StackRadar

CVE-2026-18374

Medium

Advisory

Published 27 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.9
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,710
of 17,803 indexed, latest versions
Container images
2,753
deployed by those charts
Fix available
2 of 5
affected packages

CVE-2026-18374 affecting package glibc 2.38-21

Carried by container images the latest versions of 2,710 of 17,803 indexed charts deploy, on 2,753 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+66 more2.41-12+deb13u3+e72,635
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibc-2.44apk2.44-r1, 2.44-r4, 2.44-r52.44-r683
glibcrpm2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3no fix listed23
glibc-2.43apk2.43-r14no fix listed5
OSV records
DEBIAN-CVE-2026-18374UBUNTU-CVE-2026-18374AZL-98042CGA-27g8-4xhq-hhr3CGA-2w63-hvq4-f4pcECHO-9169-1fd9-0c1c
Also known as
CGA-2r7g-4qmv-r3hh, CGA-3qmp-39qm-cjf8, CGA-3xw7-x4r7-x678, CGA-5g65-xm2q-rjhf, CGA-5wh2-vg99-j76x, CGA-63j2-v7q6-8x84, CGA-6rf5-rrq5-7pff, CGA-772j-3386-6g56, CGA-79v3-g2j9-ffq2, CGA-8hxc-pvg5-xr9j, CGA-c62g-2q4h-pjjg, CGA-f52m-j726-w2p6, CGA-h33h-m88h-4gc6, CGA-m923-g68q-v4rq, CGA-m9qj-fr43-382g, CGA-mm85-9c9x-q266, CGA-rh5w-p243-vcf7, CGA-v3jf-jvqj-vgxj, CGA-x2q5-w2xg-rgqc, CGA-x3rq-r7j3-jgpx

Charts affected

2,710 by stars
ChartLatestAffected imagesRadar Score
stornxstornxVerified publisher1.1.13 of 9See more

stornx stornx 1.1.1

3 of the 9 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
glibc@2.39-0ubuntu8.7
no fix listed
alazidis/stornx:1.1.1602d4f7f090c
glibc@2.36-9+deb12u13
no fix listed
istio/pilot:1.29.1f8b0e412ac4a
glibc@2.39-0ubuntu8.7
no fix listed

Open the chart page →

11,826
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
glibc@2.39-0ubuntu8.7
no fix listed

Open the chart page →

2,906
supabasesupabse0.8.06 of 11See more

supabase supabse 0.8.0

6 of the 11 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.30.13b709e4a0e5e
glibc@2.39-0ubuntu8.6
no fix listed
kong/kong:3.9.16addf50e6bd8
glibc@2.39-0ubuntu8.4
no fix listed
supabase/edge-runtime:v1.74.02781daf92394
glibc@2.36-9+deb12u13
no fix listed
supabase/postgres-meta:v0.96.6a84cc713585e
glibc@2.36-9+deb12u13
no fix listed
supabase/realtime:v2.102.3aa1c92c0cf32
glibc@2.36-9+deb12u14
no fix listed
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

18,434
supersonicsupersonicVerified publisher0.3.11 of 2See more

supersonic supersonic 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.92956bd9de830
glibc@2.35-0ubuntu3.8
no fix listed

Open the chart page →

2,153
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
glibc@2.41-12+deb13u2
no fix listed

Open the chart page →

3,295
mumblesyntaxerror404Verified publisher1.0.41 of 1See more

mumble syntaxerror404 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
glibc@2.39-0ubuntu8.7
no fix listed

Open the chart page →

2,161
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,879
headscaleszpadel-chartsVerified publisher0.30.22 of 3See more

headscale szpadel-charts 0.30.2

2 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:0.29.18453e47ea6bf
glibc@2.41-12+deb13u3
no fix listed
ghcr.io/tale/headplane:0.6.39476cc5adb12
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

1,906
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,879
teamcity-serverteamcity-server3.3.51 of 2See more

teamcity-server teamcity-server 3.3.5

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/haproxy:3.2de601ccc9a79
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

872
tbotteleport-agent-kube18.11.11 of 1See more

tbot teleport-agent-kube 18.11.1

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
public.ecr.aws/gravitational/tbot-distroless:18.11.1f64ff28fd9bd
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

380
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
glibc@2.41-12+deb13u3+dhi1
no fix listed

Open the chart page →

2,600
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
glibc@2.36-9+deb12u3
no fix listed

Open the chart page →

9,131
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
glibc@2.36-9+deb12u3
no fix listed

Open the chart page →

9,131
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
glibc@2.41-12+deb13u1
no fix listed

Open the chart page →

13,678
traefikeetraefikOfficialVerified publisher4.2.101 of 2See more

traefikee traefik 4.2.10

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
traefik/traefikee:v2.12.10acc7fcca5f1c
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

559
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
glibc@2.39-0ubuntu8.3
no fix listed

Open the chart page →

4,095
typemilltypemill-helm-chart2.2.02 of 2See more

typemill typemill-helm-chart 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
kixote/typemilldigest-pinned4e9dff179519
glibc@2.41-12+deb13u3
no fix listed
kixote/typemilldigest-pinned628f79a08cc7
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

5,564
typesensetypesenseVerified publisher1.1.41 of 1See more

typesense typesense 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
typesense/typesense:30.191604dc128e2
glibc@2.35-0ubuntu3.11
no fix listed

Open the chart page →

1,922
ueransim-gnbueransim-gnbVerified publisher0.2.61 of 1See more

ueransim-gnb ueransim-gnb 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
glibc@2.35-0ubuntu3.8
no fix listed

Open the chart page →

3,938
ueransim-uesueransim-uesVerified publisher0.1.21 of 1See more

ueransim-ues ueransim-ues 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
glibc@2.35-0ubuntu3.8
no fix listed

Open the chart page →

3,938
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

12,682
taigaunxwaresVerified publisher2026.3.82 of 6See more

taiga unxwares 2026.3.8

2 of the 6 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
glibc@2.41-12+deb13u3
no fix listed
taigaio/taiga-protected:latestfd4568a97a59
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

9,248
varnish-cachevarnishVerified publisher1.1.11 of 1See more

varnish-cache varnish 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/varnish:7.5.04d0bb287d87b
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

4,424
varnish-ingress-controllervarnish-ingress-controllerVerified publisher0.5.01 of 1See more

varnish-ingress-controller varnish-ingress-controller 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
mariusm/vingress:0.5.0b3db186c3d72
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

2,353
vaultwarden-kubernetes-secretsvaultwarden-kubernetes-secrets0.0.0-main1 of 2See more

vaultwarden-kubernetes-secrets vaultwarden-kubernetes-secrets 0.0.0-main

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
glibc@2.39-0ubuntu8.6
no fix listed

Open the chart page →

4,093
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

5,284
phpipamvquieVerified publisher1.0.31 of 3See more

phpipam vquie 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/mariadb:10.11.21c33370a599c
glibc@2.35-0ubuntu3.1
no fix listed

Open the chart page →

7,083
waldurwaldur-chartsVerified publisher8.1.22 of 3See more

waldur waldur-charts 8.1.2

2 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
glibc@2.41-12+deb13u3
no fix listed
opennode/waldur-mastermind:8.1.24c82b15d9042
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

5,066
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
glibc@2.27-3ubuntu1.2
no fix listed

Open the chart page →

16,037
kafka-devwikimedia0.2.01 of 1See more

kafka-dev wikimedia 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
eglibc@2.19-0ubuntu6.3
no fix listed

Open the chart page →

41,473
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
glibc@2.31-0ubuntu9.17
no fix listed

Open the chart page →

51,717
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
glibc@2.41-12
no fix listed

Open the chart page →

7,814
wordpress-helmwordpress-helm0.2.91 of 4See more

wordpress-helm wordpress-helm 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
glibc@2.41-12+deb13u2
no fix listed

Open the chart page →

8,368
workflows-aggregatorworkflows-aggregatorVerified publisher0.16.91 of 1See more

workflows-aggregator workflows-aggregator 0.16.9

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
glibc@2.43-2ubuntu2.3
no fix listed

Open the chart page →

1,411
workflows-informerworkflows-informerVerified publisher0.4.41 of 1See more

workflows-informer workflows-informer 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

1,177
workflows-sinkworkflows-sinkVerified publisher0.16.31 of 1See more

workflows-sink workflows-sink 0.16.3

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

1,440
wraftwraft0.1.121 of 9See more

wraft wraft 0.1.12

1 of the 9 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
typesense/typesense:28.0.rc35dea1b62b7b6e
glibc@2.35-0ubuntu3.8
no fix listed

Open the chart page →

10,311
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
glibc@2.35-0ubuntu3.1
no fix listed

Open the chart page →

9,865
yugawareyugabyteVerified publisher2026.1.11 of 3See more

yugaware yugabyte 2026.1.1

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/postgres:14.22eba8ddbdd837
glibc@2.41-12+deb13u2
no fix listed

Open the chart page →

2,687
qleverzazukoVerified publisher0.7.11 of 2See more

qlever zazuko 0.7.1

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/zazukoians/qlever-server:v0.10.11de7869ab46e
glibc@2.39-0ubuntu8.9
no fix listed

Open the chart page →

2,513
zcash-stackzcashVerified publisher0.4.51 of 2See more

zcash-stack zcash 0.4.5

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
electriccoinco/lightwalletd:v0.5.42ae3a551e111
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

2,954
crowdsec-web-uizekker6Verified publisher0.51.01 of 1See more

crowdsec-web-ui zekker6 0.51.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,461
mikochizer0tonin1.11.01 of 1See more

mikochi zer0tonin 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
zer0tonin/mikochi:1.11.009872bae1554
glibc@2.43-2ubuntu2
no fix listed

Open the chart page →

1,009
backendzymtraceOfficialVerified publisher26.9.23 of 6See more

backend zymtrace 26.9.2

3 of the 6 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.3.14.14b627d7a9bc0e
glibc@2.35-0ubuntu3.11
no fix listed
library/postgres:17.4304ab8135187
glibc@2.36-9+deb12u10
no fix listed
ghcr.io/zystem-io/zymtrace-pub-gateway:26.9.2ae9ae0925ff8
glibc@2.35-0ubuntu3.11
no fix listed

Open the chart page →

9,295
acos-prometheus-exporter-helm-charta10-prometheus-exporter0.1.01 of 1See more

acos-prometheus-exporter-helm-chart a10-prometheus-exporter 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
a10networks/acos-prometheus-exporter:latest8dc58d434d71
glibc@2.27-3ubuntu1
no fix listed

Open the chart page →

74,391
abstract-nodeabstract-nodeVerified publisher0.1.491 of 2See more

abstract-node abstract-node 0.1.49

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
matterlabs/external-node:9734bf2-17870579939295dadc06bdf3b
glibc@2.36-9+deb12u8
no fix listed

Open the chart page →

4,600
active-mqactivemq-helm-chartVerified publisher1.8.21 of 3See more

active-mq activemq-helm-chart 1.8.2

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.44.00305c26f19ed
glibc@2.39-0ubuntu8.6
no fix listed

Open the chart page →

3,246
open5gsadaptivenetlabVerified publisher1.0.32 of 3See more

open5gs adaptivenetlab 1.0.3

2 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
free5gmano/nextepc-mongodb:latest36f806935519
glibc@2.23-0ubuntu10
no fix listed
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

99,481
jenkinsaditisingh-jenkins1.0.01 of 1See more

jenkins aditisingh-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

2,517

Container images carrying it

2,753 by charts deploying them

A fixed version is listed for 2 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
glibc@2.36-9+deb12u10
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.