StackRadar

CVE-2026-40228

Low

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,552
of 17,828 indexed, latest versions
Container images
2,551
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,552 of 17,828 indexed charts deploy, on 2,551 images.

Affected packageAffected versionsFixed inImages
systemddeb204-5ubuntu20.7, 204-5ubuntu20.10, 204-5ubuntu20.24, 204-5ubuntu20.28+115 moreno fix listed2,551
OSV records
DEBIAN-CVE-2026-40228UBUNTU-CVE-2026-40228

Charts affected

2,552 by stars
ChartLatestAffected imagesRadar Score
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
systemd@237-3ubuntu10.53
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
systemd@245.4-4ubuntu3.15
no fix listed

Open the chart page →

9,340
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
systemd@249.11-0ubuntu3.21
no fix listed

Open the chart page →

8,105

Container images carrying it

2,551 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
selenium/hub:4.48.0-20260905d47c27474cb4
systemd@255.4-1ubuntu8.17
no fix listed
1
selenium/node-chrome:4.48.0-202609055ac71fd8dd1e
systemd@255.4-1ubuntu8.17
no fix listed
1
selenium/node-firefox:4.48.0-2026090574a5c1c90f95
systemd@255.4-1ubuntu8.17
no fix listed
1
seoulorigin/janus-ml-sidecar:v3.192cbaad0c540
systemd@257.13-1~deb13u1
no fix listed
1
sepehrmdn/mirasys-assignment:1.0.12567228e33c8
systemd@252.39-1~deb12u1
no fix listed
1
serversideup/php:8.5-fpm-nginx8f8c2f010ac5
systemd@257.13-1~deb13u1
no fix listed
1
shamimkuet/nginx:1.0.2b82902a76a04
systemd@252.26-1~deb12u2
no fix listed
1
shaowenchen/ops-controller-manager:latest35575d4f2bfe
systemd@249.11-0ubuntu3.22
no fix listed
1
shaowenchen/ops-server:latest6bac5cebd125
systemd@249.11-0ubuntu3.16
no fix listed
1
sharanalwar/redchef-backend:latest8d3cab80df49
systemd@252.36-1~deb12u1
no fix listed
1
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
systemd@237-3ubuntu10.47
no fix listed
1
shwcloud/seawise-backup:v1.7.1a97479a54df4
systemd@257.13-1~deb13u1
no fix listed
1
sifrai/grandine:unstablea4fa0c3f0ca7
systemd@255.4-1ubuntu8.17
no fix listed
1
signalen/backend:2.50.14760256000738
systemd@252.39-1~deb12u2
no fix listed
1
signoz/signoz-otel-collector:v0.144.1034ecb436b687
systemd@252.36-1~deb12u1
no fix listed
1
sigp/lighthouse:v7.0.12cae720e9a35
systemd@249.11-0ubuntu3.15
no fix listed
1
sigp/lighthouse:v7.1.0870934e38931
systemd@249.11-0ubuntu3.16
no fix listed
1
sigp/lighthouse:v2.1.2ad501f02cfef
systemd@245.4-4ubuntu3.15
no fix listed
1
sigp/siren:v3.0.42c219b04758e
systemd@252.36-1~deb12u1
no fix listed
1
sigscale/cse:latest67d0c886516b
systemd@252.39-1~deb12u2
no fix listed
1
sigscale/ocs:latest3c1bdc9732e2
systemd@252.39-1~deb12u2
no fix listed
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
systemd@252.26-1~deb12u2
no fix listed
1
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
systemd@252.26-1~deb12u2
no fix listed
1
sirrend/helmup-notifications-service:0.1.3997866417011
systemd@252.26-1~deb12u2
no fix listed
1
sismics/docs:v1.10f4b0ef019cf1
systemd@237-3ubuntu3
no fix listed
1
sissbruecker/linkding:1.35.00c5dddf0b37c
systemd@252.30-1~deb12u2
no fix listed
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
systemd@252.38-1~deb12u1
no fix listed
1
sissbruecker/linkding:1.47.0e35cb50e0581
systemd@257.8-1~deb13u2
no fix listed
1
slagattollas/weatherservice-practica:latest68e7f56393fc
systemd@237-3ubuntu10.44
no fix listed
1
snipe/snipe-it:v8.3.1141ebf2386fe
systemd@255.4-1ubuntu8.10
no fix listed
1
snipe/snipe-it:v6.0.1455fb7636a98c
systemd@245.4-4ubuntu3.18
no fix listed
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
systemd@245.4-4ubuntu3.22
no fix listed
1
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
systemd@237-3ubuntu10.56
no fix listed
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
systemd@252.12-1~deb12u1
no fix listed
1
socialmediamacroscope/image_crawler:0.1.2f508216be63c
systemd@237-3ubuntu10.56
no fix listed
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
systemd@252.12-1~deb12u1
no fix listed
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
systemd@252.12-1~deb12u1
no fix listed
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
systemd@252.12-1~deb12u1
no fix listed
1
softwaremill/bootzooka:latest845b5e8f8056
systemd@259.5-0ubuntu3
no fix listed
1
solarwinds/solarwinds-otel-collector:0.152.3-k8s3c1110e8bdfb
systemd@252.39-1~deb12u2
no fix listed
1
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
systemd@252.39-1~deb12u2
no fix listed
1
soldevelo/pgpool:4.6.3-debian-12-r0044d16a65129
systemd@252.39-1~deb12u1
no fix listed
1
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
systemd@252.39-1~deb12u2
no fix listed
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
systemd@245.4-4ubuntu3.17
no fix listed
1
somnathmore/custom-nginx:v2bdfc06cad4ec
systemd@252.22-1~deb12u1
no fix listed
1
sondresjo/altinnendata-api:v1.8.1d90ca67f028d
systemd@255.4-1ubuntu8.17
no fix listed
1
sondresjo/altinnendata-app:v1.9.2caa49ba0d92a
systemd@257.13-1~deb13u1
no fix listed
1
sondresjo/bobby-api:latestfe534731909a
systemd@252.38-1~deb12u1
no fix listed
1
sondresjo/garge-api:v2.12.762dfd5c9b2e4
systemd@255.4-1ubuntu8.17
no fix listed
1
sondresjo/garge-app:v1.20.861bc5b249b62
systemd@257.13-1~deb13u1
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.