StackRadar

CVE-2026-94287

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
310
of 17,939 indexed, latest versions
Container images
159
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 310 of 17,939 indexed charts deploy, on 159 images.

Affected packageAffected versionsFixed inImages
libxpmdeb1:3.5.12-1.1, 1:3.5.12-1.1+deb12u1, 1:3.5.17-1+b3, 1:3.5.17-1+deb13u1+1 moreno fix listed159
OSV records
DEBIAN-CVE-2026-94287

Charts affected

310 by stars
ChartLatestAffected imagesRadar Score
unlaunla0.10.01 of 3See more

unla unla 0.10.0

1 of the 3 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
ghcr.io/amoylab/unla/web:latesteac1df1c5e66
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

9,279
opencloudunxwaresVerified publisher0.2.36 of 13See more

opencloud unxwares 0.2.3

6 of the 13 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

46,329
argus-test-envvk-helm-charts2.0.01 of 1See more

argus-test-env vk-helm-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxpm@1:3.5.17-1+deb13u1
no fix listed

Open the chart page →

1,686
juicefs-csi-driverwener0.33.01 of 5See more

juicefs-csi-driver wener 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

9,369
juicefs-csi-driverwenerme0.33.01 of 5See more

juicefs-csi-driver wenerme 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

9,369
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

7,949
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxpm@1:3.5.17-1+deb13u1
no fix listed

Open the chart page →

1,686
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
library/nginx:stableb972f831f200
libxpm@1:3.5.17-1+deb13u1
no fix listed

Open the chart page →

1,686
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxpm@1:3.5.17-1+deb13u1
no fix listed

Open the chart page →

1,686
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

4,879

Container images carrying it

159 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
oneuptime/probe:release91dac418f5ba
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
onyxdotapp/onyx-backend:latest60e83a098ae4
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
openbas/caldera-server:5.1.0a277796d9724
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
libxpm@1:3.5.17-1+b3
no fix listed
1
penpotapp/exporter:2.18.0beb2c2bd9660
libxpm@1:3.5.17-1+deb13u1+dhi0
no fix listed
1
phan2410/dummy-service:0.0.89c6ed6de26ca
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
libxpm@1:3.5.17-1+b3
no fix listed
1
pk910/powfaucet:v2-stable3dcae6a62896
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
praravind1801/helmimages:3.0.0f29d637b9ce1
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
reallibrephotos/librephotos-proxy:1.0.398a13dabbadc
libxpm@1:3.5.17-1+b3
no fix listed
1
rocketadmin/rocketadmin:1.17.710955ef540b9
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
santisbon/evwatcher:latestc4e994ca4540
libxpm@1:3.5.12-1.1
no fix listed
1
santisbon/evworker:lateste807283f8d69
libxpm@1:3.5.12-1.1
no fix listed
1
santisbon/speedtest:latest8ee3a1697227
libxpm@1:3.5.12-1.1
no fix listed
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
shamimkuet/nginx:1.0.2b82902a76a04
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
signalen/backend:2.50.1826bb090bc4e4
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
sissbruecker/linkding:1.35.00c5dddf0b37c
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
somnathmore/custom-nginx:v2bdfc06cad4ec
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
libxpm@1:3.5.17-1+b3
no fix listed
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
swimmwatch/cloakbrowser-mcp:1.14.1f6986203a121
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
tinymediamanager/tinymediamanager:5.3.36f332431a2ae
libxpm@1:3.5.17-1+b3
no fix listed
1
wiktorn/overpass-api:latest9bb5f4a9b54c
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
yetiplatform/yeti-frontend:latest709064278c7e
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
yetiplatform/yeti-frontend:2.9.0873ef15d267b
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
ghcr.io/aeharding/voyager:latest8e9d9ed499e3
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
ghcr.io/amoylab/unla/web:latesteac1df1c5e66
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
libxpm@1:3.5.17-1+b3
no fix listed
1
ghcr.io/argonix-io/argonix-api:0.5.349f21389f4e7
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
ghcr.io/cjmalloy/jasper-ui:v1.3.623246dc2160efe
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
ghcr.io/damap-org/damap-frontend:5.0.2c9d4f0f8b331
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
ghcr.io/ente/web:5ab0c5b4c7a89c4e470ef6f793600da33cebf35d3f4864eb7f11
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
ghcr.io/flanksource/facet:0.1.73a0323f4283e5
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
ghcr.io/getsentry/taskbroker:26.7.264d0da74a578
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
libxpm@1:3.5.17-1+b3
no fix listed
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.