StackRadar

CVE-2021-40528

Medium

Advisory

Published 25 Jun 2021In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
859
of 17,787 indexed, latest versions
Container images
746
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libgcrypt security update

Carried by container images the latest versions of 859 of 17,787 indexed charts deploy, on 746 images.

Affected packageAffected versionsFixed inImages
libgcrypt20deb1.6.5-2ubuntu0.2, 1.6.5-2ubuntu0.3, 1.6.5-2ubuntu0.4, 1.6.5-2ubuntu0.5+10 more1.6.5-2ubuntu0.6+esm1, 1.7.6-2+deb9u4, 1.8.1-4ubuntu1.3, 1.8.1-4ubuntu1.fips.3+2 more627
libgcryptrpm1.8.2-lp151.9.4.1, 1.8.3-2.el8, 1.8.3-4.el8, 1.8.5-4.el8+1 more0:1.8.5-7.el8_6, 1.10.1-1.171
libgcryptapk1.8.5-r0, 1.8.7-r0, 1.8.8-r01.8.8-r148
OSV records
ALPINE-CVE-2021-40528RHSA-2022:5311UBUNTU-CVE-2021-40528DLA-2691-1openSUSE-SU-2024:12540-1
Also known as
USN-5080-1, USN-5080-2

Charts affected

859 by stars
ChartLatestAffected imagesRadar Score
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4

Open the chart page →

22,665
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1

Open the chart page →

6,323
nginxwiremindVerified publisher2.1.11 of 1See more

nginx wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
library/nginx:1.17-alpine763e7f0188e3
libgcrypt@1.8.5-r0
1.8.8-r1

Open the chart page →

966
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libgcrypt@1.8.5-6.el8
0:1.8.5-7.el8_6

Open the chart page →

11,592
upsourcexykongVerified publisher0.1.11 of 1See more

upsource xykong 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4

Open the chart page →

702
helmexampleycztest0.1.01 of 1See more

helmexample ycztest 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4

Open the chart page →

702
mychartyi-test-chart0.1.01 of 1See more

mychart yi-test-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4

Open the chart page →

702
helmexampleyunpeng-helmexample0.1.01 of 1See more

helmexample yunpeng-helmexample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4

Open the chart page →

702
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2021-40528.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
libgcrypt20@1.8.1-4ubuntu1.3
1.8.1-4ubuntu1.fips.3
yandex/clickhouse-server:21.3.204eccfffb01d7
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1

Open the chart page →

9,250

Container images carrying it

746 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
libgcrypt@1.8.2-lp151.9.4.1
1.10.1-1.1
1
chaerr/kridge:demo-operator-v0.1.266833deec017
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
chetangautamm/repo:sipp.v3e7f7049e1544
libgcrypt20@1.8.5-5ubuntu1
1.8.5-5ubuntu1.1
1
cheyang/distributed-tf:1.6.046cc34755493
libgcrypt20@1.6.5-2ubuntu0.3
1.6.5-2ubuntu0.6+esm1
1
circleci/runner:launch-agent9bdc62f02162
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
citizenstig/httpbin:latestb81c818ccb86
libgcrypt20@1.6.5-2ubuntu0.2
1.6.5-2ubuntu0.6+esm1
1
clickhouse/clickhouse-server:24.81ffa82edee00
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
clickhouse/clickhouse-server:24.4.12e6587b81a26
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
clickhouse/clickhouse-server:23.8512bb8a21483
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
cloudve/janis-terminal:latestaf56e77ca587
libgcrypt20@1.8.1-4ubuntu1.2
1.8.1-4ubuntu1.3
1
cloudve/ttyd:latestd79c1c5881c0
libgcrypt20@1.8.1-4ubuntu1.2
1.8.1-4ubuntu1.3
1
cockroachdb/cockroach-operator:v2.1.0983312754620
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
codaprotocol/buildkite-exporter:0.2.137c68e67a401
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
codaprotocol/coda-user-agent:0.1.54ba4dd3a041f
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
codeskyblue/gohttpserver:latestcaa862590e34
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
conduction/agendaservice-nginx:lateste1c176458aaf
libgcrypt20@1.7.6-2+deb9u2
1.7.6-2+deb9u4
1
conduction/balance-registration-nginx:dev9e24264ea8f3
libgcrypt20@1.7.6-2+deb9u2
1.7.6-2+deb9u4
1
conduction/balance-registration-varnish:dev07c44005da9d
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
conduction/betaalservice-nginx:latestd3577ddd5c67
libgcrypt20@1.7.6-2+deb9u2
1.7.6-2+deb9u4
1
conduction/cgrc-nginx:devd8e23f10e882
libgcrypt20@1.7.6-2+deb9u2
1.7.6-2+deb9u4
1
conduction/cgrc-varnish:deve154d5781c8a
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
conduction/checkin-component-nginx:dev583d2cd8476c
libgcrypt20@1.7.6-2+deb9u2
1.7.6-2+deb9u4
1
conduction/checkin-component-varnish:devef3a3fb0ad47
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
conduction/conduction-ui-nginx:devd9b38e234de9
libgcrypt20@1.7.6-2+deb9u2
1.7.6-2+deb9u4
1
conduction/conduction-ui-varnish:dev5f5add2c12e0
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
conduction/contactmoment-component-nginx:dev353dc46303ac
libgcrypt20@1.7.6-2+deb9u2
1.7.6-2+deb9u4
1
conduction/contactmoment-component-varnish:deve3546b97faea
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
conduction/docparser-nginx:dev08524d8327b8
libgcrypt20@1.7.6-2+deb9u2
1.7.6-2+deb9u4
1
conduction/docparser-varnish:dev45f20c4cd2fa
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
conduction/kvk-nginx:devcf163d2b95b5
libgcrypt20@1.7.6-2+deb9u2
1.7.6-2+deb9u4
1
conduction/kvk-varnish:dev8722700f1768
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
conduction/pan-nginx:devaf3e9f551ad1
libgcrypt20@1.7.6-2+deb9u2
1.7.6-2+deb9u4
1
conduction/pan-varnish:devc3e5737ae68f
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
libgcrypt@1.8.5-6.el8
0:1.8.5-7.el8_6
1
confluentinc/cp-kafkacat:4.1.25f990b0f43c9
libgcrypt20@1.7.6-2+deb9u3
1.7.6-2+deb9u4
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
cortezaproject/corteza:2024.9.08eb7a26605c9
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
countly/countly-server:25.05.4e3c238248f99
libgcrypt20@1.8.5-5ubuntu1.1
1.8.5-5ubuntu1.fips.1.1
1
cradlepoint/pgbouncer:1.0.18f5720b0cd03
libgcrypt20@1.8.1-4ubuntu1.1
1.8.1-4ubuntu1.3
1
craftypath/sops-operator:v0.8.0402a0024c732
libgcrypt@1.8.5-4.el8
0:1.8.5-7.el8_6
1
cribl/cribl:3.0.2762747cb6796
libgcrypt20@1.8.1-4ubuntu1.2
1.8.1-4ubuntu1.3
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
libgcrypt20@1.6.5-2ubuntu0.6
1.6.5-2ubuntu0.6+esm1
1
ctron/hawkbit-operator:0.1.48fdea8f76499
libgcrypt@1.8.3-4.el8
0:1.8.5-7.el8_6
1
daedalusproject/base_kubectl:latest6f72b5119eda
libgcrypt20@1.8.5-5ubuntu1
1.8.5-5ubuntu1.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.