CVE-2026-1489
MediumAdvisory
Published 27 Jan 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.4
- base score, highest
- EPSS
- 0.003
- 26th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 333
- of 17,781 indexed, latest versions
- Container images
- 344
- deployed by those charts
- Fix available
- 1 of 1
- affected package
The matching OSV records carry no description.
Carried by container images the latest versions of 333 of 17,781 indexed charts deploy, on 344 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| glib2.0deb | 2.40.2-0ubuntu1, 2.48.2-0ubuntu1, 2.48.2-0ubuntu4.1, 2.48.2-0ubuntu4.4+40 more | 2.72.4-0ubuntu2.9, 2.74.6-2+deb12u9, 2.80.0-6ubuntu3.8, 2.84.4-3~deb13u3+1 more | 344 |
- OSV records
- DEBIAN-CVE-2026-1489UBUNTU-CVE-2026-1489
- Also known as
- USN-8017-1
Charts affected
333 by stars
Container images carrying it
344 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | ce85ef0ce665 | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| ghcr.io/ | 1cdfd1bcf476 | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| ghcr.io/ | 85c9935ff31b | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| ghcr.io/ | ff2af53897e7 | glib2.0 | no fix listed | 1 |
| ghcr.io/ | 0642357c5dbd | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| ghcr.io/ | 4b05bcd28e69 | glib2.0 | 2.84.4-3~deb13u3 | 1 |
| ghcr.io/ | 57ad9565bff3 | glib2.0 | 2.84.4-3~deb13u3 | 1 |
| ghcr.io/ | 665f2f5cc548 | glib2.0 | 2.84.4-3~deb13u3 | 1 |
| ghcr.io/ | ab255bea133e | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| ghcr.io/ | b89f83345532 | glib2.0 | 2.84.4-3~deb13u3 | 1 |
| ghcr.io/ | ed07e7ca098d | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| ghcr.io/ | 3c8375dc5487 | glib2.0 | no fix listed | 1 |
| ghcr.io/ | 5ecb16015aa8 | glib2.0 | no fix listed | 1 |
| ghcr.io/ | 1dcca70c6446 | glib2.0 | no fix listed | 1 |
| ghcr.io/ | 8368359c8dd0 | glib2.0 | no fix listed | 1 |
| ghcr.io/ | 91fca773a63f | glib2.0 | 2.80.0-6ubuntu3.8 | 1 |
| ghcr.io/ | 89969b78fb07 | glib2.0 | 2.80.0-6ubuntu3.8 | 1 |
| ghcr.io/ | bf816072380e | glib2.0 | 2.80.0-6ubuntu3.8 | 1 |
| ghcr.io/ | d7bdfa7b41da | glib2.0 | 2.80.0-6ubuntu3.8 | 1 |
| ghcr.io/ | 8e3cb38953a3 | glib2.0 | 2.80.0-6ubuntu3.8 | 1 |
| ghcr.io/ | 26953ec68d5d | glib2.0 | no fix listed | 1 |
| ghcr.io/ | d7c43c3135c6 | glib2.0 | no fix listed | 1 |
| ghcr.io/ | a56dfe91f5b1 | glib2.0 | 2.72.4-0ubuntu2.9 | 1 |
| ghcr.io/ | 916746209ac5 | glib2.0 | 2.72.4-0ubuntu2.9 | 1 |
| ghcr.io/ | 63873f3f698e | glib2.0 | 2.72.4-0ubuntu2.9 | 1 |
| ghcr.io/ | 6e04659a3baa | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| ghcr.io/ | dbaa8527bf4c | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| ghcr.io/ | d19d886d5090 | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| ghcr.io/ | 8e6a9516eac0 | glib2.0 | no fix listed | 1 |
| ghcr.io/ | 7bff29dcec72 | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| ghcr.io/ | fbba58ddb1a6 | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| ghcr.io/ | 7dc0ee57b628 | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| mcr.microsoft.com/ | 13221ac5f673 | glib2.0 | no fix listed | 1 |
| mcr.microsoft.com/ | 49a57dc220b1 | glib2.0 | no fix listed | 1 |
| mcr.microsoft.com/ | fbf79e0fea59 | glib2.0 | no fix listed | 1 |
| public.ecr.aws/ | b1493760c716 | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| public.ecr.aws/ | 5cd62142d6ed | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| public.ecr.aws/ | 046ef5c9ed50 | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| public.ecr.aws/ | 573779e57fae | glib2.0 | no fix listed | 1 |
| public.ecr.aws/ | f74851ce31f5 | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| quay.io/ | a2d3a4c67b0f | glib2.0 | no fix listed | 1 |
| quay.io/ | c6a934439421 | glib2.0 | no fix listed | 1 |
| quay.io/ | e0d9b93dbf2b | glib2.0 | 2.74.6-2+deb12u9 | 1 |
| registry.gitlab.com/ | f6385712935f | glib2.0 | no fix listed | 1 |