StackRadar

CVE-2026-27456

Medium

Advisory

Published 3 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,161
of 17,803 indexed, latest versions
Container images
2,332
deployed by those charts
Fix available
3 of 3
affected packages

libblkid-devel-2.42-1.1 on GA media

Carried by container images the latest versions of 2,161 of 17,803 indexed charts deploy, on 2,332 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:4.16.0-2+really2.41-5, 2.20.1-5.1ubuntu20.2+44 more2.37.2-4ubuntu3.6, 2.39.3-9ubuntu6.6, 2.41.3-3ubuntu2.2, 2.41.5-0+deb13u1+1 more2,217
util-linuxapk2.41-r9, 2.41.2-r02.41.4-r0, 2.41.6-r0104
util-linuxrpm2.33.1-lp151.3.3.2, 2.40.4-150700.2.4, 2.40.4-150700.4.10.1, 2.41.1-160000.2.2+1 more2.40.4-150700.4.13.1, 2.41.1-160000.4.1, 2.42-1.111
OSV records
ALPINE-CVE-2026-27456DEBIAN-CVE-2026-27456UBUNTU-CVE-2026-27456ECHO-a95f-c9f9-a568openSUSE-SU-2026:10736-1SUSE-SU-2026:22332-1SUSE-SU-2026:2485-1
Also known as
USN-8702-1

Charts affected

2,161 by stars
ChartLatestAffected imagesRadar Score
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
library/mariadb:ltsdd9b303aed4f
util-linux@2.39.3-9ubuntu6.5
2.39.3-9ubuntu6.6

Open the chart page →

5,737
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
util-linux@2.37.2-4ubuntu3.4
2.37.2-4ubuntu3.6

Open the chart page →

14,226
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
util-linux@2.38.1-5+deb12u2
no fix listed

Open the chart page →

11,643
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

7,672
xkopsxkops0.1.04 of 5See more

xkops xkops 0.1.0

4 of the 5 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
util-linux@2.38.1-5+deb12u1
no fix listed
hamzaarshad10/querypodpy:1.7154f38e8668e
util-linux@2.38.1-5+deb12u1
no fix listed
library/mongo:latest5211c51171f5
util-linux@2.39.3-9ubuntu6.5
2.39.3-9ubuntu6.6
murtazashah46/helmfile:latest4d11726cf803
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

13,875
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
util-linux@2.39.3-9ubuntu6
2.39.3-9ubuntu6.6

Open the chart page →

2,156
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
util-linux@2.41-5
2.41.5-0+deb13u1

Open the chart page →

1,330
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

2,710
changedetection-iozekker6Verified publisher1.101.01 of 1See more

changedetection-io zekker6 1.101.0

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.6eb4a9f718801
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,649
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
util-linux@2.31.1-0.4ubuntu3.7
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

9,280
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
util-linux@2.37.2-4ubuntu3.5
2.37.2-4ubuntu3.6

Open the chart page →

7,949

Container images carrying it

2,332 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
wallarm/api-gateway:0.2.0a3d4d2f780e8
util-linux@2.38.1-5+deb12u3
no fix listed
1
wallarm/gateway-controller:0.4.09c6ed23e2f0e
util-linux@2.41-5
2.41.5-0+deb13u1
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
util-linux@2.34-0.1ubuntu9.3
no fix listed
1
wasmcloud/wasmcloud:0.81.05c7acfe7e8e1
util-linux@2.38.1-5+b1
no fix listed
1
wateim/lighthouse-launch:latest2520149ee574
util-linux@2.37.2-4ubuntu3.4
2.37.2-4ubuntu3.6
1
wavefronthq/proxy:9.2d1064d28f6eb
util-linux@2.31.1-0.4ubuntu3.6
no fix listed
1
wazuh/wazuh-dashboard:4.4.11787550d2358
util-linux@2.34-0.1ubuntu9.3
no fix listed
1
wazuh/wazuh-manager:4.4.121994f40e0da
util-linux@2.34-0.1ubuntu9.3
no fix listed
1
wekanteam/wekan:v4.2268a51f0327df
util-linux@2.34-0.1ubuntu9
no fix listed
1
wger/server:2.6997ead43aabd
util-linux@2.39.3-9ubuntu6.5
2.39.3-9ubuntu6.6
1
wiktorn/overpass-api:latest9bb5f4a9b54c
util-linux@2.38.1-5+deb12u3
no fix listed
1
wistefan/mvf:lateste0887302b2d8
util-linux@2.37.2-4ubuntu3
2.37.2-4ubuntu3.6
1
wolveix/satisfactory-server:v1.9.1199be1064b18
util-linux@2.37.2-4ubuntu3.4
2.37.2-4ubuntu3.6
1
wolveix/satisfactory-server:v1.9.9464d11e36e10
util-linux@2.37.2-4ubuntu3.4
2.37.2-4ubuntu3.6
1
woojoong/wowza:latestec230db19652
util-linux@2.31.1-0.4ubuntu3.2
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
util-linux@2.37.2-4ubuntu3.4
2.37.2-4ubuntu3.6
1
xeladock/mysql_dns:latest4baf531453f1
util-linux@2.37.2-4ubuntu3
2.37.2-4ubuntu3.6
1
xeladock/nginx2:latestc259a67b1dff
util-linux@2.37.2-4ubuntu3
2.37.2-4ubuntu3.6
1
xeotek/kadeck:6.3.439a3b37a17c5
util-linux@2.37.2-4ubuntu3.4
2.37.2-4ubuntu3.6
1
xeotek/kadeck:4.2.94c6b04d9ce55
util-linux@2.34-0.1ubuntu9.3
no fix listed
1
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
util-linux@2.27.1-6ubuntu3.10
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
util-linux@2.38.1-5+deb12u1
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
util-linux@2.38.1-5+deb12u1
no fix listed
1
yandex/clickhouse-client:21.3863f94a0f607
util-linux@2.31.1-0.4ubuntu3.7
no fix listed
1
yandex/clickhouse-server:latest1cbf75aabe1e
util-linux@2.34-0.1ubuntu9.1
no fix listed
1
yandex/clickhouse-server:21.3.204eccfffb01d7
util-linux@2.34-0.1ubuntu9.1
no fix listed
1
yandex/clickhouse-server:19.17ab1738a64b70
util-linux@2.31.1-0.4ubuntu3.6
no fix listed
1
yandex/clickhouse-server:19.14ccf9c2b5e3f2
util-linux@2.31.1-0.4ubuntu3.6
no fix listed
1
yandex/clickhouse-server:19.16d210dc69321e
util-linux@2.31.1-0.4ubuntu3.6
no fix listed
1
ymuski/geo-checker:5.0.05ba7fd8c7bdc
util-linux@2.41-r9
2.41.6-r0
1
youkadev/api-snap:0.1.14db0f9428e67
util-linux@2.38.1-5+b1
no fix listed
1
youssef11gaber10/flask-service:latest9c727fcfde76
util-linux@2.41-5
2.41.5-0+deb13u1
1
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
util-linux@2.34-0.1ubuntu9.1
no fix listed
1
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
util-linux@2.39.3-9ubuntu6.4
2.39.3-9ubuntu6.6
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
util-linux@2.37.2-4ubuntu3
2.37.2-4ubuntu3.6
1
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
util-linux@2.39.3-9ubuntu6.1
2.39.3-9ubuntu6.6
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
util-linux@2.34-0.1ubuntu9.1
no fix listed
1
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
util-linux@2.39.3-9ubuntu6.4
2.39.3-9ubuntu6.6
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
util-linux@2.37.2-4ubuntu3
2.37.2-4ubuntu3.6
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
util-linux@2.39.3-9ubuntu6.2
2.39.3-9ubuntu6.6
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
util-linux@2.34-0.1ubuntu9.1
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
util-linux@2.39.3-9ubuntu6.4
2.39.3-9ubuntu6.6
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
util-linux@2.37.2-4ubuntu3
2.37.2-4ubuntu3.6
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
util-linux@2.39.3-9ubuntu6.4
2.39.3-9ubuntu6.6
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
util-linux@2.37.2-4ubuntu3
2.37.2-4ubuntu3.6
1
zbalogh/reservation-angular-ui:1.0.95eb19e460b3c
util-linux@2.41-r9
2.41.6-r0
1
zenmldocker/zenml-server:0.96.409027a6312ee
util-linux@2.38.1-5+deb12u3
no fix listed
1
zepai/knowledge-graph-mcp:v0.2.16ab0ee79926b
util-linux@2.38.1-5+deb12u3
no fix listed
1
zer0tonin/mikochi:1.11.009872bae1554
util-linux@2.41.3-3ubuntu2
2.41.3-3ubuntu2.2
1
zimengxiong/excalidash-frontend:0.4.27242629350b06
util-linux@2.41.2-r0
2.41.4-r0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.