StackRadar

CVE-2026-40228

Low

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,552
of 17,828 indexed, latest versions
Container images
2,551
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,552 of 17,828 indexed charts deploy, on 2,551 images.

Affected packageAffected versionsFixed inImages
systemddeb204-5ubuntu20.7, 204-5ubuntu20.10, 204-5ubuntu20.24, 204-5ubuntu20.28+115 moreno fix listed2,551
OSV records
DEBIAN-CVE-2026-40228UBUNTU-CVE-2026-40228

Charts affected

2,552 by stars
ChartLatestAffected imagesRadar Score
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
systemd@237-3ubuntu10.53
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
systemd@245.4-4ubuntu3.15
no fix listed

Open the chart page →

9,340
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
systemd@249.11-0ubuntu3.21
no fix listed

Open the chart page →

8,105

Container images carrying it

2,551 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/nginx:1.25:1.25.5a484819eb602
systemd@252.22-1~deb12u1
no fix listed
3
library/node:lts64af3819f927
systemd@252.39-1~deb12u2
no fix listed
3
library/ubuntu:24.04008173c23f95
systemd@255.4-1ubuntu8.17
no fix listed
3
library/ubuntu:latest2260313b31c8
systemd@259.5-0ubuntu3.4
no fix listed
3
library/ubuntu:latestda6fc2be5478
systemd@259.5-0ubuntu3.4
no fix listed
3
linuxserver/plex:1.43.4:latest1f6f97d76e7b
systemd@259.5-0ubuntu3.4
no fix listed
3
localstack/localstack:latest4abc29e923e5
systemd@257.13-1~deb13u1
no fix listed
3
mcp/grafana:latest9362bcf6aa0e
systemd@252.39-1~deb12u2
no fix listed
3
meshery/meshery:stable-latest44b64ee128fb
systemd@252.39-1~deb12u2
no fix listed
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
systemd@229-4ubuntu21.15
no fix listed
3
opencsghq/postgres:15.19b98600564e07
systemd@257.13-1~deb13u1
no fix listed
3
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
systemd@249.11-0ubuntu3.6
no fix listed
3
openebs/node-disk-operator:2.1.06afe2123c457
systemd@249.11-0ubuntu3.6
no fix listed
3
selenium/hub:3.141.5902f251d48d5f
systemd@245.4-4ubuntu3.3
no fix listed
3
sigp/lighthouse:latest-amd6450f66cfebb6d
systemd@249.11-0ubuntu3.17
no fix listed
3
vaultwarden/server:1.37.1ebdfe70701c6
systemd@257.13-1~deb13u1
no fix listed
3
xenondb/percona:5.7.330e26872a2b67
systemd@245.4-4ubuntu3.5
no fix listed
3
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
systemd@255.4-1ubuntu8.4
no fix listed
3
ghcr.io/api7/adc:0.27.1f65f53dd9668
systemd@252.39-1~deb12u2
no fix listed
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
systemd@252.31-1~deb12u1
no fix listed
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
systemd@252.6-1
no fix listed
3
ghcr.io/dgtlmoon/changedetection.io:0.60.7:latest096dae27b5d6
systemd@252.39-1~deb12u2
no fix listed
3
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
systemd@252.39-1~deb12u2
no fix listed
3
ghcr.io/flaresolverr/flaresolverr:latest:v3.5.2c80ae007ce2c
systemd@252.39-1~deb12u2
no fix listed
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
systemd@252.26-1~deb12u2
no fix listed
3
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
systemd@252.39-1~deb12u1
no fix listed
3
ghcr.io/tremolosecurity/kube-oidc-proxy:1.0.13a89736c586ba
systemd@255.4-1ubuntu8.17
no fix listed
3
quay.io/cilium/cilium:v1.20.22939231d0d3e
systemd@259.5-0ubuntu3.4
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
systemd@252.30-1~deb12u2
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
systemd@249.11-0ubuntu3.6
no fix listed
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
systemd@255.4-1ubuntu8.4
no fix listed
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
systemd@255.4-1ubuntu8.4
no fix listed
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
systemd@255.4-1ubuntu8.4
no fix listed
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
systemd@255.4-1ubuntu8.4
no fix listed
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
systemd@245.4-4ubuntu3.15
no fix listed
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
systemd@255.4-1ubuntu8.4
no fix listed
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
systemd@229-4ubuntu21.31
no fix listed
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
systemd@249.11-0ubuntu3.9
no fix listed
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
systemd@255.4-1ubuntu8.4
no fix listed
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
systemd@255.4-1ubuntu8.4
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
systemd@252.39-1~deb12u1
no fix listed
3
actualbudget/actual-server:26.9.0552beab3dec8
systemd@252.39-1~deb12u2
no fix listed
2
alazidis/kube-netlag:1.1.00e8c84152201
systemd@255.4-1ubuntu8.12
no fix listed
2
apache/nifi-registry:1.26.07cdfd8deec92
systemd@249.11-0ubuntu3.12
no fix listed
2
apache/rocketmq:5.4.0319cd8a81ed1
systemd@255.4-1ubuntu8.12
no fix listed
2
apache/tika:2.9.0.092d055a84e9e
systemd@249.11-0ubuntu3.7
no fix listed
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
systemd@255.4-1ubuntu8
no fix listed
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
systemd@252.38-1~deb12u1
no fix listed
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
systemd@252.36-1~deb12u1
no fix listed
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
systemd@252.30-1~deb12u2
no fix listed
2

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.