CVE-2026-40356
HighAdvisory
Published 28 Apr 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.006
- 47th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 936
- of 17,792 indexed, latest versions
- Container images
- 991
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Red Hat Security Advisory: krb5 security update
Carried by container images the latest versions of 936 of 17,792 indexed charts deploy, on 991 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| krb5deb | 1.19.2-2, 1.19.2-2ubuntu0.1, 1.19.2-2ubuntu0.2, 1.19.2-2ubuntu0.3+20 more | 1.19.2-2ubuntu0.8, 1.20.1-2+deb12u5, 1.20.1-6ubuntu2.7, 1.21.3-5+deb13u1+2 more | 961 |
| krb5rpm | 1.20.1-8.el9, 1.20.1-9.el9_2, 1.21.1-1.el9, 1.21.1-2.el9_4+2 more | 0:1.20.1-9.el9_2.6, 0:1.21.1-2.el9_4.5, 0:1.21.1-8.el9_6.2 | 30 |
- OSV records
- DEBIAN-CVE-2026-40356RHSA-2026:24683RHSA-2026:24685RHSA-2026:24686UBUNTU-CVE-2026-40356ECHO-874c-29e0-d62b
- Also known as
- USN-8585-1
Charts affected
936 by stars
Container images carrying it
991 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| public.ecr.aws/ | f8fb4eea4071 | krb5 | 1.20.1-2+deb12u5 | 1 |
| public.ecr.aws/ | 046ef5c9ed50 | krb5 | 1.20.1-2+deb12u5 | 1 |
| public.ecr.aws/ | dc5a516c2333 | krb5 | 1.20.1-2+deb12u5 | 1 |
| public.ecr.aws/ | 36d051110158 | krb5 | 1.20.1-2+deb12u5 | 1 |
| public.ecr.aws/ | 9e14a72b066d | krb5 | 1.20.1-2+deb12u5 | 1 |
| public.ecr.aws/ | f7567ce3419d | krb5 | 1.20.1-2+deb12u5 | 1 |
| public.ecr.aws/ | 86380a01587d | krb5 | 1.20.1-6ubuntu2.7 | 1 |
| public.ecr.aws/ | f74851ce31f5 | krb5 | 1.20.1-2+deb12u5 | 1 |
| public.ecr.aws/ | 794b3bff9510 | krb5 | 0:1.21.1-2.el9_4.5 | 1 |
| quay.io/ | 70fd7c00418d | krb5 | 1.19.2-2ubuntu0.8 | 1 |
| quay.io/ | 578934444f04 | krb5 | 1.19.2-2ubuntu0.8 | 1 |
| quay.io/ | 70d138997acd | krb5 | 0:1.21.1-2.el9_4.5 | 1 |
| quay.io/ | 5b6701d8fb31 | krb5 | 1.19.2-2ubuntu0.8 | 1 |
| quay.io/ | 95b5cf7ba6fe | krb5 | 1.20.1-6ubuntu2.7 | 1 |
| quay.io/ | a36ab0c0860c | krb5 | 1.20.1-6ubuntu2.7 | 1 |
| quay.io/ | acaf37352569 | krb5 | 1.19.2-2ubuntu0.8 | 1 |
| quay.io/ | 351d6685dc6f | krb5 | 1.19.2-2ubuntu0.8 | 1 |
| quay.io/ | a9f835d1b241 | krb5 | 1.20.1-2+deb12u5 | 1 |
| quay.io/ | d9f0bec83ef0 | krb5 | 1.19.2-2ubuntu0.8 | 1 |
| quay.io/ | 60950ef63764 | krb5 | 1.19.2-2ubuntu0.8 | 1 |
| quay.io/ | 3c886ce5c056 | krb5 | 0:1.21.1-8.el9_6.2 | 1 |
| quay.io/ | 93889c3d8a34 | krb5 | 1.19.2-2ubuntu0.8 | 1 |
| quay.io/ | 113e372cf71b | krb5 | 1.20.1-2+deb12u5 | 1 |
| quay.io/ | 92f883d09270 | krb5 | 1.20.1-2+deb12u5 | 1 |
| quay.io/ | 150f76e844d9 | krb5 | 0:1.21.1-8.el9_6.2 | 1 |
| quay.io/ | 2169032c5840 | krb5 | 1.20.1-2+deb12u5 | 1 |
| quay.io/ | b05101723412 | krb5 | 0:1.21.1-8.el9_6.2 | 1 |
| quay.io/ | 7f728514fead | krb5 | 0:1.21.1-8.el9_6.2 | 1 |
| quay.io/ | d8f66f4117fe | krb5 | 1.21.3-5+deb13u1 | 1 |
| quay.io/ | 59fe607dfdf2 | krb5 | 0:1.21.1-2.el9_4.5 | 1 |
| quay.io/ | 7b4202c25b67 | krb5 | 0:1.20.1-9.el9_2.6 | 1 |
| quay.io/ | 030ade9b9428 | krb5 | 0:1.21.1-2.el9_4.5 | 1 |
| quay.io/ | 58c727cd2e68 | krb5 | 0:1.21.1-8.el9_6.2 | 1 |
| quay.io/ | e0d9b93dbf2b | krb5 | 1.20.1-2+deb12u5 | 1 |
| registry.gitlab.com/ | 166a06f73d8c | krb5 | 1.20.1-6ubuntu2.7 | 1 |
| registry.gitlab.com/ | 66353ce9bf98 | krb5 | 1.21.3-5+deb13u1 | 1 |
| registry.gitlab.com/ | 0e3cd8c7776d | krb5 | 1.20.1-2+deb12u5 | 1 |
| registry.gitlab.com/ | 301847adfe16 | krb5 | 0:1.21.1-8.el9_6.2 | 1 |
| registry.k8s.io/ | 0e64aedb0d0a | krb5 | 1.21.3-5+deb13u1 | 1 |
| registry.k8s.io/ | fd9722fd02e3 | krb5 | 1.20.1-2+deb12u5 | 1 |
| registry.k8s.io/ | ce5b5ccd5eb0 | krb5 | 1.20.1-2+deb12u5 | 1 |