StackRadar

CVE-2026-41989

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,955
of 17,797 indexed, latest versions
Container images
2,167
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libgcrypt security update

Carried by container images the latest versions of 1,955 of 17,797 indexed charts deploy, on 2,167 images.

Affected packageAffected versionsFixed inImages
libgcryptrpm1.8.3-2.el8, 1.8.3-4.el8, 1.8.5-4.el8, 1.8.5-6.el8+7 more0:1.8.5-8.el8_10, 0:1.10.0-13.el9_8, 1.11.0-150700.5.10.1, 1.12.1-160000.3.1378
libgcrypt20deb1.6.5-2ubuntu0.2, 1.6.5-2ubuntu0.3, 1.6.5-2ubuntu0.4, 1.6.5-2ubuntu0.5+18 more1.9.4-3ubuntu3.2, 1.10.1-3+deb12u1, 1.10.3-2ubuntu0.1, 1.11.0-7+deb13u1+4 more1,789
OSV records
RHSA-2026:47117RHSA-2026:50147RLSA-2026:47117RLSA-2026:50147DEBIAN-CVE-2026-41989UBUNTU-CVE-2026-41989ECHO-afba-f32f-e1d7SUSE-SU-2026:22826-1SUSE-SU-2026:3182-1
Also known as
RHSA-2026:52950, RHSA-2026:52952, RHSA-2026:52953, RHSA-2026:58977, RHSA-2026:58978, RHSA-2026:58979, USN-8319-1

Charts affected

1,955 by stars
ChartLatestAffected imagesRadar Score
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

2,692
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

6,017
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

3,697
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

9,272
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed

Open the chart page →

7,936

Container images carrying it

2,167 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kubeflownotebookswg/volumes-web-app:v1.9.2f63c3e550af3
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
kubegems/redis:7.2.5-debian-12-r2870ee3a77add
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
kuberay/operator:v1.0.04e6ac8a3a2c4
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
kubeshop/bitnami-mongodb:8.3.8d48b172d99d8
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
1
kubesphere/examples-bookinfo-reviews-v2:1.13.06d93129beb32
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
1
kudobuilder/controller:v0.9.069072d979708
libgcrypt20@1.8.1-4ubuntu1.1
no fix listed
1
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
kusionstack/kusion:v0.14.0126c8f0b0976
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
kuzwolka/aws9:main1ad759b961b1
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
kuzwolka/aws9:news3e8880fbbb96
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
kuzwolka/aws9:blog4a7707410bf1
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
kuzwolka/aws9:shop84a9d9766345
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
laly9999/node-app:1dd0e503913e1
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
lancachenet/monolithic:latest37f28b362c93
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
1
langflowai/langflow-frontend:latest54f67f1961fe
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
langgenius/dify-api:1.0.0066035f93856
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
langgenius/dify-api:0.6.11fca918260dd6
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
langgenius/dify-ee-audit:3.9.8-ubi9e99aed151fc5
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
langgenius/dify-ee-collector:3.9.8-ubi9a9b91fd62c94
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
langgenius/dify-ee-enterprise:3.9.8-ubi9c392a36a4ef7
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
langgenius/dify-ee-gateway:3.9.8-ubi99e314c29a61f
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
langgenius/dify-ee-plugin-crd:3.9.8-ubi96f4e0e5f6e5a
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
langgenius/dify-ee-plugin-manager:3.9.8-ubi9207b343013a0
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
1
lib42/jackett:latesta55596cda383
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
library/cassandra:3.11.10b095ff3248c6
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
library/convertigo:8.4.3ae605bfcda05
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
1
library/couchdb:3.4.22817ad50b5c5
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
library/debian:12.5-slim67f3931ad8cb
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
library/debian:12.12-slimd5d3f9c23164
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
library/elasticsearch:8.17.32cc40b15dff8
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
library/elasticsearch:8.15.0310b9fc03b06
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
library/elasticsearch:7.17.0332c6d416808
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
library/elasticsearch:7.17.1588c2ec10c7f2
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
library/elasticsearch:7.17.8fdc73b3249c1
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
library/flink:1.14.6-scala_2.122461f02672b3
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
library/ghost:6.37.01ef2e532ca4d
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
library/ghost:6.25.12654b1e90413
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
library/ghost:6.41.129773d6be407
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
library/ghost:5.79.083f7bf209844
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
library/haproxy:3.1-bookworm49a0a0d6f0b8
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.