StackRadar

CVE-2026-96889

High

Advisory

Published 23 Sept 2026In the index since 25 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
206
of 17,844 indexed, latest versions
Container images
213
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 206 of 17,844 indexed charts deploy, on 213 images.

Affected packageAffected versionsFixed inImages
librsvgdeb2.40.13-3, 2.40.20-2, 2.40.20-2ubuntu0.2, 2.48.9-1ubuntu0.20.04.1+8 moreno fix listed213
OSV records
DEBIAN-CVE-2026-96889UBUNTU-CVE-2026-96889

Charts affected

206 by stars
ChartLatestAffected imagesRadar Score
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

18,032
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
librsvg@2.54.5+dfsg-1
no fix listed

Open the chart page →

15,031
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

11,423
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
librsvg@2.52.5+dfsg-3ubuntu0.2
no fix listed

Open the chart page →

14,813
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed

Open the chart page →

4,800
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-96889.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
librsvg@2.52.5+dfsg-3ubuntu0.2
no fix listed

Open the chart page →

8,360

Container images carrying it

213 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
librsvg@2.60.0+dfsg-1
no fix listed
5
ciscolabs/rtsp-client:latesta7b60ec88285
librsvg@2.48.9-1ubuntu0.20.04.1
no fix listed
3
ciscolabs/rtsp-server:latestb59fc10bb821
librsvg@2.48.9-1ubuntu0.20.04.1
no fix listed
3
library/node:lts64af3819f927
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
librsvg@2.40.13-3
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
3
gjeanmart/safe-ganache-node:latest926264c8f2d1
librsvg@2.54.5+dfsg-1
no fix listed
2
homebridge/homebridge:latest77c685a40911
librsvg@2.58.0+dfsg-1build1
no fix listed
2
kurento/kurento-media-server:latest03c0d34d0828
librsvg@2.58.0+dfsg-1build1
no fix listed
2
library/python:3.7eedf63967cdb
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
librsvg@2.58.0+dfsg-1build1
no fix listed
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
librsvg@2.48.9-1ubuntu0.20.04.1
no fix listed
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
librsvg@2.48.9-1ubuntu0.20.04.1
no fix listed
2
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
librsvg@2.60.0+dfsg-1
no fix listed
2
ghcr.io/paperless-ngx/paperless-ngx:3.2.15fa76604a81d
librsvg@2.60.0+dfsg-1
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
2
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
librsvg@2.60.0+dfsg-1
no fix listed
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
librsvg@2.48.9-1ubuntu0.20.04.1
no fix listed
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
librsvg@2.52.5+dfsg-3ubuntu0.2
no fix listed
1
archivebox/archivebox:0.7.41a5a37331091
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
librsvg@2.48.9-1ubuntu0.20.04.4
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
librsvg@2.54.5+dfsg-1
no fix listed
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
bnjbvr/kresus:0.22.137e216b182c8
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
librsvg@2.48.9-1ubuntu0.20.04.1
no fix listed
1
camptocamp/mapserver:master5f9ddd0b9c5b
librsvg@2.61.3+dfsg-3
no fix listed
1
camptocamp/mapserver:latest98e908c81ff8
librsvg@2.58.0+dfsg-1build1
no fix listed
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
castopod/castopod:1.12.101fd37280cbb2
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
castopod/castopod:1.15.54e4f0440520f
librsvg@2.60.0+dfsg-1
no fix listed
1
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
librsvg@2.60.0+dfsg-1
no fix listed
1
chocobozzz/peertube:v8.1.5052712130691
librsvg@2.60.0+dfsg-1
no fix listed
1
codedesignplus/ms-emails-grpc:latest4fc116f5e879
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
codedesignplus/ms-emails-rest:latest7629e746a5b3
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
librsvg@2.48.9-1ubuntu0.20.04.4
no fix listed
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
librsvg@2.60.0+dfsg-1
no fix listed
1
deconzcommunity/deconz:2.29.2062de2362641
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
deconzcommunity/deconz:2.26.123c86008d73f
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
librsvg@2.60.0+dfsg-1
no fix listed
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
librsvg@2.40.20-2ubuntu0.2
no fix listed
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
librsvg@2.40.20-2ubuntu0.2
no fix listed
1
felipecs8/app-db-connection-test:v129e06c9c6385
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
librsvg@2.48.9-1ubuntu0.20.04.4
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
librsvg@2.54.7+dfsg-1~deb12u1
no fix listed
1
instill/artifact-backend:b28766ac4a393e601ed
librsvg@2.60.0+dfsg-1
no fix listed
1

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.