StackRadar

CVE-2026-18938

Medium

Advisory

Published 7 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,142
of 17,803 indexed, latest versions
Container images
2,090
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-18938 affecting package p11-kit for versions less than 0.26.5-1

Carried by container images the latest versions of 2,142 of 17,803 indexed charts deploy, on 2,090 images.

Affected packageAffected versionsFixed inImages
p11-kitdeb0.23.9-2, 0.23.9-2ubuntu0.1, 0.23.20-1build1, 0.23.20-1ubuntu0.1+8 more0.23.9-2ubuntu0.1+esm1, 0.23.20-1ubuntu0.1+esm1, 0.24.0-6ubuntu0.1, 0.25.3-4ubuntu2.2+1 more2,089
p11-kitrpm0.25.0-1.azl30.26.5-11
OSV records
DEBIAN-CVE-2026-18938UBUNTU-CVE-2026-18938AZL-95481ECHO-09a0-891c-526d
Also known as
USN-8687-1

Charts affected

2,142 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,090 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
p11-kit@0.26.2-2
no fix listed
1
gethue/hue:4.11.011b649636e68
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
gethue/hue:4.10.05702b2c37ff9
p11-kit@0.23.9-2ubuntu0.1
0.23.9-2ubuntu0.1+esm1
1
gethue/hue:latest7d5c1b9f8a79
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
getsentry/relay:24.10.0ba7bf9163219
p11-kit@0.24.1-2
no fix listed
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
p11-kit@0.24.1-2
no fix listed
1
ghusta/postgres-world-db:latest879d0919fdcc
p11-kit@0.25.5-3
no fix listed
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
glasskube/operator:0.12.2be5133100d63
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
glpi/glpi:latest4b681082a79e
p11-kit@0.25.5-3
no fix listed
1
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
p11-kit@0.24.1-2
no fix listed
1
golenski/fibonacci-task-manager:2.0.03a2b36df247b
p11-kit@0.24.1-2
no fix listed
1
golenski/fibonacci-worker:2.0.0954caf4aaf6a
p11-kit@0.24.1-2
no fix listed
1
gotenberg/gotenberg:8.30206a6c708fc6
p11-kit@0.25.5-3
no fix listed
1
gotenberg/gotenberg:8.3467097317623a
p11-kit@0.25.5-3
no fix listed
1
gotenberg/gotenberg:8-chromiuma40f92d7419a
p11-kit@0.25.5-3
no fix listed
1
gotson/komga:0.99.49b15ea6bfc30
p11-kit@0.23.9-2
0.23.9-2ubuntu0.1+esm1
1
gradiant/open5gs-dbctl:0.10.3332031245fce
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
grafana/agent:v0.44.23364714a2f64
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
grafana/alloy:v1.5.101a63f4e032c
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
grafana/alloy:v1.4.306bdcbb51fc2
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
grafana/alloy:v1.18.10f4434c92b3e
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
grafana/alloy:v1.18.0491b0578c049
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
grafana/alloy:v1.16.384b76d56c594
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
grafana/alloy:v1.11.38c7256f412fe
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
grafana/alloy:v1.19.2b8ec653c4423
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
grafana/alloy:v1.14.0f50931848bd8
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
grafana/beyla:1.3.336d07f8d276e
p11-kit@0.24.1-2
no fix listed
1
grafana/fluent-plugin-loki:latest8a3882e8c28b
p11-kit@0.24.1-2
no fix listed
1
grafana/mcp-grafana:0.14.042f541f22063
p11-kit@0.24.1-2
no fix listed
1
grafana/promtail:3.5.165bfae480b57
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
grafana/promtail:3.6.18dcfdf466da0
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
graphprotocol/graph-node:latestb0436347fb24
p11-kit@0.24.1-2
no fix listed
1
graphprotocol/graph-node:v0.37.0f4452cdedd68
p11-kit@0.24.1-2
no fix listed
1
graylog/graylog:6.1.1019de1aff48c2
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
graylog/graylog-enterprise:7.1.88a1f641cd7aa
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
greenkube/greenkube:0.3.00c01932282a4
p11-kit@0.24.1-2
no fix listed
1
grpl/grapple-cli:0.2.127c00aafee6629
p11-kit@0.25.3-4ubuntu2
0.25.3-4ubuntu2.2
1
guacamole/guacamole:1.5.50f62f6d17ab3
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
guillh/web3-prometheus-exporter:0.3.04fb99dbc32b2
p11-kit@0.24.1-2
no fix listed
1
gulacedia/web-dvwa-new:v367b467d961ca
p11-kit@0.24.1-2
no fix listed
1
hamidyousefi93/saam-test:latestc34f071f6ed0
p11-kit@0.24.1-2
no fix listed
1
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
p11-kit@0.24.1-2
no fix listed
1
hamzaarshad10/querypodpy:1.7154f38e8668e
p11-kit@0.24.1-2
no fix listed
1
hansehe/locust:1.1.0bc8e45262bc4
p11-kit@0.24.1-2
no fix listed
1
haohanyang/compass-web:0.5.054f2112602ee
p11-kit@0.24.1-2
no fix listed
1
haohanyang/compass-web:0.5.1f4f8fe4e21f1
p11-kit@0.24.1-2
no fix listed
1
hassroutyyoussef/accountservice:latest1f01edf1ee0c
p11-kit@0.24.1-2
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.