StackRadar

CVE-2026-38754

High

Advisory

Published 15 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
44
of 17,781 indexed, latest versions
Container images
40
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 44 of 17,781 indexed charts deploy, on 40 images.

Affected packageAffected versionsFixed inImages
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed25
busyboxapk1.36.1-r10, 1.36.1-r11, 1.37.0-r0, 1.37.0-r48+4 more1.38.0-r015
OSV records
UBUNTU-CVE-2026-38754DEBIAN-CVE-2026-38754CGA-6834-prq9-6rx2
Also known as
CGA-vvh3-57pg-xrhx

Charts affected

44 by stars
ChartLatestAffected imagesRadar Score
nextcloudnextcloud9.2.61 of 1See more

nextcloud nextcloud 9.2.6

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
library/nextcloud:34.0.3-apacheb97df9e0e1ee
busybox@1:1.37.0-6+b8
no fix listed

Open the chart page →

4,507
falcofalcosecurity9.1.01 of 3See more

falco falcosecurity 9.1.0

1 of the 3 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
falcosecurity/falco:0.44.1d0cfe422d6ac
busybox@1.37.0-r60
1.38.0-r0

Open the chart page →

5,227
concourseconcourseVerified publisher20.3.01 of 2See more

concourse concourse 20.3.0

1 of the 2 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
concourse/concourse:8.3.040a143ce5873
busybox@1.37.0-r61
1.38.0-r0

Open the chart page →

2,022
gocdgocdOfficialVerified publisher2.18.12 of 2See more

gocd gocd 2.18.1

2 of the 2 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
gocd/gocd-agent-wolfi:v26.1.0753b9f696f45
busybox@1.37.0-r61
1.38.0-r0
gocd/gocd-server:v26.1.0720d1012b93f
busybox@1.37.0-r61
1.38.0-r0

Open the chart page →

1,362
oneuptimeoneuptimeOfficialVerified publisher13.0.41 of 7See more

oneuptime oneuptime 13.0.4

1 of the 7 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.701b81d1432c4
busybox@1:1.30.1-7ubuntu3.1
no fix listed

Open the chart page →

11,192
nextcloudgroundhog2k0.22.51 of 3See more

nextcloud groundhog2k 0.22.5

1 of the 3 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
busybox@1:1.37.0-6+b8
no fix listed

Open the chart page →

4,507
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
busybox@1:1.37.0-6+b3
no fix listed

Open the chart page →

5,634
syftopenmined0.9.52 of 6See more

syft openmined 0.9.5

2 of the 6 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
openmined/syft-backend:0.9.5b72f74a68b32
busybox@1.37.0-r0
1.38.0-r0
openmined/syft-frontend:0.9.5d11524a3854a
busybox@1.37.0-r0
1.38.0-r0

Open the chart page →

17,245
observalobservalVerified publisher1.13.11 of 8See more

observal observal 1.13.1

1 of the 8 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.3810861a2e2d0
busybox@1:1.30.1-7ubuntu3.1
no fix listed

Open the chart page →

5,828
openbaogitlabVerified publisher0.18.11 of 1See more

openbao gitlab 0.18.1

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
busybox@1:1.37.0-6+b8
no fix listed

Open the chart page →

1,769
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
busybox@1:1.30.1-4ubuntu6.4
no fix listed

Open the chart page →

12,422
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
busybox@1.37.0-r48
1.38.0-r0

Open the chart page →

4,292
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
gpappsoft/privacyidea-docker:3.12.2af7841adad26
busybox@1.37.0-r50
1.38.0-r0

Open the chart page →

5,440
clickhousesinextraVerified publisher0.22.01 of 1See more

clickhouse sinextra 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.3.1092098d3b31dd
busybox@1:1.30.1-7ubuntu3.1
no fix listed

Open the chart page →

1,974
kafka-devwikimedia0.2.01 of 1See more

kafka-dev wikimedia 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
busybox@1:1.21.0-1ubuntu1
no fix listed

Open the chart page →

41,427
opensipschetan-opensips0.1.01 of 1See more

opensips chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
chetangautamm/repo:Opensips_Buildb4b94155ff5a
busybox@1:1.21.0-1ubuntu1.4
no fix listed

Open the chart page →

30,140
guestbookcloudnativeapp0.2.01 of 3See more

guestbook cloudnativeapp 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
resouer/redis-slave:v2e2f198b49ba7
busybox@1:1.21.0-1ubuntu1
no fix listed

Open the chart page →

36,839
galaxy-stablecloudve2.0.02 of 5See more

galaxy-stable cloudve 2.0.0

2 of the 5 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
busybox@1:1.21.0-1ubuntu1
no fix listed
galaxy/galaxy-stable:v18.018e577a626dfd
busybox@1:1.21.0-1ubuntu1
no fix listed

Open the chart page →

70,895
csghubcsghubVerified publisher2.4.32 of 34See more

csghub csghub 2.4.3

2 of the 34 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
busybox@1:1.35.0-4+b3
no fix listed
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
busybox@1:1.35.0-4+b3
no fix listed

Open the chart page →

58,897
dapr-agentsdapr-agents-devVerified publisher0.1.51 of 31See more

dapr-agents dapr-agents-dev 0.1.5

1 of the 31 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
ghcr.io/kagent-dev/doc2vec/mcp:1.1.14ace1de323f4a
busybox@1.37.0-r50
1.38.0-r0

Open the chart page →

22,193
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
busybox@1:1.30.1-7ubuntu3
no fix listed

Open the chart page →

12,949
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
busybox@1:1.30.1-7ubuntu3
no fix listed

Open the chart page →

12,949
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
busybox@1.37.0-r60
1.38.0-r0

Open the chart page →

7,459
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
busybox@1:1.30.1-4ubuntu6.4
no fix listed

Open the chart page →

15,722
clickhousehelmforgeVerified publisher2.0.11 of 1See more

clickhouse helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.8.2fa394da808cc
busybox@1:1.30.1-7ubuntu3.1
no fix listed

Open the chart page →

1,695
deepflowkubesphere-stable6.2.6061 of 8See more

deepflow kubesphere-stable 6.2.606

1 of the 8 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
busybox@1:1.30.1-7ubuntu3
no fix listed

Open the chart page →

18,316
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
busybox@1:1.30.1-7ubuntu3
no fix listed

Open the chart page →

12,791
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
busybox@1:1.30.1-7ubuntu3
no fix listed

Open the chart page →

12,791
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
busybox@1:1.21.0-1ubuntu1
no fix listed

Open the chart page →

41,427
sebaopencord1.0.01 of 17See more

seba opencord 1.0.0

1 of the 17 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
voltha/voltha-envoy:1.6.059ab2a00f712
busybox@1:1.21.0-1ubuntu1
no fix listed

Open the chart page →

93,855
dokuopenlit0.1.41 of 3See more

doku openlit 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latestfa394da808cc
busybox@1:1.30.1-7ubuntu3.1
no fix listed

Open the chart page →

1,695
openpanelopenpanel0.9.01 of 6See more

openpanel openpanel 0.9.0

1 of the 6 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
busybox@1:1.30.1-7ubuntu3.1
no fix listed

Open the chart page →

3,423
opslevelopslevelVerified publisher2025.1.221 of 10See more

opslevel opslevel 2025.1.22

1 of the 10 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
replicated/replicated-sdk:1.0.0-beta.318751b4963250
busybox@1.37.0-r0
1.38.0-r0

Open the chart page →

5,554
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
busybox@1:1.21.0-1ubuntu1
no fix listed

Open the chart page →

26,339
kubecostradar-baseVerified publisher1.0.01 of 7See more

kubecost radar-base 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-network-costs:v0.17.6ab6a54c53fd8
busybox@1.36.1-r11
1.38.0-r0

Open the chart page →

9,355
kubewatchrobusta3.5.01 of 1See more

kubewatch robusta 3.5.0

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
robustadev/kubewatch:v2.9.00457a51e36e8
busybox@1.36.1-r11
1.38.0-r0

Open the chart page →

1,766
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
busybox@1:1.30.1-7ubuntu3
no fix listed

Open the chart page →

12,949
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
busybox@1:1.37.0-6+b3
no fix listed

Open the chart page →

9,755
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
busybox@1.37.0-r54
1.38.0-r0

Open the chart page →

5,201
giropops-senhas-prdtechpreta0.1.01 of 2See more

giropops-senhas-prd techpreta 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
nataliagranato/redis:v1.0.052bd9b79a8f2
busybox@1.36.1-r10
1.38.0-r0

Open the chart page →

913
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
busybox@1:1.35.0-4+b4
no fix listed

Open the chart page →

10,086
tyk-control-planetyk-helm5.3.01 of 7See more

tyk-control-plane tyk-helm 5.3.0

1 of the 7 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
tykio/tyk-gateway-ee:v5.13.13e907e675bf9
busybox@1:1.37.0-6+dhi1
no fix listed

Open the chart page →

2,925
tyk-data-planetyk-helm5.3.01 of 3See more

tyk-data-plane tyk-helm 5.3.0

1 of the 3 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
tykio/tyk-gateway-ee:v5.13.13e907e675bf9
busybox@1:1.37.0-6+dhi1
no fix listed

Open the chart page →

848
tyk-stacktyk-helm5.3.01 of 7See more

tyk-stack tyk-helm 5.3.0

1 of the 7 container images this version deploys carry CVE-2026-38754.

Container imageDigestPackageFixed in
tykio/tyk-gateway-ee:v5.13.13e907e675bf9
busybox@1:1.37.0-6+dhi1
no fix listed

Open the chart page →

2,875

Container images carrying it

40 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
tykio/tyk-gateway-ee:v5.13.13e907e675bf9
busybox@1:1.37.0-6+dhi1
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
busybox@1:1.30.1-7ubuntu3
no fix listed
3
clickhouse/clickhouse-server:26.8.2:latestfa394da808cc
busybox@1:1.30.1-7ubuntu3.1
no fix listed
2
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
busybox@1:1.37.0-6+b8
no fix listed
2
wurstmeister/zookeeper:latest7a7fd44a7210
busybox@1:1.21.0-1ubuntu1
no fix listed
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
busybox@1:1.30.1-7ubuntu3
no fix listed
2
anguda/ant-media:2.5c435285fc241
busybox@1:1.30.1-4ubuntu6.4
no fix listed
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
busybox@1:1.21.0-1ubuntu1.4
no fix listed
1
clickhouse/clickhouse-server:26.701b81d1432c4
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:26.3810861a2e2d0
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:26.3.1092098d3b31dd
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
concourse/concourse:8.3.040a143ce5873
busybox@1.37.0-r61
1.38.0-r0
1
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
busybox@1:1.30.1-7ubuntu3
no fix listed
1
falcosecurity/falco:0.44.1d0cfe422d6ac
busybox@1.37.0-r60
1.38.0-r0
1
galaxy/galaxy-init:v18.010267bad550e6
busybox@1:1.21.0-1ubuntu1
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
busybox@1:1.21.0-1ubuntu1
no fix listed
1
gocd/gocd-agent-wolfi:v26.1.0753b9f696f45
busybox@1.37.0-r61
1.38.0-r0
1
gocd/gocd-server:v26.1.0720d1012b93f
busybox@1.37.0-r61
1.38.0-r0
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
busybox@1.37.0-r50
1.38.0-r0
1
library/nextcloud:31.0.6-apache588609d76b21
busybox@1:1.35.0-4+b4
no fix listed
1
library/nextcloud:31.0.10-apacheb7faa1653c39
busybox@1:1.37.0-6+b3
no fix listed
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
busybox@1.37.0-r54
1.38.0-r0
1
nataliagranato/redis:v1.0.052bd9b79a8f2
busybox@1.36.1-r10
1.38.0-r0
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
busybox@1:1.35.0-4+b3
no fix listed
1
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
busybox@1:1.35.0-4+b3
no fix listed
1
openmined/syft-backend:0.9.5b72f74a68b32
busybox@1.37.0-r0
1.38.0-r0
1
openmined/syft-frontend:0.9.5d11524a3854a
busybox@1.37.0-r0
1.38.0-r0
1
opsmx11/issuegen:v2.1.05c50ca123d88
busybox@1:1.21.0-1ubuntu1
no fix listed
1
replicated/replicated-sdk:1.0.0-beta.318751b4963250
busybox@1.37.0-r0
1.38.0-r0
1
resouer/redis-slave:v2e2f198b49ba7
busybox@1:1.21.0-1ubuntu1
no fix listed
1
robustadev/kubewatch:v2.9.00457a51e36e8
busybox@1.36.1-r11
1.38.0-r0
1
voltha/voltha-envoy:1.6.059ab2a00f712
busybox@1:1.21.0-1ubuntu1
no fix listed
1
gcr.io/kubecost1/kubecost-network-costs:v0.17.6ab6a54c53fd8
busybox@1.36.1-r11
1.38.0-r0
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
busybox@1.37.0-r48
1.38.0-r0
1
ghcr.io/kagent-dev/doc2vec/mcp:1.1.14ace1de323f4a
busybox@1.37.0-r50
1.38.0-r0
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
busybox@1:1.30.1-4ubuntu6.4
no fix listed
1
ghcr.io/monicahq/monica-next:main8be69156acbb
busybox@1:1.37.0-6+b3
no fix listed
1
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
busybox@1.37.0-r60
1.38.0-r0
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
busybox@1:1.37.0-6+b8
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.