StackRadar

CVE-2026-40228

Low

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,524
of 17,813 indexed, latest versions
Container images
2,517
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,524 of 17,813 indexed charts deploy, on 2,517 images.

Affected packageAffected versionsFixed inImages
systemddeb204-5ubuntu20.7, 204-5ubuntu20.10, 204-5ubuntu20.24, 204-5ubuntu20.28+115 moreno fix listed2,517
OSV records
DEBIAN-CVE-2026-40228UBUNTU-CVE-2026-40228

Charts affected

2,524 by stars
ChartLatestAffected imagesRadar Score
capsizefairwinds-incubator0.2.01 of 1See more

capsize fairwinds-incubator 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/python:3-slimcad9a2c87176
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

861
datadog-apmfairwinds-incubator2.0.11 of 1See more

datadog-apm fairwinds-incubator 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
systemd@255.4-1ubuntu8.11
no fix listed

Open the chart page →

2,898
oom-event-generatorfairwinds-incubator0.2.21 of 1See more

oom-event-generator fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
systemd@229-4ubuntu21.31
no fix listed

Open the chart page →

4,667
yelbfairwinds-incubator0.1.11 of 5See more

yelb fairwinds-incubator 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

5,165
event-generatorfalcosecurity0.4.01 of 1See more

event-generator falcosecurity 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
falcosecurity/event-generator:latest932956d86c99
systemd@252.39-1~deb12u1
no fix listed

Open the chart page →

3,847
farm-observabilityfarm-observabilityOfficialVerified publisher0.27.22 of 18See more

farm-observability farm-observability 0.27.2

2 of the 18 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
grafana/alloy:v1.16.384b76d56c594
systemd@255.4-1ubuntu8.15
no fix listed
grafana/alloy:v1.12.2f94b1c82957a
systemd@255.4-1ubuntu8.12
no fix listed

Open the chart page →

13,610
jenkinsfatihtepe-jenkins1.0.01 of 1See more

jenkins fatihtepe-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

2,549
quickstartfeatureformVerified publisher0.1.12 of 3See more

quickstart featureform 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
systemd@257.13-1~deb13u1
no fix listed
library/redis:latest298e5b3bc566
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

3,658
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
systemd@249.11-0ubuntu3.4
no fix listed

Open the chart page →

13,540
rospoferama0.4.31 of 1See more

rospo ferama 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
systemd@252.19-1~deb12u1
no fix listed

Open the chart page →

6,244
vipienferama0.2.81 of 1See more

vipien ferama 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
systemd@245.4-4ubuntu3.15
no fix listed

Open the chart page →

7,545
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
systemd@229-4ubuntu21.27
no fix listed

Open the chart page →

14,728
ferriscompanyferriscompany0.1.01 of 1See more

ferriscompany ferriscompany 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
systemd@252.30-1~deb12u2
no fix listed

Open the chart page →

10,962
fibfibonacci-cluster-appsVerified publisher1.0.03 of 5See more

fib fibonacci-cluster-apps 1.0.0

3 of the 5 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
systemd@252.12-1~deb12u1
no fix listed
golenski/fibonacci-task-manager:2.0.03a2b36df247b
systemd@252.12-1~deb12u1
no fix listed
golenski/fibonacci-worker:2.0.0954caf4aaf6a
systemd@252.12-1~deb12u1
no fix listed

Open the chart page →

17,154
infrafibonacci-cluster-infraVerified publisher1.0.03 of 4See more

infra fibonacci-cluster-infra 1.0.0

3 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.37.0bae523439ee3
systemd@255.4-1ubuntu8.2
no fix listed
library/postgres:16.4e62fbf9d3e2b
systemd@252.31-1~deb12u1
no fix listed
library/redis:7.4.1bb142a9c18ac
systemd@252.31-1~deb12u1
no fix listed

Open the chart page →

12,677
fineractfineract-openshift0.1.12 of 4See more

fineract fineract-openshift 0.1.1

2 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/mariadb:11.4611a2fcc5fa7
systemd@255.4-1ubuntu8.17
no fix listed
library/nginx:latest05b8cb60c354
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

7,978
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

5,266
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
systemd@257.9-1~deb13u1
no fix listed
fireflyiii/data-importer:version-2.2.3ab52bf932546
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

10,714
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

5,056
flask-contactsfirst-idror-chart1.0.12 of 3See more

flask-contacts first-idror-chart 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
systemd@257.13-1~deb13u1
no fix listed
shashkist/flask-contacts-app:latest581de1fd6084
systemd@252.31-1~deb12u1
no fix listed

Open the chart page →

5,908
business-api-ecosystemfiware1.1.02 of 4See more

business-api-ecosystem fiware 1.1.0

2 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
systemd@245.4-4ubuntu3.24
no fix listed
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
systemd@252.36-1~deb12u1
no fix listed

Open the chart page →

113,143
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

1,915
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

1,557
apm-hubflanksourceVerified publisher0.0.472 of 2See more

apm-hub flanksource 0.0.47

2 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
flanksource/apm-hub:v0.0.471dacc3195bf9
systemd@249.11-0ubuntu3.9
no fix listed
library/postgres:14156f0b253fd6
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

6,221
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
systemd@255.4-1ubuntu8.10
no fix listed

Open the chart page →

5,544
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
systemd@252.36-1~deb12u1
no fix listed

Open the chart page →

4,713
facetflanksourceVerified publisher0.1.721 of 1See more

facet flanksource 0.1.72

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/flanksource/facet:0.1.7237237038be15
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

21,571
flanksource-uiflanksourceVerified publisher1.4.3191 of 1See more

flanksource-ui flanksource 1.4.319

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.319953948a194c9
systemd@252.36-1~deb12u1
no fix listed

Open the chart page →

2,616
mission-controlflanksourceVerified publisher0.1.3382 of 8See more

mission-control flanksource 0.1.338

2 of the 8 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
systemd@252.39-1~deb12u1
no fix listed
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
systemd@252.36-1~deb12u1
no fix listed

Open the chart page →

9,129
mission-control-ai-assistantflanksourceVerified publisher1.0.121 of 1See more

mission-control-ai-assistant flanksource 1.0.12

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/flanksource/mission-control-ai-assistant:1.0.1229a635cbeeb5
systemd@252.39-1~deb12u1
no fix listed

Open the chart page →

1,347
flask-contactsflask-contacts-generic1.0.12 of 3See more

flask-contacts flask-contacts-generic 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
systemd@257.13-1~deb13u1
no fix listed
shashkist/flask-contacts-app:latest581de1fd6084
systemd@252.31-1~deb12u1
no fix listed

Open the chart page →

5,908
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
systemd@252.33-1~deb12u1
no fix listed

Open the chart page →

4,124
flinkflink0.5.11 of 1See more

flink flink 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/flink:1.14.6-scala_2.122461f02672b3
systemd@249.11-0ubuntu3.6
no fix listed

Open the chart page →

5,717
floriapp-mongodbfloriapp1.0.01 of 1See more

floriapp-mongodb floriapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
systemd@237-3ubuntu10.48
no fix listed

Open the chart page →

8,069
fluent-bit-aggregatorfluent-bit-aggregatorOfficialVerified publisher1.1.21 of 1See more

fluent-bit-aggregator fluent-bit-aggregator 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
fluent/fluent-bit:5.1.2d792375ca8e5
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

957
fluent-bit-collectorfluent-bit-collectorOfficialVerified publisher1.1.21 of 1See more

fluent-bit-collector fluent-bit-collector 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
fluent/fluent-bit:5.1.2d792375ca8e5
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

957
fluentd-aggregatorfluentd-aggregatorOfficialVerified publisher1.0.01 of 2See more

fluentd-aggregator fluentd-aggregator 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,808
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

3,604
dump1090fnzv0.2.81 of 1See more

dump1090 fnzv 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
fnzv/dump1090:latestb3079b95c336
systemd@249.11-0ubuntu3.11
no fix listed

Open the chart page →

4,157
fr24feederfnzv0.1.21 of 1See more

fr24feeder fnzv 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest917e53402d51
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

2,493
mod-z3950folio-org0.1.31 of 1See more

mod-z3950 folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
folioci/mod-z3950:latest2493041ce880
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

2,605
ledgerformance1.2.01 of 1See more

ledger formance 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
systemd@249.11-0ubuntu3.7
no fix listed

Open the chart page →

4,681
ff-testfrankframework0.7.61 of 2See more

ff-test frankframework 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/postgres:17-bookworm051f7b7b3abd
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

1,808
frank2examplefrankframework0.7.41 of 2See more

frank2example frankframework 0.7.4

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/postgres:17-bookworm051f7b7b3abd
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

1,808
plexfydrah-charts2.2.01 of 1See more

plex fydrah-charts 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
systemd@229-4ubuntu21.4
no fix listed

Open the chart page →

9,002
passboltg0dscookie0.5.21 of 2See more

passbolt g0dscookie 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/mariadb:10.79a48ac9f196f
systemd@245.4-4ubuntu3.21
no fix listed

Open the chart page →

8,022
changedetection-iogabe565Verified publisher0.12.01 of 2See more

changedetection-io gabe565 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:latestecacd9fd0c66
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

2,697
esphomegabe565Verified publisher0.15.01 of 1See more

esphome gabe565 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:latest000c5ee5ee96
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

3,233
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
systemd@252.17-1~deb12u1
no fix listed

Open the chart page →

13,459
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
systemd@257.8-1~deb13u2
no fix listed

Open the chart page →

6,489

Container images carrying it

2,517 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabdc1a8972c640
systemd@252.39-1~deb12u2
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.26645e014f75d
systemd@257.13-1~deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
systemd@257.13-1~deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3aca1bb3d5b7e
systemd@257.13-1~deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.02256b49461fa
systemd@257.13-1~deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
systemd@257.13-1~deb13u1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
systemd@245.4-4ubuntu3.5
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
systemd@252.39-1~deb12u2
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
systemd@252.39-1~deb12u2
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
systemd@257.8-1~deb13u2
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
systemd@252.17-1~deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
systemd@252.30-1~deb12u2
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
systemd@252.39-1~deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
systemd@252.36-1~deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
systemd@252.39-1~deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
systemd@252.39-1~deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
systemd@252.36-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.