StackRadar

CVE-2026-19499

High

Advisory

Published 26 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,844
of 17,792 indexed, latest versions
Container images
1,822
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,844 of 17,792 indexed charts deploy, on 1,822 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.36-9, 2.36-9+deb12u1, 2.36-9+deb12u3, 2.36-9+deb12u4+26 more2.39-0ubuntu8.9, 2.41-12+deb13u3+e5, 2.43-2ubuntu2.41,822
OSV records
DEBIAN-CVE-2026-19499UBUNTU-CVE-2026-19499ECHO-0b68-19f2-1a40
Also known as
USN-8737-1, USN-8737-2

Charts affected

1,844 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

1,822 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
qdrant/qdrant:v1.19.112364fe851b9
glibc@2.41-12+deb13u3
no fix listed
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
glibc@2.36-9+deb12u7
no fix listed
2
quickwit/quickwit:v0.8.2363ff56ce456
glibc@2.36-9+deb12u7
no fix listed
2
rajnandan1/kener:3.2.1930407afca731
glibc@2.36-9+deb12u9
no fix listed
2
rotationalio/quarterdeck:0.16.00e7ad3a031dc
glibc@2.36-9+deb12u14
no fix listed
2
safeglobal/safe-config-service:latest09a5e495c219
glibc@2.41-12+deb13u3
no fix listed
2
safeglobal/safe-transaction-service:latest80db836cc5d5
glibc@2.41-12+deb13u3
no fix listed
2
sikalabs/hello-world-server:latest5f49bf889a64
glibc@2.41-12+deb13u3
no fix listed
2
siscc/dotstatsuite-core-transfer:master46b7e3c888c4
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
glibc@2.36-9+deb12u4
no fix listed
2
taigaio/taiga-back:latest4beed8f62c9f
glibc@2.41-12+deb13u3
no fix listed
2
taigaio/taiga-protected:latestfd4568a97a59
glibc@2.41-12+deb13u3
no fix listed
2
technitium/dns-server:15.4.0df7d90ef0f7b
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.9
2
timberio/vector:0.58.0-distroless-libc6c93dfe2554c
glibc@2.36-9+deb12u14
no fix listed
2
uffizzi/controller:latest0344805f267b
glibc@2.36-9+deb12u4
no fix listed
2
valkey/valkey:83fbd2e3e4b6e
glibc@2.41-12+deb13u3
no fix listed
2
valkey/valkey:9.1.2475ee65cc75c
glibc@2.41-12+deb13u3
no fix listed
2
valkey/valkey:9.0.1546304417fea
glibc@2.41-12
no fix listed
2
valkey/valkey:8.1.481db6d39e1bb
glibc@2.41-12
no fix listed
2
valkey/valkey:9.1.08e8d64b405ce
glibc@2.41-12+deb13u3
no fix listed
2
vaultwarden/server:1.37.31587c45feaa4
glibc@2.41-12+deb13u3
no fix listed
2
vdiogov/glpi-conteiner:latest6945f84f0058
glibc@2.36-9+deb12u7
no fix listed
2
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.9
2
gcr.io/cloud-tagging-10302018/gtm-cloud-image:stable688d35c6c544
glibc@2.41-12+deb13u3
no fix listed
2
ghcr.io/api7/adc:0.27.1f65f53dd9668
glibc@2.36-9+deb12u14
no fix listed
2
ghcr.io/astriaorg/conductor:latest3ea8164b0eae
glibc@2.36-9+deb12u13
no fix listed
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.9
2
ghcr.io/chroma-core/chroma:1.5.91e0b73a187a2
glibc@2.41-12+deb13u2
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
glibc@2.36-9+deb12u13
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
glibc@2.36-9+deb12u14
no fix listed
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
glibc@2.36-9+deb12u14
no fix listed
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
glibc@2.36-9+deb12u7
no fix listed
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
glibc@2.36-9+deb12u10
no fix listed
2
ghcr.io/juanfont/headscale:0.29.3:v0.29.30e7f1c6e4ce6
glibc@2.41-12+deb13u3
no fix listed
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
glibc@2.36-9+deb12u14
no fix listed
2
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.9
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
glibc@2.36-9+deb12u8
no fix listed
2
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
glibc@2.36-9+deb12u10
no fix listed
2
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
glibc@2.36-9+deb12u10
no fix listed
2
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
glibc@2.36-9+deb12u3
no fix listed
2
ghcr.io/project-zot/zot:v2.1.216b69512c00dc
glibc@2.41-12+deb13u3
no fix listed
2
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
glibc@2.36-9+deb12u9
no fix listed
2
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
glibc@2.36-9+deb12u10
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
glibc@2.36-9+deb12u13
no fix listed
2
ghcr.io/voyagermesh/gateway:v1.8.24237fd16a3cb
glibc@2.41-12+deb13u3
no fix listed
2
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2:latestb53a854bd7c1
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9
2
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
glibc@2.41-12
no fix listed
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.9
2
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
glibc@2.36-9+deb12u14
no fix listed
2

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.