StackRadar

CVE-2026-18938

Medium

Advisory

Published 7 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,154
of 17,803 indexed, latest versions
Container images
2,107
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-18938 affecting package p11-kit for versions less than 0.26.5-1

Carried by container images the latest versions of 2,154 of 17,803 indexed charts deploy, on 2,107 images.

Affected packageAffected versionsFixed inImages
p11-kitdeb0.23.9-2, 0.23.9-2ubuntu0.1, 0.23.20-1build1, 0.23.20-1ubuntu0.1+8 more0.23.9-2ubuntu0.1+esm1, 0.23.20-1ubuntu0.1+esm1, 0.24.0-6ubuntu0.1, 0.25.3-4ubuntu2.2+1 more2,106
p11-kitrpm0.25.0-1.azl30.26.5-11
OSV records
DEBIAN-CVE-2026-18938UBUNTU-CVE-2026-18938AZL-95481ECHO-09a0-891c-526d
Also known as
USN-8687-1

Charts affected

2,154 by stars
ChartLatestAffected imagesRadar Score
changedetection-iozekker6Verified publisher1.101.01 of 1See more

changedetection-io zekker6 1.101.0

1 of the 1 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.6eb4a9f718801
p11-kit@0.24.1-2
no fix listed

Open the chart page →

2,649
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
p11-kit@0.25.5-3
no fix listed

Open the chart page →

1,879
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
p11-kit@0.23.9-2ubuntu0.1
0.23.9-2ubuntu0.1+esm1
yandex/clickhouse-server:21.3.204eccfffb01d7
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1

Open the chart page →

9,280
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-18938.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1

Open the chart page →

7,949

Container images carrying it

2,107 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
wasmcloud/wasmcloud:0.81.05c7acfe7e8e1
p11-kit@0.24.1-2
no fix listed
1
wateim/lighthouse-launch:latest2520149ee574
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
wavefronthq/proxy:9.2d1064d28f6eb
p11-kit@0.23.9-2
0.23.9-2ubuntu0.1+esm1
1
wazuh/wazuh-dashboard:4.4.11787550d2358
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
wazuh/wazuh-manager:4.4.121994f40e0da
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
weblate/weblate:2026.9.1.0990720d1737a
p11-kit@0.26.2-2
no fix listed
1
wekanteam/wekan:v4.2268a51f0327df
p11-kit@0.23.20-1build1
0.23.20-1ubuntu0.1+esm1
1
wger/server:2.6997ead43aabd
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
wiktorn/overpass-api:latest9bb5f4a9b54c
p11-kit@0.24.1-2
no fix listed
1
wistefan/mvf:lateste0887302b2d8
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
wolveix/satisfactory-server:v1.9.1199be1064b18
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
wolveix/satisfactory-server:v1.9.9464d11e36e10
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
woojoong/wowza:latestec230db19652
p11-kit@0.23.9-2
0.23.9-2ubuntu0.1+esm1
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
xeladock/mysql_dns:latest4baf531453f1
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
xeladock/nginx2:latestc259a67b1dff
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
xeotek/kadeck:6.3.439a3b37a17c5
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
xeotek/kadeck:4.2.94c6b04d9ce55
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
p11-kit@0.24.1-2
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
p11-kit@0.24.1-2
no fix listed
1
yandex/clickhouse-client:21.3863f94a0f607
p11-kit@0.23.9-2ubuntu0.1
0.23.9-2ubuntu0.1+esm1
1
yandex/clickhouse-server:latest1cbf75aabe1e
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
yandex/clickhouse-server:21.3.204eccfffb01d7
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
yandex/clickhouse-server:19.17ab1738a64b70
p11-kit@0.23.9-2
0.23.9-2ubuntu0.1+esm1
1
yandex/clickhouse-server:19.14ccf9c2b5e3f2
p11-kit@0.23.9-2
0.23.9-2ubuntu0.1+esm1
1
yandex/clickhouse-server:19.16d210dc69321e
p11-kit@0.23.9-2
0.23.9-2ubuntu0.1+esm1
1
ybucci/traefik-external-dns-controller:2.2.08d27ad8b5f73
p11-kit@0.25.5-3
no fix listed
1
yetiplatform/yeti:2.9.09bcbe2650a14
p11-kit@0.25.5-3
no fix listed
1
yetiplatform/yeti:latest9c3006cedcca
p11-kit@0.25.5-3
no fix listed
1
yetiplatform/yeti-frontend:latest709064278c7e
p11-kit@0.25.5-3
no fix listed
1
yetiplatform/yeti-frontend:2.9.0873ef15d267b
p11-kit@0.25.5-3
no fix listed
1
youkadev/api-snap:0.1.14db0f9428e67
p11-kit@0.24.1-2
no fix listed
1
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
p11-kit@0.23.20-1ubuntu0.1
0.23.20-1ubuntu0.1+esm1
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
p11-kit@0.25.3-4ubuntu2.1
0.25.3-4ubuntu2.2
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
zenmldocker/zenml-server:0.96.409027a6312ee
p11-kit@0.24.1-2
no fix listed
1
zepai/knowledge-graph-mcp:v0.2.16ab0ee79926b
p11-kit@0.24.1-2
no fix listed
1
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1
gcr.io/abacus-labs-dev/hyperlane-agent:10c0ab1-20231215-220639f33e88324a40
p11-kit@0.24.0-6build1
0.24.0-6ubuntu0.1
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.