StackRadar

CVE-2026-94285

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
5.1
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
528
of 17,939 indexed, latest versions
Container images
408
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 528 of 17,939 indexed charts deploy, on 408 images.

Affected packageAffected versionsFixed inImages
libx11deb2:1.8.4-2, 2:1.8.4-2+deb12u1, 2:1.8.4-2+deb12u2, 2:1.8.12-1+1 moreno fix listed408
OSV records
DEBIAN-CVE-2026-94285

Charts affected

528 by stars
ChartLatestAffected imagesRadar Score
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

5,054
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

5,323
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

5,539
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

10,240
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

5,733
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

4,192
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

10,859
voyagertibuntu1.2.01 of 1See more

voyager tibuntu 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
ghcr.io/aeharding/voyager:latest8e9d9ed499e3
libx11@2:1.8.12-1
no fix listed

Open the chart page →

2,087
test0tohlejezkouska0.1.01 of 2See more

test0 tohlejezkouska 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libx11@2:1.8.12-1
no fix listed

Open the chart page →

3,159
pr-previewtrainyard-pr-previewVerified publisher1.1.11 of 1See more

pr-preview trainyard-pr-preview 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,686
trident-protect-consoletrident-protect100.2609.0-console1 of 3See more

trident-protect-console trident-protect 100.2609.0-console

1 of the 3 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v3.0.0cad26cd945d1
libx11@2:1.8.12-1
no fix listed

Open the chart page →

6,240
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

18,061
applicationuniversal-helm-chartVerified publisher0.4.51 of 1See more

application universal-helm-chart 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,686
unlaunla0.10.01 of 3See more

unla unla 0.10.0

1 of the 3 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
ghcr.io/amoylab/unla/web:latesteac1df1c5e66
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

9,279
opencloudunxwaresVerified publisher0.2.36 of 13See more

opencloud unxwares 0.2.3

6 of the 13 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
libx11@2:1.8.4-2+deb12u2
no fix listed
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
libx11@2:1.8.4-2+deb12u2
no fix listed
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
libx11@2:1.8.4-2+deb12u2
no fix listed
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
libx11@2:1.8.4-2+deb12u2
no fix listed
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
libx11@2:1.8.4-2+deb12u2
no fix listed
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

46,329
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libx11@2:1.8.4-2+deb12u1
no fix listed

Open the chart page →

15,061
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

11,466
argus-test-envvk-helm-charts2.0.01 of 1See more

argus-test-env vk-helm-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,686
juicefs-csi-driverwener0.33.01 of 5See more

juicefs-csi-driver wener 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

9,369
juicefs-csi-driverwenerme0.33.01 of 5See more

juicefs-csi-driver wenerme 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

9,369
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
library/wordpress:latest8746e7e072e3
libx11@2:1.8.12-1
no fix listed

Open the chart page →

4,872
wordpresswordpress-ng1.0.101 of 2See more

wordpress wordpress-ng 1.0.10

1 of the 2 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
cloudtooling/wordpress:7.1.20b390e7e3425
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

4,061
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

7,949
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,686
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
library/nginx:stableb972f831f200
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,686
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

2,871
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libx11@2:1.8.12-1
no fix listed

Open the chart page →

1,686
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-94285.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
libx11@2:1.8.4-2+deb12u2
no fix listed

Open the chart page →

4,879

Container images carrying it

408 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/nginx:1.31:latest:mainline:trixieabe47724e466
libx11@2:1.8.12-1
no fix listed
108
library/nginx:stable0aa2d81d65bc
libx11@2:1.8.12-1
no fix listed
12
library/nginx:stableb972f831f200
libx11@2:1.8.12-1
no fix listed
11
jellyfin/jellyfin:10.11:10.11.11:latestaefb67e6a7ff
libx11@2:1.8.12-1
no fix listed
6
library/phpmyadmin:5.2.3-apache:latest9e915766488a
libx11@2:1.8.12-1
no fix listed
6
flaresolverr/flaresolverr:latest:v3.5.0139dfee1c6f8
libx11@2:1.8.4-2+deb12u2
no fix listed
4
library/nginx:1.27.1287ff321f9e3
libx11@2:1.8.4-2+deb12u2
no fix listed
4
opea/llm-tgi:1.00c25aab3f106
libx11@2:1.8.4-2+deb12u2
no fix listed
4
ghcr.io/flaresolverr/flaresolverr:latest:v3.5.2c80ae007ce2c
libx11@2:1.8.4-2+deb12u2
no fix listed
4
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
libx11@2:1.8.12-1
no fix listed
4
library/nginx:1.25:1.25.5a484819eb602
libx11@2:1.8.4-2+deb12u2
no fix listed
3
library/node:lts64af3819f927
libx11@2:1.8.4-2+deb12u2
no fix listed
3
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
libx11@2:1.8.4-2+deb12u2
no fix listed
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
libx11@2:1.8.4-2
no fix listed
3
ghcr.io/paperless-ngx/paperless-ngx:3.2.15fa76604a81d
libx11@2:1.8.12-1
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
libx11@2:1.8.4-2+deb12u2
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
libx11@2:1.8.4-2+deb12u2
no fix listed
3
freikin/dawarich:1.15.2e58334ca5697
libx11@2:1.8.12-1
no fix listed
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
libx11@2:1.8.4-2
no fix listed
2
gotenberg/gotenberg:8.36.087c16b9f3642
libx11@2:1.8.12-1
no fix listed
2
gotenberg/gotenberg:8:8.37.0f29984bd1e22
libx11@2:1.8.12-1
no fix listed
2
graviteeio/apim-gateway:4.12.20-debian8f1a14449381
libx11@2:1.8.12-1
no fix listed
2
graviteeio/apim-management-api:4.12.20-debiand30d085395ca
libx11@2:1.8.12-1
no fix listed
2
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
libx11@2:1.8.4-2+deb12u2
no fix listed
2
library/nginx:latest6e23479198b9
libx11@2:1.8.12-1
no fix listed
2
library/nginx:1.27.098f8ec75657d
libx11@2:1.8.4-2+deb12u2
no fix listed
2
library/nginx:1.29.49dd288848f44
libx11@2:1.8.12-1
no fix listed
2
library/python:3.7eedf63967cdb
libx11@2:1.8.4-2+deb12u1
no fix listed
2
library/redmine:6.1.3-trixief474a901faec
libx11@2:1.8.12-1
no fix listed
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
libx11@2:1.8.12-1
no fix listed
2
library/wordpress:latest8746e7e072e3
libx11@2:1.8.12-1
no fix listed
2
library/wordpress:latesta85a30d9e752
libx11@2:1.8.12-1
no fix listed
2
louislam/uptime-kuma:2.5.4917318f9d7be
libx11@2:1.8.4-2+deb12u2
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
libx11@2:1.8.4-2+deb12u2
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
libx11@2:1.8.4-2+deb12u2
no fix listed
2
louislam/uptime-kuma:2.5.5c74379ac4509
libx11@2:1.8.4-2+deb12u2
no fix listed
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
libx11@2:1.8.4-2+deb12u2
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
libx11@2:1.8.4-2+deb12u2
no fix listed
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
libx11@2:1.8.4-2+deb12u2
no fix listed
2
nginxinc/nginx-unprivileged:stable0918d093d608
libx11@2:1.8.12-1
no fix listed
2
nousresearch/hermes-agent:v2026.9.24fca358f12efd
libx11@2:1.8.12-1
no fix listed
2
opea/embedding-tei:1.05c9639de61c1
libx11@2:1.8.4-2+deb12u2
no fix listed
2
opea/reranking-tei:1.0e48613afb191
libx11@2:1.8.4-2+deb12u2
no fix listed
2
opea/retriever-redis:1.0eb746b263705
libx11@2:1.8.4-2+deb12u2
no fix listed
2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
libx11@2:1.8.4-2+deb12u2
no fix listed
2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
libx11@2:1.8.4-2+deb12u2
no fix listed
2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
libx11@2:1.8.4-2+deb12u2
no fix listed
2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
libx11@2:1.8.4-2+deb12u2
no fix listed
2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
libx11@2:1.8.4-2+deb12u2
no fix listed
2
opencsghq/label-studio:v2.5.047e22aa71870
libx11@2:1.8.12-1
no fix listed
2

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.