StackRadar

CVE-2026-18938

Medium

Advisory

Published 7 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,158
of 17,790 indexed, latest versions
Container images
2,114
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-18938 affecting package p11-kit for versions less than 0.26.5-1

Carried by container images the latest versions of 2,158 of 17,790 indexed charts deploy, on 2,114 images.

Affected packageAffected versionsFixed inImages
p11-kitdeb0.23.9-2, 0.23.9-2ubuntu0.1, 0.23.20-1build1, 0.23.20-1ubuntu0.1+8 more0.23.9-2ubuntu0.1+esm1, 0.23.20-1ubuntu0.1+esm1, 0.24.0-6ubuntu0.1, 0.25.3-4ubuntu2.2+1 more2,113
p11-kitrpm0.25.0-1.azl30.26.5-11
OSV records
DEBIAN-CVE-2026-18938UBUNTU-CVE-2026-18938AZL-95481ECHO-09a0-891c-526d
Also known as
USN-8687-1

Charts affected

2,158 by stars
ChartLatestAffected imagesRadar Score
xkopsxkops0.1.04 of 5See more

xkops xkops 0.1.0

4 of the 5 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
p11-kit@0.24.1-2
no fix listed
hamzaarshad10/querypodpy:1.7154f38e8668e
p11-kit@0.24.1-2
no fix listed
library/mongo:latest5211c51171f5
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
murtazashah46/helmfile:latest4d11726cf803
p11-kit@0.24.1-2
no fix listed

Open the chart page →

13,783
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
p11-kit@0.25.3-4ubuntu2
0.25.3-4ubuntu2.2

Open the chart page →

2,142
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
p11-kit@0.25.5-3
no fix listed

Open the chart page →

1,849
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
p11-kit@0.25.5-3
no fix listed

Open the chart page →

1,849
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
p11-kit@0.24.1-2
no fix listed

Open the chart page →

2,684
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
p11-kit@0.25.5-3
no fix listed

Open the chart page →

1,849
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
p11-kit@0.23.9-2ubuntu0.1
0.23.9-2ubuntu0.1+esm1
yandex/clickhouse-server:21.3.204eccfffb01d7
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1

Open the chart page →

9,256
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1

Open the chart page →

7,929

Container images carrying it

2,114 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/mongo:4.4.66efa05203990
p11-kit@0.23.9-2ubuntu0.1
0.23.9-2ubuntu0.1+esm1
4
library/nginx:1.27.1287ff321f9e3
p11-kit@0.24.1-2
no fix listed
4
library/postgres:134689940c6838
p11-kit@0.25.5-3
no fix listed
4
library/rabbitmq:3.11-managementc3f70098e01d
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
4
library/redis:7:7.4:7.4.1171da9275c5f3
p11-kit@0.24.1-2
no fix listed
4
mastercloudapps/planner:v1.2340a950b311b2
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
4
opea/llm-tgi:1.00c25aab3f106
p11-kit@0.24.1-2
no fix listed
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
p11-kit@0.23.9-2ubuntu0.1
0.23.9-2ubuntu0.1+esm1
4
shashkist/flask-contacts-app:latest581de1fd6084
p11-kit@0.24.1-2
no fix listed
4
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
4
ghcr.io/linuxserver/plex:latest7f9a1d574958
p11-kit@0.26.2-2
no fix listed
4
apache/superset:6.1.0:latest16b50bbef664
p11-kit@0.24.1-2
no fix listed
3
bitnamilegacy/kubectl:latestcd354d5b2556
p11-kit@0.24.1-2
no fix listed
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
p11-kit@0.24.1-2
no fix listed
3
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
p11-kit@0.24.1-2
no fix listed
3
ciscolabs/rtsp-client:latesta7b60ec88285
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
3
ciscolabs/rtsp-server:latestb59fc10bb821
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
3
codeurjc/planner:v1.0800cf520c245
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
3
dgraph/dgraph:v21.12.03b55ea83fffe
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
p11-kit@0.24.1-2
no fix listed
3
envoyproxy/envoy:v1.31.02bf7f042e396
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
3
fluent/fluent-bit:5.1.2:latestd792375ca8e5
p11-kit@0.25.5-3
no fix listed
3
gchq/hdfs:3.3.35ec58edbb2db
p11-kit@0.25.3-4ubuntu2
0.25.3-4ubuntu2.2
3
guacamole/guacamole:1.6.0f344085e618b
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
3
jacobalberty/unifi:v10.0.162896c0ab82d33
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
3
library/ghost:6.63.0e05bc1169fb2
p11-kit@0.24.1-2
no fix listed
3
library/nginx:1.25:1.25.5a484819eb602
p11-kit@0.24.1-2
no fix listed
3
library/node:ltsbe23f54a88d3
p11-kit@0.24.1-2
no fix listed
3
library/rabbitmq:4.3.5-management:4-management:managementffd1b50c522a
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
3
library/ubuntu:24.0433ceb71981b6
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
3
louislam/uptime-kuma:2.5.4917318f9d7be
p11-kit@0.24.1-2
no fix listed
3
mcp/grafana:latest9362bcf6aa0e
p11-kit@0.24.1-2
no fix listed
3
selenium/hub:3.141.5902f251d48d5f
p11-kit@0.23.20-1build1
0.23.20-1ubuntu0.1+esm1
3
sigp/lighthouse:latest-amd6450f66cfebb6d
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
3
vaultwarden/server:1.37.1ebdfe70701c6
p11-kit@0.25.5-3
no fix listed
3
xenondb/percona:5.7.330e26872a2b67
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
p11-kit@0.24.1-2
no fix listed
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
p11-kit@0.24.1-2
no fix listed
3
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
p11-kit@0.24.1-2
no fix listed
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
p11-kit@0.24.1-2
no fix listed
3
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
p11-kit@0.24.1-2
no fix listed
3
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
p11-kit@0.26.2-2
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
p11-kit@0.24.1-2
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
3

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.