StackRadar

CVE-2026-41989

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,948
of 17,792 indexed, latest versions
Container images
2,155
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libgcrypt security update

Carried by container images the latest versions of 1,948 of 17,792 indexed charts deploy, on 2,155 images.

Affected packageAffected versionsFixed inImages
libgcryptrpm1.8.3-2.el8, 1.8.3-4.el8, 1.8.5-4.el8, 1.8.5-6.el8+7 more0:1.8.5-8.el8_10, 0:1.10.0-13.el9_8, 1.11.0-150700.5.10.1, 1.12.1-160000.3.1378
libgcrypt20deb1.6.5-2ubuntu0.2, 1.6.5-2ubuntu0.3, 1.6.5-2ubuntu0.4, 1.6.5-2ubuntu0.5+18 more1.9.4-3ubuntu3.2, 1.10.1-3+deb12u1, 1.10.3-2ubuntu0.1, 1.11.0-7+deb13u1+4 more1,777
OSV records
RHSA-2026:47117RHSA-2026:50147RLSA-2026:47117RLSA-2026:50147DEBIAN-CVE-2026-41989UBUNTU-CVE-2026-41989ECHO-afba-f32f-e1d7SUSE-SU-2026:22826-1SUSE-SU-2026:3182-1
Also known as
RHSA-2026:52950, RHSA-2026:52952, RHSA-2026:52953, RHSA-2026:58977, RHSA-2026:58978, RHSA-2026:58979, USN-8319-1

Charts affected

1,948 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,155 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
1
erigontech/erigon:v2.61.288706754b627
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
erlangsolutions/mongooseim:6.6.0cc5bf032931f
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
esphome/esphome:2024.3.09ab8cc88b28c
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
esphome/esphome:2024.12.2b2c6322700ac
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
esphome/esphome:2025.3.0def8b6e4f517
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ethanbergstrom/duoauthproxy:5.5.0345c2a46c103
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
libgcrypt20@1.6.5-2ubuntu0.3
no fix listed
1
ethersphere/bee:2.2.0a884fd84b72f
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ethersphere/beekeeper:lateste4cda693ed63
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ethpandaops/eleel:mainb8f1b707aee0
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
ethpandaops/observoor:masterc7e5055defcb
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
falcosecurity/event-generator:latest932956d86c99
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
federid/webhook:0.1.0fbfb7c6510a7
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
felipecs8/app-db-connection-test:v129e06c9c6385
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
firefart/requesttracker:5.0.40d6249906d8c
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
fiware/mintaka:0.7.092a3c5cf43c0
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10
1
fiware/mintaka:latestefc6793388cc
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10
1
fiware/orion-ld:1.10.03c490a746f65
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
flanksource/apm-hub:v0.0.471dacc3195bf9
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
flanksource/batch-runner:v1.0.44689687a7cf95
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
flashcatcloud/categraf:latest42e6ab16472e
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
fluent/fluent-bit:4.0.4ca08b7d2df5b
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
fluent/fluent-bit:4.0-debuge76397ef3983
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
flyway/flyway:9.1545b5d7cdc75a
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
fnzv/dump1090:latestb3079b95c336
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
foldingathome/fah-gpu:latest5ef7742d1eb4
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
folioci/mod-z3950:latest2493041ce880
libgcrypt20@1.11.0-7
1.11.0-7+deb13u1
1
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
frankescobar/allure-docker-service:latestdc171ec796d5
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
1
free5gmano/nextepc-mongodb:latest36f806935519
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
1
freedom98/flask:k3.0d7ce1533f297
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
galaxy/cloudman-server:lateste5c265fe9fcd
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
gchq/accumulo:2.0.1c460bb587d6d
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
geopython/pycsw:3.0.0-beta284662ea6b78b
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.