StackRadar

CVE-2026-27456

Medium

Advisory

Published 3 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,161
of 17,828 indexed, latest versions
Container images
2,336
deployed by those charts
Fix available
3 of 3
affected packages

libblkid-devel-2.42-1.1 on GA media

Carried by container images the latest versions of 2,161 of 17,828 indexed charts deploy, on 2,336 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:4.16.0-2+really2.41-5, 2.20.1-5.1ubuntu20.2+44 more2.37.2-4ubuntu3.6, 2.39.3-9ubuntu6.6, 2.41.3-3ubuntu2.2, 2.41.5-0+deb13u1+1 more2,218
util-linuxapk2.41-r9, 2.41.2-r02.41.4-r0, 2.41.6-r0104
util-linuxrpm2.33.1-lp151.3.3.2, 2.33.1-lp152.5.3.1, 2.40.4-150700.2.4, 2.40.4-150700.4.10.1+2 more2.40.4-150700.4.13.1, 2.41.1-160000.4.1, 2.42-1.114
OSV records
ALPINE-CVE-2026-27456DEBIAN-CVE-2026-27456UBUNTU-CVE-2026-27456ECHO-a95f-c9f9-a568openSUSE-SU-2026:10736-1SUSE-SU-2026:22332-1SUSE-SU-2026:2485-1
Also known as
USN-8702-1

Charts affected

2,161 by stars
ChartLatestAffected imagesRadar Score
kube-prometheus-stackprometheus-communityOfficialVerified publisher91.4.11 of 6See more

kube-prometheus-stack prometheus-community 91.4.1

1 of the 6 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
util-linux@2.41-r9
2.41.6-r0

Open the chart page →

682
lokigrafana7.3.01 of 6See more

loki grafana 7.3.0

1 of the 6 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
util-linux@2.41-r9
2.41.6-r0

Open the chart page →

3,958
gitlabgitlabVerified publisher10.4.01 of 21See more

gitlab gitlab 10.4.0

1 of the 21 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabdc1a8972c640
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

16,478
jenkinsjenkinsciOfficialVerified publisher5.9.631 of 2See more

jenkins jenkinsci 5.9.63

1 of the 2 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
util-linux@2.41-r9
2.41.6-r0

Open the chart page →

2,491
airflowapache-airflowOfficialVerified publisher1.22.01 of 4See more

airflow apache-airflow 1.22.0

1 of the 4 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
library/redis:7.2-bookworm0637954999d0
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

3,197
giteagiteaOfficialVerified publisher12.7.03 of 4See more

gitea gitea 12.7.0

3 of the 4 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
util-linux@2.38.1-5+deb12u3
no fix listed
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
util-linux@2.38.1-5+deb12u3
no fix listed
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

8,751
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
util-linux@2.37.2-4ubuntu3
2.37.2-4ubuntu3.6

Open the chart page →

6,725
artifact-hubartifact-hubVerified publisher1.23.02 of 7See more

artifact-hub artifact-hub 1.23.0

2 of the 7 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
util-linux@2.41-5
2.41.5-0+deb13u1
artifacthub/tracker:v1.23.05368d21a6e5c
util-linux@2.41-5
2.41.5-0+deb13u1

Open the chart page →

10,881
alloygrafana1.12.11 of 2See more

alloy grafana 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
grafana/alloy:v1.19.2b8ec653c4423
util-linux@2.39.3-9ubuntu6.5
2.39.3-9ubuntu6.6

Open the chart page →

1,191
jupyterhubjupyterhubOfficialVerified publisher4.4.22 of 7See more

jupyterhub jupyterhub 4.4.2

2 of the 7 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
util-linux@2.38.1-5+deb12u3
no fix listed
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

8,003
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

30,740
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

11,379
victoria-metrics-k8s-stackvictoriametricsVerified publisher0.93.01 of 7See more

victoria-metrics-k8s-stack victoriametrics 0.93.0

1 of the 7 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.8.1abb55b2165c6
util-linux@2.41-r9
2.41.6-r0

Open the chart page →

1,955
openebsopenebsOfficialVerified publisher4.6.12 of 35See more

openebs openebs 4.6.1

2 of the 35 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
util-linux@2.39.3-9ubuntu6.2
2.39.3-9ubuntu6.6
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

24,290
apisixapisix2.17.02 of 3See more

apisix apisix 2.17.0

2 of the 3 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
apache/apisix:3.18.0-ubuntu9ee5df1611f9
util-linux@2.39.3-9ubuntu6.5
2.39.3-9ubuntu6.6
bitnamilegacy/etcd:latest99b408c15272
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

3,107
zabbixzabbix-communityVerified publisher7.1.04 of 5See more

zabbix zabbix-community 7.1.0

4 of the 5 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
util-linux@2.39.3-9ubuntu6.4
2.39.3-9ubuntu6.6
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
util-linux@2.39.3-9ubuntu6.4
2.39.3-9ubuntu6.6
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
util-linux@2.39.3-9ubuntu6.4
2.39.3-9ubuntu6.6
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
util-linux@2.39.3-9ubuntu6.4
2.39.3-9ubuntu6.6

Open the chart page →

13,636
keycloakcloudpirates-keycloakVerified publisher0.21.401See more

keycloak cloudpirates-keycloak 0.21.40

1 container image this version deploys carries CVE-2026-27456.

Container imageDigestPackageFixed in
library/postgres:18.0073e7c8b84e2
util-linux@2.41-5
2.41.5-0+deb13u1

Open the chart page →

fluentdfluent0.6.01 of 1See more

fluentd fluent 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.19.3-debian-elasticsearch7-1.1de9cf5f1127a
util-linux@2.41-5
2.41.5-0+deb13u1

Open the chart page →

973
node-problem-detectordeliveryheroVerified publisher2.4.11 of 1See more

node-problem-detector deliveryhero 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,017
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
boky/postfix:v5.1.0aafc77238423
util-linux@2.41-5
2.41.5-0+deb13u1

Open the chart page →

5,531
vaultwardengissilabs1.4.21 of 1See more

vaultwarden gissilabs 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
util-linux@2.41-5
2.41.5-0+deb13u1

Open the chart page →

1,711
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

5,579
openldap-stack-hahelm-openldapVerified publisher4.3.31 of 5See more

openldap-stack-ha helm-openldap 4.3.3

1 of the 5 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
jpgouin/openldap:2.6.9-fixbfdd0088c776
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

5,528
zammadzammadOfficialVerified publisher19.0.01 of 5See more

zammad zammad 19.0.0

1 of the 5 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
util-linux@2.41-5
2.41.5-0+deb13u1

Open the chart page →

6,450
chaos-meshchaos-meshVerified publisher2.8.42 of 4See more

chaos-mesh chaos-mesh 2.8.4

2 of the 4 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
util-linux@2.38.1-5+deb12u3
no fix listed
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.48a8ec8d4c9ea
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

6,545
csi-driver-nfscsi-driver-nfsVerified publisher4.13.41 of 6See more

csi-driver-nfs csi-driver-nfs 4.13.4

1 of the 6 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

3,350
reflectoremberstackVerified publisher10.0.651 of 1See more

reflector emberstack 10.0.65

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
emberstack/kubernetes-reflector:10.0.6551dbd5880929
util-linux@2.39.3-9ubuntu6.5
2.39.3-9ubuntu6.6

Open the chart page →

723
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
util-linux@2.37.2-4ubuntu3
2.37.2-4ubuntu3.6

Open the chart page →

9,236
milvusmilvus4.0.312 of 5See more

milvus milvus 4.0.31

2 of the 5 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
util-linux@2.34-0.1ubuntu9.1
no fix listed
milvusdb/milvus:v2.2.13a3a55e1c1497
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

171,935
grafana-agentgrafana0.44.21 of 2See more

grafana-agent grafana 0.44.2

1 of the 2 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
grafana/agent:v0.44.23364714a2f64
util-linux@2.39.3-9ubuntu6.2
2.39.3-9ubuntu6.6

Open the chart page →

3,561
mesherymesheryOfficialVerified publisher1.0.701 of 1See more

meshery meshery 1.0.70

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest44b64ee128fb
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,504
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
util-linux@2.38.1-5+deb12u2
no fix listed

Open the chart page →

10,750
penpotpenpotOfficialVerified publisher1.9.02 of 4See more

penpot penpot 1.9.0

2 of the 4 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
penpotapp/exporter:2.17.272a8061e8806
util-linux@2.41.3-3ubuntu2
2.41.3-3ubuntu2.2
penpotapp/mcp:2.17.284f3f07ead11
util-linux@2.41.3-3ubuntu2
2.41.3-3ubuntu2.2

Open the chart page →

4,482
signozsignoz0.142.11 of 5See more

signoz signoz 0.142.1

1 of the 5 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
signoz/signoz-otel-collector:v0.144.1034ecb436b687
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

7,636
weblateweblateOfficialVerified publisher0.5.382See more

weblate weblate 0.5.38

2 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
util-linux@2.38.1-5+deb12u3
no fix listed
bitnamilegacy/redis:latest5927ff3702df
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

locustdeliveryheroVerified publisher0.35.01 of 1See more

locust deliveryhero 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

2,853
emqxemqx-operator5.8.91 of 1See more

emqx emqx-operator 5.8.9

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
emqx/emqx:5.8.935b46f7aa7a0
util-linux@2.41-5
2.41.5-0+deb13u1

Open the chart page →

2,674
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

4,769
node-rednode-redVerified publisher0.40.21 of 1See more

node-red node-red 0.40.2

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
nodered/node-red:4.1.2216e7403aab9
util-linux@2.41-r9
2.41.6-r0

Open the chart page →

2,181
difydoubanVerified publisher0.10.03 of 6See more

dify douban 0.10.0

3 of the 6 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
util-linux@2.38.1-5+deb12u1
no fix listed
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
util-linux@2.38.1-5+deb12u1
no fix listed
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
util-linux@2.39.3-9ubuntu6.3
2.39.3-9ubuntu6.6

Open the chart page →

74,650
dragonflydragonflyVerified publisher1.8.51 of 3See more

dragonfly dragonfly 1.8.5

1 of the 3 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.59fe2a1d6206f
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

4,191
secrets-store-csi-driversecret-store-csi-driver1.6.11 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

1 of the 4 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,825
code-servernicholaswildeVerified publisher1.1.11 of 1See more

code-server nicholaswilde 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/code-server:version-v3.11.1a385ba5cb161
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

16,377
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
util-linux@2.41.3-3ubuntu2
2.41.3-3ubuntu2.2

Open the chart page →

1,620
pulsarapache4.7.01 of 10See more

pulsar apache 4.7.0

1 of the 10 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
util-linux@2.41-r9
2.41.6-r0

Open the chart page →

9,950
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
util-linux@2.39.3-9ubuntu6.2
2.39.3-9ubuntu6.6

Open the chart page →

3,823
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

6,943
difydify-helmVerified publisher0.38.05 of 11See more

dify dify-helm 0.38.0

5 of the 11 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
util-linux@2.38.1-5+deb12u3
no fix listed
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
util-linux@2.38.1-5+deb12u3
no fix listed
langgenius/dify-api:1.16.1dcefa5f7c47c
util-linux@2.38.1-5+deb12u3
no fix listed
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
util-linux@2.39.3-9ubuntu6.5
2.39.3-9ubuntu6.6
langgenius/dify-sandbox:0.2.15750e1111426e
util-linux@2.41-5
2.41.5-0+deb13u1

Open the chart page →

63,843
pyroscopegrafana2.3.11 of 3See more

pyroscope grafana 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
grafana/alloy:v1.12.2f94b1c82957a
util-linux@2.39.3-9ubuntu6.4
2.39.3-9ubuntu6.6

Open the chart page →

3,275
stacks-blockchainhirosystemsVerified publisher2.2.21 of 1See more

stacks-blockchain hirosystems 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-27456.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,347

Container images carrying it

2,336 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

No deployed image carries CVE-2026-27456.

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.