StackRadar

CVE-2026-18938

Medium

Advisory

Published 7 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,154
of 17,803 indexed, latest versions
Container images
2,107
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-18938 affecting package p11-kit for versions less than 0.26.5-1

Carried by container images the latest versions of 2,154 of 17,803 indexed charts deploy, on 2,107 images.

Affected packageAffected versionsFixed inImages
p11-kitdeb0.23.9-2, 0.23.9-2ubuntu0.1, 0.23.20-1build1, 0.23.20-1ubuntu0.1+8 more0.23.9-2ubuntu0.1+esm1, 0.23.20-1ubuntu0.1+esm1, 0.24.0-6ubuntu0.1, 0.25.3-4ubuntu2.2+1 more2,106
p11-kitrpm0.25.0-1.azl30.26.5-11
OSV records
DEBIAN-CVE-2026-18938UBUNTU-CVE-2026-18938AZL-95481ECHO-09a0-891c-526d
Also known as
USN-8687-1

Charts affected

2,154 by stars
ChartLatestAffected imagesRadar Score
changedetection-iozekker6Verified publisher1.101.01 of 1See more

changedetection-io zekker6 1.101.0

1 of the 1 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.6eb4a9f718801
p11-kit@0.24.1-2
no fix listed

Open the chart page →

2,649
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
p11-kit@0.25.5-3
no fix listed

Open the chart page →

1,879
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
p11-kit@0.23.9-2ubuntu0.1
0.23.9-2ubuntu0.1+esm1
yandex/clickhouse-server:21.3.204eccfffb01d7
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1

Open the chart page →

9,280
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1

Open the chart page →

7,949

Container images carrying it

2,107 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
proxysql/proxysql:2.7.3a4d6c35c2949
p11-kit@0.24.1-2
no fix listed
1
pschichtel/mindustry-server:v145.1b543e9c2d371
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
psorab/elibrary:latest53b68896c4ce
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
puppet/puppet-agent:7.14.00b6fd9a6b7da
p11-kit@0.23.9-2ubuntu0.1
0.23.9-2ubuntu0.1+esm1
1
qdrant/qdrant:v1.7.45f2a56b95266
p11-kit@0.24.1-2
no fix listed
1
qdrant/qdrant:v1.4.166ee661d5241
p11-kit@0.24.1-2
no fix listed
1
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
p11-kit@0.25.5-3
no fix listed
1
qonstrukt/php:8.4-v8-apache089af7925aa1
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
quickwit/quickwit:v0.8.1d29332bdadcc
p11-kit@0.24.1-2
no fix listed
1
qumine/minecraft-server:v0.1.15c0b650d51132
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
qxip/qryn:3.2.3977acc9c7a9fd
p11-kit@0.24.1-2
no fix listed
1
rabeh/apibootspring:1.0941007b6946e
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
radondb/clickhouse-server:v21.1.3.32-stable4732df471073
p11-kit@0.23.9-2ubuntu0.1
0.23.9-2ubuntu0.1+esm1
1
razorbladex401/dayz:latest6a4d79248e7d
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
readysettech/sqp:latest588f3507280e
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
readysettech/sqp-duckdb:latest67a83203ce60
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
reallibrephotos/librephotos-proxy:1.0.398a13dabbadc
p11-kit@0.25.5-3
no fix listed
1
redash/redash:25.8.000d813437db5
p11-kit@0.24.1-2
no fix listed
1
redash/redash:26.3.0c5c9148f5c38
p11-kit@0.24.1-2
no fix listed
1
redimp/otterwiki:2778bf30da3da
p11-kit@0.24.1-2
no fix listed
1
redis/redis-stack-server:6.2.6-v251a58f32d412
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
redis/redis-stack-server:latest798ab84d9f26
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
redis/redis-stack-server:7.4.0-v0887cf87cc744
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
redpandadata/redpanda:latest468bd13a9f2b
p11-kit@0.25.5-3
no fix listed
1
resurfaceio/resurface:3.7.84d5cda2f64109
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
rezachalak/bzen-mongo:1.0.034f694325191
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
rhasspy/wyoming-piper:2.3.169b7f797ae3a
p11-kit@0.24.1-2
no fix listed
1
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
p11-kit@0.24.1-2
no fix listed
1
rhasspy/wyoming-whisper:3.5.0308b7959a925
p11-kit@0.24.1-2
no fix listed
1
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
rnwood/smtp4dev:3.6.1912304153668
p11-kit@0.24.1-2
no fix listed
1
robotshop/rs-mongodb:latest119b545823cd
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
rocketadmin/rocketadmin:1.17.710955ef540b9
p11-kit@0.24.1-2
no fix listed
1
rocketchat/freeswitch:stablecfba5c20a5cc
p11-kit@0.24.1-2
no fix listed
1
rotationalio/endeavor:1.3.0ac566baddc06
p11-kit@0.24.1-2
no fix listed
1
rotationalio/genoa:1.2.03ab583519215
p11-kit@0.24.1-2
no fix listed
1
rotationalio/honu:0.5.069fd30c2e31c
p11-kit@0.24.1-2
no fix listed
1
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
p11-kit@0.25.5-3
no fix listed
1
rraahul/test:latestbfe2c1183bc0
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
rrobetti/ojp:0.1.0-beta1141bd88232b
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
rstmdb/rstmdb:lateste5187f2aaace
p11-kit@0.24.1-2
no fix listed
1
rtuszik/photon-docker:2.4.021549c60f9e6
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
ryshe/terraria:latestb1c89f7f359a
p11-kit@0.24.1-2
no fix listed
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
ryuunosukeds3/orbital:latest0879f7261b10
p11-kit@0.24.1-2
no fix listed
1
salaboy/agenda-service-0967b907d9920c99918e2b91b91937b3ce9ce8293e4e
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
salaboy/c4p-service-a3dc0474cbfa348afcdf47a8eee70ba9bb64bf14467d
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.