StackRadar

CVE-2026-40356

High

Advisory

Published 28 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
936
of 17,792 indexed, latest versions
Container images
991
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: krb5 security update

Carried by container images the latest versions of 936 of 17,792 indexed charts deploy, on 991 images.

Affected packageAffected versionsFixed inImages
krb5deb1.19.2-2, 1.19.2-2ubuntu0.1, 1.19.2-2ubuntu0.2, 1.19.2-2ubuntu0.3+20 more1.19.2-2ubuntu0.8, 1.20.1-2+deb12u5, 1.20.1-6ubuntu2.7, 1.21.3-5+deb13u1+2 more961
krb5rpm1.20.1-8.el9, 1.20.1-9.el9_2, 1.21.1-1.el9, 1.21.1-2.el9_4+2 more0:1.20.1-9.el9_2.6, 0:1.21.1-2.el9_4.5, 0:1.21.1-8.el9_6.230
OSV records
DEBIAN-CVE-2026-40356RHSA-2026:24683RHSA-2026:24685RHSA-2026:24686UBUNTU-CVE-2026-40356ECHO-874c-29e0-d62b
Also known as
USN-8585-1

Charts affected

936 by stars
ChartLatestAffected imagesRadar Score
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5

Open the chart page →

10,159
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5

Open the chart page →

25,423
orchestra-login-portaltremolo2.3.981 of 1See more

orchestra-login-portal tremolo 2.3.98

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
krb5@1.19.2-2ubuntu0.7
1.19.2-2ubuntu0.8

Open the chart page →

3,004
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5

Open the chart page →

17,396
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.2.0-v10e44b2b49d059
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.8

Open the chart page →

5,602
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5

Open the chart page →

8,642
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5

Open the chart page →

5,245
opencloudunxwaresVerified publisher0.2.37 of 13See more

opencloud unxwares 0.2.3

7 of the 13 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
krb5@1.20.1-6ubuntu2
1.20.1-6ubuntu2.7
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5

Open the chart page →

45,472
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
krb5@1.20.1-2
1.20.1-2+deb12u5

Open the chart page →

14,431
telegram-rebotvcnngrVerified publisher1.0.02 of 3See more

telegram-rebot vcnngr 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
vcnngr/telegram-login:latest1a849a997b6d
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
vcnngr/telegram-rebot:latest30f1f05e57a6
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5

Open the chart page →

5,060
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5

Open the chart page →

4,411
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.8

Open the chart page →

9,424
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5

Open the chart page →

10,813
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7

Open the chart page →

4,364
bugsinkvictorlane0.3.71 of 2See more

bugsink victorlane 0.3.7

1 of the 2 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
library/mariadb:12.0-noble607835cd628b
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7

Open the chart page →

4,128
twenty-crmvictorlane0.0.12 of 3See more

twenty-crm victorlane 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
redis/redis-stack-server:latest798ab84d9f26
krb5@1.19.2-2ubuntu0.7
1.19.2-2ubuntu0.8
twentycrm/twenty-postgres-spilo:latest2f78405a78be
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.8

Open the chart page →

13,575
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7

Open the chart page →

7,679
api-gatewaywallarmVerified publisher0.2.01 of 1See more

api-gateway wallarm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
wallarm/api-gateway:0.2.0a3d4d2f780e8
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5

Open the chart page →

2,311
eth-validatorwateim1.4.51 of 3See more

eth-validator wateim 1.4.5

1 of the 3 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
wateim/lighthouse-launch:latest2520149ee574
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.8

Open the chart page →

5,090
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5

Open the chart page →

6,007
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.8

Open the chart page →

6,282
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5

Open the chart page →

7,166
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
krb5@1.20.1-2
1.20.1-2+deb12u5

Open the chart page →

10,111
welcome-elos-webappwelcome-elos-webappVerified publisher2.0.01 of 1See more

welcome-elos-webapp welcome-elos-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
pococze/python-hello-elos:2.0.07a1aab425e51
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5

Open the chart page →

2,695
giteawenerme12.7.02 of 4See more

gitea wenerme 12.7.0

2 of the 4 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5

Open the chart page →

8,874
openebswenerme3.10.02 of 3See more

openebs wenerme 3.10.0

2 of the 3 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.8
openebs/node-disk-operator:2.1.06afe2123c457
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.8

Open the chart page →

10,587
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.8

Open the chart page →

9,320
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7

Open the chart page →

2,235
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5

Open the chart page →

7,664
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5

Open the chart page →

5,559
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5

Open the chart page →

2,496
wordpress-alpinewordpress-alpine1.5.181 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

1 of the 6 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
library/mariadb:12.3.2628f228f0fd5
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7

Open the chart page →

4,063
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.8

Open the chart page →

14,173
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5

Open the chart page →

7,697
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
hamzaarshad10/querypodpy:1.7154f38e8668e
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
murtazashah46/helmfile:latest4d11726cf803
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5

Open the chart page →

13,783
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-40356.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
krb5@1.20.1-6ubuntu2
1.20.1-6ubuntu2.7

Open the chart page →

2,142

Container images carrying it

991 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
krb5@1.21.1-2.el9_4
0:1.21.1-2.el9_4.5
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.8
1
quay.io/aerokube/keygen:1.0.1578934444f04
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.8
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
krb5@1.21.1-2.el9_4
0:1.21.1-2.el9_4.5
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
krb5@1.19.2-2
1.19.2-2ubuntu0.8
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
krb5@1.20.1-6ubuntu2.5
1.20.1-6ubuntu2.7
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.8
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.8
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
krb5@1.19.2-2ubuntu0.7
1.19.2-2ubuntu0.8
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
krb5@1.19.2-2
1.19.2-2ubuntu0.8
1
quay.io/fiware/trusted-issuers-list:0.9.13c886ce5c056
krb5@1.21.1-8.el9_6
0:1.21.1-8.el9_6.2
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
krb5@1.19.2-2
1.19.2-2ubuntu0.8
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5
1
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
krb5@1.21.1-8.el9_6
0:1.21.1-8.el9_6.2
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
krb5@1.20.1-2+deb12u3
1.20.1-2+deb12u5
1
quay.io/mongodb/mongodb-enterprise-operator-ubi:1.33.0b05101723412
krb5@1.21.1-8.el9_6
0:1.21.1-8.el9_6.2
1
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
krb5@1.21.1-8.el9_6
0:1.21.1-8.el9_6.2
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
krb5@1.21.3-5
1.21.3-5+deb13u1
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
krb5@1.21.1-1.el9
0:1.21.1-2.el9_4.5
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
krb5@1.20.1-9.el9_2
0:1.20.1-9.el9_2.6
1
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
krb5@1.21.1-1.el9
0:1.21.1-2.el9_4.5
1
quay.io/strimzi/operator:0.45.158c727cd2e68
krb5@1.21.1-8.el9_6
0:1.21.1-8.el9_6.2
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
krb5@1.20.1-2
1.20.1-2+deb12u5
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
krb5@1.20.1-6ubuntu2.6
1.20.1-6ubuntu2.7
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
krb5@1.21.3-5
1.21.3-5+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
krb5@1.20.1-2+deb12u4
1.20.1-2+deb12u5
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
krb5@1.21.1-8.el9_6
0:1.21.1-8.el9_6.2
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
krb5@1.21.3-5
1.21.3-5+deb13u1
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u5
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u5
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.