StackRadar

CVE-2026-40228

Low

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,524
of 17,813 indexed, latest versions
Container images
2,517
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,524 of 17,813 indexed charts deploy, on 2,517 images.

Affected packageAffected versionsFixed inImages
systemddeb204-5ubuntu20.7, 204-5ubuntu20.10, 204-5ubuntu20.24, 204-5ubuntu20.28+115 moreno fix listed2,517
OSV records
DEBIAN-CVE-2026-40228UBUNTU-CVE-2026-40228

Charts affected

2,524 by stars
ChartLatestAffected imagesRadar Score
multicaicoretechVerified publisher0.5.01 of 5See more

multica icoretech 0.5.0

1 of the 5 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
pgvector/pgvector:pg17cf134a767f47
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

2,320
nextjsicoretechVerified publisher1.2.01 of 1See more

nextjs icoretech 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,956
tolgeeicoretechVerified publisher0.49.11 of 3See more

tolgee icoretech 0.49.1

1 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/postgres:18.369e8582b781c
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

2,802
eoloserverihuertas2021-vmartinp2021-helm0.1.03 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
systemd@237-3ubuntu10.57
no fix listed
library/mongo:5.0.6-focal8e70544b6c76
systemd@245.4-4ubuntu3.15
no fix listed
library/rabbitmq:3.9-management8a279e9396a8
systemd@249.11-0ubuntu3.12
no fix listed

Open the chart page →

27,941
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
systemd@255.4-1ubuntu8.8
no fix listed

Open the chart page →

9,255
ikigaiikigai-chartVerified publisher0.0.94 of 58See more

ikigai ikigai-chart 0.0.9

4 of the 58 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
systemd@249.11-0ubuntu3.9
no fix listed
jupyterhub/k8s-hub:1.2.0e4770285aaf7
systemd@245.4-4ubuntu3.13
no fix listed
library/zookeeper:3.8-temurin55d1e5b2e601
systemd@249.11-0ubuntu3.10
no fix listed
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
systemd@245.4-4ubuntu3.19
no fix listed

Open the chart page →

113,426
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

2,252
ilum-hive-metastoreilumVerified publisher1.2.01 of 2See more

ilum-hive-metastore ilum 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
systemd@252.31-1~deb12u1
no fix listed

Open the chart page →

3,649
ilum-marquezilumVerified publisher6.7.02 of 3See more

ilum-marquez ilum 6.7.0

2 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
systemd@252.31-1~deb12u1
no fix listed
ilum/marquez:0.54.06e1d709d41f8
systemd@252.39-1~deb12u1
no fix listed

Open the chart page →

6,394
ilum-streamlitilumVerified publisher0.1.01 of 1See more

ilum-streamlit ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ilum/streamlit-example:1.0.0ce5dcdeb22ba
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

2,850
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
systemd@252.36-1~deb12u1
no fix listed

Open the chart page →

12,038
web-chartimcherry57780.1.01 of 1See more

web-chart imcherry5778 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,956
onechartimioVerified publisher0.76.01 of 1See more

onechart imio 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,956
plausible-analyticsimioVerified publisher0.4.23 of 5See more

plausible-analytics imio 0.4.2

3 of the 5 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
bitnamilegacy/clickhouse:24.12.3-debian-12-r13cf6544f6c6c
systemd@252.33-1~deb12u1
no fix listed
bitnamilegacy/clickhouse:24.12.4c7e70bf1d3fb
systemd@252.33-1~deb12u1
no fix listed
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
systemd@252.38-1~deb12u1
no fix listed

Open the chart page →

10,808
smtp4devimioVerified publisher0.1.11 of 1See more

smtp4dev imio 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
rnwood/smtp4dev:3.6.1912304153668
systemd@252.22-1~deb12u1
no fix listed

Open the chart page →

3,249
apexkube-agentimprowisedVerified publisher1.4.01 of 2See more

apexkube-agent improwised 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.31.02bf7f042e396
systemd@249.11-0ubuntu3.12
no fix listed

Open the chart page →

3,374
kore-boardimprowisedVerified publisher0.5.81 of 4See more

kore-board improwised 0.5.8

1 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
systemd@237-3ubuntu10.56
no fix listed

Open the chart page →

16,421
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
systemd@249.11-0ubuntu3.12
no fix listed

Open the chart page →

5,423
pgcatimprowisedVerified publisher0.1.01 of 1See more

pgcat improwised 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
systemd@252.19-1~deb12u1
no fix listed

Open the chart page →

3,832
proxysqlimprowisedVerified publisher1.0.01 of 1See more

proxysql improwised 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
improwised/proxysql:master-6b26e59-171765063828940522e8b7
systemd@252.22-1~deb12u1
no fix listed

Open the chart page →

3,551
impulseimpulse1.0.161 of 1See more

impulse impulse 1.0.16

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/eslupmi/impulse:v3.7.03ded1b7ebca0
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,403
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

3,114
influxdb3-coreinfluxdata0.1.11 of 1See more

influxdb3-core influxdata 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/influxdb:3.10.5-core695a8063ff10
systemd@255.4-1ubuntu8.17
no fix listed

Open the chart page →

872
influxdb3-enterpriseinfluxdata0.12.01 of 1See more

influxdb3-enterprise influxdata 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/influxdb:3.11.2-enterprise6ce2bf22499b
systemd@255.4-1ubuntu8.17
no fix listed

Open the chart page →

853
influxdb-enterpriseinfluxdata0.2.12 of 2See more

influxdb-enterprise influxdata 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/influxdb:1.12.3-meta8812029260b5
systemd@252.39-1~deb12u1
no fix listed
library/influxdb:1.12.3-datab0f9fc41ed79
systemd@252.39-1~deb12u1
no fix listed

Open the chart page →

6,042
influxdbinfluxdb20.1.01 of 1See more

influxdb influxdb2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/influxdb:latestf75e48af0598
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

2,389
ai-stackinfracloud-chartsVerified publisher0.6.11 of 3See more

ai-stack infracloud-charts 0.6.1

1 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/chroma-core/chroma:1.5.91e0b73a187a2
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

1,325
chromadbinfracloud-chartsVerified publisher0.3.01 of 1See more

chromadb infracloud-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/chroma-core/chroma:1.5.91e0b73a187a2
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

1,325
guardrails-usvcinfracloud-chartsVerified publisher1.0.11 of 1See more

guardrails-usvc infracloud-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
opea/guardrails-tgi:latestf68bec6a1271
systemd@252.31-1~deb12u1
no fix listed

Open the chart page →

5,152
erigoninfradao0.0.51 of 2See more

erigon infradao 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
testinprod/op-erigon:latest0a125bd77a2d
systemd@252.31-1~deb12u1
no fix listed

Open the chart page →

2,932
op-stackinfradao0.0.11 of 1See more

op-stack infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,956
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
systemd@249.11-0ubuntu3.11
no fix listed

Open the chart page →

10,601
gmaintelVerified publisher0.1.01 of 1See more

gma intel 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
systemd@245.4-4ubuntu3.18
no fix listed

Open the chart page →

76,149
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
systemd@245.4-4ubuntu3.17
no fix listed

Open the chart page →

89,173
map5gintelVerified publisher1.0.01 of 1See more

map5g intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
systemd@245.4-4ubuntu3.18
no fix listed

Open the chart page →

76,149
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization-streaming:3.01a89327e499b
systemd@245.4-4ubuntu3.17
no fix listed

Open the chart page →

81,916
tcs-issuerintelVerified publisher0.5.01 of 2See more

tcs-issuer intel 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
intel/trusted-certificate-issuer:0.5.0591a9db4a427
systemd@245.4-4ubuntu3.19
no fix listed

Open the chart page →

6,020
intelowlintelowl-helm6.6.1-01-06-20262 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

2 of the 5 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
systemd@252.19-1~deb12u1
no fix listed
library/redis:8.6.34d25e2fe601f
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

18,220
interbtc-parachaininterlay0.4.131 of 1See more

interbtc-parachain interlay 0.4.13

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
interlayhq/interbtc:latesta66d0e35e70f
systemd@245.4-4ubuntu3.24
no fix listed

Open the chart page →

3,217
interbtc-vaultinterlay0.1.131 of 1See more

interbtc-vault interlay 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
interlayhq/interbtc-clients:vault-masterc3e311de67da
systemd@245.4-4ubuntu3.14
no fix listed

Open the chart page →

3,894
polkabtc-parachaininterlay0.2.411 of 4See more

polkabtc-parachain interlay 0.2.41

1 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
interlayhq/interbtc:latesta66d0e35e70f
systemd@245.4-4ubuntu3.24
no fix listed

Open the chart page →

3,961
polkabtc-vaultinterlay0.1.111 of 1See more

polkabtc-vault interlay 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
interlayhq/interbtc-clients:vault-masterc3e311de67da
systemd@245.4-4ubuntu3.14
no fix listed

Open the chart page →

3,894
inventreeinventreeOfficialVerified publisher0.4.292 of 2See more

inventree inventree 0.4.29

2 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
inventree/inventree:1.5.55dc64d7ceee3
systemd@257.13-1~deb13u1
no fix listed
library/nginx:stable0aa2d81d65bc
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

5,036
istio-aws-private-ingress-customizedistio-aws-private-ingress-customized1.0.01 of 1See more

istio-aws-private-ingress-customized istio-aws-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
systemd@249.11-0ubuntu3.9
no fix listed

Open the chart page →

5,600
istio-azure-private-ingress-customizedistio-azure-private-ingress-customized1.0.01 of 1See more

istio-azure-private-ingress-customized istio-azure-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
systemd@249.11-0ubuntu3.9
no fix listed

Open the chart page →

5,600
istio-bookinfoistio-bookinfo1.2.23 of 6See more

istio-bookinfo istio-bookinfo 1.2.2

3 of the 6 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.15.040e8aba77c1b
systemd@229-4ubuntu21.21
no fix listed
istio/examples-bookinfo-reviews-v2:1.15.0e86d247b7ac2
systemd@229-4ubuntu21.21
no fix listed
istio/examples-bookinfo-reviews-v3:1.15.0e454cab754cf
systemd@229-4ubuntu21.21
no fix listed

Open the chart page →

19,082
ztunnelistio-ztunnelVerified publisher1.25.01 of 1See more

ztunnel istio-ztunnel 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
istio/ztunnel:1.25.005f3972d80a9
systemd@255.4-1ubuntu8.5
no fix listed

Open the chart page →

2,524
appswitcher-serverit-at-mOfficialVerified publisher2.0.21 of 1See more

appswitcher-server it-at-m 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
systemd@249.11-0ubuntu3.15
no fix listed

Open the chart page →

3,829
daveit-at-mOfficialVerified publisher0.2.162 of 11See more

dave it-at-m 0.2.16

2 of the 11 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
systemd@252.38-1~deb12u1
no fix listed
bitnamilegacy/postgresql:latest42a8200d3597
systemd@252.38-1~deb12u1
no fix listed

Open the chart page →

12,533
dynamic-ip-loadbalancer-controlleritsmethemojoVerified publisher0.1.01 of 1See more

dynamic-ip-loadbalancer-controller itsmethemojo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/buildpack-deps:curl04907bdd423b
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,727

Container images carrying it

2,517 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabdc1a8972c640
systemd@252.39-1~deb12u2
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.26645e014f75d
systemd@257.13-1~deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
systemd@257.13-1~deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3aca1bb3d5b7e
systemd@257.13-1~deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.02256b49461fa
systemd@257.13-1~deb13u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
systemd@257.13-1~deb13u1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
systemd@245.4-4ubuntu3.5
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
systemd@252.39-1~deb12u2
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
systemd@252.39-1~deb12u2
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
systemd@257.8-1~deb13u2
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
systemd@252.17-1~deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
systemd@252.30-1~deb12u2
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
systemd@252.39-1~deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
systemd@252.36-1~deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
systemd@252.39-1~deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
systemd@252.39-1~deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
systemd@252.36-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.