StackRadar

CVE-2026-0915

High

Advisory

Published 15 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,564
of 17,781 indexed, latest versions
Container images
1,694
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-0915 affecting package glibc for versions less than 2.38-18

Carried by container images the latest versions of 1,564 of 17,781 indexed charts deploy, on 1,694 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+49 more2.23-0ubuntu11.3+esm9, 2.27-3ubuntu1.6+esm6, 2.31-0ubuntu9.18+esm1, 2.35-0ubuntu3.13+4 more1,667
glibcapk2.37-r6, 2.38-r6, 2.39-r7, 2.40-r1+6 more2.42-r619
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibcrpm2.38-16.azl32.38-181
OSV records
CGA-9f7x-88h6-rvv4DEBIAN-CVE-2026-0915UBUNTU-CVE-2026-0915AZL-74633
Also known as
CGA-rm33-3ph7-88mp, USN-8005-1

Charts affected

1,564 by stars
ChartLatestAffected imagesRadar Score
aramid-participationbiatec-repoVerified publisher4.4.11 of 1See more

aramid-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.13

Open the chart page →

7,190
aramid-relaybiatec-repoVerified publisher4.4.11 of 1See more

aramid-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.7

Open the chart page →

5,059
voimain-participationbiatec-repoVerified publisher4.4.11 of 1See more

voimain-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.13

Open the chart page →

7,190
prometheus-airbyte-exporterbotify-helm-chartsVerified publisher0.7.11 of 1See more

prometheus-airbyte-exporter botify-helm-charts 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
glibc@2.36-9+deb12u3
2.36-9+deb12u14

Open the chart page →

2,897
geoserver-cloudcamptocamp20.0.56 of 11See more

geoserver-cloud camptocamp2 0.0.5

6 of the 11 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.18+esm1
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.18+esm1
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.18+esm1
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.18+esm1
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.18+esm1
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.18+esm1

Open the chart page →

84,444
geoserverCloudcamptocamp20.0.66 of 11See more

geoserverCloud camptocamp2 0.0.6

6 of the 11 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.18+esm1
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.18+esm1
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.18+esm1
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.18+esm1
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.18+esm1
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.18+esm1

Open the chart page →

84,444
cbioportalcbioportalOfficialVerified publisher1.1.01 of 1See more

cbioportal cbioportal 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.7

Open the chart page →

3,674
cert-vaultcert-vaultOfficialVerified publisher2.12.04 of 7See more

cert-vault cert-vault 2.12.0

4 of the 7 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
glibc@2.36-9+deb12u10
2.36-9+deb12u14
bitnamilegacy/postgresql:17.4.0-debian-12-r11fb3806e823c2
glibc@2.36-9+deb12u10
2.36-9+deb12u14
bitnamilegacy/redis:7.4.2-debian-12-r66a5b1d0b5942
glibc@2.36-9+deb12u10
2.36-9+deb12u14
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

15,863
passbolt-hachristianhuthVerified publisher6.0.12 of 4See more

passbolt-ha christianhuth 6.0.1

2 of the 4 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
glibc@2.36-9+deb12u10
2.36-9+deb12u14
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

10,817
squestchristianhuthVerified publisher6.6.73 of 4See more

squest christianhuth 6.6.7

3 of the 4 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
glibc@2.36-9+deb12u10
2.36-9+deb12u14
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
glibc@2.36-9+deb12u10
2.36-9+deb12u14
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

9,971
typo3christianhuthVerified publisher7.7.02 of 2See more

typo3 christianhuth 7.7.0

2 of the 2 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
glibc@2.36-9+deb12u10
2.36-9+deb12u14
martinhelmich/typo3:12.4c83a4f3fd7ae
glibc@2.36-9+deb12u13
2.36-9+deb12u14

Open the chart page →

8,466
chromadbchromadb-helmVerified publisher0.2.21 of 1See more

chromadb chromadb-helm 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
ghcr.io/chroma-core/chroma:1.5.3cfd193653bd6
glibc@2.41-12+deb13u1
2.41-12+deb13u2

Open the chart page →

1,432
nethermindchronicleVerified publisher0.0.131 of 1See more

nethermind chronicle 0.0.13

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
nethermind/nethermind:1.31.9aeca3b55bda5
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.7

Open the chart page →

2,031
spectrechronicleVerified publisher0.3.81 of 1See more

spectre chronicle 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
glibc@2.36-9+deb12u13
2.36-9+deb12u14

Open the chart page →

1,515
cloudflared-ingress-operatorcloudflared-ingress-operatorVerified publisher0.3.21 of 1See more

cloudflared-ingress-operator cloudflared-ingress-operator 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
glibc@2.41-12+deb13u1
2.41-12+deb13u2

Open the chart page →

1,724
tensorflow-notebookcloudnativeapp0.1.21 of 1See more

tensorflow-notebook cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
tensorflow/tensorflow:1.6.0-devel1e3172090703
glibc@2.23-0ubuntu10
2.23-0ubuntu11.3+esm9

Open the chart page →

36,094
cloudttycloudtty0.8.91 of 2See more

cloudtty cloudtty 0.8.9

1 of the 2 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
ghcr.io/cloudtty/cloudshell-operator:v0.8.9e43ad91f0684
glibc@2.36-9+deb12u13
2.36-9+deb12u14

Open the chart page →

3,951
clustereye-stackclustereyeVerified publisher0.1.11 of 5See more

clustereye-stack clustereye 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.31.02bf7f042e396
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.13

Open the chart page →

4,855
cluster-setupcluster-setup1.5.01 of 8See more

cluster-setup cluster-setup 1.5.0

1 of the 8 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.7

Open the chart page →

10,037
istio-allcode4devsVerified publisher1.2.02 of 6See more

istio-all code4devs 1.2.0

2 of the 6 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
glibc@2.40-r3
2.42-r6
istio/ztunnel:1.24.2-distroless3e475eb88965
glibc@2.40-r3
2.42-r6

Open the chart page →

4,784
istio-control-planecode4devsVerified publisher1.0.02 of 3See more

istio-control-plane code4devs 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
glibc@2.40-r3
2.42-r6
istio/ztunnel:1.24.2-distroless3e475eb88965
glibc@2.40-r3
2.42-r6

Open the chart page →

2,360
commonground-gatewaycommonground-gateway1.5.41 of 7See more

commonground-gateway commonground-gateway 1.5.4

1 of the 7 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
glibc@2.36-9
2.36-9+deb12u14

Open the chart page →

9,724
cosmotech-copilot-apicosmotech-apiVerified publisher0.1.11 of 1See more

cosmotech-copilot-api cosmotech-api 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
glibc@2.41-12+deb13u1
2.41-12+deb13u2

Open the chart page →

11,205
oci-registrycronce0.4.51 of 1See more

oci-registry cronce 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
mcronce/oci-registry:v0.4.509519cd7bd2f
glibc@2.36-9+deb12u4
2.36-9+deb12u14

Open the chart page →

1,300
paperless-ngxcrystalnetVerified publisher0.2.221 of 3See more

paperless-ngx crystalnet 0.2.22

1 of the 3 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
glibc@2.36-9+deb12u8
2.36-9+deb12u14

Open the chart page →

13,761
nifid4nVerified publisher2.0.01 of 5See more

nifi d4n 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
glibc@2.35-0ubuntu3.7
2.35-0ubuntu3.13

Open the chart page →

5,398
data-fairdata354-helmVerified publisher1.1.22 of 12See more

data-fair data354-helm 1.1.2

2 of the 12 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
glibc@2.31-0ubuntu9.17
2.31-0ubuntu9.18+esm1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.18+esm1

Open the chart page →

38,346
datacube-explorerdatacube-charts0.5.321 of 1See more

datacube-explorer datacube-charts 0.5.32

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
opendatacube/explorer:latest120457ffcd69
glibc@2.39-0ubuntu8.5
2.39-0ubuntu8.7

Open the chart page →

4,854
dbrepodbrepo1.13.315 of 25See more

dbrepo dbrepo 1.13.3

15 of the 25 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
glibc@2.36-9+deb12u9
2.36-9+deb12u14
bitnamilegacy/mariadb:11.4.5-debian-12-r128bc50a0961a7
glibc@2.36-9+deb12u10
2.36-9+deb12u14
bitnamilegacy/mariadb-galera:11.3.2-debian-12-r9aee9c668098f
glibc@2.36-9+deb12u7
2.36-9+deb12u14
bitnamilegacy/mysqld-exporter:0.15.1-debian-12-r2611a5f0b79e79
glibc@2.36-9+deb12u7
2.36-9+deb12u14
bitnamilegacy/nginx:1.28.0-debian-12-r0eaf9066e86f6
glibc@2.36-9+deb12u10
2.36-9+deb12u14
bitnamilegacy/openldap:2.6.8-debian-12-r16e412c178ef9
glibc@2.36-9+deb12u7
2.36-9+deb12u14
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
glibc@2.36-9+deb12u8
2.36-9+deb12u14
bitnamilegacy/os-shell:12-debian-12-r3217444b4b2c96
glibc@2.36-9+deb12u8
2.36-9+deb12u14
bitnamilegacy/postgres-exporter:0.15.0-debian-12-r44e7e1b3a90682
glibc@2.36-9+deb12u8
2.36-9+deb12u14
bitnamilegacy/postgresql:17.0.0-debian-12-r9d885ac277163
glibc@2.36-9+deb12u8
2.36-9+deb12u14
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
glibc@2.36-9+deb12u10
2.36-9+deb12u14
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
glibc@2.36-9+deb12u8
2.36-9+deb12u14
bitnamilegacy/rabbitmq:3.13.7-debian-12-r2cd593809e359
glibc@2.36-9+deb12u7
2.36-9+deb12u14
bitnamilegacy/seaweedfs:3.87.0-debian-12-r10cb31d0fc356
glibc@2.36-9+deb12u10
2.36-9+deb12u14
bitnamilegacy/valkey:latest0384ca2eec63
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

52,635
dial-coredialOfficialVerified publisher6.0.01 of 2See more

dial-core dial 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
glibc@2.41-12+deb13u1
2.41-12+deb13u2

Open the chart page →

1,521
powershelluniversaldigitalhubVerified publisher0.1.21 of 1See more

powershelluniversal digitalhub 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
ironmansoftware/universal:3.3.1-ubuntu-20.041943c73cce31
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.18+esm1

Open the chart page →

6,940
directusdirectus-io2.1.02 of 3See more

directus directus-io 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
glibc@2.36-9+deb12u10
2.36-9+deb12u14
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

7,473
dominodominoVerified publisher0.1.112 of 3See more

domino domino 0.1.11

2 of the 3 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
glibc@2.41-12
2.41-12+deb13u2
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
glibc@2.36-9+deb12u4
2.36-9+deb12u14

Open the chart page →

8,823
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.13

Open the chart page →

10,858
dragonfly-stackdragonflyVerified publisher0.1.21 of 7See more

dragonfly-stack dragonfly 0.1.2

1 of the 7 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
dragonflyoss/client:v0.1.82edf3e921f4e0
glibc@2.36-9+deb12u7
2.36-9+deb12u14

Open the chart page →

18,376
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.7

Open the chart page →

5,670
elchi-stackelchi1.13.03 of 10See more

elchi-stack elchi 1.13.0

3 of the 10 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.81ffa82edee00
glibc@2.31-0ubuntu9.16
2.31-0ubuntu9.18+esm1
envoyproxy/envoy:v1.33.056da5afd7df3
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.13
library/mongo:6.0.12646902910d6a
glibc@2.35-0ubuntu3.6
2.35-0ubuntu3.13

Open the chart page →

15,383
enbuildenbuildVerified publisher0.0.501 of 6See more

enbuild enbuild 0.0.50

1 of the 6 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
glibc@2.36-9+deb12u7
2.36-9+deb12u14

Open the chart page →

31,510
kubevirtencircle360-ossVerified publisher0.2.11 of 1See more

kubevirt encircle360-oss 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
quay.io/kubevirt/virt-operator:v1.7.037d2ef21e3e5
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

850
beaconchain-explorerethereum-helm-chartsVerified publisher0.1.61 of 2See more

beaconchain-explorer ethereum-helm-charts 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
glibc@2.35-0ubuntu3.9
2.35-0ubuntu3.13

Open the chart page →

3,048
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
glibc@2.36-9+deb12u7
2.36-9+deb12u14

Open the chart page →

11,458
mcrouterevryfs-ossVerified publisher0.4.01 of 2See more

mcrouter evryfs-oss 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
glibc@2.27-3ubuntu1.6
2.27-3ubuntu1.6+esm6

Open the chart page →

6,500
akauntingf3k-techVerified publisher1.3121.01 of 4See more

akaunting f3k-tech 1.3121.0

1 of the 4 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:latestbbd4e17f1ef8
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

4,333
cap-captcha-serverf3k-techVerified publisher0.21.01 of 1See more

cap-captcha-server f3k-tech 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
tiago2/cap:2.159f5ae4e261e
glibc@2.41-12+deb13u1
2.41-12+deb13u2

Open the chart page →

1,664
recaptcha-v3-verifierf3k-techVerified publisher1.110.01 of 1See more

recaptcha-v3-verifier f3k-tech 1.110.0

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
f3ktech/recaptcha-v3-verifier:1.1.048e78987cf91
glibc@2.36-9+deb12u13
2.36-9+deb12u14

Open the chart page →

1,208
fastapi-microservice-appfast-api-microservice-app1.3.03 of 4See more

fastapi-microservice-app fast-api-microservice-app 1.3.0

3 of the 4 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
omkara25/simple-microservice-app-order-service:v2.18327546c7aac
glibc@2.36-9+deb12u10
2.36-9+deb12u14
omkara25/simple-microservice-app-payment-service:v2afff40172b6b
glibc@2.36-9+deb12u10
2.36-9+deb12u14
omkara25/simple-microservice-app-user-service:v2d62cba548580
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

9,562
federidfederidOfficialVerified publisher0.1.21 of 1See more

federid federid 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
federid/webhook:0.1.0fbfb7c6510a7
glibc@2.36-9+deb12u9
2.36-9+deb12u14

Open the chart page →

2,064
zabbix-server-mysqlfermosit3.0.23 of 4See more

zabbix-server-mysql fermosit 3.0.2

3 of the 4 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.7
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.7
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.7

Open the chart page →

12,840
flink-operatorflink-operator0.1.11 of 2See more

flink-operator flink-operator 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
glibc@2.27-3ubuntu1
2.27-3ubuntu1.6+esm6

Open the chart page →

12,908
bazarrgeek-cookbookVerified publisher10.6.21 of 1See more

bazarr geek-cookbook 10.6.2

1 of the 1 container images this version deploys carry CVE-2026-0915.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.18+esm1

Open the chart page →

17,377

Container images carrying it

1,694 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
castopod/castopod:1.15.54e4f0440520f
glibc@2.41-12+deb13u1
2.41-12+deb13u2
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.7
1
chaerr/kridge:demo-operator-v0.1.266833deec017
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.18+esm1
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
glibc@2.36-9+deb12u9
2.36-9+deb12u14
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
eglibc@2.19-0ubuntu6.15
no fix listed
1
chetangautamm/repo:sipp.v3e7f7049e1544
glibc@2.31-0ubuntu9.1
2.31-0ubuntu9.18+esm1
1
cheveo/azp-agent:1.0.282240f890884
glibc@2.35-0ubuntu3.9
2.35-0ubuntu3.13
1
cheyang/distributed-tf:1.6.046cc34755493
glibc@2.23-0ubuntu10
2.23-0ubuntu11.3+esm9
1
chriseaton/adventureworks:latest54c3384ce701
glibc@2.35-0ubuntu3.9
2.35-0ubuntu3.13
1
circleci/runner:launch-agent9bdc62f02162
glibc@2.31-0ubuntu9.16
2.31-0ubuntu9.18+esm1
1
ciscolabs/msm-nc:0710202336d02faad958
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.13
1
citizenstig/httpbin:latestb81c818ccb86
glibc@2.23-0ubuntu5
2.23-0ubuntu11.3+esm9
1
ckulka/baikal:0.10.1-nginx434bdd162247
glibc@2.36-9+deb12u10
2.36-9+deb12u14
1
clickhouse/clickhouse-server:24.81ffa82edee00
glibc@2.31-0ubuntu9.16
2.31-0ubuntu9.18+esm1
1
clickhouse/clickhouse-server:24.4.12e6587b81a26
glibc@2.31-0ubuntu9.15
2.31-0ubuntu9.18+esm1
1
clickhouse/clickhouse-server:23.8512bb8a21483
glibc@2.31-0ubuntu9.16
2.31-0ubuntu9.18+esm1
1
clickhouse/clickhouse-server:25.3.2.398745843b17f9
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.13
1
clickhouse/clickhouse-server:24.12.6a65ca89ddbe8
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.13
1
clickhouse/clickhouse-server:25.3.14.14b627d7a9bc0e
glibc@2.35-0ubuntu3.11
2.35-0ubuntu3.13
1
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.13
1
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
glibc@2.35-0ubuntu3.11
2.35-0ubuntu3.13
1
cloudflare/cloudflared:2025.8.0eb5c9324efe3
glibc@2.36-9+deb12u10
2.36-9+deb12u14
1
cloudve/janis-terminal:latestaf56e77ca587
glibc@2.27-3ubuntu1
2.27-3ubuntu1.6+esm6
1
cloudve/ttyd:latestd79c1c5881c0
glibc@2.27-3ubuntu1
2.27-3ubuntu1.6+esm6
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
cm2network/squad:latest8cba47f53df5
glibc@2.41-12+deb13u1
2.41-12+deb13u2
1
collabora/code:24.04.13.2.101dc4ab83977
glibc@2.36-9+deb12u9
2.36-9+deb12u14
1
collabora/code:23.05.10.1.105299b452f7f
glibc@2.36-9+deb12u4
2.36-9+deb12u14
1
consensys/teku:25.4.1bf6ecd2ea716
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.7
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
glibc@2.36-9+deb12u8
2.36-9+deb12u14
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
glibc@2.35-0ubuntu3.11
2.35-0ubuntu3.13
1
cortezaproject/corteza:2024.9.08eb7a26605c9
glibc@2.31-0ubuntu9.16
2.31-0ubuntu9.18+esm1
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
glibc@2.35-0ubuntu3.10
2.35-0ubuntu3.13
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
glibc@2.36-9+deb12u10
2.36-9+deb12u14
1
countly/countly-server:25.05.4e3c238248f99
glibc@2.31-0ubuntu9.7
2.31-0ubuntu9.18+esm1
1
cradlepoint/pgbouncer:1.0.18f5720b0cd03
glibc@2.27-3ubuntu1
2.27-3ubuntu1.6+esm6
1
cribl/cribl:3.0.2762747cb6796
glibc@2.27-3ubuntu1.4
2.27-3ubuntu1.6+esm6
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
glibc@2.23-0ubuntu11.3
2.23-0ubuntu11.3+esm9
1
cspconsole/config-provider:1.0.365524a26a6c23
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
cspconsole/report-collector:1.0.15839750248193b
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
cspconsole/report-processor:1.0.279a2d8840bfdf
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
cubejs/cubestore:v1.5.334ac523a9bab
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
glibc@2.41-12
2.41-12+deb13u2
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
glibc@2.36-9+deb12u3
2.36-9+deb12u14
1
daedalusproject/base_kubectl:latest6f72b5119eda
glibc@2.31-0ubuntu9.1
2.31-0ubuntu9.18+esm1
1
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
dannielkil/book-frontend:latest937993927694
glibc@2.36-9+deb12u8
2.36-9+deb12u14
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.