StackRadar

CVE-2026-40612

Medium

Advisory

Published 11 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
428
of 17,781 indexed, latest versions
Container images
341
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 428 of 17,781 indexed charts deploy, on 341 images.

Affected packageAffected versionsFixed inImages
jqdeb1.5+dfsg-1, 1.5+dfsg-1ubuntu0.1, 1.5+dfsg-2, 1.6-1ubuntu0.20.04.1+14 more1.7.1-6+deb13u3236
jqapk1.7.1-r0, 1.8.0-r0, 1.8.1-r01.8.2-r0105
OSV records
ALPINE-CVE-2026-40612DEBIAN-CVE-2026-40612UBUNTU-CVE-2026-40612

Charts affected

428 by stars
ChartLatestAffected imagesRadar Score
portalsmo-helm-chart6.0.01 of 8See more

portal smo-helm-chart 6.0.0

1 of the 8 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
jq@1.5+dfsg-1
no fix listed

Open the chart page →

27,477
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
jq@1.5+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

25,769
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
jq@1.5+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
jq@1.5+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
jq@1.5+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
jq@1.5+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
jq@1.5+dfsg-1ubuntu0.1
no fix listed

Open the chart page →

25,769
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
jq@1.6-1ubuntu0.20.04.1
no fix listed

Open the chart page →

30,687
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
library/mongo:4.4.18d23ec07162ca
jq@1.6-1ubuntu0.20.04.1
no fix listed

Open the chart page →

13,646
prowlarrsudo-kraken-prowlarrVerified publisher3.2.11 of 1See more

prowlarr sudo-kraken-prowlarr 3.2.1

1 of the 1 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
ghcr.io/home-operations/prowlarr:2.3.01a8a4b11972b
jq@1.8.1-r0
1.8.2-r0

Open the chart page →

876
qbittorrentsudo-kraken-qbittorrentVerified publisher5.1.51 of 2See more

qbittorrent sudo-kraken-qbittorrent 5.1.5

1 of the 2 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
ghcr.io/home-operations/qbittorrent:5.1.4bb82ad6668f8
jq@1.8.1-r0
1.8.2-r0

Open the chart page →

2,129
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
jq@1.6-1ubuntu0.20.04.1
no fix listed

Open the chart page →

18,756
stateful-data-generatortalhajuikar-helm-charts0.1.21 of 2See more

stateful-data-generator talhajuikar-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
jq@1.6-1ubuntu0.20.04.1
no fix listed

Open the chart page →

4,860
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
supabase/realtime:latestd3aa0c86c7b3
jq@1.7.1-6+deb13u2
1.7.1-6+deb13u3

Open the chart page →

9,556
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
library/mongo:5.0.217c81758cb295
jq@1.6-1ubuntu0.20.04.1
no fix listed

Open the chart page →

20,270
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
jq@1.6-1ubuntu0.20.04.1
no fix listed

Open the chart page →

10,006
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
library/mongo:7-jammy406a4fdca9fc
jq@1.6-2.1ubuntu3.2
no fix listed

Open the chart page →

7,248
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
jq@1.8.1-r0
1.8.2-r0

Open the chart page →

1,675
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
jq@1.8.1-r0
1.8.2-r0

Open the chart page →

5,550
simple-mongodbtyk-helm0.1.11 of 1See more

simple-mongodb tyk-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
jq@1.6-1ubuntu0.20.04.1
no fix listed

Open the chart page →

4,087
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
jq@1.6-2.1
no fix listed

Open the chart page →

8,607
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
jq@1.6-2.1ubuntu3
no fix listed

Open the chart page →

9,347
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
jq@1.6-2.1ubuntu3
no fix listed

Open the chart page →

13,459
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
jq@1.7.1-3ubuntu0.24.04.1
no fix listed

Open the chart page →

7,628
ciliumvks-helm-chartsVerified publisher1.17.141 of 3See more

cilium vks-helm-charts 1.17.14

1 of the 3 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
jq@1.7.1-3ubuntu0.24.04.1
no fix listed

Open the chart page →

4,046
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
jq@1.6-1ubuntu0.20.04.1
no fix listed

Open the chart page →

28,605
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
jq@1.8.0-r0
1.8.2-r0

Open the chart page →

14,983
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-40612.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
jq@1.7.1-3ubuntu0.24.04.2
no fix listed

Open the chart page →

13,677

Container images carrying it

341 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/mongo:8:8.3.8:latest5211c51171f5
jq@1.7.1-3ubuntu0.24.04.2
no fix listed
12
oomk8s/readiness-check:2.0.2875814cc853d
jq@1.5+dfsg-1ubuntu0.1
no fix listed
11
library/mongo:5.0.6-focal8e70544b6c76
jq@1.6-1ubuntu0.20.04.1
no fix listed
10
oomk8s/readiness-check:2.0.07daa08b81954
jq@1.5+dfsg-1
no fix listed
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
jq@1.6-2.1
no fix listed
5
library/mongo:4.44be76f674fc4
jq@1.6-1ubuntu0.20.04.1
no fix listed
5
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
jq@1.5+dfsg-1ubuntu0.1
no fix listed
4
library/mongo:5.0-focal5e15a3f014ed
jq@1.6-1ubuntu0.20.04.1
no fix listed
4
library/mongo:4.2.12-bionic628741415fc9
jq@1.5+dfsg-2
no fix listed
4
library/mongo:4.4.66efa05203990
jq@1.5+dfsg-2
no fix listed
4
linuxserver/sonarr:4.0.19:latest4d9df314875e
jq@1.8.1-r0
1.8.2-r0
4
pihole/pihole:2026.07.2:latestf7d1be836e3b
jq@1.8.1-r0
1.8.2-r0
4
ghcr.io/linuxserver/plex:latest7f9a1d574958
jq@1.8.1-4ubuntu2
no fix listed
4
bitnamilegacy/kubectl:latestcd354d5b2556
jq@1.6-2.1
no fix listed
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
jq@1.6-2.1
no fix listed
3
dgraph/dgraph:v21.12.03b55ea83fffe
jq@1.6-1ubuntu0.20.04.1
no fix listed
3
gchq/hdfs:3.3.35ec58edbb2db
jq@1.7.1-3build1
no fix listed
3
natsio/nats-box:0.19.28031d190c7ee
jq@1.8.0-r0
1.8.2-r0
3
natsio/nats-box:0.19.7ffce8bd10338
jq@1.8.1-r0
1.8.2-r0
3
selenium/hub:3.141.5902f251d48d5f
jq@1.6-1ubuntu0.20.04.1
no fix listed
3
quay.io/cilium/cilium:v1.20.1ae9ea21f7427
jq@1.8.1-4ubuntu2
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
jq@1.6-2.1ubuntu3
no fix listed
3
quay.io/jupyterhub/configurable-http-proxy:5.2.0522738d5285e
jq@1.8.1-r0
1.8.2-r0
3
alpine/k8s:1.32.12048f8d9c8cc7
jq@1.8.1-r0
1.8.2-r0
2
apache/nifi-registry:1.26.07cdfd8deec92
jq@1.6-2.1ubuntu3
no fix listed
2
cribl/cribl:4.19.2044f9a5fac9a
jq@1.7.1-3ubuntu0.24.04.2
no fix listed
2
gisaia/arlas-fam-wui:0.18.13700dcaf7a75
jq@1.8.1-r0
1.8.2-r0
2
gisaia/arlas-wui:28.0.3b83b3e067173
jq@1.8.1-r0
1.8.2-r0
2
gisaia/arlas-wui-builder:28.0.1a35977a5bb7d
jq@1.8.1-r0
1.8.2-r0
2
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
jq@1.8.1-r0
1.8.2-r0
2
homebridge/homebridge:latest77c685a40911
jq@1.7.1-3ubuntu0.24.04.2
no fix listed
2
jupyterhub/configurable-http-proxy:5.3.0:latest69a7170eeeda
jq@1.8.1-r0
1.8.2-r0
2
library/mongo:8.0.20098862b1339f
jq@1.7.1-3ubuntu0.24.04.1
no fix listed
2
library/mongo:7.0-jammy:7-jammy406a4fdca9fc
jq@1.6-2.1ubuntu3.2
no fix listed
2
library/mongo:5.041108d183e97
jq@1.6-1ubuntu0.20.04.1
no fix listed
2
library/mongo:4.2.358b25d51baa1
jq@1.5+dfsg-2
no fix listed
2
library/mongo:8.3.981a1c8842a09
jq@1.7.1-3ubuntu0.24.04.2
no fix listed
2
library/mongo:7b096b4cb9269
jq@1.6-2.1ubuntu3.2
no fix listed
2
library/mongo:7.0b6421fd6d1c5
jq@1.6-2.1ubuntu3.2
no fix listed
2
linuxserver/ddclient:4.0.06468911d00b1
jq@1.8.1-r0
1.8.2-r0
2
linuxserver/jackett:latest609a1830692d
jq@1.8.1-r0
1.8.2-r0
2
mesosphere/kubectl:v1.35.0-alpineea01a9387771
jq@1.8.1-r0
1.8.2-r0
2
wolveix/satisfactory-server:latest:v1.9.10e103700ae6ae
jq@1.6-2.1ubuntu3.1
no fix listed
2
ghcr.io/astriaorg/astria-geth:latest4249e403225a
jq@1.8.0-r0
1.8.2-r0
2
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
jq@1.8.0-r0
1.8.2-r0
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
jq@1.8.0-r0
1.8.2-r0
2
ghcr.io/home-assistant/home-assistant:2026.9.1:latest612d76760b54
jq@1.8.1-r0
1.8.2-r0
2
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
jq@1.8.1-r0
1.8.2-r0
2
ghcr.io/home-operations/radarr:6.4.3:6.4.3.106450ebb4ae26ee9
jq@1.8.1-r0
1.8.2-r0
2
ghcr.io/home-operations/readarr:0.4.18:0.4.18.28058f7551205fbd
jq@1.8.0-r0
1.8.2-r0
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.