StackRadar

CVE-2026-94287

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
310
of 17,939 indexed, latest versions
Container images
159
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 310 of 17,939 indexed charts deploy, on 159 images.

Affected packageAffected versionsFixed inImages
libxpmdeb1:3.5.12-1.1, 1:3.5.12-1.1+deb12u1, 1:3.5.17-1+b3, 1:3.5.17-1+deb13u1+1 moreno fix listed159
OSV records
DEBIAN-CVE-2026-94287

Charts affected

310 by stars
ChartLatestAffected imagesRadar Score
unlaunla0.10.01 of 3See more

unla unla 0.10.0

1 of the 3 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
ghcr.io/amoylab/unla/web:latesteac1df1c5e66
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

9,279
opencloudunxwaresVerified publisher0.2.36 of 13See more

opencloud unxwares 0.2.3

6 of the 13 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

46,329
argus-test-envvk-helm-charts2.0.01 of 1See more

argus-test-env vk-helm-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxpm@1:3.5.17-1+deb13u1
no fix listed

Open the chart page →

1,686
juicefs-csi-driverwener0.33.01 of 5See more

juicefs-csi-driver wener 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

9,369
juicefs-csi-driverwenerme0.33.01 of 5See more

juicefs-csi-driver wenerme 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

9,369
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

7,949
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxpm@1:3.5.17-1+deb13u1
no fix listed

Open the chart page →

1,686
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
library/nginx:stableb972f831f200
libxpm@1:3.5.17-1+deb13u1
no fix listed

Open the chart page →

1,686
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxpm@1:3.5.17-1+deb13u1
no fix listed

Open the chart page →

1,686
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

4,879

Container images carrying it

159 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
deconzcommunity/deconz:2.26.123c86008d73f
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
libxpm@1:3.5.17-1+b3
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
egorz/netology-diploma-web-app:4.05627a54bd1ad
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
emqx/ecp-ui:2.5.1e33e9816f147
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
escaping/core-keeper-dedicated:latest87fa79255962
libxpm@1:3.5.17-1+b3
no fix listed
1
felipecs8/app-db-connection-test:v129e06c9c6385
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
firefart/requesttracker:5.0.40d6249906d8c
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
gotenberg/gotenberg:8-chromium0d28ae9a9644
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
gotenberg/gotenberg:8.30206a6c708fc6
libxpm@1:3.5.17-1+b3
no fix listed
1
gotenberg/gotenberg:8.3467097317623a
libxpm@1:3.5.17-1+b3
no fix listed
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
hazegoodlife/haaze:milksite8d4c63169e14
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
hecrom/myweatherangularclient:1.3.11bb0372939c19
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
jaedb/iris:latest048cfbf58d57
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
jbtronics/part-db1:latestfd68338829ed
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
kuzwolka/aws9:main1ad759b961b1
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
kuzwolka/aws9:news3e8880fbbb96
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
kuzwolka/aws9:blog4a7707410bf1
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
kuzwolka/aws9:shop84a9d9766345
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
langflowai/langflow-frontend:latest54f67f1961fe
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
library/nginx:1.31:1.31.5:latest:trixie05b8cb60c354
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
library/nginx:1.27.409369da6b103
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
library/nginx:1.28146adea4768b
libxpm@1:3.5.17-1+b3
no fix listed
1
library/nginx:1.291881968aff6f
libxpm@1:3.5.17-1+b3
no fix listed
1
library/nginx:1.276784fb0834aa
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
library/nginx:1.25.167f9a4f10d14
libxpm@1:3.5.12-1.1
no fix listed
1
library/nginx:1.31.6908dc23e643a
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
library/nginx:1.25.49ff236ed47fe
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
library/nginx:1.31a53fc6c27208
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
library/nginx:latestcfb8a89ac237
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
library/nginx:1.27.3fb197595ebe7
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
library/phpmyadmin:5.2.3-apache0b38dba8580a
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
library/phpmyadmin:5.2.3-apacheadc486045303
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
logiqai/flash:v3.10.265b996bc7bdc
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
louislam/uptime-kuma:2.0.24c364ef96aad
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
louislam/uptime-kuma:2.4.091e963bfda56
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
makersquad/harp-proxy:0.8.1a40dd258c527
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
mautic/mautic:7-apacheeb8cc73d97e1
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
moreillon/camera-viewer:lateste418cc694bd5
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
moreillon/group-manager-front:latest5f0a38498271
libxpm@1:3.5.17-1+b3
no fix listed
1
moreillon/user-manager-front:v5.1.06597e6b98d21
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
nginxinc/nginx-unprivileged:latest31e97ebaac04
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
libxpm@1:3.5.17-1+b3
no fix listed
1
nginx/nginx-ingress:5.6.33e97f06dce1c
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
nginx/nginx-ingress:edged127d1013198
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
nirmalnaveen/supermario:latest8541a39162f3
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.