StackRadar

CVE-2026-40228

Low

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,493
of 17,821 indexed, latest versions
Container images
2,480
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,493 of 17,821 indexed charts deploy, on 2,480 images.

Affected packageAffected versionsFixed inImages
systemddeb204-5ubuntu20.7, 204-5ubuntu20.10, 204-5ubuntu20.24, 204-5ubuntu20.28+115 moreno fix listed2,480
OSV records
DEBIAN-CVE-2026-40228UBUNTU-CVE-2026-40228

Charts affected

2,493 by stars
ChartLatestAffected imagesRadar Score
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
systemd@252.31-1~deb12u1
no fix listed

Open the chart page →

2,995
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
systemd@245.4-4ubuntu3.18
no fix listed
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
systemd@245.4-4ubuntu3.18
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
systemd@245.4-4ubuntu3.18
no fix listed

Open the chart page →

251,237
snappasssnappassVerified publisher0.4.32 of 3See more

snappass snappass 0.4.3

2 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
systemd@257.9-1~deb13u1
no fix listed
valkey/valkey:8.1.61f84517eca8e
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

3,107
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
systemd@257.8-1~deb13u2
no fix listed

Open the chart page →

14,621
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/redis:8.10.18a1efc5f4795
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,935
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

7,432
postgresql-ha-chartsoldevelo-postgresql-ha-chart16.3.42 of 2See more

postgresql-ha-chart soldevelo-postgresql-ha-chart 16.3.4

2 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
soldevelo/pgpool:4.6.3-debian-12-r0044d16a65129
systemd@252.39-1~deb12u1
no fix listed
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

4,701
rabbitmqsolidchartsVerified publisher0.7.61 of 2See more

rabbitmq solidcharts 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.6-management534e4fefc5f0
systemd@255.4-1ubuntu8.17
no fix listed

Open the chart page →

824
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
systemd@252.22-1~deb12u1
no fix listed

Open the chart page →

5,758
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
systemd@252.39-1~deb12u1
no fix listed

Open the chart page →

10,579
squidsquid-helmVerified publisher0.1.01 of 1See more

squid squid-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ubuntu/squid:5.2-22.04_beta723891b5bc74
systemd@249.11-0ubuntu3.17
no fix listed

Open the chart page →

2,666
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
graphprotocol/graph-node:v0.37.0f4452cdedd68
systemd@252.31-1~deb12u1
no fix listed

Open the chart page →

4,741
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
systemd@245.4-4ubuntu3.18
no fix listed

Open the chart page →

13,622
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
systemd@245.4-4ubuntu3.6
no fix listed

Open the chart page →

102,717
stornxstornxVerified publisher1.1.13 of 9See more

stornx stornx 1.1.1

3 of the 9 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
systemd@255.4-1ubuntu8.12
no fix listed
alazidis/stornx:1.1.1602d4f7f090c
systemd@252.39-1~deb12u1
no fix listed
istio/pilot:1.29.1f8b0e412ac4a
systemd@255.4-1ubuntu8.12
no fix listed

Open the chart page →

11,854
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
systemd@255.4-1ubuntu8.15
no fix listed

Open the chart page →

2,941
supabasesupabse0.8.06 of 11See more

supabase supabse 0.8.0

6 of the 11 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.30.13b709e4a0e5e
systemd@255.4-1ubuntu8.11
no fix listed
kong/kong:3.9.16addf50e6bd8
systemd@255.4-1ubuntu8.6
no fix listed
supabase/edge-runtime:v1.74.02781daf92394
systemd@252.39-1~deb12u1
no fix listed
supabase/postgres-meta:v0.96.6a84cc713585e
systemd@252.39-1~deb12u1
no fix listed
supabase/realtime:v2.102.3aa1c92c0cf32
systemd@252.39-1~deb12u1
no fix listed
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

18,318
supersonicsupersonicVerified publisher0.3.11 of 2See more

supersonic supersonic 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.92956bd9de830
systemd@249.11-0ubuntu3.12
no fix listed

Open the chart page →

2,162
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

3,374
mumblesyntaxerror404Verified publisher1.0.51 of 1See more

mumble syntaxerror404 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
systemd@255.4-1ubuntu8.16
no fix listed

Open the chart page →

2,176
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,580
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,580
teamcity-serverteamcity-server3.3.51 of 2See more

teamcity-server teamcity-server 3.3.5

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/haproxy:3.2ad870ce41292
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

582
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
systemd@257.13-1~deb13u1+dhi1
no fix listed

Open the chart page →

2,480
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
systemd@252.17-1~deb12u1
no fix listed

Open the chart page →

9,166
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
systemd@252.17-1~deb12u1
no fix listed

Open the chart page →

9,166
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

13,743
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
systemd@255.4-1ubuntu8.4
no fix listed

Open the chart page →

4,104
typemilltypemill-helm-chart2.2.02 of 2See more

typemill typemill-helm-chart 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
kixote/typemilldigest-pinned4e9dff179519
systemd@257.13-1~deb13u1
no fix listed
kixote/typemilldigest-pinned628f79a08cc7
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

5,611
typesensetypesenseVerified publisher1.1.41 of 1See more

typesense typesense 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
typesense/typesense:30.191604dc128e2
systemd@249.11-0ubuntu3.17
no fix listed

Open the chart page →

1,931
ueransim-gnbueransim-gnbVerified publisher0.2.61 of 1See more

ueransim-gnb ueransim-gnb 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
systemd@249.11-0ubuntu3.12
no fix listed

Open the chart page →

3,981
ueransim-uesueransim-uesVerified publisher0.1.21 of 1See more

ueransim-ues ueransim-ues 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
systemd@249.11-0ubuntu3.12
no fix listed

Open the chart page →

3,981
u-storeunifieVerified publisher1.2.01 of 1See more

u-store unifie 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
systemd@252.22-1~deb12u1
no fix listed

Open the chart page →

15,329
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
systemd@252.33-1~deb12u1
no fix listed

Open the chart page →

12,807
taigaunxwaresVerified publisher2026.3.82 of 6See more

taiga unxwares 2026.3.8

2 of the 6 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
systemd@257.13-1~deb13u1
no fix listed
taigaio/taiga-protected:latestfd4568a97a59
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

9,263
varnish-cachevarnishVerified publisher1.1.11 of 1See more

varnish-cache varnish 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/varnish:7.5.04d0bb287d87b
systemd@252.36-1~deb12u1
no fix listed

Open the chart page →

4,446
varnish-ingress-controllervarnish-ingress-controllerVerified publisher0.5.01 of 1See more

varnish-ingress-controller varnish-ingress-controller 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
mariusm/vingress:0.5.0b3db186c3d72
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

2,373
vaultwarden-kubernetes-secretsvaultwarden-kubernetes-secrets0.0.0-main1 of 2See more

vaultwarden-kubernetes-secrets vaultwarden-kubernetes-secrets 0.0.0-main

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
systemd@255.4-1ubuntu8.12
no fix listed

Open the chart page →

4,105
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
systemd@252.38-1~deb12u1
no fix listed

Open the chart page →

5,294
phpipamvquieVerified publisher1.0.31 of 3See more

phpipam vquie 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/mariadb:10.11.21c33370a599c
systemd@249.11-0ubuntu3.9
no fix listed

Open the chart page →

7,093
waldurwaldur-chartsVerified publisher8.1.22 of 3See more

waldur waldur-charts 8.1.2

2 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
systemd@257.13-1~deb13u1
no fix listed
opennode/waldur-mastermind:8.1.24c82b15d9042
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

4,695
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
systemd@237-3ubuntu10.41
no fix listed

Open the chart page →

16,052
reflectorwener10.0.651 of 1See more

reflector wener 10.0.65

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
emberstack/kubernetes-reflector:10.0.6551dbd5880929
systemd@255.4-1ubuntu8.16
no fix listed

Open the chart page →

723
kafka-devwikimedia0.2.01 of 1See more

kafka-dev wikimedia 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
systemd@204-5ubuntu20.7
no fix listed

Open the chart page →

41,493
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
systemd@245.4-4ubuntu3.24
no fix listed

Open the chart page →

56,312
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

7,929
wordpress-helmwordpress-helm0.2.91 of 4See more

wordpress-helm wordpress-helm 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

8,503
workflows-aggregatorworkflows-aggregatorVerified publisher0.16.91 of 1See more

workflows-aggregator workflows-aggregator 0.16.9

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
systemd@259.5-0ubuntu3.4
no fix listed

Open the chart page →

1,419
workflows-sinkworkflows-sinkVerified publisher0.16.31 of 1See more

workflows-sink workflows-sink 0.16.3

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

1,446
wraftwraft0.1.121 of 9See more

wraft wraft 0.1.12

1 of the 9 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
typesense/typesense:28.0.rc35dea1b62b7b6e
systemd@249.11-0ubuntu3.12
no fix listed

Open the chart page →

9,302

Container images carrying it

2,480 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

No deployed image carries CVE-2026-40228.

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.