StackRadar

CVE-2026-19499

High

Advisory

Published 26 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,856
of 17,803 indexed, latest versions
Container images
1,838
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,856 of 17,803 indexed charts deploy, on 1,838 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.36-9, 2.36-9+deb12u1, 2.36-9+deb12u3, 2.36-9+deb12u4+27 more2.39-0ubuntu8.9, 2.41-12+deb13u3+e5, 2.43-2ubuntu2.41,838
OSV records
DEBIAN-CVE-2026-19499UBUNTU-CVE-2026-19499ECHO-0b68-19f2-1a40
Also known as
USN-8737-1, USN-8737-2

Charts affected

1,856 by stars
ChartLatestAffected imagesRadar Score
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,311
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,861
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
glibc@2.36-9+deb12u4
no fix listed

Open the chart page →

2,692
changedetection-iozekker6Verified publisher1.101.01See more

changedetection-io zekker6 1.101.0

1 container image this version deploys carries CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.6eb4a9f718801
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

485
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,861

Container images carrying it

1,838 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
glibc@2.36-9+deb12u10
no fix listed
1
utkuozdemir/nvidia_gpu_exporter:1.15.17aee2d42836a
glibc@2.41-12+deb13u3
no fix listed
1
v3xl/kubesend:0.1.06f62ca96be82
glibc@2.36-9+deb12u10
no fix listed
1
valkey/valkey:8.1.61f84517eca8e
glibc@2.41-12+deb13u2
no fix listed
1
valkey/valkey:9.0.54c64dfeae602
glibc@2.41-12+deb13u3
no fix listed
1
valkey/valkey:8.0.1c5d4f082b76d
glibc@2.36-9+deb12u8
no fix listed
1
vaultwarden/server:1.35.443498a94b22f
glibc@2.41-12+deb13u1
no fix listed
1
vaultwarden/server:1.34.384fd8a47f58d
glibc@2.36-9+deb12u10
no fix listed
1
vaultwarden/server:1.35.79a8eec71f4a5
glibc@2.41-12+deb13u2
no fix listed
1
vcnngr/telegram-login:latest1a849a997b6d
glibc@2.36-9+deb12u10
no fix listed
1
vcnngr/telegram-rebot:latest30f1f05e57a6
glibc@2.36-9+deb12u10
no fix listed
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
glibc@2.36-9+deb12u10
no fix listed
1
venturenox/redis:latest83b471c193ba
glibc@2.36-9+deb12u9
no fix listed
1
vineyardcloudnative/vineyard-operator:latest9d419aa18faa
glibc@2.36-9+deb12u7
no fix listed
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
glibc@2.36-9+deb12u9
no fix listed
1
vlebediantsev/notes-admin-front:latest007c6670ff48
glibc@2.36-9+deb12u1
no fix listed
1
vlebediantsev/notes-project-front:latest945675fd2636
glibc@2.36-9+deb12u1
no fix listed
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
glibc@2.36-9+deb12u1
no fix listed
1
wallarm/aih-scanner:2.7.11f1cb26db1f5b
glibc@2.41-12+deb13u3
no fix listed
1
wallarm/api-gateway:0.2.0a3d4d2f780e8
glibc@2.36-9+deb12u13
no fix listed
1
wallarm/gateway-controller:0.4.09c6ed23e2f0e
glibc@2.41-12+deb13u3
no fix listed
1
wasmcloud/wasmcloud:0.81.05c7acfe7e8e1
glibc@2.36-9+deb12u3
no fix listed
1
weblate/weblate:2026.9.1.0990720d1737a
glibc@2.43-2ubuntu2.3
2.43-2ubuntu2.4
1
wger/server:2.6997ead43aabd
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.9
1
wiktorn/overpass-api:latest9bb5f4a9b54c
glibc@2.36-9+deb12u14
no fix listed
1
worthnl/notifynl-omc:2.2.009fca4ed1c71
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
glibc@2.36-9+deb12u7
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
glibc@2.36-9+deb12u7
no fix listed
1
ybucci/traefik-external-dns-controller:2.2.08d27ad8b5f73
glibc@2.41-12+deb13u3
no fix listed
1
yetiplatform/yeti:2.9.09bcbe2650a14
glibc@2.41-12+deb13u3
no fix listed
1
yetiplatform/yeti:latest9c3006cedcca
glibc@2.41-12+deb13u3
no fix listed
1
yetiplatform/yeti-frontend:latest709064278c7e
glibc@2.41-12+deb13u3
no fix listed
1
yetiplatform/yeti-frontend:2.9.0873ef15d267b
glibc@2.41-12+deb13u3
no fix listed
1
youkadev/api-snap:0.1.14db0f9428e67
glibc@2.36-9+deb12u4
no fix listed
1
youssef11gaber10/flask-service:latest9c727fcfde76
glibc@2.41-12+deb13u2
no fix listed
1
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.9
1
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.9
1
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.9
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.9
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.9
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.9
1
zenmldocker/zenml-server:0.96.409027a6312ee
glibc@2.36-9+deb12u14
no fix listed
1
zepai/knowledge-graph-mcp:v0.2.16ab0ee79926b
glibc@2.36-9+deb12u10
no fix listed
1
zer0tonin/mikochi:1.11.009872bae1554
glibc@2.43-2ubuntu2
2.43-2ubuntu2.4
1
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.9
1
gcr.io/datadoghq/observability-pipelines-worker:2.21.1de6ff0f1a854
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9
1
gcr.io/datadoghq/private-action-runner:v1.21.05f5918f843a4
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.9
1
gcr.io/istio-testing/install-cni:latestec6f9ea5757b
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9
1
gcr.io/istio-testing/operator:latest8d4576f7b98f
glibc@2.39-0ubuntu8.2
2.39-0ubuntu8.9
1
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
glibc@2.36-9+deb12u8
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.