StackRadar

CVE-2026-41989

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,955
of 17,797 indexed, latest versions
Container images
2,167
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libgcrypt security update

Carried by container images the latest versions of 1,955 of 17,797 indexed charts deploy, on 2,167 images.

Affected packageAffected versionsFixed inImages
libgcryptrpm1.8.3-2.el8, 1.8.3-4.el8, 1.8.5-4.el8, 1.8.5-6.el8+7 more0:1.8.5-8.el8_10, 0:1.10.0-13.el9_8, 1.11.0-150700.5.10.1, 1.12.1-160000.3.1378
libgcrypt20deb1.6.5-2ubuntu0.2, 1.6.5-2ubuntu0.3, 1.6.5-2ubuntu0.4, 1.6.5-2ubuntu0.5+18 more1.9.4-3ubuntu3.2, 1.10.1-3+deb12u1, 1.10.3-2ubuntu0.1, 1.11.0-7+deb13u1+4 more1,789
OSV records
RHSA-2026:47117RHSA-2026:50147RLSA-2026:47117RLSA-2026:50147DEBIAN-CVE-2026-41989UBUNTU-CVE-2026-41989ECHO-afba-f32f-e1d7SUSE-SU-2026:22826-1SUSE-SU-2026:3182-1
Also known as
RHSA-2026:52950, RHSA-2026:52952, RHSA-2026:52953, RHSA-2026:58977, RHSA-2026:58978, RHSA-2026:58979, USN-8319-1

Charts affected

1,955 by stars
ChartLatestAffected imagesRadar Score
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

2,692
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

6,017
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

3,697
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

9,272
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed

Open the chart page →

7,936

Container images carrying it

2,167 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
redash/redash:26.3.0c5c9148f5c38
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
redislabs/operator:8.0.18-119078e713bb6a
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
redis/redis-stack-server:6.2.6-v251a58f32d412
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
redis/redis-stack-server:latest798ab84d9f26
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
redis/redis-stack-server:7.4.0-v0887cf87cc744
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
resurfaceio/resurface:3.7.84d5cda2f64109
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
rezachalak/bzen-mongo:1.0.034f694325191
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
rm3l/dev-feed-api:latest9a7f732245a3
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8
1
rm3l/mac-oui:1.8.03a5e1f95c132
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
rnwood/smtp4dev:3.6.1912304153668
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
robotshop/rs-mongodb:latest119b545823cd
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
rocketadmin/rocketadmin:1.17.710955ef540b9
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
rocketchat/freeswitch:stablecfba5c20a5cc
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
rosette/root-rli:7.23.21.c82.0a4467d3bb211
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
rotationalio/honu:0.5.069fd30c2e31c
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
rraahul/test:latestbfe2c1183bc0
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
rrobetti/ojp:0.1.0-beta1141bd88232b
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
rtuszik/photon-docker:2.4.021549c60f9e6
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
rundeck/rundeck:3.2.74d64fe56f767
libgcrypt20@1.6.5-2ubuntu0.6
no fix listed
1
rundeck/rundeck:3.0.16b13e8059ad72
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
1
ryshe/terraria:latestb1c89f7f359a
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
ryuunosukeds3/orbital:latest0879f7261b10
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
salaboy/agenda-service-0967b907d9920c99918e2b91b91937b3ce9ce8293e4e
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
salaboy/c4p-service-a3dc0474cbfa348afcdf47a8eee70ba9bb64bf14467d
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
salaboy/notifications-service-0e27884e01429ab7e350cb5dff61b525799c35f9f306
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
santisbon/evwatcher:latestc4e994ca4540
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
santisbon/evworker:lateste807283f8d69
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
santisbon/speedtest:latest8ee3a1697227
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
sarwansharma/minio:v359d1da9385d1
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
schemahero/schemahero-manager:0.22.11609e1a05cd3
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
scrapinghub/splash:3.4.1a5f89bc84606
libgcrypt20@1.8.1-4ubuntu1.1
no fix listed
1
scsibug/nostr-rs-relay:0.9.003f54bfbffff
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
seafileltd/seafile-mc:9.0.106693911bcc40
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
seafileltd/seafile-mc:10.0.170628f29c663
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
seafileltd/seafile-mc:9.0.97ac833196f60
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
seldonio/locust-core:0.81d0da98a2d76
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
1
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.