StackRadar

CVE-2026-41989

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,955
of 17,797 indexed, latest versions
Container images
2,167
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libgcrypt security update

Carried by container images the latest versions of 1,955 of 17,797 indexed charts deploy, on 2,167 images.

Affected packageAffected versionsFixed inImages
libgcryptrpm1.8.3-2.el8, 1.8.3-4.el8, 1.8.5-4.el8, 1.8.5-6.el8+7 more0:1.8.5-8.el8_10, 0:1.10.0-13.el9_8, 1.11.0-150700.5.10.1, 1.12.1-160000.3.1378
libgcrypt20deb1.6.5-2ubuntu0.2, 1.6.5-2ubuntu0.3, 1.6.5-2ubuntu0.4, 1.6.5-2ubuntu0.5+18 more1.9.4-3ubuntu3.2, 1.10.1-3+deb12u1, 1.10.3-2ubuntu0.1, 1.11.0-7+deb13u1+4 more1,789
OSV records
RHSA-2026:47117RHSA-2026:50147RLSA-2026:47117RLSA-2026:50147DEBIAN-CVE-2026-41989UBUNTU-CVE-2026-41989ECHO-afba-f32f-e1d7SUSE-SU-2026:22826-1SUSE-SU-2026:3182-1
Also known as
RHSA-2026:52950, RHSA-2026:52952, RHSA-2026:52953, RHSA-2026:58977, RHSA-2026:58978, RHSA-2026:58979, USN-8319-1

Charts affected

1,955 by stars
ChartLatestAffected imagesRadar Score
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

2,692
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

6,017
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

3,697
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

9,272
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed

Open the chart page →

7,936

Container images carrying it

2,167 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
photoprism/photoprism:240711-cefc6fd632ca74
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
libgcrypt20@1.11.0-7
1.11.0-7+deb13u1
1
pk910/powfaucet:v2-stable3dcae6a62896
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
platform9community/admin-server:latestde3fa9b70df1
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
platform9community/api-gateway:latest40a4970de568
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
platform9community/customers-service:latest2089811e5cc6
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
platform9community/vets-service:latestd1165c94dfb3
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
platform9community/visits-service:latest8d11b50368c6
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
plexinc/pms-docker:1.43.3.10896-cb3ebc72d83a425ae9e13
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
1
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
libgcrypt@1.8.3-4.el8
0:1.8.5-8.el8_10
1
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
pococze/python-hello-elos:2.0.07a1aab425e51
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
posit/package-manager:2026.09.0-ubuntu-24.04527493ef621b
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11
1
pozetroninc/keydb:v6.0.1653ae64f29da8
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
pposkrobko/risk-advisor:v1.0.0eaf260341dba
libgcrypt20@1.6.5-2ubuntu0.2
no fix listed
1
praravind1801/helmimages:3.0.0f29d637b9ce1
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
prodrigestivill/postgres-backup-local:latestf70742ebe42b
libgcrypt20@1.11.0-7
1.11.0-7+deb13u1
1
project2team4/react:latest3ff031a08887
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
prom/cloudwatch-exporter:v0.16.071c2e988af06
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
promzeus/redis-sentinel-gateway:v182f6d56e280b
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
proxysql/proxysql:3.0.8947a7abad45b
libgcrypt20@1.11.0-7
1.11.0-7+deb13u1
1
proxysql/proxysql:2.7.3a4d6c35c2949
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
pschichtel/mindustry-server:v145.1b543e9c2d371
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
psorab/elibrary:latest53b68896c4ce
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
puppet/puppet-agent:7.14.00b6fd9a6b7da
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
1
qdrant/qdrant:v1.7.45f2a56b95266
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
qdrant/qdrant:v1.4.166ee661d5241
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
qonstrukt/php:8.4-v8-apache089af7925aa1
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
1
quickwit/quickwit:v0.8.1d29332bdadcc
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
qumine/minecraft-server:v0.1.15c0b650d51132
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
qxip/qryn:3.2.3977acc9c7a9fd
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
rabeh/apibootspring:1.0941007b6946e
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
radondb/clickhouse-server:v21.1.3.32-stable4732df471073
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
rancher/harvester-csi-driver:v0.2.9f9099b5ef8cb
libgcrypt@1.12.1-160000.1.1
1.12.1-160000.3.1
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
1
rancher/nginx-ingress-controller:v1.14.5-hardened26cbc1e932b5b
libgcrypt@1.11.1-160000.2.2
1.12.1-160000.3.1
1
razorbladex401/dayz:latest6a4d79248e7d
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
razzy10/product-service:latest702e411956db
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
readysettech/sqp:latest588f3507280e
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
readysettech/sqp-duckdb:latest67a83203ce60
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
redash/redash:25.8.000d813437db5
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.