StackRadar

CVE-2026-40200

High

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,055
of 17,790 indexed, latest versions
Container images
1,113
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,055 of 17,790 indexed charts deploy, on 1,113 images.

Affected packageAffected versionsFixed inImages
muslapk1.2.4_git20230717-r4, 1.2.4_git20230717-r5, 1.2.5-r0, 1.2.5-r1+5 more1.2.4_git20230717-r6, 1.2.5-r3, 1.2.5-r11, 1.2.5-r12+2 more1,112
musldeb1.2.2-4no fix listed1
OSV records
ALPINE-CVE-2026-40200UBUNTU-CVE-2026-40200

Charts affected

1,055 by stars
ChartLatestAffected imagesRadar Score
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-40200.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
musl@1.2.5-r0
1.2.5-r3

Open the chart page →

13,783
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-40200.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
musl@1.2.5-r0
1.2.5-r3

Open the chart page →

9,395
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-40200.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
musl@1.2.5-r21
1.2.5-r23

Open the chart page →

1,571
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-40200.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6

Open the chart page →

569
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-40200.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
musl@1.2.5-r21
1.2.5-r23

Open the chart page →

1,159

Container images carrying it

1,113 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/gabe565/domain-watch:latest34c5a1e351d6
musl@1.2.5-r9
1.2.5-r11
1
ghcr.io/gabe565/limo:latest6dfdbc9853bb
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/gabe565/matrimony:latestd39a9d7c3e1b
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/gabe565/mnemonic-ninja:latest1fd90a9e4d04
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/gochain/rpc-proxy/rpc-proxy:latestca01f5ab95f7
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.2c7adcc4db378
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/gurucomputing/headscale-ui:2026.03.17015f5ba04bcb
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/helm/chartmuseum:v0.16.3c81f105c3682
musl@1.2.5-r9
1.2.5-r11
1
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
musl@1.2.5-r9
1.2.5-r11
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/home-operations/lidarr:3.1.29df1e14c8e09
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/home-operations/lidarr:3.1.2.4902dab0e07502a3
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/home-operations/prowlarr:2.3.01a8a4b11972b
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/home-operations/qbittorrent:5.1.4bb82ad6668f8
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/huscker/townsquare-frontend:2.15.2dc6384d10cc8
musl@1.2.5-r9
1.2.5-r11
1
ghcr.io/huseyinbabal/kubetag:lateste161eddc59a0
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/imcitius/checker-edge:1.1.1174426c1fe00f
musl@1.2.5-r9
1.2.5-r11
1
ghcr.io/imunhatep/kube-node-ready:0.5.07439f6f9f85c
musl@1.2.5-r9
1.2.5-r11
1
ghcr.io/innago-property-management/innago-vault-k8s-role-operator:2.0.0ed1c3fd04057
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/interplex-ai/interplex:v1.1.041b0dd0d55b2
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/jaydee94/kubeseal-webgui/ui:4.5.34447636e8102
musl@1.2.5-r9
1.2.5-r11
1
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/jeffvli/feishin:1.11.01eed97d6272d
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/jeremylong/open-vulnerability-data-mirror:v9.0.49a69aa14dc3e
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/justwatchcom/sql_exporter:v0.8c4b1d3d0f052
musl@1.2.5-r9
1.2.5-r11
1
ghcr.io/kadajett/podscope:0.2.3eeedf17112d7
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
musl@1.2.5-r1
1.2.5-r3
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/keel-hq/keel:0.22.3315e188a07c2
musl@1.2.5-r0
1.2.5-r3
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/kluster-manager/fluxcd-addon:v0.0.103475404bef5c
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/kluster-manager/fluxcd-addon:v0.0.23acba3df8827
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/klustrefs/klustre-csi-plugin:0.1.1bcf42ccda0f9
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/kubeservice-stack/customlimitrange-manager:v1.3.0d3ed97d142d4
musl@1.2.5-r9
1.2.5-r11
1
ghcr.io/kubiyabot/tool-manager:0.5.80cca6760763a
musl@1.2.4_git20230717-r5
1.2.4_git20230717-r6
1
ghcr.io/kubiyabot/workflow-engine:v1.46.2560a16a56d4e
musl@1.2.4_git20230717-r5
1.2.4_git20230717-r6
1
ghcr.io/kuoss/lethe:v0.3.1c59f082ba8b2
musl@1.2.5-r1
1.2.5-r3
1
ghcr.io/kuoss/lethe:v0.3.3ebdf55fd5705
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/kuoss/venti:v0.3.38ee3e70d77f1
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/lbi22/trivy-webhook-elasticsearch:v0.1.4b51b824e4f19
musl@1.2.5-r0
1.2.5-r3
1
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/linuxoid69/school-bot:v0.3.3c8872438f1e0
musl@1.2.5-r0
1.2.5-r3
1
ghcr.io/linuxoid69/webdav:1.26.2-r065bacf19caa7
musl@1.2.5-r0
1.2.5-r3
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
musl@1.2.5-r9
1.2.5-r11
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
musl@1.2.5-r9
1.2.5-r11
1
ghcr.io/linuxserver/radarr:6.0.4.10291-ls2896c0948b42c14
musl@1.2.5-r10
1.2.5-r12
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.