StackRadar

CVE-2026-40355

High

Advisory

Published 28 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
914
of 17,787 indexed, latest versions
Container images
970
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 914 of 17,787 indexed charts deploy, on 970 images.

Affected packageAffected versionsFixed inImages
krb5deb1.19.2-2, 1.19.2-2ubuntu0.1, 1.19.2-2ubuntu0.2, 1.19.2-2ubuntu0.3+20 more1.19.2-2ubuntu0.8, 1.20.1-2+deb12u5, 1.20.1-6ubuntu2.7, 1.21.3-5+deb13u1+2 more970
OSV records
DEBIAN-CVE-2026-40355UBUNTU-CVE-2026-40355ECHO-3921-9f59-f2e1
Also known as
USN-8585-1

Charts affected

914 by stars
ChartLatestAffected imagesRadar Score
welcome-elos-webappwelcome-elos-webappVerified publisher2.0.01 of 1See more

welcome-elos-webapp welcome-elos-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
pococze/python-hello-elos:2.0.07a1aab425e51
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5

Open the chart page →

2,538
giteawenerme12.7.02 of 4See more

gitea wenerme 12.7.0

2 of the 4 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5

Open the chart page →

8,842
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5

Open the chart page →

8,824
openebswenerme3.10.02 of 3See more

openebs wenerme 3.10.0

2 of the 3 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.8
openebs/node-disk-operator:2.1.06afe2123c457
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.8

Open the chart page →

10,568
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.8

Open the chart page →

9,296
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7

Open the chart page →

2,229
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5

Open the chart page →

7,643
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5

Open the chart page →

5,548
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5

Open the chart page →

2,383
wordpress-alpinewordpress-alpine1.5.181 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

1 of the 6 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
library/mariadb:12.3.2628f228f0fd5
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7

Open the chart page →

4,032
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.8

Open the chart page →

14,172
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5

Open the chart page →

7,685
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
hamzaarshad10/querypodpy:1.7154f38e8668e
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
murtazashah46/helmfile:latest4d11726cf803
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5

Open the chart page →

13,197
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
krb5@1.20.1-6ubuntu2
1.20.1-6ubuntu2.7

Open the chart page →

2,136

Container images carrying it

970 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/mariadb:11.7.2fcc7fcd7114a
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7
1
library/matomo:5.1.2-apache2415789e1602
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
library/mongo:7.0.140032d2ca20db
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.8
1
library/mongo:6.0.12646902910d6a
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.8
1
library/mongo:7.0.28-jammy88785f6f665a
krb5@1.19.2-2ubuntu0.7
1.19.2-2ubuntu0.8
1
library/mongo:7.0.12ae1cf99fa7bf
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.8
1
library/mongo:8.0.11dca8d11fe467
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7
1
library/mysql:8.0-debian9382e4f6f7f0
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5
1
library/nextcloud:31.0.6-apache588609d76b21
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5
1
library/nextcloud:31.0.10-apacheb7faa1653c39
krb5@1.21.3-5
1.21.3-5+deb13u1
1
library/nginx:1.27.409369da6b103
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
library/nginx:1.291881968aff6f
krb5@1.21.3-5
1.21.3-5+deb13u1
1
library/nginx:1.276784fb0834aa
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5
1
library/nginx:1.25.167f9a4f10d14
krb5@1.20.1-2
1.20.1-2+deb12u5
1
library/nginx:1.25.49ff236ed47fe
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5
1
library/nginx:1.27.3fb197595ebe7
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
library/node:208f693eaa7e0a
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5
1
library/postgres:18.0073e7c8b84e2
krb5@1.21.3-5
1.21.3-5+deb13u1
1
library/postgres:17.4304ab8135187
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
library/postgres:16.11468e1f126ca5
krb5@1.21.3-5
1.21.3-5+deb13u1
1
library/postgres:16.6557fea37a744
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
library/postgres:18.369e8582b781c
krb5@1.21.3-5
1.21.3-5+deb13u1
1
library/postgres:15.38775adb39f0d
krb5@1.20.1-2
1.20.1-2+deb12u5
1
library/postgres:18.48ff36f3c6637
krb5@1.21.3-5
1.21.3-5+deb13u1
1
library/postgres:18.3a9abf4275f9e
krb5@1.21.3-5
1.21.3-5+deb13u1
1
library/postgres:17.5aadf2c0696f5
krb5@1.21.3-5
1.21.3-5+deb13u1
1
library/postgres:13.12ced3ba927f4c
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5
1
library/postgres:14.22eba8ddbdd837
krb5@1.21.3-5
1.21.3-5+deb13u1
1
library/postgres:17.5-bookwormfbcea1bd13b6
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5
1
library/python:3.8d41127070014
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
library/python:3.9da5aee29682d
krb5@1.21.3-5
1.21.3-5+deb13u1
1
library/rabbitmq:3.12.100742852455ad
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.8
1
library/sonarqube:10.7.0-community0842dcd4c8f8
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.8
1
library/sonarqube:10.0.0-communityef9723cf4fe4
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.8
1
library/telegraf:1.27507a3eecf809
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5
1
library/varnish:7.5.04d0bb287d87b
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
library/wordpress:6.4.3-apache8ae66efb09a2
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
krb5@1.21.3-5
1.21.3-5+deb13u1
1
library/wordpress:php8.1-apachef73396626d2f
krb5@1.21.3-5
1.21.3-5+deb13u1
1
library/zookeeper:3.8-temurin55d1e5b2e601
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.8
1
library/zookeeper:3.9.4dfa9ba46d14b
krb5@1.19.2-2ubuntu0.7
1.19.2-2ubuntu0.8
1
libretranslate/libretranslate:v1.9.61de2d7056bb8
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5
1
linuxserver/calibre-web:0.6.24241009026e6f
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7
1
linuxserver/code-server:4.10.1a5e43a05ae79
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.8
1
linuxserver/foldingathome:7.6.219a997426d71e
krb5@1.20.1-6ubuntu2
1.20.1-6ubuntu2.7
1
linuxserver/plex:1.43.22785a6ad64d3
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7
1
lis314/project-zomboid-docker:latestaa2089c37920
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
livekit/ingress:v1.2.21ab01641b366
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.8
1
localstack/localstack:3.19d278167f2b7
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5
1
locustio/locust:2.24.151d866285170
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.