StackRadar

CVE-2026-40228

Low

Advisory

Published 10 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,552
of 17,828 indexed, latest versions
Container images
2,551
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,552 of 17,828 indexed charts deploy, on 2,551 images.

Affected packageAffected versionsFixed inImages
systemddeb204-5ubuntu20.7, 204-5ubuntu20.10, 204-5ubuntu20.24, 204-5ubuntu20.28+115 moreno fix listed2,551
OSV records
DEBIAN-CVE-2026-40228UBUNTU-CVE-2026-40228

Charts affected

2,552 by stars
ChartLatestAffected imagesRadar Score
penpotpenpotOfficialVerified publisher1.9.02 of 4See more

penpot penpot 1.9.0

2 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
penpotapp/exporter:2.17.272a8061e8806
systemd@259.5-0ubuntu3.4
no fix listed
penpotapp/mcp:2.17.284f3f07ead11
systemd@259.5-0ubuntu3.4
no fix listed

Open the chart page →

4,646
signozsignoz0.142.11 of 5See more

signoz signoz 0.142.1

1 of the 5 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
signoz/signoz-otel-collector:v0.144.1034ecb436b687
systemd@252.36-1~deb12u1
no fix listed

Open the chart page →

7,632
weblateweblateOfficialVerified publisher0.5.383 of 3See more

weblate weblate 0.5.38

3 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
systemd@252.38-1~deb12u1
no fix listed
bitnamilegacy/redis:latest5927ff3702df
systemd@252.38-1~deb12u1
no fix listed
weblate/weblate:2026.9.1.2f0be5b122b38
systemd@259.5-0ubuntu3.4
no fix listed

Open the chart page →

6,707
locustdeliveryheroVerified publisher0.35.01 of 1See more

locust deliveryhero 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
systemd@252.30-1~deb12u2
no fix listed

Open the chart page →

2,849
postgresgroundhog2k1.6.81 of 1See more

postgres groundhog2k 1.6.8

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/postgres:18.686c951e05bf5
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,268
emqxemqx-operator5.8.91 of 1See more

emqx emqx-operator 5.8.9

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
emqx/emqx:5.8.935b46f7aa7a0
systemd@257.9-1~deb13u1
no fix listed

Open the chart page →

2,752
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
systemd@252.17-1~deb12u1
no fix listed

Open the chart page →

4,840
mariadbcloudpirates-mariadbVerified publisher0.16.151 of 1See more

mariadb cloudpirates-mariadb 0.16.15

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/mariadb:13.0.2d4fdec0510ad
systemd@259.5-0ubuntu3.4
no fix listed

Open the chart page →

1,435
difydoubanVerified publisher0.10.03 of 6See more

dify douban 0.10.0

3 of the 6 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
systemd@252.22-1~deb12u1
no fix listed
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
systemd@252.22-1~deb12u1
no fix listed
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
systemd@255.4-1ubuntu8.11
no fix listed

Open the chart page →

74,142
dragonflydragonflyVerified publisher1.8.51 of 3See more

dragonfly dragonfly 1.8.5

1 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.59fe2a1d6206f
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

4,187
secrets-store-csi-driversecret-store-csi-driver1.6.11 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

1 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

1,821
mongodbcloudpirates-mongodbVerified publisher0.18.151 of 1See more

mongodb cloudpirates-mongodb 0.18.15

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/mongo:8.3.115d7043a4ffe0
systemd@255.4-1ubuntu8.17
no fix listed

Open the chart page →

958
code-servernicholaswildeVerified publisher1.1.11 of 1See more

code-server nicholaswilde 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/code-server:version-v3.11.1a385ba5cb161
systemd@237-3ubuntu10.51
no fix listed

Open the chart page →

16,393
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
systemd@259.5-0ubuntu3.3
no fix listed

Open the chart page →

1,663
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
systemd@255.4-1ubuntu8.6
no fix listed

Open the chart page →

3,860
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
systemd@252.22-1~deb12u1
no fix listed

Open the chart page →

7,014
difydify-helmVerified publisher0.38.06 of 11See more

dify dify-helm 0.38.0

6 of the 11 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
systemd@252.39-1~deb12u2
no fix listed
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
systemd@252.39-1~deb12u2
no fix listed
langgenius/dify-api:1.16.1dcefa5f7c47c
systemd@252.39-1~deb12u2
no fix listed
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
systemd@255.4-1ubuntu8.16
no fix listed
langgenius/dify-sandbox:0.2.15750e1111426e
systemd@257.9-1~deb13u1
no fix listed
library/nginx:latestabe47724e466
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

63,436
pyroscopegrafana2.3.11 of 3See more

pyroscope grafana 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
grafana/alloy:v1.12.2f94b1c82957a
systemd@255.4-1ubuntu8.12
no fix listed

Open the chart page →

3,298
plantumlstevehipwellVerified publisher3.49.01 of 1See more

plantuml stevehipwell 3.49.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
systemd@255.4-1ubuntu8.12
no fix listed

Open the chart page →

2,087
rabbitmqgroundhog2k2.3.91 of 2See more

rabbitmq groundhog2k 2.3.9

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.667bad329974a
systemd@255.4-1ubuntu8.17
no fix listed

Open the chart page →

848
stacks-blockchainhirosystemsVerified publisher2.2.21 of 1See more

stacks-blockchain hirosystems 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
systemd@252.38-1~deb12u1
no fix listed

Open the chart page →

1,418
ingresskongOfficialVerified publisher0.24.01 of 2See more

ingress kong 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/kong:3.912972ce1ab63
systemd@255.4-1ubuntu8.17
no fix listed

Open the chart page →

867
oktetooktetoOfficialVerified publisher0.0.0-2026-08-241 of 10See more

okteto okteto 0.0.0-2026-08-24

1 of the 10 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-243e56bdd1b90d
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

5,587
yourlsyourlsOfficialVerified publisher8.10.21 of 2See more

yourls yourls 8.10.2

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/yourls/yourls:1.10.67550ff86b15f
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,990
apisix-ingress-controllerapisix1.4.01 of 2See more

apisix-ingress-controller apisix 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

1,705
istiocloudposse1.1.02 of 8See more

istio cloudposse 1.1.0

2 of the 8 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
systemd@229-4ubuntu21.21
no fix listed
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
systemd@229-4ubuntu21.21
no fix listed

Open the chart page →

131,456
actualbudgetcommunity-chartsVerified publisher1.9.41 of 1See more

actualbudget community-charts 1.9.4

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

1,137
concourseconcourseVerified publisher20.3.01 of 2See more

concourse concourse 20.3.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,670
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
systemd@237-3ubuntu10.51
no fix listed

Open the chart page →

4,212
openprojectopenproject-helm-chartsOfficialVerified publisher13.12.04 of 5See more

openproject openproject-helm-charts 13.12.0

4 of the 5 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
bitnamilegacy/memcached:1.6.24-debian-12-r01d80b6a96f00
systemd@252.22-1~deb12u1
no fix listed
library/postgres:16f1c3376c26f2
systemd@257.13-1~deb13u1
no fix listed
openproject/hocuspocus:release-338001b288dc1359dfb5
systemd@252.38-1~deb12u1
no fix listed
openproject/openproject:17.8.0-slim48952034215d
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

20,190
sftpgosftpgoOfficialVerified publisher0.48.01 of 1See more

sftpgo sftpgo 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/drakkan/sftpgo:v2.7.59011fe608d33
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,250
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
systemd@252.22-1~deb12u1
no fix listed

Open the chart page →

11,588
lemmyananace-chartsVerified publisher0.6.152 of 5See more

lemmy ananace-charts 0.6.15

2 of the 5 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
dessalines/lemmy:0.19.2079e9f02c286c
systemd@252.39-1~deb12u2
no fix listed
dessalines/lemmy-ui:0.19.20ee4c620d8e93
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

7,262
zabbixcetic3.1.35 of 5See more

zabbix cetic 3.1.3

5 of the 5 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/postgres:14816cf7d06ec3
systemd@257.13-1~deb13u1
no fix listed
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
systemd@249.11-0ubuntu3.4
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
systemd@249.11-0ubuntu3.4
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
systemd@249.11-0ubuntu3.4
no fix listed
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
systemd@249.11-0ubuntu3.4
no fix listed

Open the chart page →

33,799
csi-driver-smbcsi-driver-smbVerified publisher1.20.31 of 6See more

csi-driver-smb csi-driver-smb 1.20.3

1 of the 6 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
systemd@252.39-1~deb12u2
no fix listed

Open the chart page →

3,027
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
systemd@252.6-1
no fix listed

Open the chart page →

4,356
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
systemd@252.26-1~deb12u2
no fix listed

Open the chart page →

6,622
stacks-blockchain-apihirosystemsVerified publisher6.5.12 of 5See more

stacks-blockchain-api hirosystems 6.5.1

2 of the 5 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
systemd@252.38-1~deb12u1
no fix listed
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
systemd@252.39-1~deb12u1
no fix listed

Open the chart page →

7,884
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
systemd@255.4-1ubuntu8.10
no fix listed

Open the chart page →

2,430
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
systemd@252.38-1~deb12u1
no fix listed

Open the chart page →

6,162
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
systemd@245.4-4ubuntu3.22
no fix listed
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
systemd@249.11-0ubuntu3.11
no fix listed

Open the chart page →

13,005
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
systemd@255.4-1ubuntu8.10
no fix listed

Open the chart page →

3,089
factorio-server-chartsfactorio-server-chartsVerified publisher2.5.21 of 1See more

factorio-server-charts factorio-server-charts 2.5.2

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
factoriotools/factorio:latest18c07a80cacc
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

1,402
netbirdjaconiVerified publisher0.15.12 of 4See more

netbird jaconi 0.15.1

2 of the 4 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
library/golang:latest3680233e3204
systemd@257.13-1~deb13u1
no fix listed
netbirdio/management:0.45.10c9994b393ea
systemd@255.4-1ubuntu8.6
no fix listed

Open the chart page →

8,167
litellm-helmlitellm1.102.01 of 2See more

litellm-helm litellm 1.102.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
systemd@252.22-1~deb12u1
no fix listed

Open the chart page →

5,102
localstacklocalstack0.7.11 of 1See more

localstack localstack 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
localstack/localstack:latest4abc29e923e5
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

2,195
gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

10,277
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
systemd@255.4-1ubuntu8.10
no fix listed

Open the chart page →

5,527
oneuptimeoneuptimeOfficialVerified publisher14.0.14 of 7See more

oneuptime oneuptime 14.0.1

4 of the 7 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.7a50b4a1579a0
systemd@249.11-0ubuntu3.22
no fix listed
library/postgres:latest86c951e05bf5
systemd@257.13-1~deb13u1
no fix listed
oneuptime/probe:releaseff73ab57aa59
systemd@252.39-1~deb12u2
no fix listed
oneuptime/runner:release8301892d9c17
systemd@257.13-1~deb13u1
no fix listed

Open the chart page →

11,243
openclawopenclaw-helmVerified publisher1.5.402 of 2See more

openclaw openclaw-helm 1.5.40

2 of the 2 container images this version deploys carry CVE-2026-40228.

Container imageDigestPackageFixed in
chromedp/headless-shell:148.0.7778.97313ed7255ae1
systemd@257.9-1~deb13u1
no fix listed
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
systemd@252.39-1~deb12u1
no fix listed

Open the chart page →

5,759

Container images carrying it

2,551 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
systemd@252.36-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.