StackRadar

CVE-2026-40228

Low

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,552
of 17,828 indexed, latest versions
Container images
2,551
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,552 of 17,828 indexed charts deploy, on 2,551 images.

Affected packageAffected versionsFixed inImages
systemddeb204-5ubuntu20.7, 204-5ubuntu20.10, 204-5ubuntu20.24, 204-5ubuntu20.28+115 moreno fix listed2,551
OSV records
DEBIAN-CVE-2026-40228UBUNTU-CVE-2026-40228

Charts affected

2,552 by stars
ChartLatestAffected imagesRadar Score
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
systemd@237-3ubuntu10.53
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
systemd@245.4-4ubuntu3.15
no fix listed

Open the chart page →

9,340
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
systemd@249.11-0ubuntu3.21
no fix listed

Open the chart page →

8,105

Container images carrying it

2,551 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mcr.microsoft.com/playwright/mcp:v0.0.43e101b832b34d
systemd@252.39-1~deb12u1
no fix listed
1
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest573542399fe4
systemd@252.39-1~deb12u2
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.66.9138c8b82c398
systemd@255.4-1ubuntu8.17
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:latestf669a6eacf8c
systemd@255.4-1ubuntu8.17
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest5d55a742a2bc
systemd@259.5-0ubuntu3.4
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
systemd@259.5-0ubuntu3.4
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.4_local5bda14f66e8e
systemd@259.5-0ubuntu3.4
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
systemd@255.4-1ubuntu8.12
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
systemd@255.4-1ubuntu8.17
no fix listed
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
systemd@259.5-0ubuntu3.4
no fix listed
1
public.ecr.aws/aktosecurity/akto-threat-detection:latesta728eb2eaf06
systemd@259.5-0ubuntu3.4
no fix listed
1
public.ecr.aws/aktosecurity/redis47200b041382
systemd@252.39-1~deb12u1
no fix listed
1
public.ecr.aws/aktosecurity/redis:latestV8.6.2832d7785830f
systemd@257.9-1~deb13u1
no fix listed
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
systemd@255.4-1ubuntu8.11
no fix listed
1
public.ecr.aws/datadog/cloudprem:v0.1.33bda08753668d
systemd@255.4-1ubuntu8.16
no fix listed
1
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
systemd@257.9-1~deb13u1
no fix listed
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
systemd@252.36-1~deb12u1
no fix listed
1
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
systemd@252.22-1~deb12u1
no fix listed
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
systemd@249.11-0ubuntu3.15
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
systemd@252.30-1~deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
systemd@252.30-1~deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
systemd@252.22-1~deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
systemd@252.19-1~deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
systemd@252.17-1~deb12u1
no fix listed
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
systemd@252.39-1~deb12u1
no fix listed
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
systemd@252.31-1~deb12u1
no fix listed
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
systemd@252.31-1~deb12u1
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
systemd@252.17-1~deb12u1
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
systemd@255.4-1ubuntu8.12
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
systemd@237-3ubuntu10.53
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
systemd@245.4-4ubuntu3.6
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
systemd@252.19-1~deb12u1
no fix listed
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
systemd@249.11-0ubuntu3.12
no fix listed
1
quay.io/aerokube/keygen:1.0.1578934444f04
systemd@249.11-0ubuntu3.12
no fix listed
1
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
systemd@259.5-0ubuntu3.4
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
systemd@249.11-0ubuntu3.4
no fix listed
1
quay.io/argoproj/argocd:v2.10.783c86003b781
systemd@249.11-0ubuntu3.12
no fix listed
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
systemd@255.4-1ubuntu8.6
no fix listed
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
systemd@255.4-1ubuntu8.10
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
systemd@249.11-0ubuntu3.11
no fix listed
1
quay.io/argoprojlabs/gitops-promoter:v0.41.0cab605cc1d1d
systemd@257.13-1~deb13u1
no fix listed
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
systemd@249.11-0ubuntu3.12
no fix listed
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
systemd@255.4-1ubuntu8.10
no fix listed
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
systemd@255.4-1ubuntu8.12
no fix listed
1
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
systemd@255.4-1ubuntu8.12
no fix listed
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
systemd@255.4-1ubuntu8.10
no fix listed
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
systemd@252.33-1~deb12u1
no fix listed
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
systemd@252.38-1~deb12u1
no fix listed
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
systemd@249.11-0ubuntu3.20
no fix listed
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
systemd@237-3ubuntu10.56
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.