StackRadar

CVE-2026-40200

High

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,055
of 17,790 indexed, latest versions
Container images
1,113
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,055 of 17,790 indexed charts deploy, on 1,113 images.

Affected packageAffected versionsFixed inImages
muslapk1.2.4_git20230717-r4, 1.2.4_git20230717-r5, 1.2.5-r0, 1.2.5-r1+5 more1.2.4_git20230717-r6, 1.2.5-r3, 1.2.5-r11, 1.2.5-r12+2 more1,112
musldeb1.2.2-4no fix listed1
OSV records
ALPINE-CVE-2026-40200UBUNTU-CVE-2026-40200

Charts affected

1,055 by stars
ChartLatestAffected imagesRadar Score
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-40200.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
musl@1.2.5-r0
1.2.5-r3

Open the chart page →

13,783
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-40200.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
musl@1.2.5-r0
1.2.5-r3

Open the chart page →

9,395
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-40200.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
musl@1.2.5-r21
1.2.5-r23

Open the chart page →

1,571
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-40200.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6

Open the chart page →

569
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-40200.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
musl@1.2.5-r21
1.2.5-r23

Open the chart page →

1,159

Container images carrying it

1,113 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/linuxserver/radarr:6.0.4c8a55bd83672
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/linuxserver/sonarr:4.0.16.2944-ls3008b9f2138ec50
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/liturgical-app/liturgical-app:1.2.041f25aded572
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/lldap/lldap:2025-05-193de697c3ba57
musl@1.2.4_git20230717-r5
1.2.4_git20230717-r6
1
ghcr.io/lldap/lldap:2026-01-06-alpine-rootless824adeb6f765
musl@1.2.4_git20230717-r5
1.2.4_git20230717-r6
1
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
musl@1.2.5-r0
1.2.5-r3
1
ghcr.io/luzifer/cert-manager-desec-webhook:v1.0.1fa1f6b2e9a6e
musl@1.2.5-r8
1.2.5-r11
1
ghcr.io/luzilla/unbound:v0.7.0-rc3252613692e5e
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/luzilla/unbound:v0.12.04fd8da9dc13c
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
musl@1.2.5-r0
1.2.5-r3
1
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/mailcow/prometheus-exporter:2.1.0cb76395b84eb
musl@1.2.5-r9
1.2.5-r11
1
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
musl@1.2.5-r1
1.2.5-r3
1
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/marthydavid/kafka-keda-golang-consumer:0.0.4e07644865dd1
musl@1.2.5-r0
1.2.5-r3
1
ghcr.io/marthydavid/kafka-keda-golang-producer:0.0.454b242c7bf2b
musl@1.2.5-r0
1.2.5-r3
1
ghcr.io/matanbaruch/cursor-admin-api-exporter:0.1.8ba3a29fc479a
musl@1.2.5-r1
1.2.5-r3
1
ghcr.io/mattn/picoclaw:latest517556c8b144
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/mglants/kea-dhcp:2.5.8e1b6eb9e37f9
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/mgumz/mtr-exporter:0.4.0f4691c8fe8eb
musl@1.2.5-r0
1.2.5-r3
1
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
musl@1.2.5-r9
1.2.5-r11
1
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
musl@1.2.5-r8
1.2.5-r11
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/mruoss/kompost:0.3.2292d9a8d67c5
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/mshade/kronic:v0.1.466e3043851cd
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/mt190502/docker-anki-sync-server:25.09.2824245fd5a57
musl@1.2.5-r8
1.2.5-r11
1
ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0dcb8c731bb1b
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.61.2f04925fe1fa6
musl@1.2.5-r0
1.2.5-r3
1
ghcr.io/onedr0p/prowlarr-develop:1.14.0.4286c77d84ebf7a6
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/onedr0p/qbittorrent:4.6.3a4ad890e8c4a
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/onedr0p/radarr:5.3.6.86128d299e59fce7
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/onedr0p/sonarr:4.0.2.118327ffdcc8a937
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/openclarity/kubeclarity:v2.23.314450f52a708
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/openclarity/kubeclarity-sbom-db:v2.23.3cef2b88bfc76
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
musl@1.2.5-r21
1.2.5-r23
1
ghcr.io/opencost/opencost-ui:1.118.0571f87e528ea
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/openfaas/cron-connector:0.7.0982498e8a41e
musl@1.2.5-r8
1.2.5-r11
1
ghcr.io/openfaas/faas-netes:0.18.1224431adc8e2d
musl@1.2.5-r8
1.2.5-r11
1
ghcr.io/openfaas/gateway:0.27.1382b15393116e
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/openfaas/gateway:0.27.14ee0eaecc490c
musl@1.2.5-r10
1.2.5-r12
1
ghcr.io/openfaasltd/federated-gateway:0.2.39066d7b3e6a1
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/openfaasltd/gcp-pubsub-connector:0.0.18df071f5b719
musl@1.2.5-r0
1.2.5-r3
1
ghcr.io/openfaasltd/jetstream-queue-worker:0.3.37d96366e208b1
musl@1.2.4_git20230717-r4
1.2.4_git20230717-r6
1
ghcr.io/openfaasltd/kafka-connector:0.7.160e58eac0e2f7
musl@1.2.5-r21
1.2.5-r23
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.