StackRadar

CVE-2021-40528

Medium

Advisory

Published 25 Jun 2021In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
859
of 17,790 indexed, latest versions
Container images
746
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libgcrypt security update

Carried by container images the latest versions of 859 of 17,790 indexed charts deploy, on 746 images.

Affected packageAffected versionsFixed inImages
libgcrypt20deb1.6.5-2ubuntu0.2, 1.6.5-2ubuntu0.3, 1.6.5-2ubuntu0.4, 1.6.5-2ubuntu0.5+10 more1.6.5-2ubuntu0.6+esm1, 1.7.6-2+deb9u4, 1.8.1-4ubuntu1.3, 1.8.1-4ubuntu1.fips.3+2 more627
libgcryptrpm1.8.2-lp151.9.4.1, 1.8.3-2.el8, 1.8.3-4.el8, 1.8.5-4.el8+1 more0:1.8.5-7.el8_6, 1.10.1-1.171
libgcryptapk1.8.5-r0, 1.8.7-r0, 1.8.8-r01.8.8-r148
OSV records
ALPINE-CVE-2021-40528RHSA-2022:5311UBUNTU-CVE-2021-40528DLA-2691-1openSUSE-SU-2024:12540-1
Also known as
USN-5080-1, USN-5080-2

Charts affected

859 by stars
ChartLatestAffected imagesRadar Score
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4

Open the chart page →

22,693
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1

Open the chart page →

6,326
nginxwiremindVerified publisher2.1.11 of 1See more

nginx wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
library/nginx:1.17-alpine763e7f0188e3
libgcrypt@1.8.5-r0
1.8.8-r1

Open the chart page →

966
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libgcrypt@1.8.5-6.el8
0:1.8.5-7.el8_6

Open the chart page →

11,603
upsourcexykongVerified publisher0.1.11 of 1See more

upsource xykong 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4

Open the chart page →

702
helmexampleycztest0.1.01 of 1See more

helmexample ycztest 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4

Open the chart page →

702
mychartyi-test-chart0.1.01 of 1See more

mychart yi-test-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4

Open the chart page →

702
helmexampleyunpeng-helmexample0.1.01 of 1See more

helmexample yunpeng-helmexample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4

Open the chart page →

702
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
libgcrypt20@1.8.1-4ubuntu1.3
1.8.1-4ubuntu1.fips.3
yandex/clickhouse-server:21.3.204eccfffb01d7
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1

Open the chart page →

9,256

Container images carrying it

746 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
ghcr.io/spidernet-io/spiderpool/spiderpool-agent:v1.2.08bb9411e47e0
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
ghcr.io/tauffer-consulting/domino-frontend:latesta923b86a0903
libgcrypt@1.8.7-r0
1.8.8-r1
1
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
libgcrypt20@1.8.1-4ubuntu1.3
1.8.1-4ubuntu1.fips.3
1
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
libgcrypt20@1.8.1-4ubuntu1.3
1.8.1-4ubuntu1.fips.3
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
libgcrypt20@1.8.1-4ubuntu1.3
1.8.1-4ubuntu1.fips.3
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
libgcrypt20@1.8.1-4ubuntu1.3
1.8.1-4ubuntu1.fips.3
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libgcrypt20@1.8.5-5ubuntu1
1.8.5-5ubuntu1.1
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
quay.io/coreos/etcd:v3.4.17c2126f99e5c9
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
quay.io/coreos/etcd:v3.4.16ea7bb56278ab
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
libgcrypt20@1.8.1-4ubuntu1.3
1.8.1-4ubuntu1.fips.3
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
libgcrypt@1.8.5-6.el8
0:1.8.5-7.el8_6
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
libgcrypt@1.8.5-6.el8
0:1.8.5-7.el8_6
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
libgcrypt@1.8.5-6.el8
0:1.8.5-7.el8_6
1
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
libgcrypt@1.8.5-6.el8
0:1.8.5-7.el8_6
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
libgcrypt@1.8.3-4.el8
0:1.8.5-7.el8_6
1
quay.io/ibmgaragecloud/nodejs:latest01c3b7acb301
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
quay.io/ibmgaragecloud/slack-notifications:latest041df93e2bac
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
libgcrypt@1.8.5-6.el8
0:1.8.5-7.el8_6
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libgcrypt@1.8.5-6.el8
0:1.8.5-7.el8_6
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
libgcrypt@1.8.3-4.el8
0:1.8.5-7.el8_6
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
libgcrypt20@1.6.5-2ubuntu0.6
1.6.5-2ubuntu0.6+esm1
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
quay.io/openshift/origin-cli:4.66722d5041b47
libgcrypt@1.8.3-4.el8
0:1.8.5-7.el8_6
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
libgcrypt@1.8.3-4.el8
0:1.8.5-7.el8_6
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libgcrypt20@1.6.5-2ubuntu0.5
1.6.5-2ubuntu0.6+esm1
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
quay.io/renokico/laravel-helm-demo:octane-0.6.0cad83090c58f
libgcrypt@1.8.8-r0
1.8.8-r1
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
libgcrypt@1.8.5-6.el8
0:1.8.5-7.el8_6
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
libgcrypt20@1.8.5-5ubuntu1
1.8.5-5ubuntu1.1
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
libgcrypt@1.8.5-6.el8
0:1.8.5-7.el8_6
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.