StackRadar

CVE-2026-93522

Medium

Advisory

Published 7 Oct 2026In the index since 9 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
24
of 18,071 indexed, latest versions
Container images
24
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 24 of 18,071 indexed charts deploy, on 24 images.

Affected packageAffected versionsFixed inImages
xorg-serverdeb2:1.18.4-0ubuntu0.7, 2:1.19.6-1ubuntu4.3, 2:1.19.6-1ubuntu4.9, 2:1.19.6-1ubuntu4.10+12 moreno fix listed24
OSV records
UBUNTU-CVE-2026-93522

Charts affected

24 by stars
ChartLatestAffected imagesRadar Score
openclawopenclawVerified publisher1.108.11 of 2See more

openclaw openclaw 1.108.1

1 of the 2 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.57.06bac628b3d82
xorg-server@2:21.1.22-1ubuntu1.2
no fix listed

Open the chart page →

2,985
selenium-gridselenium-grid0.59.12 of 4See more

selenium-grid selenium-grid 0.59.1

2 of the 4 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
selenium/node-chrome:4.48.0-202609055ac71fd8dd1e
xorg-server@2:21.1.12-1ubuntu1.6
no fix listed
selenium/node-firefox:4.48.0-2026090574a5c1c90f95
xorg-server@2:21.1.12-1ubuntu1.6
no fix listed

Open the chart page →

9,189
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
xorg-server@2:21.1.12-1ubuntu1.6
no fix listed

Open the chart page →

11,972
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
xorg-server@2:1.20.11-1ubuntu1~20.04.2
no fix listed

Open the chart page →

102,701
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
xorg-server@2:1.19.6-1ubuntu4.9
no fix listed

Open the chart page →

24,343
napcatredish101Verified publisher0.1.31 of 1See more

napcat redish101 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
mlikiowa/napcat-docker:latest2cc70b45244a
xorg-server@2:21.1.4-2ubuntu1.7~22.04.12
no fix listed

Open the chart page →

71,378
browserlessalekcVerified publisher1.3.01 of 1See more

browserless alekc 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
ghcr.io/browserless/chrome:v2.57.0f4fcb054396a
xorg-server@2:21.1.22-1ubuntu1.2
no fix listed

Open the chart page →

1,312
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
xorg-server@2:1.18.4-0ubuntu0.7
no fix listed

Open the chart page →

137,288
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
xorg-server@2:1.20.13-1ubuntu1~20.04.20
no fix listed

Open the chart page →

119,130
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
xorg-server@2:1.20.13-1ubuntu1~20.04.3
no fix listed

Open the chart page →

29,572
openaevhelm-openbasVerified publisher2.0.111 of 7See more

openaev helm-openbas 2.0.11

1 of the 7 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
openaev/platform:3.261005.0eaf26c4106a1
xorg-server@2:21.1.12-1ubuntu1.8
no fix listed

Open the chart page →

21,338
browserlessicoretechVerified publisher0.18.11 of 1See more

browserless icoretech 0.18.1

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.57.06bac628b3d82
xorg-server@2:21.1.22-1ubuntu1.2
no fix listed

Open the chart page →

1,239
audacitynicholaswildeVerified publisher0.1.41 of 1See more

audacity nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/audacity:version-3.0.2cdf203db1e50
xorg-server@2:1.20.9-2ubuntu1.2~20.04.2
no fix listed

Open the chart page →

24,476
digikamnicholaswildeVerified publisher1.0.01 of 1See more

digikam nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
xorg-server@2:1.19.6-1ubuntu4.9
no fix listed

Open the chart page →

26,604
doublecommandernicholaswildeVerified publisher1.0.21 of 1See more

doublecommander nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
xorg-server@2:1.19.6-1ubuntu4.9
no fix listed

Open the chart page →

27,771
remminanicholaswildeVerified publisher0.1.41 of 1See more

remmina nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
xorg-server@2:1.19.6-1ubuntu4.10
no fix listed

Open the chart page →

24,481
sqlitebrowsernicholaswildeVerified publisher1.0.11 of 1See more

sqlitebrowser nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
xorg-server@2:1.19.6-1ubuntu4.10
no fix listed

Open the chart page →

25,824
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
xorg-server@2:1.19.6-1ubuntu4.3
no fix listed

Open the chart page →

95,859
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
xorg-server@2:1.20.13-1ubuntu1~20.04.2
no fix listed

Open the chart page →

16,596
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
xorg-server@2:21.1.12-1ubuntu1.5
no fix listed

Open the chart page →

7,298
suwayomirubxkubeVerified publisher0.1.21 of 1See more

suwayomi rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
xorg-server@2:21.1.12-1ubuntu1.6
no fix listed

Open the chart page →

2,165
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
xorg-server@2:21.1.4-2ubuntu1.7~22.04.16
no fix listed

Open the chart page →

8,525
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
xorg-server@2:21.1.12-1ubuntu1.5
no fix listed

Open the chart page →

5,353
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-93522.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
xorg-server@2:21.1.4-2ubuntu1.7~22.04.10
no fix listed

Open the chart page →

15,868

Container images carrying it

24 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/browserless/chromium:v2.57.06bac628b3d82
xorg-server@2:21.1.22-1ubuntu1.2
no fix listed
2
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
xorg-server@2:1.20.11-1ubuntu1~20.04.2
no fix listed
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
xorg-server@2:1.20.13-1ubuntu1~20.04.20
no fix listed
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
xorg-server@2:1.19.6-1ubuntu4.9
no fix listed
1
mlikiowa/napcat-docker:latest2cc70b45244a
xorg-server@2:21.1.4-2ubuntu1.7~22.04.12
no fix listed
1
openaev/platform:3.261005.0eaf26c4106a1
xorg-server@2:21.1.12-1ubuntu1.8
no fix listed
1
openkm/openkm-ce:6.3.113bc465a7461b
xorg-server@2:1.20.13-1ubuntu1~20.04.3
no fix listed
1
project2team4/react:latest3ff031a08887
xorg-server@2:1.20.13-1ubuntu1~20.04.2
no fix listed
1
scrapinghub/splash:3.4.1a5f89bc84606
xorg-server@2:1.19.6-1ubuntu4.3
no fix listed
1
selenium/node-chrome:4.48.0-202609055ac71fd8dd1e
xorg-server@2:21.1.12-1ubuntu1.6
no fix listed
1
selenium/node-firefox:4.48.0-2026090574a5c1c90f95
xorg-server@2:21.1.12-1ubuntu1.6
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
xorg-server@2:1.18.4-0ubuntu0.7
no fix listed
1
trueosiris/vrising:latest9356f98ad561
xorg-server@2:21.1.4-2ubuntu1.7~22.04.16
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
xorg-server@2:21.1.4-2ubuntu1.7~22.04.10
no fix listed
1
ghcr.io/browserless/chrome:v2.57.0f4fcb054396a
xorg-server@2:21.1.22-1ubuntu1.2
no fix listed
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
xorg-server@2:21.1.12-1ubuntu1.6
no fix listed
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
xorg-server@2:21.1.12-1ubuntu1.5
no fix listed
1
ghcr.io/linuxserver/audacity:version-3.0.2cdf203db1e50
xorg-server@2:1.20.9-2ubuntu1.2~20.04.2
no fix listed
1
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
xorg-server@2:1.19.6-1ubuntu4.9
no fix listed
1
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
xorg-server@2:1.19.6-1ubuntu4.9
no fix listed
1
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
xorg-server@2:1.19.6-1ubuntu4.10
no fix listed
1
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
xorg-server@2:1.19.6-1ubuntu4.10
no fix listed
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
xorg-server@2:21.1.12-1ubuntu1.5
no fix listed
1
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
xorg-server@2:21.1.12-1ubuntu1.6
no fix listed
1

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.