StackRadar

CVE-2026-40228

Low

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,445
of 17,803 indexed, latest versions
Container images
2,408
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,445 of 17,803 indexed charts deploy, on 2,408 images.

Affected packageAffected versionsFixed inImages
systemddeb204-5ubuntu20.7, 204-5ubuntu20.10, 204-5ubuntu20.24, 204-5ubuntu20.28+114 moreno fix listed2,408
OSV records
DEBIAN-CVE-2026-40228UBUNTU-CVE-2026-40228

Charts affected

2,445 by stars
ChartLatestAffected imagesRadar Score
kyoorubxkubeVerified publisher0.1.104 of 9See more

kyoo rubxkube 0.1.10

4 of the 9 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
systemd@252.31-1~deb12u1
no fix listed
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
systemd@252.31-1~deb12u1
no fix listed
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
systemd@252.31-1~deb12u1
no fix listed
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
systemd@252.31-1~deb12u1
no fix listed

Open the chart page →

30,468
conference-appsalaboy1.0.03 of 7See more

conference-app salaboy 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
salaboy/agenda-service-0967b907d9920c99918e2b91b91937b3digest-pinnedce9ce8293e4e
systemd@249.11-0ubuntu3.9
no fix listed
salaboy/c4p-service-a3dc0474cbfa348afcdf47a8eee70ba9digest-pinnedbb64bf14467d
systemd@249.11-0ubuntu3.9
no fix listed
salaboy/notifications-service-0e27884e01429ab7e350cb5dff61b525digest-pinned799c35f9f306
systemd@249.11-0ubuntu3.9
no fix listed

Open the chart page →

11,052
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
systemd@252.39-1~deb12u1
no fix listed

Open the chart page →

38,479
teamcityscalified-teamcityVerified publisher2026.2.01 of 3See more

teamcity scalified-teamcity 2026.2.0

1 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,667
sceptresceptreai0.1.122 of 5See more

sceptre sceptreai 0.1.12

2 of the 5 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
maponyacharles/sceptreai:mlflow-0.1.1242d418654ebd
systemd@257.13-1~deb13u1
no fix listed
maponyacharles/sceptreai:api-0.1.127b37b092130a
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

4,424
schemaheroschemahero1.4.01 of 1See more

schemahero schemahero 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
schemahero/schemahero-manager:0.22.11609e1a05cd3
systemd@255.4-1ubuntu8.8
no fix listed

Open the chart page →

2,194
searxngsearxngVerified publisher0.1.111 of 3See more

searxng searxng 0.1.11

1 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
valkey/valkey:9.1.1-trixie64e361b630ec
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

836
securosecuroVerified publisher0.16.01See more

securo securo 0.16.0

1 container image this version deploys carries CVE-2026-40228.

Container imageDigestPackageFixed in
pgvector/pgvector:pg16ccc6e83d6e35
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

immichsecustorVerified publisher2.0.61 of 1See more

immich secustor 2.0.6

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.279cc1623323d
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

3,094
viya4-home-dir-builderselerityVerified publisher1.1.01 of 2See more

viya4-home-dir-builder selerity 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/python:3.12-slim78387bc3881b
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

881
sentry-k8ssentry-k8sVerified publisher1.4.15 of 11See more

sentry-k8s sentry-k8s 1.4.1

5 of the 11 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
systemd@249.11-0ubuntu3.16
no fix listed
library/postgres:16f1c3376c26f2
systemd@257.13-1~deb13u1
no fix listed
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
systemd@252.33-1~deb12u1
no fix listed
ghcr.io/getsentry/snuba:26.7.210f8d164109b
systemd@257.9-1~deb13u1
no fix listed
ghcr.io/getsentry/taskbroker:26.7.264d0da74a578
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

16,646
seq-input-gelfseq-input-gelfVerified publisher0.3.11 of 2See more

seq-input-gelf seq-input-gelf 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
datalust/seq-input-gelf:3.0.441-x643de34aed5642
systemd@245.4-4ubuntu3.18
no fix listed

Open the chart page →

3,563
vuiseriohub1.0.62 of 3See more

vui seriohub 1.0.6

2 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
dserio83/velero-api:0.3.16b3d9115fee2
systemd@252.38-1~deb12u1
no fix listed
dserio83/velero-watchdog:0.1.8d5deae589229
systemd@252.36-1~deb12u1
no fix listed

Open the chart page →

11,564
sigscale-csesigscale-cseOfficialVerified publisher1.4.221 of 1See more

sigscale-cse sigscale-cse 1.4.22

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
sigscale/cse:latest67d0c886516b
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

2,301
sigscale-ocssigscale-ocsOfficialVerified publisher1.1.171 of 1See more

sigscale-ocs sigscale-ocs 1.1.17

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
sigscale/ocs:latest3c1bdc9732e2
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

2,301
mssqlserver-2019simcube1.2.31 of 1See more

mssqlserver-2019 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
systemd@245.4-4ubuntu3.16
no fix listed

Open the chart page →

6,903
clickhousesinextraVerified publisher0.22.01 of 1See more

clickhouse sinextra 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.3.1092098d3b31dd
systemd@249.11-0ubuntu3.20
no fix listed

Open the chart page →

2,022
mongodb-backupsinextraVerified publisher1.1.01 of 1See more

mongodb-backup sinextra 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
systemd@252.38-1~deb12u1
no fix listed

Open the chart page →

4,282
postgresql-singlesinextraVerified publisher1.15.11 of 1See more

postgresql-single sinextra 1.15.1

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

4,952
gitlab-omnibusslamdev0.1.61 of 2See more

gitlab-omnibus slamdev 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
daedalusproject/base_kubectl:latest6f72b5119eda
systemd@245.4-4ubuntu3.3
no fix listed

Open the chart page →

2,859
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
systemd@252.31-1~deb12u1
no fix listed

Open the chart page →

2,952
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
systemd@245.4-4ubuntu3.18
no fix listed
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
systemd@245.4-4ubuntu3.18
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
systemd@245.4-4ubuntu3.18
no fix listed

Open the chart page →

46,080
snappasssnappassVerified publisher0.4.32 of 3See more

snappass snappass 0.4.3

2 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
systemd@257.9-1~deb13u1
no fix listed
valkey/valkey:8.1.61f84517eca8e
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

3,054
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
systemd@257.8-1~deb13u2
no fix listed

Open the chart page →

14,569
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

2,337
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

7,319
postgresql-ha-chartsoldevelo-postgresql-ha-chart16.3.42 of 2See more

postgresql-ha-chart soldevelo-postgresql-ha-chart 16.3.4

2 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
soldevelo/pgpool:4.6.3-debian-12-r0044d16a65129
systemd@252.39-1~deb12u1
no fix listed
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

4,637
rabbitmqsolidchartsVerified publisher0.7.61 of 2See more

rabbitmq solidcharts 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.6-management534e4fefc5f0
systemd@255.4-1ubuntu8.17
no fix listed

Open the chart page →

814
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
systemd@252.22-1~deb12u1
no fix listed

Open the chart page →

5,716
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
systemd@252.39-1~deb12u1
no fix listed

Open the chart page →

10,494
squidsquid-helmVerified publisher0.1.01 of 1See more

squid squid-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ubuntu/squid:5.2-22.04_beta723891b5bc74
systemd@249.11-0ubuntu3.17
no fix listed

Open the chart page →

2,635
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
graphprotocol/graph-node:v0.37.0f4452cdedd68
systemd@252.31-1~deb12u1
no fix listed

Open the chart page →

4,701
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
systemd@245.4-4ubuntu3.18
no fix listed

Open the chart page →

13,549
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
systemd@245.4-4ubuntu3.6
no fix listed

Open the chart page →

25,064
stornxstornxVerified publisher1.1.13 of 9See more

stornx stornx 1.1.1

3 of the 9 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
systemd@255.4-1ubuntu8.12
no fix listed
alazidis/stornx:1.1.1602d4f7f090c
systemd@252.39-1~deb12u1
no fix listed
istio/pilot:1.29.1f8b0e412ac4a
systemd@255.4-1ubuntu8.12
no fix listed

Open the chart page →

11,760
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
systemd@255.4-1ubuntu8.15
no fix listed

Open the chart page →

2,901
supabasesupabse0.8.06 of 11See more

supabase supabse 0.8.0

6 of the 11 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.30.13b709e4a0e5e
systemd@255.4-1ubuntu8.11
no fix listed
kong/kong:3.9.16addf50e6bd8
systemd@255.4-1ubuntu8.6
no fix listed
supabase/edge-runtime:v1.74.02781daf92394
systemd@252.39-1~deb12u1
no fix listed
supabase/postgres-meta:v0.96.6a84cc713585e
systemd@252.39-1~deb12u1
no fix listed
supabase/realtime:v2.102.3aa1c92c0cf32
systemd@252.39-1~deb12u1
no fix listed
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

18,327
supersonicsupersonicVerified publisher0.3.11 of 2See more

supersonic supersonic 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.92956bd9de830
systemd@249.11-0ubuntu3.12
no fix listed

Open the chart page →

2,149
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

3,276
mumblesyntaxerror404Verified publisher1.0.41 of 1See more

mumble syntaxerror404 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
systemd@255.4-1ubuntu8.16
no fix listed

Open the chart page →

2,157
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,861
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,861
teamcity-serverteamcity-server3.3.51 of 2See more

teamcity-server teamcity-server 3.3.5

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/haproxy:3.2de601ccc9a79
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

853
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
systemd@257.13-1~deb13u1+dhi1
no fix listed

Open the chart page →

2,566
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
systemd@252.17-1~deb12u1
no fix listed

Open the chart page →

9,126
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
systemd@252.17-1~deb12u1
no fix listed

Open the chart page →

9,126
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

13,025
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
systemd@255.4-1ubuntu8.4
no fix listed

Open the chart page →

4,082
typemilltypemill-helm-chart2.2.02 of 2See more

typemill typemill-helm-chart 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
kixote/typemilldigest-pinned4e9dff179519
systemd@257.13-1~deb13u1
no fix listed
kixote/typemilldigest-pinned628f79a08cc7
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

5,526
typesensetypesenseVerified publisher1.1.41 of 1See more

typesense typesense 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
typesense/typesense:30.191604dc128e2
systemd@249.11-0ubuntu3.17
no fix listed

Open the chart page →

1,918

Container images carrying it

2,408 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
systemd@257.8-1~deb13u2
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
systemd@252.17-1~deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
systemd@252.30-1~deb12u2
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
systemd@252.39-1~deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
systemd@252.36-1~deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
systemd@252.39-1~deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
systemd@252.39-1~deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
systemd@252.36-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.