StackRadar

CVE-2026-19499

High

Advisory

Published 26 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,844
of 17,792 indexed, latest versions
Container images
1,822
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,844 of 17,792 indexed charts deploy, on 1,822 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.36-9, 2.36-9+deb12u1, 2.36-9+deb12u3, 2.36-9+deb12u4+26 more2.39-0ubuntu8.9, 2.41-12+deb13u3+e5, 2.43-2ubuntu2.41,822
OSV records
DEBIAN-CVE-2026-19499UBUNTU-CVE-2026-19499ECHO-0b68-19f2-1a40
Also known as
USN-8737-1, USN-8737-2

Charts affected

1,844 by stars
ChartLatestAffected imagesRadar Score
backstage-pyactionsbackstage-pyactionsVerified publisher0.1.01 of 1See more

backstage-pyactions backstage-pyactions 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
mawad98/backstage-pyactions:demo99422c56a274
glibc@2.41-12+deb13u2
no fix listed

Open the chart page →

2,760
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
glibc@2.36-9+deb12u3
no fix listed

Open the chart page →

6,321
my-nginx-appbassant-nginx-app0.1.01 of 1See more

my-nginx-app bassant-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,849
mealiebdclark-helm-chartsVerified publisher0.1.151 of 1See more

mealie bdclark-helm-charts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
glibc@2.41-12+deb13u2
no fix listed

Open the chart page →

4,059
wyoming-piperbdclark-helm-chartsVerified publisher0.1.41 of 1See more

wyoming-piper bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
rhasspy/wyoming-piper:2.5.27d39aafac409
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,202
pangolinbdcode0.14.11 of 1See more

pangolin bdcode 0.14.1

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
fosrl/pangolin:latest83a55f933b4d
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

1,923
helm-samplebehnambm-helm-chart1.0.11 of 3See more

helm-sample behnambm-helm-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/redis:771da9275c5f3
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

2,750
algorand-relaybiatec-repoVerified publisher4.4.11 of 1See more

algorand-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.9

Open the chart page →

5,117
bitpokebitpokeVerified publisher1.8.191 of 1See more

bitpoke bitpoke 1.8.19

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

2,336
sm-operatorbitwarden2.0.31 of 1See more

sm-operator bitwarden 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/bitwarden/sm-operator:2.1.0846624161f32
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

526
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

10,225
bdbablackduck2026.6.36 of 9See more

bdba blackduck 2026.6.3

6 of the 9 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
blackducksoftware/bdba-fluentd:2026.6.3c14bbbf45536
glibc@2.41-12+deb13u3
no fix listed
blackducksoftware/bdba-frontend:2026.6.3b10eaea94fd3
glibc@2.41-12+deb13u3
no fix listed
fluent/fluent-bit:4.2.6a52221a2a3eb
glibc@2.41-12+deb13u3
no fix listed
library/memcached:1.6.42-trixiee2a8683c7fbb
glibc@2.41-12+deb13u3
no fix listed
library/postgres:15.18-bookworme8db9bd3e9e1
glibc@2.36-9+deb12u14
no fix listed
library/rabbitmq:4.2.87561d672fae4
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.9

Open the chart page →

9,667
bluespacebluespace0.3.01 of 1See more

bluespace bluespace 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,849
colosseumbook-k8sinfra-v21.0.183 of 5See more

colosseum book-k8sinfra-v2 1.0.18

3 of the 5 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
glibc@2.36-9+deb12u10
no fix listed
sysnet4admin/colosseum-prm:log5802bfcd7fed
glibc@2.36-9+deb12u10
no fix listed
sysnet4admin/colosseum-rwd:log74ded2d92f07
glibc@2.41-12
no fix listed

Open the chart page →

27,215
csi-driver-nfsbook-k8sinfra-v24.12.11 of 6See more

csi-driver-nfs book-k8sinfra-v2 4.12.1

1 of the 6 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

6,289
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
glibc@2.36-9+deb12u4
no fix listed

Open the chart page →

8,339
flaresolverrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

flaresolverr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

27,554
tenantsbrbarmex-tenant2.0.01 of 1See more

tenants brbarmex-tenant 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,849
tautullibryanalves0.1.01 of 1See more

tautulli bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
tautulli/tautulli:latest670e68dd9efc
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,929
node-appbryopsida0.5.12 of 2See more

node-app bryopsida 0.5.1

2 of the 2 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
glibc@2.36-9+deb12u14
no fix listed
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.9

Open the chart page →

14,513
plexbryopsida0.2.01 of 1See more

plex bryopsida 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:latest7f9a1d574958
glibc@2.43-2ubuntu2.3
2.43-2ubuntu2.4

Open the chart page →

854
nginx-chartbtrepoVerified publisher0.1.01 of 1See more

nginx-chart btrepo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,849
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9

Open the chart page →

11,958
gotenbergbysamioVerified publisher0.2.01 of 1See more

gotenberg bysamio 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8-chromiuma40f92d7419a
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

9,270
mariadbbysamioVerified publisher1.0.21 of 1See more

mariadb bysamio 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/mariadb:12.0.2607835cd628b
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.9

Open the chart page →

2,948
rediscagriekinVerified publisher1.5.21 of 2See more

redis cagriekin 1.5.2

1 of the 2 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/redis:8.8.1-trixie3eafabb4c93f
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,394
ct-singlecalltelemetry0.8.41 of 7See more

ct-single calltelemetry 0.8.4

1 of the 7 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
calltelemetry/web:0.8.1-rc7205d13269e350
glibc@2.36-9+deb12u8
no fix listed

Open the chart page →

10,661
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
glibc@2.36-9+deb12u1
no fix listed

Open the chart page →

8,024
geoservercamptocamp20.0.31 of 12See more

geoserver camptocamp2 0.0.3

1 of the 12 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

88,618
httpd-ldapauth-proxycamptocamp31.0.21 of 1See more

httpd-ldapauth-proxy camptocamp3 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/httpd:2.4.631ae8051591a5
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

3,334
nginx-s3-gatewaycamptocamp31.0.01 of 1See more

nginx-s3-gateway camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss-202503313db8145349a3
glibc@2.36-9+deb12u8
no fix listed

Open the chart page →

5,062
pgbouncer-tlscamptocamp32.3.02 of 2See more

pgbouncer-tls camptocamp3 2.3.0

2 of the 2 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/haproxy:3.2de601ccc9a79
glibc@2.41-12+deb13u3
no fix listed
ghcr.io/camptocamp/pgbouncer:latest19dc5663cac4
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,910
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

10,867
apachecamptocamp-apache0.4.01 of 2See more

apache camptocamp-apache 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
camptocamp/mapserver:latestbf2e8e118c9b
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9

Open the chart page →

1,490
caninecanine0.1.101 of 7See more

canine canine 0.1.10

1 of the 7 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/caninehq/canine:latesta058034ca006
glibc@2.36-9+deb12u7
no fix listed

Open the chart page →

14,179
castai-hibernatecastaiVerified publisher0.2.121 of 1See more

castai-hibernate castai 0.2.12

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
castai/hibernate:v0.14da62858c8381
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,169
catalyst-agentscatalyst-agents0.1.331See more

catalyst-agents catalyst-agents 0.1.33

1 container image this version deploys carries CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

getoutlinecfi20171.2.02 of 4See more

getoutline cfi2017 1.2.0

2 of the 4 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/postgres:18.06f3e42ad37de
glibc@2.41-12
no fix listed
library/redis:8.2.3d31852005202
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

4,459
opencvecfi20170.1.25 of 7See more

opencve cfi2017 0.1.2

5 of the 7 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/nginx:trixie05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed
library/postgres:18.06f3e42ad37de
glibc@2.41-12
no fix listed
library/redis:7.2-bookworm74566c6910d1
glibc@2.36-9+deb12u14
no fix listed
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
glibc@2.36-9+deb12u9
no fix listed
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

15,490
nginx-chartchanhk10.1.01 of 1See more

nginx-chart chanhk1 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,849
charon-relaycharonOfficialVerified publisher0.8.01 of 2See more

charon-relay charon 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
obolnetwork/charon:v1.10.0278c7e2897b6
glibc@2.41-12+deb13u2
no fix listed

Open the chart page →

4,440
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
obolnetwork/charon:v1.10.0278c7e2897b6
glibc@2.41-12+deb13u2
no fix listed

Open the chart page →

7,501
helioscharonVerified publisher0.1.51 of 1See more

helios charon 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
obolnetwork/helios:e10e753cb7e97d39d46
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.9

Open the chart page →

2,133
remote-signercharonVerified publisher0.4.01 of 2See more

remote-signer charon 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/obolnetwork/remote-signer:v0.4.0534baa453d3d
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

349
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

5,840
kitchenowlchart-kitchenowl0.1.121 of 2See more

kitchenowl chart-kitchenowl 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
glibc@2.41-12+deb13u2
no fix listed

Open the chart page →

4,829
calibre-webcharts-derwitt-devVerified publisher1.1.21 of 1See more

calibre-web charts-derwitt-dev 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

4,930
paperless-ngxcharts-derwitt-devVerified publisher2.1.41 of 1See more

paperless-ngx charts-derwitt-dev 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

4,651
chat-searchchat-searchVerified publisher0.1.71 of 1See more

chat-search chat-search 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/hemslo/chat-search:latest39d48995a5bd
glibc@2.36-9+deb12u7
no fix listed

Open the chart page →

4,059
fhir-server-exporterchglVerified publisher1.2.391 of 1See more

fhir-server-exporter chgl 1.2.39

1 of the 1 container images this version deploys carry CVE-2026-19499.

Container imageDigestPackageFixed in
ghcr.io/chgl/fhir-server-exporter:v3.0.18b7d58a342e94
glibc@2.43-2ubuntu2.3
2.43-2ubuntu2.4

Open the chart page →

217

Container images carrying it

1,822 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
glibc@2.36-9+deb12u14
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
glibc@2.36-9+deb12u14
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
glibc@2.41-12+deb13u3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
glibc@2.41-12+deb13u3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
glibc@2.41-12+deb13u2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
glibc@2.36-9+deb12u14
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
glibc@2.41-12+deb13u3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
glibc@2.36-9+deb12u7
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
glibc@2.41-12+deb13u3
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
glibc@2.36-9+deb12u3
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
glibc@2.36-9+deb12u13
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
glibc@2.36-9+deb12u7
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
glibc@2.41-12
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
glibc@2.36-9+deb12u3
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
glibc@2.36-9+deb12u8
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
glibc@2.36-9+deb12u13
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
glibc@2.36-9+deb12u10
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
glibc@2.36-9+deb12u10
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.