StackRadar

CVE-2026-18374

Medium

Advisory

Published 27 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.9
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,759
of 17,828 indexed, latest versions
Container images
2,808
deployed by those charts
Fix available
2 of 5
affected packages

CVE-2026-18374 affecting package glibc 2.38-21

Carried by container images the latest versions of 2,759 of 17,828 indexed charts deploy, on 2,808 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+66 more2.41-12+deb13u3+e72,753
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibc-2.44apk2.44-r1, 2.44-r4, 2.44-r52.44-r634
glibcrpm2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3no fix listed13
glibc-2.43apk2.43-r14no fix listed1
OSV records
DEBIAN-CVE-2026-18374UBUNTU-CVE-2026-18374AZL-98042CGA-27g8-4xhq-hhr3CGA-2w63-hvq4-f4pcECHO-9169-1fd9-0c1c
Also known as
CGA-3qmp-39qm-cjf8, CGA-3xw7-x4r7-x678, CGA-5g65-xm2q-rjhf, CGA-5wh2-vg99-j76x, CGA-63j2-v7q6-8x84, CGA-6rf5-rrq5-7pff, CGA-772j-3386-6g56, CGA-79v3-g2j9-ffq2, CGA-8hxc-pvg5-xr9j, CGA-c62g-2q4h-pjjg, CGA-f52m-j726-w2p6, CGA-h33h-m88h-4gc6, CGA-m923-g68q-v4rq, CGA-m9qj-fr43-382g, CGA-mm85-9c9x-q266, CGA-v3jf-jvqj-vgxj, CGA-x2q5-w2xg-rgqc, CGA-x3rq-r7j3-jgpx

Charts affected

2,759 by stars
ChartLatestAffected imagesRadar Score
postgresql-singlesinextraVerified publisher1.15.21 of 1See more

postgresql-single sinextra 1.15.2

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

4,962
registry-mirrorssinextraVerified publisher2.0.191 of 1See more

registry-mirrors sinextra 2.0.19

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/project-zot/zot:v2.1.216b69512c00dc
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

371
gitlab-omnibusslamdev0.1.61 of 2See more

gitlab-omnibus slamdev 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
daedalusproject/base_kubectl:latest6f72b5119eda
glibc@2.31-0ubuntu9.1
no fix listed

Open the chart page →

2,892
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

2,986
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
glibc@2.31-0ubuntu9.9
no fix listed
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
glibc@2.31-0ubuntu9.9
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
glibc@2.31-0ubuntu9.9
no fix listed

Open the chart page →

243,889
snappasssnappassVerified publisher0.4.32 of 3See more

snappass snappass 0.4.3

2 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
glibc@2.41-12+deb13u1
no fix listed
valkey/valkey:8.1.61f84517eca8e
glibc@2.41-12+deb13u2
no fix listed

Open the chart page →

3,102
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
glibc@2.41-12
no fix listed

Open the chart page →

14,620
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/redis:8.10.18a1efc5f4795
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

1,932
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
glibc@2.41-12+deb13u1
no fix listed

Open the chart page →

7,481
postgresql-ha-chartsoldevelo-postgresql-ha-chart16.3.42 of 2See more

postgresql-ha-chart soldevelo-postgresql-ha-chart 16.3.4

2 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
soldevelo/pgpool:4.6.3-debian-12-r0044d16a65129
glibc@2.36-9+deb12u13
no fix listed
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

4,704
rabbitmqsolidchartsVerified publisher0.7.61 of 2See more

rabbitmq solidcharts 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.6-management534e4fefc5f0
glibc@2.39-0ubuntu8.9
no fix listed

Open the chart page →

848
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
glibc@2.36-9+deb12u7
no fix listed

Open the chart page →

5,752
speckle-serverspeckleVerified publisher2.26.34 of 4See more

speckle-server speckle 2.26.3

4 of the 4 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
speckle/speckle-monitor-deployment:2.26.3d51e1b0cf231
glibc@2.36-9+deb12u7
no fix listed
speckle/speckle-preview-service:2.26.3092384dba45d
glibc@2.36-9+deb12u7
no fix listed
speckle/speckle-server:2.26.379f14a2bf931
glibc@2.36-9+deb12u10
no fix listed
speckle/speckle-webhook-service:2.26.3c58eb372c488
glibc@2.36-9+deb12u7
no fix listed

Open the chart page →

10,549
squidsquid-helmVerified publisher0.1.01 of 1See more

squid squid-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ubuntu/squid:5.2-22.04_beta723891b5bc74
glibc@2.35-0ubuntu3.11
no fix listed

Open the chart page →

2,713
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
graphprotocol/graph-node:v0.37.0f4452cdedd68
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

4,731
stardogstardog3.1.01 of 3See more

stardog stardog 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
stardog/stardog:latest2714e5c4b3c1
glibc-2.44@2.44-r4
2.44-r6

Open the chart page →

413
multusstartechnicaVerified publisher0.1.21 of 1See more

multus startechnica 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:stableec4e5dfe12b6
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

524
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
glibc@2.31-0ubuntu9.9
no fix listed

Open the chart page →

13,652
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

100,276
stornxstornxVerified publisher1.1.13 of 9See more

stornx stornx 1.1.1

3 of the 9 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
glibc@2.39-0ubuntu8.7
no fix listed
alazidis/stornx:1.1.1602d4f7f090c
glibc@2.36-9+deb12u13
no fix listed
istio/pilot:1.29.1f8b0e412ac4a
glibc@2.39-0ubuntu8.7
no fix listed

Open the chart page →

11,890
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
glibc@2.39-0ubuntu8.7
no fix listed

Open the chart page →

2,976
supabasesupabse0.8.06 of 11See more

supabase supabse 0.8.0

6 of the 11 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.30.13b709e4a0e5e
glibc@2.39-0ubuntu8.6
no fix listed
kong/kong:3.9.16addf50e6bd8
glibc@2.39-0ubuntu8.4
no fix listed
supabase/edge-runtime:v1.74.02781daf92394
glibc@2.36-9+deb12u13
no fix listed
supabase/postgres-meta:v0.96.6a84cc713585e
glibc@2.36-9+deb12u13
no fix listed
supabase/realtime:v2.102.3aa1c92c0cf32
glibc@2.36-9+deb12u14
no fix listed
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

18,347
supersonicsupersonicVerified publisher0.3.11 of 2See more

supersonic supersonic 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.92956bd9de830
glibc@2.35-0ubuntu3.8
no fix listed

Open the chart page →

2,185
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
glibc@2.41-12+deb13u2
no fix listed

Open the chart page →

3,375
mumblesyntaxerror404Verified publisher1.0.51 of 1See more

mumble syntaxerror404 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
glibc@2.39-0ubuntu8.7
no fix listed

Open the chart page →

2,233
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

1,589
headscaleszpadel-chartsVerified publisher0.30.22 of 3See more

headscale szpadel-charts 0.30.2

2 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:0.29.18453e47ea6bf
glibc@2.41-12+deb13u3
no fix listed
ghcr.io/tale/headplane:0.6.39476cc5adb12
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

1,904
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

1,589
teamcity-serverteamcity-server3.3.51 of 2See more

teamcity-server teamcity-server 3.3.5

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/haproxy:3.2ad870ce41292
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

579
tbotteleport-agent-kube18.11.11 of 1See more

tbot teleport-agent-kube 18.11.1

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
public.ecr.aws/gravitational/tbot-distroless:18.11.1f64ff28fd9bd
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

379
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
glibc@2.41-12+deb13u3+dhi1
no fix listed

Open the chart page →

2,488
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
glibc@2.36-9+deb12u3
no fix listed

Open the chart page →

9,155
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
glibc@2.36-9+deb12u3
no fix listed

Open the chart page →

9,155
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
glibc@2.41-12+deb13u1
no fix listed

Open the chart page →

13,742
traefikeetraefikOfficialVerified publisher4.2.101 of 2See more

traefikee traefik 4.2.10

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
traefik/traefikee:v2.12.10acc7fcca5f1c
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

557
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
glibc@2.39-0ubuntu8.3
no fix listed

Open the chart page →

4,127
typemilltypemill-helm-chart2.2.02 of 2See more

typemill typemill-helm-chart 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
kixote/typemilldigest-pinned4e9dff179519
glibc@2.41-12+deb13u3
no fix listed
kixote/typemilldigest-pinned628f79a08cc7
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

5,606
typesensetypesenseVerified publisher1.1.41 of 1See more

typesense typesense 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
typesense/typesense:30.191604dc128e2
glibc@2.35-0ubuntu3.11
no fix listed

Open the chart page →

1,953
ueransim-gnbueransim-gnbVerified publisher0.2.61 of 1See more

ueransim-gnb ueransim-gnb 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
glibc@2.35-0ubuntu3.8
no fix listed

Open the chart page →

4,004
ueransim-uesueransim-uesVerified publisher0.1.21 of 1See more

ueransim-ues ueransim-ues 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
glibc@2.35-0ubuntu3.8
no fix listed

Open the chart page →

4,004
u-storeunifieVerified publisher1.2.01 of 1See more

u-store unifie 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
glibc@2.36-9+deb12u7
no fix listed

Open the chart page →

15,337
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

12,815
taigaunxwaresVerified publisher2026.3.82 of 6See more

taiga unxwares 2026.3.8

2 of the 6 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
glibc@2.41-12+deb13u3
no fix listed
taigaio/taiga-protected:latestfd4568a97a59
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

9,260
varnish-cachevarnishVerified publisher1.1.11 of 1See more

varnish-cache varnish 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/varnish:7.5.04d0bb287d87b
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

4,462
varnish-ingress-controllervarnish-ingress-controllerVerified publisher0.5.01 of 1See more

varnish-ingress-controller varnish-ingress-controller 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
mariusm/vingress:0.5.0b3db186c3d72
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

2,377
vaultwarden-kubernetes-secretsvaultwarden-kubernetes-secrets0.0.0-main1 of 2See more

vaultwarden-kubernetes-secrets vaultwarden-kubernetes-secrets 0.0.0-main

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
glibc@2.39-0ubuntu8.6
no fix listed

Open the chart page →

4,139
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

5,283
phpipamvquieVerified publisher1.0.31 of 3See more

phpipam vquie 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/mariadb:10.11.21c33370a599c
glibc@2.35-0ubuntu3.1
no fix listed

Open the chart page →

7,129
waldurwaldur-chartsVerified publisher8.1.22 of 3See more

waldur waldur-charts 8.1.2

2 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
glibc@2.41-12+deb13u4
no fix listed
opennode/waldur-mastermind:8.1.24c82b15d9042
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

4,681
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
glibc@2.27-3ubuntu1.2
no fix listed

Open the chart page →

16,078

Container images carrying it

2,808 by charts deploying them

A fixed version is listed for 2 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
glibc@2.41-12
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
glibc@2.36-9+deb12u3
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
glibc@2.36-9+deb12u8
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
glibc@2.36-9+deb12u13
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
glibc@2.36-9+deb12u10
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
glibc@2.36-9+deb12u10
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.