StackRadar

CVE-2026-18374

Medium

Advisory

Published 27 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.9
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,754
of 17,813 indexed, latest versions
Container images
2,809
deployed by those charts
Fix available
2 of 5
affected packages

CVE-2026-18374 affecting package glibc 2.38-21

Carried by container images the latest versions of 2,754 of 17,813 indexed charts deploy, on 2,809 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+66 more2.41-12+deb13u3+e72,717
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibc-2.44apk2.44-r1, 2.44-r4, 2.44-r52.44-r663
glibcrpm2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3no fix listed19
glibc-2.43apk2.43-r14no fix listed3
OSV records
DEBIAN-CVE-2026-18374UBUNTU-CVE-2026-18374AZL-98042CGA-27g8-4xhq-hhr3CGA-2w63-hvq4-f4pcECHO-9169-1fd9-0c1c
Also known as
CGA-2r7g-4qmv-r3hh, CGA-3qmp-39qm-cjf8, CGA-3xw7-x4r7-x678, CGA-5g65-xm2q-rjhf, CGA-5wh2-vg99-j76x, CGA-63j2-v7q6-8x84, CGA-6rf5-rrq5-7pff, CGA-772j-3386-6g56, CGA-79v3-g2j9-ffq2, CGA-8hxc-pvg5-xr9j, CGA-c62g-2q4h-pjjg, CGA-f52m-j726-w2p6, CGA-h33h-m88h-4gc6, CGA-m923-g68q-v4rq, CGA-m9qj-fr43-382g, CGA-mm85-9c9x-q266, CGA-rh5w-p243-vcf7, CGA-v3jf-jvqj-vgxj, CGA-x2q5-w2xg-rgqc, CGA-x3rq-r7j3-jgpx

Charts affected

2,754 by stars
ChartLatestAffected imagesRadar Score
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

493
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,956
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
glibc@2.27-3ubuntu1.4
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

9,296
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
glibc@2.35-0ubuntu3.14
no fix listed

Open the chart page →

7,966

Container images carrying it

2,809 by charts deploying them

A fixed version is listed for 2 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
glibc@2.39-0ubuntu8.3
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-load-generatorb130d6cee6cb
glibc@2.36-9+deb12u14
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-recommendationserviceb294a4278407
glibc@2.36-9+deb12u8
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-accountingbfd9d13ac58a
glibc@2.39-0ubuntu8.9
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-agentd0f4ae0b32a8
glibc@2.41-12+deb13u4
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-addfd7a4697116
glibc@2.39-0ubuntu8.5
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-frontend-proxyfd4da88bfeaa
glibc@2.35-0ubuntu3.14
no fix listed
1
ghcr.io/openunison/openunison-k8s:1.0.51128081dae281
glibc@2.39-0ubuntu8.9
no fix listed
1
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
glibc@2.35-0ubuntu3.10
no fix listed
1
ghcr.io/open-webui/mcpo:git-39b4867f06525afac6b
glibc@2.36-9+deb12u10
no fix listed
1
ghcr.io/open-webui/open-terminal:0.13.0-slimdec44673c865
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/open-webui/terminals:latest5d2fd44366a4
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/open-webui/terminals-operator:latest6287ce8be502
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
glibc@2.31-0ubuntu9.9
no fix listed
1
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
glibc@2.36-9+deb12u13
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
glibc@2.36-9+deb12u8
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
glibc@2.41-12+deb13u2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
glibc@2.41-12
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
glibc@2.41-12+deb13u1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
glibc@2.36-9+deb12u7
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
glibc@2.36-9+deb12u3
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
glibc@2.41-12+deb13u2
no fix listed
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/paradigmxyz/reth:v1.3.121e5290e8b743
glibc@2.35-0ubuntu3.9
no fix listed
1
ghcr.io/paradigmxyz/reth:v2.2.0505fca5e87d6
glibc@2.39-0ubuntu8.7
no fix listed
1
ghcr.io/paradigmxyz/reth:latest8ce703acf113
glibc@2.39-0ubuntu8.9
no fix listed
1
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.00b97452674a3
glibc@2.41-12
no fix listed
1
ghcr.io/parmincloud/haproxy-redis-sentinel:1.0.040a00a6456ae
glibc@2.36-9+deb12u10
no fix listed
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
glibc@2.27-3ubuntu1.6
no fix listed
1
ghcr.io/platformrelay/kollect:v0.20.0c95fa31ead03
glibc@2.36-9+deb12u14
no fix listed
1
ghcr.io/port-labs/port-agent:v0.8.12c92d1e223f5c
glibc@2.41-12+deb13u3+e1
2.41-12+deb13u3+e7
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
glibc@2.35-0ubuntu3.6
no fix listed
1
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/qovery/iam-eks-user-mapper:mainc41e3efc6097
glibc@2.41-12
no fix listed
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/quenchworks/images/airflow66d1498b17ca
glibc-2.44@2.44-r5
2.44-r6
1
ghcr.io/quenchworks/images/apisix2b242df1ab22
glibc-2.44@2.44-r1
2.44-r6
1
ghcr.io/quenchworks/images/busybox96bfb56285a6
glibc-2.43@2.43-r14
no fix listed
1
ghcr.io/quenchworks/images/caddy73689c430946
glibc-2.43@2.43-r14
no fix listed
1
ghcr.io/quenchworks/images/cassandra688f215f101f
glibc-2.44@2.44-r1
2.44-r6
1
ghcr.io/quenchworks/images/cockroachdb999d37602d17
glibc-2.44@2.44-r1
2.44-r6
1
ghcr.io/quenchworks/images/coolify-appce43126a3842
glibc-2.44@2.44-r5
2.44-r6
1
ghcr.io/quenchworks/images/dex8b41a7c5f1bf
glibc-2.43@2.43-r14
no fix listed
1
ghcr.io/quenchworks/images/documentdbbe72db1f2865
glibc-2.44@2.44-r1
2.44-r6
1
ghcr.io/quenchworks/images/drupal1969d8357d81
glibc-2.44@2.44-r1
2.44-r6
1
ghcr.io/quenchworks/images/excalidraw08a23c56caba
glibc-2.44@2.44-r1
2.44-r6
1
ghcr.io/quenchworks/images/floci1c83a712bf07
glibc-2.44@2.44-r1
2.44-r6
1
ghcr.io/quenchworks/images/fluent-bit5d4db482f1b6
glibc-2.44@2.44-r1
2.44-r6
1
ghcr.io/quenchworks/images/forgejo9fde07ee32a0
glibc-2.44@2.44-r5
2.44-r6
1
ghcr.io/quenchworks/images/harbor-portalc5cf43e186b5
glibc-2.44@2.44-r1
2.44-r6
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.