StackRadar

CVE-2026-40355

High

Advisory

Published 28 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
914
of 17,787 indexed, latest versions
Container images
970
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 914 of 17,787 indexed charts deploy, on 970 images.

Affected packageAffected versionsFixed inImages
krb5deb1.19.2-2, 1.19.2-2ubuntu0.1, 1.19.2-2ubuntu0.2, 1.19.2-2ubuntu0.3+20 more1.19.2-2ubuntu0.8, 1.20.1-2+deb12u5, 1.20.1-6ubuntu2.7, 1.21.3-5+deb13u1+2 more970
OSV records
DEBIAN-CVE-2026-40355UBUNTU-CVE-2026-40355ECHO-3921-9f59-f2e1
Also known as
USN-8585-1

Charts affected

914 by stars
ChartLatestAffected imagesRadar Score
welcome-elos-webappwelcome-elos-webappVerified publisher2.0.01 of 1See more

welcome-elos-webapp welcome-elos-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
pococze/python-hello-elos:2.0.07a1aab425e51
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5

Open the chart page →

2,538
giteawenerme12.7.02 of 4See more

gitea wenerme 12.7.0

2 of the 4 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5

Open the chart page →

8,842
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5

Open the chart page →

8,824
openebswenerme3.10.02 of 3See more

openebs wenerme 3.10.0

2 of the 3 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.8
openebs/node-disk-operator:2.1.06afe2123c457
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.8

Open the chart page →

10,568
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.8

Open the chart page →

9,296
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7

Open the chart page →

2,229
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5

Open the chart page →

7,643
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5

Open the chart page →

5,548
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5

Open the chart page →

2,383
wordpress-alpinewordpress-alpine1.5.181 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

1 of the 6 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
library/mariadb:12.3.2628f228f0fd5
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7

Open the chart page →

4,032
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.8

Open the chart page →

14,172
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5

Open the chart page →

7,685
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
hamzaarshad10/querypodpy:1.7154f38e8668e
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
murtazashah46/helmfile:latest4d11726cf803
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5

Open the chart page →

13,197
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-40355.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
krb5@1.20.1-6ubuntu2
1.20.1-6ubuntu2.7

Open the chart page →

2,136

Container images carrying it

970 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
opea/codetrans:1.0e2436483b73d
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
opea/codetrans-ui:1.03ef121f34610
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5
1
opea/docsum:1.03eaa91849512
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
opea/docsum-ui:1.07f854e9bffaf
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5
1
opea/guardrails-tgi:1.0262c6048aab8
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
opea/guardrails-tgi:latestf68bec6a1271
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
opea/speecht5:1.0249afad3d268
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
opea/tts:1.0257ae94709e9
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
opea/web-retriever-chroma:1.0fe08165d7770
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
openbas/caldera-server:5.1.0a277796d9724
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
openbas/platform:2.0.5d986d80b0a75
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5
1
opencsghq/csghub-server:v2.4.0-ee302c9d45d8a8
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5
1
opencsghq/csghub-xnet:v2.4.0-ee04121fd19ef9
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
opencsghq/kubectl:latestb6d87e1048c2
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5
1
opendatacube/explorer:latest120457ffcd69
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7
1
opendatacube/wps:latest80df355a660b
krb5@1.19.2-2ubuntu0.7
1.19.2-2ubuntu0.8
1
openproject/hocuspocus:release-338001b288dc1359dfb5
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5
1
openvino/model_server:2025.2.11e7cd1d70cc1
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7
1
owncloud/server:10.16.274c53d341076
krb5@1.19.2-2ubuntu0.7
1.19.2-2ubuntu0.8
1
pangeo/base-notebook:2024.01.155fbe688a4f80
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.8
1
payara/server-full:7.2026.2-jdk2531f1253f0cf8
krb5@1.19.2-2ubuntu0.7
1.19.2-2ubuntu0.8
1
penpotapp/backend:2.2.147853d9bb9dd
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.8
1
penpotapp/exporter:2.2.15c835ffd87ab
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.8
1
phan2410/dummy-service:0.0.89c6ed6de26ca
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.8
1
photoprism/photoprism:220629-jammy2954334adbda
krb5@1.19.2-2
1.19.2-2ubuntu0.8
1
photoprism/photoprism:260601650c6ad5a651
krb5@1.22.1-2ubuntu4
1.22.1-2ubuntu4.1
1
photoprism/photoprism:251130db16ee6b1ba3
krb5@1.21.3-5ubuntu2
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
krb5@1.20.1-6ubuntu2
1.20.1-6ubuntu2.7
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
krb5@1.21.3-5
1.21.3-5+deb13u1
1
pk910/powfaucet:v2-stable3dcae6a62896
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5
1
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7
1
pococze/python-hello-elos:2.0.07a1aab425e51
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
praravind1801/helmimages:3.0.0f29d637b9ce1
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
prodrigestivill/postgres-backup-local:latestf70742ebe42b
krb5@1.21.3-5
1.21.3-5+deb13u1
1
prom/cloudwatch-exporter:v0.16.071c2e988af06
krb5@1.20.1-6ubuntu2.1
1.20.1-6ubuntu2.7
1
proxysql/proxysql:3.0.8947a7abad45b
krb5@1.21.3-5
1.21.3-5+deb13u1
1
pschichtel/mindustry-server:v145.1b543e9c2d371
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.8
1
qonstrukt/php:8.4-v8-apache089af7925aa1
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7
1
quickwit/quickwit:v0.8.1d29332bdadcc
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5
1
qumine/minecraft-server:v0.1.15c0b650d51132
krb5@1.19.2-2
1.19.2-2ubuntu0.8
1
rabeh/apibootspring:1.0941007b6946e
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.8
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
krb5@1.20.1-6ubuntu2.5
1.20.1-6ubuntu2.7
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.