StackRadar

CVE-2026-18374

Medium

Advisory

Published 27 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.9
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,746
of 17,821 indexed, latest versions
Container images
2,798
deployed by those charts
Fix available
2 of 5
affected packages

CVE-2026-18374 affecting package glibc 2.38-21

Carried by container images the latest versions of 2,746 of 17,821 indexed charts deploy, on 2,798 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+66 more2.41-12+deb13u3+e72,741
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibc-2.44apk2.44-r1, 2.44-r4, 2.44-r52.44-r635
glibcrpm2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3no fix listed14
glibc-2.43apk2.43-r14no fix listed1
OSV records
DEBIAN-CVE-2026-18374UBUNTU-CVE-2026-18374AZL-98042CGA-27g8-4xhq-hhr3CGA-2w63-hvq4-f4pcECHO-9169-1fd9-0c1c
Also known as
CGA-3qmp-39qm-cjf8, CGA-3xw7-x4r7-x678, CGA-5g65-xm2q-rjhf, CGA-5wh2-vg99-j76x, CGA-63j2-v7q6-8x84, CGA-6rf5-rrq5-7pff, CGA-772j-3386-6g56, CGA-79v3-g2j9-ffq2, CGA-8hxc-pvg5-xr9j, CGA-c62g-2q4h-pjjg, CGA-f52m-j726-w2p6, CGA-h33h-m88h-4gc6, CGA-m923-g68q-v4rq, CGA-m9qj-fr43-382g, CGA-mm85-9c9x-q266, CGA-v3jf-jvqj-vgxj, CGA-x2q5-w2xg-rgqc, CGA-x3rq-r7j3-jgpx

Charts affected

2,746 by stars
ChartLatestAffected imagesRadar Score
kubernetes-kiosk-chromiumkubernetes-kiosk-chromium0.1.21 of 1See more

kubernetes-kiosk-chromium kubernetes-kiosk-chromium 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

29,519
kubernetes-netskope-publisherkubernetes-netskope-publisherVerified publisher1.5.01 of 2See more

kubernetes-netskope-publisher kubernetes-netskope-publisher 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
netskopeprivateaccess/publisher_u22:latest0b43204c37d6
glibc@2.35-0ubuntu3.14
no fix listed

Open the chart page →

39,277
kube-httpcachekubernetes-replicator0.9.11 of 1See more

kube-httpcache kubernetes-replicator 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
quay.io/mittwald/kube-httpcache:stable2169032c5840
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

4,611
kube-mailkubernetes-replicator0.11.11 of 3See more

kube-mail kubernetes-replicator 0.11.1

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
quay.io/mittwald/kube-mail:latest04f1099241fc
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

2,581
databend-metakubesphere-stable0.7.31 of 1See more

databend-meta kubesphere-stable 0.7.3

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
datafuselabs/databend-meta:v1.2.279ba877ee6cb4d
glibc@2.36-9+deb12u3
no fix listed

Open the chart page →

2,873
databend-querykubesphere-stable0.8.31 of 1See more

databend-query kubesphere-stable 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
datafuselabs/databend-query:v1.2.279a936843b85b4
glibc@2.36-9+deb12u3
no fix listed

Open the chart page →

2,873
deepflowkubesphere-stable6.2.6062 of 8See more

deepflow kubesphere-stable 6.2.606

2 of the 8 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
glibc@2.31-0ubuntu9.9
no fix listed
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
glibc@2.35-0ubuntu3.1
no fix listed

Open the chart page →

18,503
iomeshkubesphere-stable1.1.04 of 25See more

iomesh kubesphere-stable 1.1.0

4 of the 25 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
iomesh/csi-driver:v2.7.25d3f9bf9240b
glibc@2.35-0ubuntu3.7
no fix listed
iomesh/node-disk-exporter:1.8.0f03148764f38
glibc@2.31-0ubuntu9.2
no fix listed
iomesh/node-disk-manager:1.8.0002c4b92fd34
glibc@2.31-0ubuntu9.2
no fix listed
iomesh/node-disk-operator:1.8.0f6c76380db34
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

49,073
IOMeshkubesphere-stable1.2.04 of 25See more

IOMesh kubesphere-stable 1.2.0

4 of the 25 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
iomesh/csi-driver:v2.8.01a151f602451
glibc@2.35-0ubuntu3.8
no fix listed
iomesh/node-disk-exporter:1.8.0f03148764f38
glibc@2.31-0ubuntu9.2
no fix listed
iomesh/node-disk-manager:1.8.0-2292ad270082e
glibc@2.39-0ubuntu8.2
no fix listed
iomesh/node-disk-operator:1.8.0-1de4aa40684ad
glibc@2.39-0ubuntu8.2
no fix listed

Open the chart page →

46,763
pulsarkubesphere-stable2.7.131 of 3See more

pulsar kubesphere-stable 2.7.13

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

91,532
clickhousekubesphere-testVerified publisher0.1.11 of 2See more

clickhouse kubesphere-test 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
radondb/clickhouse-server:v21.1.3.32-stable4732df471073
glibc@2.27-3ubuntu1.4
no fix listed

Open the chart page →

6,724
csi-neonsankubesphere-testVerified publisher1.3.01 of 6See more

csi-neonsan kubesphere-test 1.3.0

1 of the 6 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
csiplugin/csi-neonsan:v1.2.21fa83d45417f
glibc@2.23-0ubuntu11.3
no fix listed

Open the chart page →

18,554
mongodbkubesphere-testVerified publisher0.3.21 of 2See more

mongodb kubesphere-test 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/mongo:4.2.16ca49afbcb2b
glibc@2.27-3ubuntu1
no fix listed

Open the chart page →

9,652
mysqlkubesphere-testVerified publisher1.0.21 of 3See more

mysql kubesphere-test 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

7,407
sample-bookinfokubesphere-testVerified publisher1.0.01 of 4See more

sample-bookinfo kubesphere-test 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
kubesphere/examples-bookinfo-reviews-v2:1.13.06d93129beb32
glibc@2.23-0ubuntu11
no fix listed

Open the chart page →

9,425
xenondbkubesphere-testVerified publisher1.0.01 of 3See more

xenondb kubesphere-test 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

7,407
vector-controllerkubevela0.2.31 of 2See more

vector-controller kubevela 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
oamdev/vector-controller:v0.2.39dd8be44ffc9
glibc@2.27-3ubuntu1.6
no fix listed

Open the chart page →

4,820
kubevirtkubevirtVerified publisher0.2.01 of 1See more

kubevirt kubevirt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
quay.io/kubevirt/virt-operator:v1.8.465d23c9ad917
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

648
kubevoipkubevoipOfficialVerified publisher0.6.81 of 1See more

kubevoip kubevoip 0.6.8

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/kubevoip/kubevoip:v0.6.841c603a93642
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,049
network-enforcerkubewardenVerified publisher0.1.21 of 3See more

network-enforcer kubewarden 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0.4ca08b7d2df5b
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

2,695
kube-wordpress-mysqlkube-wordpress-mysql0.1.01 of 2See more

kube-wordpress-mysql kube-wordpress-mysql 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/wordpress:php8.1-apachef73396626d2f
glibc@2.41-12
no fix listed

Open the chart page →

8,944
penpotkubitodevVerified publisher1.2.12 of 5See more

penpot kubitodev 1.2.1

2 of the 5 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
glibc@2.35-0ubuntu3.8
no fix listed
penpotapp/exporter:2.2.15c835ffd87ab
glibc@2.35-0ubuntu3.8
no fix listed

Open the chart page →

17,075
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.43 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

3 of the 9 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
grafana/alloy:v1.5.101a63f4e032c
glibc@2.39-0ubuntu8.3
no fix listed
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
glibc@2.41-12
no fix listed
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

20,417
ctrlmeshkusionstackVerified publisher0.2.01 of 1See more

ctrlmesh kusionstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
glibc@2.31-0ubuntu9.16
no fix listed

Open the chart page →

3,489
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
glibc@2.35-0ubuntu3.8
no fix listed

Open the chart page →

63,783
sample-operatorkusionstackVerified publisher0.1.21 of 1See more

sample-operator kusionstack 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
chaerr/kridge:demo-operator-v0.1.266833deec017
glibc@2.31-0ubuntu9.9
no fix listed

Open the chart page →

2,524
kustomize-patcherkustomize-patcher1.0.21 of 2See more

kustomize-patcher kustomize-patcher 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/themesama/kubernetes-kustomize-patcher:latestb1bf0669e3a0
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

908
fstyr-ddp-keycloak-application-platform-configkvalitetsitVerified publisher0.1.131 of 1See more

fstyr-ddp-keycloak-application-platform-config kvalitetsit 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
glibc@2.39-0ubuntu8.3
no fix listed

Open the chart page →

3,173
keycloak-application-platform-configkvalitetsitVerified publisher0.0.291 of 1See more

keycloak-application-platform-config kvalitetsit 0.0.29

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
glibc@2.39-0ubuntu8.2
no fix listed

Open the chart page →

3,403
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
glibc@2.27-3ubuntu1.4
no fix listed

Open the chart page →

16,735
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
glibc@2.35-0ubuntu3.8
no fix listed

Open the chart page →

7,864
nginx-chartkyb-nginx0.1.01 of 1See more

nginx-chart kyb-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,887
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
glibc@2.27-3ubuntu1
no fix listed

Open the chart page →

26,563
pageslatif-pages1.0.02 of 3See more

pages latif-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
glibc@2.31-0ubuntu9.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
glibc@2.27-3ubuntu1
no fix listed

Open the chart page →

20,287
pageslavanya-pages1.0.02 of 3See more

pages lavanya-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
glibc@2.31-0ubuntu9.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
glibc@2.27-3ubuntu1
no fix listed

Open the chart page →

20,287
homebridgelbenicio-communityVerified publisher0.1.151 of 1See more

homebridge lbenicio-community 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
glibc@2.39-0ubuntu8.8
no fix listed

Open the chart page →

34,371
kubernetes-dashboardlbenicio-communityVerified publisher7.14.91 of 5See more

kubernetes-dashboard lbenicio-community 7.14.9

1 of the 5 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/kong:3.912972ce1ab63
glibc@2.39-0ubuntu8.9
no fix listed

Open the chart page →

1,945
smtplbenicio-communityVerified publisher0.1.31 of 1See more

smtp lbenicio-community 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,418
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

33,946
jenkinsleechistest2.7.11 of 2See more

jenkins leechistest 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

4,399
kinesaliteleprechaun-charts0.1.21 of 1See more

kinesalite leprechaun-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
instructure/kinesalite:latest34400d82f28f
glibc@2.31-0ubuntu9.17
no fix listed

Open the chart page →

4,297
owntracks-exporterleprechaun-charts0.1.111 of 1See more

owntracks-exporter leprechaun-charts 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
glibc@2.36-9+deb12u1
no fix listed

Open the chart page →

4,108
vaultwardenleprechaun-charts0.1.281 of 1See more

vaultwarden leprechaun-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.1ebdfe70701c6
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

2,085
jackettlib42Verified publisher1.1.01 of 1See more

jackett lib42 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
lib42/jackett:latesta55596cda383
glibc@2.36-9+deb12u3
no fix listed

Open the chart page →

4,608
libredb-studiolibredb-studio-oci0.1.671 of 1See more

libredb-studio libredb-studio-oci 0.1.67

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.16.2c398419c29a7
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,201
librenmslibrenms10.1.21 of 5See more

librenms librenms 10.1.2

1 of the 5 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/redis:8.10.1602d361c4da9
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

2,749
kube-iptables-tailerlifen0.2.31 of 1See more

kube-iptables-tailer lifen 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
glibc@2.31-0ubuntu9.7
no fix listed

Open the chart page →

4,481
lightlyticslightlytics0.1.212 of 2See more

lightlytics lightlytics 0.1.21

2 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
glibc@2.36-9+deb12u9
no fix listed
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

5,475
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

38,704
weblinzhengen0.1.71 of 1See more

web linzhengen 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,887

Container images carrying it

2,798 by charts deploying them

A fixed version is listed for 2 of the 5 affected packages.

No deployed image carries CVE-2026-18374.

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.