StackRadar

CVE-2026-95512

Medium

Advisory

Published 2 Oct 2026In the index since 3 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,019
of 18,026 indexed, latest versions
Container images
818
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,019 of 18,026 indexed charts deploy, on 818 images.

Affected packageAffected versionsFixed inImages
freetypedeb2.5.2-1ubuntu2.2, 2.5.2-1ubuntu2.8, 2.6.1-0.1ubuntu2.3, 2.6.1-0.1ubuntu2.4+20 moreno fix listed818
OSV records
DEBIAN-CVE-2026-95512UBUNTU-CVE-2026-95512
Trending
Rank 5 in indexed charts, since 3 Oct 2026. See the ranking →

Charts affected

1,019 by stars
ChartLatestAffected imagesRadar Score
jenkinswebencryptor1.9.181 of 1See more

jenkins webencryptor 1.9.18

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

3,141
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
freetype@2.10.1-2ubuntu0.1
no fix listed

Open the chart page →

15,135
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
freetype@2.10.1-2ubuntu0.1
no fix listed

Open the chart page →

30,189
juicefs-csi-driverwener0.33.01 of 5See more

juicefs-csi-driver wener 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
freetype@2.12.1+dfsg-5+deb12u4
no fix listed

Open the chart page →

11,170
juicefs-csi-driverwenerme0.33.01 of 5See more

juicefs-csi-driver wenerme 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
freetype@2.12.1+dfsg-5+deb12u4
no fix listed

Open the chart page →

11,170
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
freetype@2.11.1+dfsg-1ubuntu0.2
no fix listed

Open the chart page →

11,876
kibanawiremindVerified publisher8.5.241 of 2See more

kibana wiremind 8.5.24

1 of the 2 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/kibana:8.19.2235544f1ff28a
freetype@2.13.2+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

1,665
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/wordpress:latest8746e7e072e3
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

5,584
wordpresswordpress-ng1.0.101 of 2See more

wordpress wordpress-ng 1.0.10

1 of the 2 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
cloudtooling/wordpress:7.1.20b390e7e3425
freetype@2.12.1+dfsg-5+deb12u4
no fix listed

Open the chart page →

4,390
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
freetype@2.11.1+dfsg-1ubuntu0.2
no fix listed

Open the chart page →

15,663
am-pattern-1wso22.6.0-71 of 6See more

am-pattern-1 wso2 2.6.0-7

1 of the 6 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
wso2/wso2am:2.6.0fbe0f4059b74
freetype@2.10.1-2ubuntu0.1
no fix listed

Open the chart page →

33,063
ei-pattern-1wso26.6.0-33 of 6See more

ei-pattern-1 wso2 6.6.0-3

3 of the 6 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
wso2/wso2ei-analytics-dashboard:6.6.0526a1ccae902
freetype@2.8.1-2ubuntu2
no fix listed
wso2/wso2ei-analytics-worker:6.6.021e6b03449ac
freetype@2.8.1-2ubuntu2
no fix listed
wso2/wso2ei-integrator:6.6.0790cd8c3a5a2
freetype@2.8.1-2ubuntu2
no fix listed

Open the chart page →

51,994
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
freetype@2.12.1+dfsg-5
no fix listed

Open the chart page →

8,545
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

1,859
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
library/nginx:stableb972f831f200
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

1,859
jenkinszanise-jenkins-helm-chart0.1.01 of 1See more

jenkins zanise-jenkins-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
freetype@2.13.3+dfsg-1+deb13u1
no fix listed

Open the chart page →

3,141
changedetection-iozekker6Verified publisher1.103.01 of 1See more

changedetection-io zekker6 1.103.0

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.834df3680db1c
freetype@2.12.1+dfsg-5+deb12u4
no fix listed

Open the chart page →

2,915
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
freetype@2.12.1+dfsg-5+deb12u4
no fix listed

Open the chart page →

4,999
zoo-project-druzoo-projectOfficialVerified publisher0.10.81 of 6See more

zoo-project-dru zoo-project 0.10.8

1 of the 6 container images this version deploys carry CVE-2026-95512.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-51e7d55383f24594959b69e58518961c6aa66740da112e8d03f1
freetype@2.11.1+dfsg-1ubuntu0.3
no fix listed

Open the chart page →

6,754

Container images carrying it

818 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
freetype@2.10.1-2ubuntu0.1
no fix listed
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
freetype@2.10.1-2ubuntu0.1
no fix listed
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
freetype@2.10.1-2ubuntu0.1
no fix listed
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
freetype@2.12.1+dfsg-5
no fix listed
2
gotenberg/gotenberg:8.36.087c16b9f3642
freetype@2.13.3+dfsg-1+deb13u1
no fix listed
2
gotenberg/gotenberg:8:8.37.0f29984bd1e22
freetype@2.13.3+dfsg-1+deb13u1
no fix listed
2
gradiant/srsran-5g:23_10_19061b1bf0f36
freetype@2.10.1-2ubuntu0.3
no fix listed
2
hookiesolutions/webhookie:latest0629694246ba
freetype@2.10.1-2ubuntu0.1
no fix listed
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
freetype@2.10.1-2ubuntu0.1
no fix listed
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
freetype@2.12.1+dfsg-5
no fix listed
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
freetype@2.13.3+dfsg-1
no fix listed
2
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
freetype@2.12.1+dfsg-5+deb12u4
no fix listed
2
kurento/kurento-media-server:latest03c0d34d0828
freetype@2.13.2+dfsg-1build3
no fix listed
2
library/cassandra:3.11.65aa8400b4b3b
freetype@2.8.1-2ubuntu2
no fix listed
2
library/cassandra:4.1.37cbcec0086ac
freetype@2.11.1+dfsg-1ubuntu0.2
no fix listed
2
library/nextcloud:35.0.1:35.0.1-apacheb1ae671e9815
freetype@2.13.3+dfsg-1+deb13u1
no fix listed
2
library/nginx:latest6e23479198b9
freetype@2.13.3+dfsg-1+deb13u1
no fix listed
2
library/nginx:1.27.098f8ec75657d
freetype@2.12.1+dfsg-5+deb12u3
no fix listed
2
library/nginx:1.29.49dd288848f44
freetype@2.13.3+dfsg-1
no fix listed
2
library/python:3.7eedf63967cdb
freetype@2.12.1+dfsg-5
no fix listed
2
library/redmine:6.1.3-trixief474a901faec
freetype@2.13.3+dfsg-1+deb13u1
no fix listed
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
freetype@2.13.3+dfsg-1
no fix listed
2
library/wordpress:latest8746e7e072e3
freetype@2.13.3+dfsg-1+deb13u1
no fix listed
2
louislam/uptime-kuma:2.5.4917318f9d7be
freetype@2.12.1+dfsg-5+deb12u4
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
freetype@2.12.1+dfsg-5+deb12u4
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
freetype@2.12.1+dfsg-5+deb12u4
no fix listed
2
louislam/uptime-kuma:2.5.5c74379ac4509
freetype@2.12.1+dfsg-5+deb12u4
no fix listed
2
mbentley/omada-controller:4.3f4e682274bed
freetype@2.8.1-2ubuntu2.2
no fix listed
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
freetype@2.12.1+dfsg-5+deb12u3
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
freetype@2.12.1+dfsg-5
no fix listed
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
freetype@2.12.1+dfsg-5
no fix listed
2
nginxinc/nginx-unprivileged:stable0918d093d608
freetype@2.13.3+dfsg-1+deb13u1
no fix listed
2
nousresearch/hermes-agent:v2026.9.24fca358f12efd
freetype@2.13.3+dfsg-1+deb13u1
no fix listed
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
freetype@2.10.1-2ubuntu0.1
no fix listed
2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
freetype@2.12.1+dfsg-5+deb12u3
no fix listed
2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
freetype@2.12.1+dfsg-5+deb12u3
no fix listed
2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
freetype@2.12.1+dfsg-5+deb12u3
no fix listed
2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
freetype@2.12.1+dfsg-5+deb12u3
no fix listed
2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
freetype@2.12.1+dfsg-5+deb12u3
no fix listed
2
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
freetype@2.11.1+dfsg-1ubuntu0.1
no fix listed
2
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
freetype@2.13.2+dfsg-1ubuntu0.1
no fix listed
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
freetype@2.12.1+dfsg-5
no fix listed
2
seafileltd/seafile-mc:11.0.12d0c66e4621bd
freetype@2.11.1+dfsg-1ubuntu0.2
no fix listed
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
freetype@2.12.1+dfsg-5
no fix listed
2
wurstmeister/zookeeper:latest7a7fd44a7210
freetype@2.5.2-1ubuntu2.2
no fix listed
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
freetype@2.11.1+dfsg-1ubuntu0.3
no fix listed
2
ghcr.io/browserless/chromium:v2.57.06bac628b3d82
freetype@2.14.2+dfsg-1ubuntu0.1
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
freetype@2.13.2+dfsg-1build3
no fix listed
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
freetype@2.11.1+dfsg-1ubuntu0.1
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
freetype@2.12.1+dfsg-5+deb12u4
no fix listed
2

syft 1.42.1 · advisories as of 5 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.