StackRadar

CVE-2026-94286

High

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
64
of 17,939 indexed, latest versions
Container images
46
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 64 of 17,939 indexed charts deploy, on 46 images.

Affected packageAffected versionsFixed inImages
libxtstdeb2:1.2.3-1.1, 2:1.2.5-1, 2:1.2.5-1+dhi0no fix listed46
OSV records
DEBIAN-CVE-2026-94286

Charts affected

64 by stars
ChartLatestAffected imagesRadar Score
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-94286.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
libxtst@2:1.2.3-1.1
no fix listed

Open the chart page →

35,383
flaresolverrluiscajl0.0.31 of 1See more

flaresolverr luiscajl 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-94286.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:latestc80ae007ce2c
libxtst@2:1.2.3-1.1
no fix listed

Open the chart page →

7,639
searchmcp-helmVerified publisher0.1.31 of 2See more

search mcp-helm 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-94286.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:latestc80ae007ce2c
libxtst@2:1.2.3-1.1
no fix listed

Open the chart page →

9,322
flaresolverrmedia-servarrVerified publisher0.18.21 of 1See more

flaresolverr media-servarr 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-94286.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
libxtst@2:1.2.3-1.1
no fix listed

Open the chart page →

7,639
tinymediamanagermedia-servarrVerified publisher1.6.41 of 2See more

tinymediamanager media-servarr 1.6.4

1 of the 2 container images this version deploys carry CVE-2026-94286.

Container imageDigestPackageFixed in
tinymediamanager/tinymediamanager:5.3.36f332431a2ae
libxtst@2:1.2.5-1
no fix listed

Open the chart page →

8,633
uptime-kumancsaVerified publisher1.7.31 of 1See more

uptime-kuma ncsa 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-94286.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.5c74379ac4509
libxtst@2:1.2.3-1.1
no fix listed

Open the chart page →

31,945
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-94286.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latest7e2ef5261764
libxtst@2:1.2.3-1.1
no fix listed

Open the chart page →

6,984
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-94286.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
libxtst@2:1.2.3-1.1
no fix listed

Open the chart page →

10,139
flaresolverrrubxkubeVerified publisher0.1.11 of 1See more

flaresolverr rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-94286.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
libxtst@2:1.2.3-1.1
no fix listed

Open the chart page →

29,040
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-94286.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
libxtst@2:1.2.3-1.1
no fix listed

Open the chart page →

32,155
uptime-kumaschoenwald1.0.101 of 1See more

uptime-kuma schoenwald 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-94286.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
libxtst@2:1.2.3-1.1
no fix listed

Open the chart page →

31,952
deconzsmall-hack0.1.01 of 1See more

deconz small-hack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-94286.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.26.123c86008d73f
libxtst@2:1.2.3-1.1
no fix listed

Open the chart page →

13,749
steadybit-agentsteadybit3.1.1751 of 6See more

steadybit-agent steadybit 3.1.175

1 of the 6 container images this version deploys carry CVE-2026-94286.

Container imageDigestPackageFixed in
ghcr.io/steadybit/agent:2.4.6d246bfa55f63
libxtst@2:1.2.5-1
no fix listed

Open the chart page →

3,915
flaresolverrsudo-kraken-flaresolverrVerified publisher2.1.41 of 1See more

flaresolverr sudo-kraken-flaresolverr 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-94286.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
libxtst@2:1.2.3-1.1
no fix listed

Open the chart page →

35,673

Container images carrying it

46 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
flaresolverr/flaresolverr:latest:v3.5.0139dfee1c6f8
libxtst@2:1.2.3-1.1
no fix listed
4
ghcr.io/flaresolverr/flaresolverr:latest:v3.5.2c80ae007ce2c
libxtst@2:1.2.3-1.1
no fix listed
4
quay.io/devtron/ai-agent:0.0.16545dac92173
libxtst@2:1.2.3-1.1
no fix listed
3
freikin/dawarich:1.15.2e58334ca5697
libxtst@2:1.2.5-1
no fix listed
2
gotenberg/gotenberg:8.36.087c16b9f3642
libxtst@2:1.2.5-1
no fix listed
2
gotenberg/gotenberg:8:8.37.0f29984bd1e22
libxtst@2:1.2.5-1
no fix listed
2
graviteeio/apim-gateway:4.12.20-debian8f1a14449381
libxtst@2:1.2.5-1
no fix listed
2
graviteeio/apim-management-api:4.12.20-debiand30d085395ca
libxtst@2:1.2.5-1
no fix listed
2
louislam/uptime-kuma:2.5.4917318f9d7be
libxtst@2:1.2.3-1.1
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
libxtst@2:1.2.3-1.1
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
libxtst@2:1.2.3-1.1
no fix listed
2
louislam/uptime-kuma:2.5.5c74379ac4509
libxtst@2:1.2.3-1.1
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
libxtst@2:1.2.3-1.1
no fix listed
2
ghcr.io/lissy93/web-check:latest7e2ef5261764
libxtst@2:1.2.3-1.1
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
libxtst@2:1.2.3-1.1
no fix listed
2
archivebox/archivebox:0.9.708c21bb233130
libxtst@2:1.2.5-1
no fix listed
1
budibase/database:2.1.0d90f656261c9
libxtst@2:1.2.3-1.1
no fix listed
1
castopod/castopod:1.15.54e4f0440520f
libxtst@2:1.2.5-1
no fix listed
1
codedesignplus/ms-emails-grpc:latest4fc116f5e879
libxtst@2:1.2.3-1.1
no fix listed
1
codedesignplus/ms-emails-rest:latest7629e746a5b3
libxtst@2:1.2.3-1.1
no fix listed
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
libxtst@2:1.2.5-1
no fix listed
1
deconzcommunity/deconz:2.29.2062de2362641
libxtst@2:1.2.3-1.1
no fix listed
1
deconzcommunity/deconz:2.26.123c86008d73f
libxtst@2:1.2.3-1.1
no fix listed
1
gotenberg/gotenberg:8-chromium0d28ae9a9644
libxtst@2:1.2.5-1
no fix listed
1
gotenberg/gotenberg:8.30206a6c708fc6
libxtst@2:1.2.5-1
no fix listed
1
gotenberg/gotenberg:8.3467097317623a
libxtst@2:1.2.5-1
no fix listed
1
jaedb/iris:latest048cfbf58d57
libxtst@2:1.2.3-1.1
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
libxtst@2:1.2.3-1.1
no fix listed
1
louislam/uptime-kuma:2.0.24c364ef96aad
libxtst@2:1.2.3-1.1
no fix listed
1
louislam/uptime-kuma:2.4.091e963bfda56
libxtst@2:1.2.3-1.1
no fix listed
1
merlos/zookeeper:3.9.3a38fc7e09ed7
libxtst@2:1.2.3-1.1
no fix listed
1
oneuptime/probe:release91dac418f5ba
libxtst@2:1.2.3-1.1
no fix listed
1
penpotapp/exporter:2.18.0beb2c2bd9660
libxtst@2:1.2.5-1+dhi0
no fix listed
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
libxtst@2:1.2.3-1.1
no fix listed
1
tinymediamanager/tinymediamanager:5.3.36f332431a2ae
libxtst@2:1.2.5-1
no fix listed
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
libxtst@2:1.2.5-1
no fix listed
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
libxtst@2:1.2.3-1.1
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
libxtst@2:1.2.3-1.1
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
libxtst@2:1.2.3-1.1
no fix listed
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
libxtst@2:1.2.3-1.1
no fix listed
1
ghcr.io/flanksource/facet:0.1.73a0323f4283e5
libxtst@2:1.2.3-1.1
no fix listed
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
libxtst@2:1.2.3-1.1
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
libxtst@2:1.2.5-1
no fix listed
1
ghcr.io/steadybit/agent:2.4.6d246bfa55f63
libxtst@2:1.2.5-1
no fix listed
1
ghcr.io/wittdennis/calibre-web:1.1.2953aa0935251
libxtst@2:1.2.3-1.1
no fix listed
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
libxtst@2:1.2.3-1.1
no fix listed
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.