StackRadar

CVE-2026-95512

Medium

Advisory

Published 2 Oct 2026In the index since 3 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,031
of 17,992 indexed, latest versions
Container images
822
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,031 of 17,992 indexed charts deploy, on 822 images.

Affected packageAffected versionsFixed inImages
freetypedeb2.5.2-1ubuntu2.2, 2.5.2-1ubuntu2.8, 2.6.1-0.1ubuntu2.3, 2.6.1-0.1ubuntu2.4+21 moreno fix listed822
OSV records
DEBIAN-CVE-2026-95512UBUNTU-CVE-2026-95512
Trending
Rank 5 in indexed charts, since 3 Oct 2026. See the ranking →

Charts affected

1,031 by stars
ChartLatestAffected imagesRadar Score
my-react-appmy-react-app0.1.51 of 1See more

my-react-app my-react-app 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

1,859
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
freetype@2.12.1+dfsg-5
no fix listed

Open the chart page →

44,665
nginx-chartnginx-chart-testVerified publisher0.1.11 of 1See more

nginx-chart nginx-chart-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

1,859
papermergenicholaswildeVerified publisher1.0.21 of 1See more

papermerge nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/papermerge:version-v2.0.198ba2dd3f0bd
freetype@2.10.1-2ubuntu0.2
no fix listed

Open the chart page →

21,019
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
freetype@2.12.1+dfsg-5+deb12u3
no fix listed

Open the chart page →

5,413
onechartonechart-slVerified publisher0.76.01 of 1See more

onechart onechart-sl 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

1,859
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
freetype@2.12.1+dfsg-5
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
freetype@2.12.1+dfsg-5+deb12u3
no fix listed

Open the chart page →

15,616
opentelemetry-demoopentelemetry-helmOfficialVerified publisher0.42.23 of 34See more

opentelemetry-demo opentelemetry-helm 0.42.2

3 of the 34 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:3.1.0-fraud-detectiona07ee694304b
freetype@2.12.1+dfsg-5+deb12u4
no fix listed
ghcr.io/open-telemetry/demo:3.1.0-load-generatorb130d6cee6cb
freetype@2.12.1+dfsg-5+deb12u4
no fix listed
ghcr.io/open-telemetry/demo:3.1.0-addfd7a4697116
freetype@2.13.2+dfsg-1build3
no fix listed

Open the chart page →

24,329
opikopikOfficialVerified publisher2.2.881 of 13See more

opik opik 2.2.88

1 of the 13 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/zookeeper:3.9.4dfa9ba46d14b
freetype@2.11.1+dfsg-1ubuntu0.3
no fix listed

Open the chart page →

15,227
opsopsVerified publisher1.2.02 of 2See more

ops ops 1.2.0

2 of the 2 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
shaowenchen/ops-controller-manager:latest35575d4f2bfe
freetype@2.11.1+dfsg-1ubuntu0.3
no fix listed
shaowenchen/ops-server:latest6bac5cebd125
freetype@2.11.1+dfsg-1ubuntu0.3
no fix listed

Open the chart page →

100,565
paperless-ngxpaperlessVerified publisher0.4.01 of 3See more

paperless-ngx paperless 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngxdigest-pinnedaa810a36942c
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

10,202
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

8,327
spring-boot-api-apppiominVerified publisher0.3.111 of 1See more

spring-boot-api-app piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
freetype@2.11.1+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

7,952
playgroundplayground0.1.11 of 1See more

playground playground 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

1,859
matomopockostVerified publisher1.4.01 of 3See more

matomo pockost 1.4.0

1 of the 3 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
pockost/matomo:5.14.0134c35415788
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

6,040
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
treskon/portrait:DEV-latest88e813f22347
freetype@2.14.2+dfsg-1ubuntu0.1
no fix listed
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
freetype@2.12.1+dfsg-5+deb12u3
no fix listed

Open the chart page →

35,784
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
freetype@2.13.2+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

62,591
minecraft-serverqumine0.1.15001 of 1See more

minecraft-server qumine 0.1.1500

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
qumine/minecraft-server:v0.1.15c0b650d51132
freetype@2.11.1+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

7,784
napcatredish101Verified publisher0.1.31 of 1See more

napcat redish101 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
mlikiowa/napcat-docker:latest2cc70b45244a
freetype@2.11.1+dfsg-1ubuntu0.2
no fix listed

Open the chart page →

71,196
redmineredmine-helm-chartVerified publisher0.2.61 of 1See more

redmine redmine-helm-chart 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

5,140
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
freetype@2.11.1+dfsg-1ubuntu0.3
no fix listed

Open the chart page →

8,582
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
freetype@2.10.1-2ubuntu0.1
no fix listed

Open the chart page →

10,500
kimai2robjuz5.0.141 of 2See more

kimai2 robjuz 5.0.14

1 of the 2 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
kimai/kimai2:2.67.03084f1e5ecdc
freetype@2.12.1+dfsg-5+deb12u4
no fix listed

Open the chart page →

6,012
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
freetype@2.12.1+dfsg-5+deb12u4
no fix listed

Open the chart page →

6,338
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
freetype@2.12.1+dfsg-5+deb12u4
no fix listed

Open the chart page →

8,479
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
freetype@2.10.1-2ubuntu0.2
no fix listed

Open the chart page →

7,357
rstudio-pmrstudioVerified publisher0.20.51 of 1See more

rstudio-pm rstudio 0.20.5

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
posit/package-manager:2026.09.0-ubuntu-24.0468d47a7a8166
freetype@2.13.2+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

36,753
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
freetype@2.12.1+dfsg-5+deb12u4
no fix listed

Open the chart page →

5,724
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
freetype@2.8.1-2ubuntu2.1
no fix listed

Open the chart page →

14,084
kyoorubxkubeVerified publisher0.1.102 of 9See more

kyoo rubxkube 0.1.10

2 of the 9 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
freetype@2.12.1+dfsg-5+deb12u3
no fix listed
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
freetype@2.12.1+dfsg-5+deb12u3
no fix listed

Open the chart page →

33,055
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
freetype@2.12.1+dfsg-5+deb12u4
no fix listed

Open the chart page →

42,509
immichsecustorVerified publisher2.0.71 of 1See more

immich secustor 2.0.7

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.4d317916b2809
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

3,297
sentry-k8ssentry-k8sVerified publisher1.4.11 of 11See more

sentry-k8s sentry-k8s 1.4.1

1 of the 11 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
ghcr.io/getsentry/taskbroker:26.7.264d0da74a578
freetype@2.12.1+dfsg-5+deb12u4
no fix listed

Open the chart page →

20,121
smarter-demosmarterOfficialVerified publisher0.1.52 of 7See more

smarter-demo smarter 0.1.5

2 of the 7 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
freetype@2.10.1-2ubuntu0.2
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
freetype@2.10.1-2ubuntu0.2
no fix listed

Open the chart page →

256,269
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
freetype@2.13.3+dfsg-1
no fix listed

Open the chart page →

8,502
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
freetype@2.12.1+dfsg-5
no fix listed

Open the chart page →

6,047
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
freetype@2.12.1+dfsg-5+deb12u4
no fix listed

Open the chart page →

11,684
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
freetype@2.10.1-2ubuntu0.2
no fix listed

Open the chart page →

14,188
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
freetype@2.13.2+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

3,226
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

3,717
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

1,859
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

1,859
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
freetype@2.12.1+dfsg-5
no fix listed

Open the chart page →

10,019
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
freetype@2.12.1+dfsg-5
no fix listed

Open the chart page →

10,019
u-storeunifieVerified publisher1.2.01 of 1See more

u-store unifie 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
freetype@2.12.1+dfsg-5
no fix listed

Open the chart page →

16,520
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
freetype@2.12.1+dfsg-5+deb12u3
no fix listed

Open the chart page →

13,609
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
freetype@2.8.1-2ubuntu2
no fix listed

Open the chart page →

16,630
kafka-devwikimedia0.2.01 of 1See more

kafka-dev wikimedia 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
freetype@2.5.2-1ubuntu2.2
no fix listed

Open the chart page →

42,107
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
freetype@2.10.1-2ubuntu0.4
no fix listed

Open the chart page →

58,080
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
freetype@2.13.3+dfsg-1
no fix listed

Open the chart page →

8,987

Container images carrying it

822 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/aktosecurity/akto-threat-detection:latesta728eb2eaf06
freetype@2.14.2+dfsg-1ubuntu0.1
no fix listed
1
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
freetype@2.12.1+dfsg-5
no fix listed
1
public.ecr.aws/jtekt-corporation/api-key-manager-gui:v0.1.10424fa47fbeb
freetype@2.13.3+dfsg-1+deb13u1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
freetype@2.12.1+dfsg-5+deb12u3
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
freetype@2.12.1+dfsg-5+deb12u3
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
freetype@2.12.1+dfsg-5
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
freetype@2.12.1+dfsg-5
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
freetype@2.12.1+dfsg-5
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
freetype@2.12.1+dfsg-5+deb12u3
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
freetype@2.10.1-2ubuntu0.1
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
freetype@2.12.1+dfsg-5
no fix listed
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
freetype@2.11.1+dfsg-1ubuntu0.1
no fix listed
1
quay.io/kannika/kannika-api:0.19.05e5a3b3a911e
freetype@2.13.3+dfsg-1+deb13u1
no fix listed
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
freetype@2.12.1+dfsg-5+deb12u4
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
freetype@2.6.1-0.1ubuntu2.3
no fix listed
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
freetype@2.14.2+dfsg-1ubuntu0.1
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
freetype@2.12.1+dfsg-5
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
freetype@2.13.2+dfsg-1ubuntu0.1
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.1126450354eba9
freetype@2.14.2+dfsg-1ubuntu0.1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
freetype@2.13.3+dfsg-1+deb13u1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
freetype@2.12.1+dfsg-5+deb12u4
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
freetype@2.12.1+dfsg-5+deb12u4
no fix listed
1

syft 1.42.1 · advisories as of 4 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.