StackRadar

CVE-2026-41989

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,953
of 17,803 indexed, latest versions
Container images
2,164
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libgcrypt security update

Carried by container images the latest versions of 1,953 of 17,803 indexed charts deploy, on 2,164 images.

Affected packageAffected versionsFixed inImages
libgcryptrpm1.8.3-2.el8, 1.8.3-4.el8, 1.8.5-4.el8, 1.8.5-6.el8+7 more0:1.8.5-8.el8_10, 0:1.10.0-13.el9_8, 1.11.0-150700.5.10.1, 1.12.1-160000.3.1378
libgcrypt20deb1.6.5-2ubuntu0.2, 1.6.5-2ubuntu0.3, 1.6.5-2ubuntu0.4, 1.6.5-2ubuntu0.5+18 more1.9.4-3ubuntu3.2, 1.10.1-3+deb12u1, 1.10.3-2ubuntu0.1, 1.11.0-7+deb13u1+4 more1,786
OSV records
RHSA-2026:47117RHSA-2026:50147RLSA-2026:47117RLSA-2026:50147DEBIAN-CVE-2026-41989UBUNTU-CVE-2026-41989ECHO-afba-f32f-e1d7SUSE-SU-2026:22826-1SUSE-SU-2026:3182-1
Also known as
RHSA-2026:52950, RHSA-2026:52952, RHSA-2026:52953, RHSA-2026:58977, RHSA-2026:58978, RHSA-2026:58979, USN-8319-1

Charts affected

1,953 by stars
ChartLatestAffected imagesRadar Score
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

3,697
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

9,272
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed

Open the chart page →

7,936

Container images carrying it

2,164 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
speckle/speckle-preview-service:2.17.14-branch.testing.72707.921a5f884fc39bca0c8
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
splunk/splunk-operator:2.0.0c4e0d3146226
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
spy86/rabbitmq-stomp:latestea649101b9fb
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
stackstorm/st2actionrunner:3.888235ba70cad
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
stackstorm/st2api:3.86f56d239d280
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
stackstorm/st2auth:3.833ecfda16608
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
stackstorm/st2notifier:3.8f190a6212195
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
stackstorm/st2rulesengine:3.8259503496ff9
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
stackstorm/st2scheduler:3.8b1de2055c362
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
stackstorm/st2stream:3.81c8904a3bf67
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
stackstorm/st2timersengine:3.81bf35bfaf00c
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
stackstorm/st2web:3.809989a26c8b7
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
stackstorm/st2workflowengine:3.819fdfffdbba8
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
stakater/workshop-operator:v0.0.3897bf456cc97c
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10
1
stashapp/stash:latest24dbd7607174
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
stashapp/stash-box:latesta534c8afdf39
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
statcan/ckan:2.93921305425b8
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
structurizr/onpremises:2025.11.094b5ffb5119c8
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
substratusai/verba:v0.4.0-baseURL261695be635eb
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
supabase/edge-runtime:v1.74.02781daf92394
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
supabase/edge-runtime:v1.59.0eff9c554d649
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
supabase/postgres-meta:v0.96.6a84cc713585e
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
supabase/postgres-meta:v0.84.2d0a96973e9f1
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
supabase/realtime:v2.102.3aa1c92c0cf32
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
supabase/realtime:v2.33.8d207e6e23ad3
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
supabase/studio:20241021-9f9b08326d8070c55e9
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
sysnet4admin/colosseum-agg:logbc25b152d88e
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed
1
sysnet4admin/colosseum-cms:loge74b43c7f492
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
tdengine/tdengine:3.0.2.24140a4021ddb
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
1
teknas09/bird-pod:latest12a1fa85c4aa
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.