StackRadar

CVE-2026-18938

Medium

Advisory

Published 7 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,148
of 17,797 indexed, latest versions
Container images
2,099
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-18938 affecting package p11-kit for versions less than 0.26.5-1

Carried by container images the latest versions of 2,148 of 17,797 indexed charts deploy, on 2,099 images.

Affected packageAffected versionsFixed inImages
p11-kitdeb0.23.9-2, 0.23.9-2ubuntu0.1, 0.23.20-1build1, 0.23.20-1ubuntu0.1+8 more0.23.9-2ubuntu0.1+esm1, 0.23.20-1ubuntu0.1+esm1, 0.24.0-6ubuntu0.1, 0.25.3-4ubuntu2.2+1 more2,098
p11-kitrpm0.25.0-1.azl30.26.5-11
OSV records
DEBIAN-CVE-2026-18938UBUNTU-CVE-2026-18938AZL-95481ECHO-09a0-891c-526d
Also known as
USN-8687-1

Charts affected

2,148 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,099 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
chocobozzz/peertube:v8.1.5052712130691
p11-kit@0.25.5-3
no fix listed
1
chriseaton/adventureworks:latest54c3384ce701
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
circleci/runner:launch-agent9bdc62f02162
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
ciscolabs/msm-nc:0710202336d02faad958
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
ckan/ckan-base:2.12.087ecf3f27ad6
p11-kit@0.24.1-2
no fix listed
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
ckulka/baikal:0.10.1-nginx434bdd162247
p11-kit@0.24.1-2
no fix listed
1
clickhouse/clickhouse-server:24.81ffa82edee00
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
clickhouse/clickhouse-server:24.4.12e6587b81a26
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
clickhouse/clickhouse-server:23.8512bb8a21483
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
clickhouse/clickhouse-server:26.3810861a2e2d0
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
clickhouse/clickhouse-server:25.3.2.398745843b17f9
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
clickhouse/clickhouse-server:26.3.1092098d3b31dd
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
clickhouse/clickhouse-server:24.12.6a65ca89ddbe8
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
clickhouse/clickhouse-server:25.3.14.14b627d7a9bc0e
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
clickhouse/clickhouse-server:26.8.2:latestfa394da808cc
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
cloudtooling/moodle:5.2.3f4f04e0fc401
p11-kit@0.24.1-2
no fix listed
1
cloudve/janis-terminal:latestaf56e77ca587
p11-kit@0.23.9-2
0.23.9-2ubuntu0.1+esm1
1
cloudve/ttyd:latestd79c1c5881c0
p11-kit@0.23.9-2
0.23.9-2ubuntu0.1+esm1
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
p11-kit@0.24.1-2
no fix listed
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
p11-kit@0.24.1-2
no fix listed
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
p11-kit@0.24.1-2
no fix listed
1
cm2network/squad:latest8cba47f53df5
p11-kit@0.25.5-3
no fix listed
1
codedesignplus/ms-emails-grpc:lateste336012bc781
p11-kit@0.24.1-2
no fix listed
1
codedesignplus/ms-emails-rest:latestac84661c605e
p11-kit@0.24.1-2
no fix listed
1
codedesignplus/ms-licenses-grpc:latest360144457f4d
p11-kit@0.24.1-2
no fix listed
1
codedesignplus/ms-modules-grpc:latest3f6aaa32d526
p11-kit@0.24.1-2
no fix listed
1
collabora/code:24.04.13.2.101dc4ab83977
p11-kit@0.24.1-2
no fix listed
1
collabora/code:23.05.10.1.105299b452f7f
p11-kit@0.24.1-2
no fix listed
1
conductoross/conductor:3.31.09fba127693e6
p11-kit@0.25.5-3
no fix listed
1
consensys/teku:latest3a4f5761ae1c
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
consensys/teku:25.4.1bf6ecd2ea716
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
consensys/web3signer:latestf146a51a1ba3
p11-kit@0.26.2-2
no fix listed
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
p11-kit@0.24.1-2
no fix listed
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
p11-kit@0.24.1-2
no fix listed
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
cortezaproject/corteza:2024.9.08eb7a26605c9
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
p11-kit@0.24.1-2
no fix listed
1
coturn/coturn:4.10.0-r1f4c2af06c3c5
p11-kit@0.25.5-3
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
cradlepoint/pgbouncer:1.0.18f5720b0cd03
p11-kit@0.23.9-2
0.23.9-2ubuntu0.1+esm1
1
cribl/cribl:3.0.2762747cb6796
p11-kit@0.23.9-2ubuntu0.1
0.23.9-2ubuntu0.1+esm1
1
cspconsole/config-provider:1.0.365524a26a6c23
p11-kit@0.24.1-2
no fix listed
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
p11-kit@0.24.1-2
no fix listed
1
cspconsole/report-collector:1.0.15839750248193b
p11-kit@0.24.1-2
no fix listed
1
cspconsole/report-processor:1.0.279a2d8840bfdf
p11-kit@0.24.1-2
no fix listed
1
cubejs/cubestore:v1.5.334ac523a9bab
p11-kit@0.24.1-2
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.