StackRadar

CVE-2026-94287

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
310
of 17,939 indexed, latest versions
Container images
159
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 310 of 17,939 indexed charts deploy, on 159 images.

Affected packageAffected versionsFixed inImages
libxpmdeb1:3.5.12-1.1, 1:3.5.12-1.1+deb12u1, 1:3.5.17-1+b3, 1:3.5.17-1+deb13u1+1 moreno fix listed159
OSV records
DEBIAN-CVE-2026-94287

Charts affected

310 by stars
ChartLatestAffected imagesRadar Score
unlaunla0.10.01 of 3See more

unla unla 0.10.0

1 of the 3 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
ghcr.io/amoylab/unla/web:latesteac1df1c5e66
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

9,279
opencloudunxwaresVerified publisher0.2.36 of 13See more

opencloud unxwares 0.2.3

6 of the 13 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

46,329
argus-test-envvk-helm-charts2.0.01 of 1See more

argus-test-env vk-helm-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxpm@1:3.5.17-1+deb13u1
no fix listed

Open the chart page →

1,686
juicefs-csi-driverwener0.33.01 of 5See more

juicefs-csi-driver wener 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

9,369
juicefs-csi-driverwenerme0.33.01 of 5See more

juicefs-csi-driver wenerme 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

9,369
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

7,949
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxpm@1:3.5.17-1+deb13u1
no fix listed

Open the chart page →

1,686
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
library/nginx:stableb972f831f200
libxpm@1:3.5.17-1+deb13u1
no fix listed

Open the chart page →

1,686
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
libxpm@1:3.5.17-1+deb13u1
no fix listed

Open the chart page →

1,686
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-94287.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
libxpm@1:3.5.12-1.1+deb12u1
no fix listed

Open the chart page →

4,879

Container images carrying it

159 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/nginx:1.31:latest:mainline:trixieabe47724e466
libxpm@1:3.5.17-1+deb13u1
no fix listed
108
library/nginx:stable0aa2d81d65bc
libxpm@1:3.5.17-1+deb13u1
no fix listed
12
library/nginx:stableb972f831f200
libxpm@1:3.5.17-1+deb13u1
no fix listed
11
library/phpmyadmin:5.2.3-apache:latest9e915766488a
libxpm@1:3.5.17-1+deb13u1
no fix listed
6
flaresolverr/flaresolverr:latest:v3.5.0139dfee1c6f8
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
4
library/nginx:1.27.1287ff321f9e3
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
4
ghcr.io/flaresolverr/flaresolverr:latest:v3.5.2c80ae007ce2c
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
4
library/nginx:1.25:1.25.5a484819eb602
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
3
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
libxpm@1:3.5.12-1.1
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
3
freikin/dawarich:1.15.2e58334ca5697
libxpm@1:3.5.17-1+deb13u1
no fix listed
2
gotenberg/gotenberg:8.36.087c16b9f3642
libxpm@1:3.5.17-1+deb13u1
no fix listed
2
gotenberg/gotenberg:8:8.37.0f29984bd1e22
libxpm@1:3.5.17-1+deb13u1
no fix listed
2
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
library/nginx:latest6e23479198b9
libxpm@1:3.5.17-1+b3
no fix listed
2
library/nginx:1.27.098f8ec75657d
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
library/nginx:1.29.49dd288848f44
libxpm@1:3.5.17-1+b3
no fix listed
2
louislam/uptime-kuma:2.5.4917318f9d7be
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
louislam/uptime-kuma:2.5.5c74379ac4509
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
nginxinc/nginx-unprivileged:stable0918d093d608
libxpm@1:3.5.17-1+deb13u1
no fix listed
2
nousresearch/hermes-agent:v2026.9.24fca358f12efd
libxpm@1:3.5.17-1+deb13u1
no fix listed
2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
ghcr.io/lissy93/web-check:latest7e2ef5261764
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
2
allegroai/clearml:2.0.0-613713ae38f7daf
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
libxpm@1:3.5.17-1+b3
no fix listed
1
anujdatar/cups:25.07.01685df04a643b
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
archivebox/archivebox:0.9.708c21bb233130
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
avzini/web-app:latestf40b30210ed0
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
budibase/proxy:3.41.38d780b6ee602
libxpm@1:3.5.17-1+deb13u1
no fix listed
1
castopod/castopod:1.12.101fd37280cbb2
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
castopod/castopod:1.15.54e4f0440520f
libxpm@1:3.5.17-1+b3
no fix listed
1
ckulka/baikal:0.10.1-nginx434bdd162247
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
codedesignplus/ms-emails-grpc:latest4fc116f5e879
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
codedesignplus/ms-emails-rest:latest7629e746a5b3
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
libxpm@1:3.5.17-1+b3
no fix listed
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
dannielkil/book-frontend:latest937993927694
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1
deconzcommunity/deconz:2.29.2062de2362641
libxpm@1:3.5.12-1.1+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.