StackRadar

CVE-2026-40225

Medium

Advisory

Published 23 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.4
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,416
of 17,787 indexed, latest versions
Container images
1,488
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 1,416 of 17,787 indexed charts deploy, on 1,488 images.

Affected packageAffected versionsFixed inImages
systemddeb245.4-4ubuntu3.1, 245.4-4ubuntu3.2, 245.4-4ubuntu3.3, 245.4-4ubuntu3.4+56 more245.4-4ubuntu3.24+esm3, 249.11-0ubuntu3.19, 252.39-1~deb12u2, 255.4-1ubuntu8.14+3 more1,488
OSV records
DEBIAN-CVE-2026-40225UBUNTU-CVE-2026-40225ECHO-5372-36f1-2a63
Also known as
USN-8119-2

Charts affected

1,416 by stars
ChartLatestAffected imagesRadar Score
openebswenerme3.10.02 of 3See more

openebs wenerme 3.10.0

2 of the 3 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
systemd@249.11-0ubuntu3.6
249.11-0ubuntu3.19
openebs/node-disk-operator:2.1.06afe2123c457
systemd@249.11-0ubuntu3.6
249.11-0ubuntu3.19

Open the chart page →

10,568
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.7.45f2a56b95266
systemd@252.19-1~deb12u1
252.39-1~deb12u2

Open the chart page →

14,618
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
systemd@249.11-0ubuntu3.11
249.11-0ubuntu3.19

Open the chart page →

9,296
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
systemd@255.4-1ubuntu8.12
255.4-1ubuntu8.14

Open the chart page →

2,229
keycloakwiremindVerified publisher25.3.12 of 2See more

keycloak wiremind 25.3.1

2 of the 2 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
systemd@252.38-1~deb12u1
252.39-1~deb12u2
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
systemd@252.39-1~deb12u1
252.39-1~deb12u2

Open the chart page →

7,643
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
systemd@245.4-4ubuntu3.24
245.4-4ubuntu3.24+esm3

Open the chart page →

6,323
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
systemd@252.19-1~deb12u1
252.39-1~deb12u2

Open the chart page →

5,548
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
systemd@252.39-1~deb12u1
252.39-1~deb12u2

Open the chart page →

2,383
rediswiremindVerified publisher23.0.61 of 1See more

redis wiremind 23.0.6

1 of the 1 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/redis:8.4.0-debian-12-r31f0f7ddc4370
systemd@252.39-1~deb12u1
252.39-1~deb12u2

Open the chart page →

2,063
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
systemd@249.11-0ubuntu3.12
249.11-0ubuntu3.19

Open the chart page →

14,172
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
systemd@252.31-1~deb12u1
252.39-1~deb12u2

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
systemd@252.22-1~deb12u1
252.39-1~deb12u2

Open the chart page →

7,685
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
systemd@252.30-1~deb12u2
252.39-1~deb12u2
hamzaarshad10/querypodpy:1.7154f38e8668e
systemd@252.30-1~deb12u2
252.39-1~deb12u2
murtazashah46/helmfile:latest4d11726cf803
systemd@252.30-1~deb12u2
252.39-1~deb12u2

Open the chart page →

13,197
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
systemd@255.4-1ubuntu8
255.4-1ubuntu8.14

Open the chart page →

2,136
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
systemd@252.22-1~deb12u1
252.39-1~deb12u2

Open the chart page →

2,674
clickhousezloi-space1.2.01 of 3See more

clickhouse zloi-space 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-40225.

Container imageDigestPackageFixed in
yandex/clickhouse-server:21.3.204eccfffb01d7
systemd@245.4-4ubuntu3.15
245.4-4ubuntu3.24+esm3

Open the chart page →

9,250

Container images carrying it

1,488 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
systemd@252.26-1~deb12u2
252.39-1~deb12u2
3
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
systemd@252.39-1~deb12u1
252.39-1~deb12u2
3
quay.io/devtron/ai-agent:0.0.16545dac92173
systemd@252.30-1~deb12u2
252.39-1~deb12u2
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
systemd@249.11-0ubuntu3.6
249.11-0ubuntu3.19
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
systemd@255.4-1ubuntu8.4
255.4-1ubuntu8.14
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
systemd@255.4-1ubuntu8.4
255.4-1ubuntu8.14
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
systemd@255.4-1ubuntu8.4
255.4-1ubuntu8.14
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
systemd@255.4-1ubuntu8.4
255.4-1ubuntu8.14
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
systemd@245.4-4ubuntu3.15
245.4-4ubuntu3.24+esm3
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
systemd@255.4-1ubuntu8.4
255.4-1ubuntu8.14
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
systemd@249.11-0ubuntu3.9
249.11-0ubuntu3.19
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
systemd@255.4-1ubuntu8.4
255.4-1ubuntu8.14
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
systemd@255.4-1ubuntu8.4
255.4-1ubuntu8.14
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
systemd@252.39-1~deb12u1
252.39-1~deb12u2
3
alazidis/kube-netlag:1.1.00e8c84152201
systemd@255.4-1ubuntu8.12
255.4-1ubuntu8.14
2
apache/nifi-registry:1.26.07cdfd8deec92
systemd@249.11-0ubuntu3.12
249.11-0ubuntu3.19
2
apache/rocketmq:5.4.0319cd8a81ed1
systemd@255.4-1ubuntu8.12
255.4-1ubuntu8.14
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
systemd@255.4-1ubuntu8
255.4-1ubuntu8.14
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
systemd@252.38-1~deb12u1
252.39-1~deb12u2
2
bitnamilegacy/etcd:latest99b408c15272
systemd@252.38-1~deb12u1
252.39-1~deb12u2
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
systemd@252.36-1~deb12u1
252.39-1~deb12u2
2
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
systemd@252.38-1~deb12u1
252.39-1~deb12u2
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
systemd@252.30-1~deb12u2
252.39-1~deb12u2
2
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
systemd@252.38-1~deb12u1
252.39-1~deb12u2
2
bitnamilegacy/redis:latest5927ff3702df
systemd@252.38-1~deb12u1
252.39-1~deb12u2
2
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
systemd@252.38-1~deb12u1
252.39-1~deb12u2
2
blockstack/stacks-core:3.2.0.0.0f79944317326
systemd@252.38-1~deb12u1
252.39-1~deb12u2
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
systemd@252.19-1~deb12u1
252.39-1~deb12u2
2
chromedp/headless-shell:148.0.7778.97313ed7255ae1
systemd@257.9-1~deb13u1
257.13-1~deb13u1
2
clickhouse/clickhouse-server:24.2ed9640bfff07
systemd@245.4-4ubuntu3.23
245.4-4ubuntu3.24+esm3
2
eqalpha/keydb:latest6537505c4235
systemd@245.4-4ubuntu3.22
245.4-4ubuntu3.24+esm3
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
systemd@245.4-4ubuntu3.22
245.4-4ubuntu3.24+esm3
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
systemd@257.9-1~deb13u1
257.13-1~deb13u1
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
systemd@257.9-1~deb13u1
257.13-1~deb13u1
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
systemd@245.4-4ubuntu3.13
245.4-4ubuntu3.24+esm3
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
systemd@245.4-4ubuntu3.13
245.4-4ubuntu3.24+esm3
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
systemd@245.4-4ubuntu3.13
245.4-4ubuntu3.24+esm3
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
systemd@245.4-4ubuntu3.13
245.4-4ubuntu3.24+esm3
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
systemd@245.4-4ubuntu3.13
245.4-4ubuntu3.24+esm3
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
systemd@245.4-4ubuntu3.13
245.4-4ubuntu3.24+esm3
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
systemd@252.6-1
252.39-1~deb12u2
2
gradiant/ueransim:3.2.6015b30d5fa0f
systemd@249.11-0ubuntu3.12
249.11-0ubuntu3.19
2
grafana/alloy:v1.8.17790f6f7fbd8
systemd@255.4-1ubuntu8.6
255.4-1ubuntu8.14
2
grafana/alloy:v1.12.2f94b1c82957a
systemd@255.4-1ubuntu8.12
255.4-1ubuntu8.14
2
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
systemd@252.6-1
252.39-1~deb12u2
2
honestica/kube-iptables-tailer:master-91a393242fb939
systemd@245.4-4ubuntu3.15
245.4-4ubuntu3.24+esm3
2
hookiesolutions/webhookie:latest0629694246ba
systemd@245.4-4ubuntu3.13
245.4-4ubuntu3.24+esm3
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
systemd@245.4-4ubuntu3.17
245.4-4ubuntu3.24+esm3
2
ilum/marquez:0.54.06e1d709d41f8
systemd@252.39-1~deb12u1
252.39-1~deb12u2
2
interlayhq/interbtc:latesta66d0e35e70f
systemd@245.4-4ubuntu3.24
245.4-4ubuntu3.24+esm3
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.