei-analytics-dashboard:6.6.0526a1ccae902
dash@0.5.8-2.10
no fix listed
wso2/wso2ei-analytics-worker:6.6.021e6b03449ac
dash@0.5.8-2.10
no fix listed
wso2/wso2ei-integrator:6.6.0790cd8c3a5a2
dash@0.5.8-2.10
no fix listed

Open the chart page →

50,773
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

13,929
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

2,266
nightingalexxl-job-adminVerified publisher0.2.111 of 6See more

nightingale xxl-job-admin 0.2.11

1 of the 6 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

10,103
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
dash@0.5.8-2.10
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
dash@0.5.10.2-6
no fix listed

Open the chart page →

9,537
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-91187.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed

Open the chart page →

8,360

Container images carrying it

1,073 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
dellcloud/pages:monitor6ba7b22caacd
dash@0.5.10.2-6
no fix listed
80
flyway/flyway:6.4.422d97ceb0c47
dash@0.5.8-2.10
no fix listed
80
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
dash@0.5.8-2.10
no fix listed
13
library/mongo:8:8.3.11:latest5d7043a4ffe0
dash@0.5.12-6ubuntu5
no fix listed
12
oomk8s/readiness-check:2.0.2875814cc853d
dash@0.5.8-2.1ubuntu2
no fix listed
11
library/mongo:5.0.6-focal8e70544b6c76
dash@0.5.10.2-6
no fix listed
10
library/rabbitmq:3.9-management8a279e9396a8
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
10
library/kong:3.6a42d2b4503e7
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
8
library/mariadb:13.0.2:latestd4fdec0510ad
dash@0.5.12-12ubuntu3
no fix listed
8
library/rabbitmq:3.13-management:3-managemente582c0bc7766
dash@0.5.12-6ubuntu5
no fix listed
8
library/kong:3.9:latest12972ce1ab63
dash@0.5.12-6ubuntu5
no fix listed
7
library/mariadb:10:10.117f22313fc130
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
6
library/ubuntu:latestda6fc2be5478
dash@0.5.12-12ubuntu3
no fix listed
6
oomk8s/readiness-check:2.0.07daa08b81954
dash@0.5.8-2.1ubuntu2
no fix listed
6
library/mariadb:12.3.3:lts805c8e104bd5
dash@0.5.12-6ubuntu5
no fix listed
5
library/mongo:4.44be76f674fc4
dash@0.5.10.2-6
no fix listed
5
solsson/kafka:latest41e5d8f6f290
dash@0.5.10.2-6
no fix listed
5
hyperledger/fabric-ca:latesta70b6ba64a08
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
4
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
dash@0.5.8-2.1ubuntu2
no fix listed
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
dash@0.5.8-2.1ubuntu2
no fix listed
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
4
library/mongo:5.0-focal5e15a3f014ed
dash@0.5.10.2-6
no fix listed
4
library/mongo:4.2.12-bionic628741415fc9
dash@0.5.8-2.10
no fix listed
4
library/mongo:4.4.66efa05203990
dash@0.5.8-2.10
no fix listed
4
library/rabbitmq:3.11-managementc3f70098e01d
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
4
mastercloudapps/planner:v1.2340a950b311b2
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
dash@0.5.8-2.10
no fix listed
4
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
4
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
dash@0.5.12-12ubuntu3
no fix listed
4
ciscolabs/rtsp-client:latesta7b60ec88285
dash@0.5.10.2-6
no fix listed
3
ciscolabs/rtsp-server:latestb59fc10bb821
dash@0.5.10.2-6
no fix listed
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
dash@0.5.10.2-6
no fix listed
3
codeurjc/planner:v1.0800cf520c245
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
3
dgraph/dgraph:v21.12.03b55ea83fffe
dash@0.5.10.2-6
no fix listed
3
envoyproxy/envoy:v1.31.02bf7f042e396
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
3
istio/kubectl:1.5.10dbb7726d1bf0
dash@0.5.8-2.10
no fix listed
3
jacobalberty/unifi:v10.0.162896c0ab82d33
dash@0.5.10.2-6
no fix listed
3
library/ubuntu:24.04008173c23f95
dash@0.5.12-6ubuntu5
no fix listed
3
library/zookeeper:3.9.57d0f24ebb67b
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
3
linuxserver/plex:1.43.4:latest1f6f97d76e7b
dash@0.5.12-12ubuntu3
no fix listed
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
dash@0.5.8-2.1ubuntu2
no fix listed
3
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
3
openebs/node-disk-operator:2.1.06afe2123c457
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
3
sigp/lighthouse:latest-amd6450f66cfebb6d
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
3
xenondb/percona:5.7.330e26872a2b67
dash@0.5.10.2-6
no fix listed
3
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
dash@0.5.12-6ubuntu5
no fix listed
3
ghcr.io/tremolosecurity/kube-oidc-proxy:1.0.13a89736c586ba
dash@0.5.12-6ubuntu5
no fix listed
3
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.74.6_local:latest8b9208c09d76
dash@0.5.12-12ubuntu3
no fix listed
3
quay.io/cilium/cilium:v1.20.22939231d0d3e
dash@0.5.12-12ubuntu3
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
3

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.