StackRadar

CVE-2026-96889

High

Advisory

Published 23 Sept 2026In the index since 25 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
206
of 17,844 indexed, latest versions
Container images
213
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 206 of 17,844 indexed charts deploy, on 213 images.

Affected packageAffected versionsFixed inImages
librsvgdeb2.40.13-3, 2.40.20-2, 2.40.20-2ubuntu0.2, 2.48.9-1ubuntu0.20.04.1+8 moreno fix listed213
OSV records
DEBIAN-CVE-2026-96889UBUNTU-CVE-2026-96889

Charts affected

206 by stars
ChartLatestAffected imagesRadar Score
discount-bandithelmforgeVerified publisher2.0.81 of 3See more

discount-bandit helmforge 2.0.8

1 of the 3 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
cybrarist/discount-bandit:v4.0.4e9e2447ac666
librsvg@2.60.0+dfsg-1
no fix listed

Open the chart page →

31,650
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
librsvg@2.60.0+dfsg-1
no fix listed

Open the chart page →

11,490
myapphelmingapp0.1.01 of 1See more

myapp helmingapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
muhammedgamal/fp23:latest74b4cd69b6fa
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

13,281
svacerhelm-svacer0.6.01 of 1See more

svacer helm-svacer 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ispras/svacer:11-2-042aa9fa9f189
librsvg@2.52.5+dfsg-3ubuntu0.2
no fix listed

Open the chart page →

6,477
homebridgehomeenterpriseinc0.5.01 of 1See more

homebridge homeenterpriseinc 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
oznu/homebridge:2021-12-19-ubuntu2e12d0e2dcce
librsvg@2.40.20-2ubuntu0.2
no fix listed

Open the chart page →

80,994
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

17,241
paperlesshpVerified publisher0.1.21 of 5See more

paperless hp 0.1.2

1 of the 5 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
librsvg@2.60.0+dfsg-1
no fix listed

Open the chart page →

28,862
hydrahydraVerified publisher0.9.51 of 2See more

hydra hydra 0.9.5

1 of the 2 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

9,626
isolated-vmhydraVerified publisher0.9.41 of 1See more

isolated-vm hydra 0.9.4

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

8,217
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

12,559
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
librsvg@2.48.9-1ubuntu0.20.04.1
no fix listed

Open the chart page →

89,928
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

19,013
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

11,359
jasperjasperVerified publisher1.0.2071 of 2See more

jasper jasper 1.0.207

1 of the 2 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

9,848
homebridgejespernohrVerified publisher0.2.01 of 1See more

homebridge jespernohr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
librsvg@2.58.0+dfsg-1build1
no fix listed

Open the chart page →

36,733
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
librsvg@2.58.0+dfsg-1build1
no fix listed

Open the chart page →

6,999
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
librsvg@2.58.0+dfsg-1build1
no fix listed

Open the chart page →

6,980
image-storage-servicejtektVerified publisher0.5.11 of 4See more

image-storage-service jtekt 0.5.1

1 of the 4 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

23,752
shinsei-managerjtektVerified publisher0.2.04 of 8See more

shinsei-manager jtekt 0.2.0

4 of the 8 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
moreillon/group-manager:latest3caa8f710ee0
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
moreillon/user-manager:v5.0.2e1c9bfab5c16
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

67,099
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

17,302
deltabadgerk8s-chartsVerified publisher2.0.01 of 1See more

deltabadger k8s-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
librsvg@2.60.0+dfsg-1
no fix listed

Open the chart page →

6,126
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
librsvg@2.58.0+dfsg-1build1
no fix listed

Open the chart page →

70,952
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
librsvg@2.60.0+dfsg-1
no fix listed

Open the chart page →

9,897
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

7,649
finops-database-handlerkrateo0.5.41 of 1See more

finops-database-handler krateo 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/finops-database-handler:0.5.32550427988e3
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

13,206
finops-webservice-api-mockkrateo0.1.01 of 1See more

finops-webservice-api-mock krateo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/finops-webservice-api-mock:0.1.00877e9452d14
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

13,436
kubeflowkromanow94-kubeflow0.5.12 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

2 of the 30 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
library/python:3.7eedf63967cdb
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

73,545
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
librsvg@2.60.0+dfsg-1
no fix listed

Open the chart page →

10,529
penpotkubitodevVerified publisher1.2.11 of 5See more

penpot kubitodev 1.2.1

1 of the 5 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
penpotapp/exporter:2.2.15c835ffd87ab
librsvg@2.52.5+dfsg-3ubuntu0.2
no fix listed

Open the chart page →

18,088
homebridgelbenicio-communityVerified publisher0.1.151 of 1See more

homebridge lbenicio-community 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
librsvg@2.58.0+dfsg-1build1
no fix listed

Open the chart page →

36,733
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

40,054
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
librsvg@2.52.5+dfsg-3
no fix listed

Open the chart page →

11,243
elastictranscoderluiscajl0.46.02 of 4See more

elastictranscoder luiscajl 0.46.0

2 of the 4 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
elastictranscoder/transcoder:627e21dcb4a0327029e6
librsvg@2.40.20-2ubuntu0.2
no fix listed
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
librsvg@2.40.20-2ubuntu0.2
no fix listed

Open the chart page →

59,437
mcp-homeassistantmcp-helmVerified publisher0.2.41 of 1See more

mcp-homeassistant mcp-helm 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
voska/hass-mcp:latest7142a431e2c5
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

11,164
tinymediamanagermedia-servarrVerified publisher1.6.31 of 2See more

tinymediamanager media-servarr 1.6.3

1 of the 2 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
librsvg@2.60.0+dfsg-1
no fix listed

Open the chart page →

8,493
cameramedia-streaming-meshVerified publisher0.2.52 of 3See more

camera media-streaming-mesh 0.2.5

2 of the 3 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
librsvg@2.48.9-1ubuntu0.20.04.1
no fix listed
ciscolabs/rtsp-server:latestb59fc10bb821
librsvg@2.48.9-1ubuntu0.20.04.1
no fix listed

Open the chart page →

19,344
msm-rtspmedia-streaming-meshVerified publisher0.0.22 of 2See more

msm-rtsp media-streaming-mesh 0.0.2

2 of the 2 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
librsvg@2.48.9-1ubuntu0.20.04.1
no fix listed
ciscolabs/rtsp-server:latestb59fc10bb821
librsvg@2.48.9-1ubuntu0.20.04.1
no fix listed

Open the chart page →

19,344
rtspmedia-streaming-meshVerified publisher0.0.142 of 2See more

rtsp media-streaming-mesh 0.0.14

2 of the 2 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
librsvg@2.48.9-1ubuntu0.20.04.1
no fix listed
ciscolabs/rtsp-server:latestb59fc10bb821
librsvg@2.48.9-1ubuntu0.20.04.1
no fix listed

Open the chart page →

19,344
mediawikimediawiki0.4.11 of 1See more

mediawiki mediawiki 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
library/mediawiki:1.43.08b19e819f2e1
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

9,357
mini-blogmini-blog-helm0.1.01 of 3See more

mini-blog mini-blog-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

13,414
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

115,176
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

26,870
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
moreillon/user-manager:v5.0.2e1c9bfab5c16
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

31,901
filestashmt1905024.0.01 of 1See more

filestash mt190502 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
machines/filestash:latest2f69ce781400
librsvg@2.60.0+dfsg-1
no fix listed

Open the chart page →

3,250
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
librsvg@2.60.0+dfsg-1
no fix listed

Open the chart page →

12,510
mum-discord-botmum-discord-botVerified publisher0.3.71 of 1See more

mum-discord-bot mum-discord-bot 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

14,394
smilencsaVerified publisher1.1.05 of 23See more

smile ncsa 1.1.0

5 of the 23 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
socialmediamacroscope/autophrase:0.1.570fb11d4f531
librsvg@2.48.9-1ubuntu0.20.04.4
no fix listed
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
socialmediamacroscope/preprocessing:0.1.3ca863306314b
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

285,287
audacitynicholaswildeVerified publisher0.1.41 of 1See more

audacity nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/audacity:version-3.0.2cdf203db1e50
librsvg@2.48.9-1ubuntu0.20.04.1
no fix listed

Open the chart page →

23,893
booksonicnicholaswildeVerified publisher1.0.11 of 1See more

booksonic nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic:version-1.2677efca1065d
librsvg@2.40.20-2ubuntu0.2
no fix listed

Open the chart page →

17,402
digikamnicholaswildeVerified publisher1.0.01 of 1See more

digikam nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
librsvg@2.40.20-2ubuntu0.2
no fix listed

Open the chart page →

25,009

Container images carrying it

213 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
ghcr.io/zammad/zammad:7.2.0-000061a2947b478e
librsvg@2.60.0+dfsg-1
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
quay.io/go-skynet/local-ai:latest0632c21ddbe4
librsvg@2.58.0+dfsg-1build1
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
librsvg@2.54.5+dfsg-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.