StackRadar

CVE-2026-19499

High

Advisory

Published 26 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,856
of 17,803 indexed, latest versions
Container images
1,838
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,856 of 17,803 indexed charts deploy, on 1,838 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.36-9, 2.36-9+deb12u1, 2.36-9+deb12u3, 2.36-9+deb12u4+27 more2.39-0ubuntu8.9, 2.41-12+deb13u3+e5, 2.43-2ubuntu2.41,838
OSV records
DEBIAN-CVE-2026-19499UBUNTU-CVE-2026-19499ECHO-0b68-19f2-1a40
Also known as
USN-8737-1, USN-8737-2

Charts affected

1,856 by stars
ChartLatestAffected imagesRadar Score
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,311
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,861
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
glibc@2.36-9+deb12u4
no fix listed

Open the chart page →

2,692
changedetection-iozekker6Verified publisher1.101.01See more

changedetection-io zekker6 1.101.0

1 container image this version deploys carries CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.6eb4a9f718801
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

485
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,861

Container images carrying it

1,838 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kubevoip/kubevoip:v0.6.841c603a93642
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
glibc@2.41-12
no fix listed
1
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
glibc@2.36-9+deb12u9
no fix listed
1
ghcr.io/lambdaclass/ethrex:latest0c7896f060d6
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9
1
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
glibc@2.36-9+deb12u1
no fix listed
1
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
glibc@2.39-0ubuntu8.1
2.39-0ubuntu8.9
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
glibc@2.36-9+deb12u8
no fix listed
1
ghcr.io/libretime/icecast:latest3c98b92e9535
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
glibc@2.36-9+deb12u14
no fix listed
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9
1
ghcr.io/linuxserver/duplicati:latesta792931146b4
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9
1
ghcr.io/linuxserver/ombi:4.53.50caadf03b804
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.9
1
ghcr.io/linuxserver/plex:version-1.41.4.9463-630c9f557e6d2775e77ec
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.9
1
ghcr.io/litesql/ha:latest4029479b8ea7
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/litesql/pocketbase-ha:latestc5b28608958b
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
glibc@2.41-12+deb13u1
no fix listed
1
ghcr.io/lloesche/valheim-server:latest20fde516ce31
glibc@2.41-12+deb13u2
no fix listed
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
glibc@2.36-9+deb12u4
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.9
1
ghcr.io/maritimeconnectivity/identityregistry:latest5009fd419742
glibc@2.43-2ubuntu2.3
2.43-2ubuntu2.4
1
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
glibc@2.36-9+deb12u9
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
glibc@2.41-12
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
glibc@2.36-9+deb12u13
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
glibc@2.41-12+deb13u2
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
glibc@2.41-12
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
glibc@2.41-12+deb13u2
no fix listed
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
glibc@2.36-9+deb12u4
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
glibc@2.41-12
no fix listed
1
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.9
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.9
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
glibc@2.39-0ubuntu8.2
2.39-0ubuntu8.9
1
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
glibc@2.39-0ubuntu8.2
2.39-0ubuntu8.9
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
glibc@2.39-0ubuntu8.2
2.39-0ubuntu8.9
1
ghcr.io/metio/tik:2026.8.2618070677f9ee7821d7
glibc@2.36-9+deb12u14
no fix listed
1
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.9
1
ghcr.io/middleware-labs/mw-kube-agent:1.21.0ff23f452813a
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.9
1
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
glibc@2.36-9+deb12u3
no fix listed
1
ghcr.io/mollyim/mollysocket:1.7.1c675622546a4
glibc@2.36-9+deb12u14
no fix listed
1
ghcr.io/monicahq/monica-next:main8be69156acbb
glibc@2.41-12
no fix listed
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
glibc@2.36-9+deb12u13
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
glibc@2.36-9+deb12u14
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
glibc@2.36-9+deb12u13
no fix listed
1
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
glibc@2.39-0ubuntu8.2
2.39-0ubuntu8.9
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.