StackRadar

CVE-2026-41989

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,959
of 17,790 indexed, latest versions
Container images
2,171
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libgcrypt security update

Carried by container images the latest versions of 1,959 of 17,790 indexed charts deploy, on 2,171 images.

Affected packageAffected versionsFixed inImages
libgcryptrpm1.8.3-2.el8, 1.8.3-4.el8, 1.8.5-4.el8, 1.8.5-6.el8+7 more0:1.8.5-8.el8_10, 0:1.10.0-13.el9_8, 1.11.0-150700.5.10.1, 1.12.1-160000.3.1379
libgcrypt20deb1.6.5-2ubuntu0.2, 1.6.5-2ubuntu0.3, 1.6.5-2ubuntu0.4, 1.6.5-2ubuntu0.5+18 more1.9.4-3ubuntu3.2, 1.10.1-3+deb12u1, 1.10.3-2ubuntu0.1, 1.11.0-7+deb13u1+4 more1,792
OSV records
RHSA-2026:47117RHSA-2026:50147RLSA-2026:47117RLSA-2026:50147DEBIAN-CVE-2026-41989UBUNTU-CVE-2026-41989ECHO-afba-f32f-e1d7SUSE-SU-2026:22826-1SUSE-SU-2026:3182-1
Also known as
RHSA-2026:52950, RHSA-2026:52952, RHSA-2026:52953, RHSA-2026:58977, RHSA-2026:58978, RHSA-2026:58979, USN-8319-1

Charts affected

1,959 by stars
ChartLatestAffected imagesRadar Score
freeradiusopencord1.0.41 of 1See more

freeradius opencord 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

15,718
mcord-cdn-remoteopencord0.1.62 of 2See more

mcord-cdn-remote opencord 0.1.6

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
woojoong/wowza:latestec230db19652
libgcrypt20@1.8.1-4ubuntu1.1
no fix listed

Open the chart page →

42,655
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed

Open the chart page →

29,156
mcord-control-planeopencord0.2.22 of 5See more

mcord-control-plane opencord 0.2.2

2 of the 5 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
libgcrypt20@1.8.1-4ubuntu1
no fix listed

Open the chart page →

15,666
oaisimopencord0.1.72 of 3See more

oaisim opencord 0.1.7

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

14,556
omec-control-planeopencord0.1.315 of 8See more

omec-control-plane opencord 0.1.31

5 of the 8 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
omecproject/c3po-hss:master-latest638671ef4842
libgcrypt20@1.6.5-2ubuntu0.6
no fix listed
omecproject/c3po-hssdb:master-latest28a90cc26716
libgcrypt20@1.8.5-5ubuntu1
no fix listed
omecproject/mme-exporter:paging-latestbcc5f19fd676
libgcrypt20@1.8.1-4ubuntu1.1
no fix listed
omecproject/ngic-cp:central-cp-multi-upfs-latest24a389a0a4fe
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
omecproject/openmme:master-latest64776cb9edb3
libgcrypt20@1.6.5-2ubuntu0.6
no fix listed

Open the chart page →

40,825
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
libgcrypt20@1.8.1-4ubuntu1.1
no fix listed

Open the chart page →

12,942
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
libgcrypt20@1.6.5-2ubuntu0.3
no fix listed

Open the chart page →

38,902
ovspluginopencord1.0.21 of 1See more

ovsplugin opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gopinatht/ovs-plugin-installer:latest632cb2e9c399
libgcrypt20@1.6.5-2ubuntu0.4
no fix listed

Open the chart page →

4,172
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed

Open the chart page →

12,626
sebaopencord1.0.05 of 17See more

seba opencord 1.0.0

5 of the 17 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
tpdock/freeradius:2.2.93da600c95a49
libgcrypt20@1.6.5-2ubuntu0.3
no fix listed
voltha/voltha-cli:1.6.0c4e41e92f046
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
voltha/voltha-netconf:1.6.037f80524c207
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
voltha/voltha-ofagent:1.6.09ee8c1f4428c
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
voltha/voltha-voltha:1.6.0ff596b62de59
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed

Open the chart page →

93,946
voltha-infraopencord2.14.04 of 10See more

voltha-infra opencord 2.14.0

4 of the 10 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
library/ubuntu:16.041f1a2d56de1d
libgcrypt20@1.6.5-2ubuntu0.6
no fix listed
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
voltha/voltha-onos:5.1.8e038acb950d3
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

41,101
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

11,051
dokuopenlit0.1.41 of 3See more

doku openlit 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latestfa394da808cc
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed

Open the chart page →

1,737
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.4.12e6587b81a26
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

5,068
minioopenobserve5.0.72 of 2See more

minio openobserve 5.0.7

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

7,471
openpanelopenpanel0.9.01 of 6See more

openpanel openpanel 0.9.0

1 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

3,465
llm-stackopenproject-helm-chartsVerified publisher1.1.01 of 2See more

llm-stack openproject-helm-charts 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
apache/apisix:3.16.0-ubuntu5e47692cac00
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

1,992
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

12,185
alquimia-studioopenshift0.2.01 of 1See more

alquimia-studio openshift 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
alquimiaai/studio:certification38a1f0341982
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

2,386
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
andrianrf/backoffice-be:latest6036614803d4
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8
andrianrf/iso-server:latest7da47f525c7d
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8

Open the chart page →

35,116
canvas-oamportalopenshift4.0.01 of 1See more

canvas-oamportal openshift 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/oam:4.0.0ed8fd2062548
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

7,519
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8

Open the chart page →

19,051
dify-enterpriseopenshift3.9.810 of 13See more

dify-enterprise openshift 3.9.8

10 of the 13 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
langgenius/dify-ee-audit:3.9.8-ubi9e99aed151fc5
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-collector:3.9.8-ubi9a9b91fd62c94
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-enterprise:3.9.8-ubi9c392a36a4ef7
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-gateway:3.9.8-ubi99e314c29a61f
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-plugin-crd:3.9.8-ubi96f4e0e5f6e5a
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-plugin-manager:3.9.8-ubi9207b343013a0
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

4,899
exporteropenshift1.0.473 of 3See more

exporter openshift 1.0.47

3 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

13,041
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/mariadb:11.4611a2fcc5fa7
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

7,866
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

9,968
fsmopenshift0.1.8-ubi.66 of 6See more

fsm openshift 0.1.8-ubi.6

6 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/toolbox-ubi8:1.2.01f5e3161cb84
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

16,563
harikubeopenshift0.16.31 of 3See more

harikube openshift 0.16.3

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

2,566
kb-cloud-installeropenshift2.1.351 of 1See more

kb-cloud-installer openshift 2.1.35

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

4,170
kite-agentopenshift1.0.01 of 1See more

kite-agent openshift 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

5,863
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi87 of 7See more

osm-edge openshift 1.2.1-ubi8

7 of the 7 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

19,471
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8

Open the chart page →

8,643
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

13,612
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

11,740
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

13,573
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

13,556
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

13,460
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

13,105
openshift-integration-operatoropenshift-integration-operatorVerified publisher0.8.21 of 2See more

openshift-integration-operator openshift-integration-operator 0.8.2

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

2,063
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

15,602
openvscode-serveropenvscode-server-helmVerified publisher2.7.371 of 2See more

openvscode-server openvscode-server-helm 2.7.37

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
antiantiops/vscode-browser-docker:1.137.0eeff80a99d92
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

4,298
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

36,252
opslevelopslevelVerified publisher2025.1.221 of 10See more

opslevel opslevel 2025.1.22

1 of the 10 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

5,658
hiveopstty0.1.91 of 4See more

hive opstty 0.1.9

1 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

4,550
grrosdfir-infrastructureVerified publisher1.0.32 of 5See more

grr osdfir-infrastructure 1.0.3

2 of the 5 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/mariadb:11.3.2e101f9db3191
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

11,021
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.020 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

20 of the 40 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/git:latest4b08d0c5af8d
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
library/mariadb:11.3.2e101f9db3191
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

72,547
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

3,670
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

3,327

Container images carrying it

2,171 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ddosify/selfhosted_backend:3.2.93c11e3182652
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
deconzcommunity/deconz:2.29.2062de2362641
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
defactops/defactops-backend:1.0.2307b663c0092a
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
dellcloud/category:distributed02fc234353a9
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
dellcloud/pages:1.04d2eb25b9225
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
devopsgoofy/k8s-platform:latestad865312099f
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
dgraph/dgraph:v24.1.4b57fa31f9b7f
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
diygod/rsshub:2025-11-097a6312cac0d5
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
djjudas21/alertify:0.1.0ba22be670c37
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
dniel/api-posts:master45a667852f2a
libgcrypt20@1.8.1-4ubuntu1.1
no fix listed
1
dobtc/bitcoin:25.1a870f7cb1105
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
dolibarr/dolibarr:22.0.47ad88fc9b13c
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
domainmod/domainmod:4.23.04017bfe4c597
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
dremio/dremio-oss:24.1.080ed2e3b7c43
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
drorivry4/rego:lateste035d49b15ca
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
drpcorg/dshackle:0.54.08858fae1859d
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
drumsergio/genieacs:1.2.16.028244054e1bf
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
dserio83/velero-api:0.3.16b3d9115fee2
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
dserio83/velero-watchdog:0.1.8d5deae589229
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
duck1123/cert-downloader:latest0e29f19fa67c
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
duck1123/lnd-fileserver:latest9d6fb247b714
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
dzikoysk/reposilite:3.5.264128c2d7a6ba
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
dzikoysk/reposilite:3.6.390de4c8e6c0e
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
libgcrypt20@1.11.0-7
1.11.0-7+deb13u1
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
elastic/apm-server:7.17.6c7a1c63257d0
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
elastictranscoder/media:627e21dc963ab3858c6b
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
elastictranscoder/media-storage:f6d861a026208b8c2359
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
elastiflow/flow-collector:7.26.0fee67842e16b
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
emqx/ecp-ui:2.5.1e33e9816f147
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
enclavenetworks/enclave:latest0a99759300d1
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
engrmth/bnkr:2.1.06d8464e6f0e8
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
envoyproxy/envoy:v1.30.92956bd9de830
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
envoyproxy/envoy:v1.38.4447f857a0146
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed
1
envoyproxy/envoy:v1.33.056da5afd7df3
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.