StackRadar

CVE-2026-0861

High

Advisory

Published 14 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,392
of 17,787 indexed, latest versions
Container images
1,504
deployed by those charts
Fix available
3 of 3
affected packages

CVE-2026-0861 affecting package glibc for versions less than 2.38-18

Carried by container images the latest versions of 1,392 of 17,787 indexed charts deploy, on 1,504 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.31-0ubuntu9, 2.31-0ubuntu9.1, 2.31-0ubuntu9.2, 2.31-0ubuntu9.7+37 more2.31-0ubuntu9.18+esm1, 2.35-0ubuntu3.13, 2.36-9+deb12u14, 2.39-0ubuntu8.7+2 more1,484
glibcapk2.37-r6, 2.38-r6, 2.39-r7, 2.40-r1+6 more2.42-r619
glibcrpm2.38-16.azl32.38-181
OSV records
CGA-2mgg-q5mj-634rDEBIAN-CVE-2026-0861UBUNTU-CVE-2026-0861AZL-74547
Also known as
CGA-r49j-3wwm-c7g6, USN-8005-1

Charts affected

1,392 by stars
ChartLatestAffected imagesRadar Score
giteagiteaOfficialVerified publisher12.7.03 of 4See more

gitea gitea 12.7.0

3 of the 4 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
glibc@2.36-9+deb12u10
2.36-9+deb12u14
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
glibc@2.36-9+deb12u10
2.36-9+deb12u14
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

8,842
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.13

Open the chart page →

6,597
artifact-hubartifact-hubVerified publisher1.23.01 of 7See more

artifact-hub artifact-hub 1.23.0

1 of the 7 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
glibc@2.41-12
2.41-12+deb13u2

Open the chart page →

10,782
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
glibc@2.36-9+deb12u4
2.36-9+deb12u14

Open the chart page →

11,372
openebsopenebsOfficialVerified publisher4.6.12 of 35See more

openebs openebs 4.6.1

2 of the 35 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.7
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

24,009
apisixapisix2.17.01 of 3See more

apisix apisix 2.17.0

1 of the 3 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

3,096
zabbixzabbix-communityVerified publisher7.1.03 of 5See more

zabbix zabbix-community 7.1.0

3 of the 5 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.7
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.7
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.7

Open the chart page →

13,875
keycloakcloudpirates-keycloakVerified publisher0.21.371 of 3See more

keycloak cloudpirates-keycloak 0.21.37

1 of the 3 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
library/postgres:18.0073e7c8b84e2
glibc@2.41-12
2.41-12+deb13u2

Open the chart page →

4,365
connectonepassword-connect2.4.12 of 2See more

connect onepassword-connect 2.4.1

2 of the 2 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
1password/connect-api:1.8.2e915c0c84397
glibc@2.41-12+deb13u1
2.41-12+deb13u2
1password/connect-sync:1.8.26297ca6136c0
glibc@2.41-12+deb13u1
2.41-12+deb13u2

Open the chart page →

2,562
node-problem-detectordeliveryheroVerified publisher2.4.11 of 1See more

node-problem-detector deliveryhero 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
glibc@2.36-9+deb12u13
2.36-9+deb12u14

Open the chart page →

1,901
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
glibc@2.41-12
2.41-12+deb13u2

Open the chart page →

5,378
openldap-stack-hahelm-openldapVerified publisher4.3.31 of 5See more

openldap-stack-ha helm-openldap 4.3.3

1 of the 5 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
jpgouin/openldap:2.6.9-fixbfdd0088c776
glibc@2.36-9+deb12u9
2.36-9+deb12u14

Open the chart page →

5,948
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.13

Open the chart page →

9,194
grafana-agentgrafana0.44.21 of 2See more

grafana-agent grafana 0.44.2

1 of the 2 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
grafana/agent:v0.44.23364714a2f64
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.7

Open the chart page →

3,514
milvusmilvus4.0.312 of 5See more

milvus milvus 4.0.31

2 of the 5 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.18+esm1
milvusdb/milvus:v2.2.13a3a55e1c1497
glibc@2.31-0ubuntu9.7
2.31-0ubuntu9.18+esm1

Open the chart page →

32,353
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
glibc@2.36-9+deb12u9
2.36-9+deb12u14

Open the chart page →

10,648
signozsignoz0.141.11 of 5See more

signoz signoz 0.141.1

1 of the 5 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
signoz/signoz-otel-collector:v0.144.972aa1e4c1ec5
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

7,582
weblateweblateOfficialVerified publisher0.5.362 of 3See more

weblate weblate 0.5.36

2 of the 3 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
glibc@2.36-9+deb12u10
2.36-9+deb12u14
bitnamilegacy/redis:latest5927ff3702df
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

6,761
locustdeliveryheroVerified publisher0.35.01 of 1See more

locust deliveryhero 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
glibc@2.36-9+deb12u8
2.36-9+deb12u14

Open the chart page →

2,660
node-local-dnsdeliveryheroVerified publisher2.9.21 of 1See more

node-local-dns deliveryhero 2.9.2

1 of the 1 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
glibc@2.36-9+deb12u13
2.36-9+deb12u14

Open the chart page →

1,691
emqxemqx-operator5.8.91 of 1See more

emqx emqx-operator 5.8.9

1 of the 1 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
emqx/emqx:5.8.935b46f7aa7a0
glibc@2.41-12
2.41-12+deb13u2

Open the chart page →

2,717
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
glibc@2.36-9+deb12u3
2.36-9+deb12u14

Open the chart page →

4,808
difydoubanVerified publisher0.10.03 of 6See more

dify douban 0.10.0

3 of the 6 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
glibc@2.36-9+deb12u7
2.36-9+deb12u14
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
glibc@2.36-9+deb12u6
2.36-9+deb12u14
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.7

Open the chart page →

19,497
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.7

Open the chart page →

3,645
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
glibc@2.36-9+deb12u4
2.36-9+deb12u14

Open the chart page →

6,949
pyroscopegrafana2.3.11 of 3See more

pyroscope grafana 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
grafana/alloy:v1.12.2f94b1c82957a
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.7

Open the chart page →

3,196
stacks-blockchainhirosystemsVerified publisher2.2.21 of 1See more

stacks-blockchain hirosystems 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

1,385
headscalegabe565Verified publisher0.16.01 of 2See more

headscale gabe565 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
glibc@2.36-9+deb12u9
2.36-9+deb12u14

Open the chart page →

1,985
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.02 of 5See more

openproject openproject-helm-charts 13.11.0

2 of the 5 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
bitnamilegacy/memcached:1.6.24-debian-12-r01d80b6a96f00
glibc@2.36-9+deb12u4
2.36-9+deb12u14
openproject/hocuspocus:release-338001b288dc1359dfb5
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

19,998
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
glibc@2.36-9+deb12u4
2.36-9+deb12u14

Open the chart page →

11,402
zabbixcetic3.1.34 of 5See more

zabbix cetic 3.1.3

4 of the 5 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.13
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.13
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.13
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.13

Open the chart page →

33,907
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
glibc@2.36-9
2.36-9+deb12u14

Open the chart page →

3,700
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
glibc@2.36-9+deb12u7
2.36-9+deb12u14

Open the chart page →

6,550
stacks-blockchain-apihirosystemsVerified publisher6.5.12 of 5See more

stacks-blockchain-api hirosystems 6.5.1

2 of the 5 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
glibc@2.36-9+deb12u10
2.36-9+deb12u14
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
glibc@2.36-9+deb12u13
2.36-9+deb12u14

Open the chart page →

8,387
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
glibc@2.39-0ubuntu8.5
2.39-0ubuntu8.7

Open the chart page →

2,360
cloudflaredkubitodevVerified publisher1.7.91 of 1See more

cloudflared kubitodev 1.7.9

1 of the 1 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
glibc@2.41-12+deb13u1
2.41-12+deb13u2

Open the chart page →

1,442
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
glibc@2.39-0ubuntu8.5
2.39-0ubuntu8.7

Open the chart page →

5,278
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

6,012
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
glibc@2.31-0ubuntu9.14
2.31-0ubuntu9.18+esm1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
glibc@2.35-0ubuntu3.6
2.35-0ubuntu3.13

Open the chart page →

12,830
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
glibc@2.39-0ubuntu8.5
2.39-0ubuntu8.7

Open the chart page →

3,031
netbirdjaconiVerified publisher0.15.13 of 4See more

netbird jaconi 0.15.1

3 of the 4 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
netbirdio/management:0.45.10c9994b393ea
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.7
netbirdio/relay:0.45.1872e3add0e1e
glibc@2.36-9+deb12u10
2.36-9+deb12u14
netbirdio/signal:0.45.146ce5a45538f
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

8,473
litellm-helmlitellm1.101.01 of 2See more

litellm-helm litellm 1.101.0

1 of the 2 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
glibc@2.36-9+deb12u4
2.36-9+deb12u14

Open the chart page →

4,574
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
glibc@2.36-9+deb12u13
2.36-9+deb12u14

Open the chart page →

5,679
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
glibc@2.39-0ubuntu8.2
2.39-0ubuntu8.7

Open the chart page →

3,422
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
glibc@2.31-0ubuntu9.7
2.31-0ubuntu9.18+esm1

Open the chart page →

7,917
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
glibc@2.35-0ubuntu3.4
2.35-0ubuntu3.13

Open the chart page →

11,971
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
glibc@2.36-9+deb12u9
2.36-9+deb12u14

Open the chart page →

5,364
milvusmilvus-helm5.0.282 of 4See more

milvus milvus-helm 5.0.28

2 of the 4 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.13
milvusdb/etcd:3.5.25-r1fededb2f2d63
glibc@2.35-0ubuntu3.11
2.35-0ubuntu3.13

Open the chart page →

10,764
prefect-serverprefectVerified publisher2026.9.141419101 of 2See more

prefect-server prefect 2026.9.14141910

1 of the 2 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
glibc@2.36-9+deb12u9
2.36-9+deb12u14

Open the chart page →

5,448
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-0861.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.18+esm1

Open the chart page →

18,570

Container images carrying it

1,504 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
glibc@2.36-9+deb12u8
2.36-9+deb12u14
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
glibc@2.36-9+deb12u10
2.36-9+deb12u14
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
glibc@2.36-9+deb12u10
2.36-9+deb12u14
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.