StackRadar

CVE-2026-41989

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,953
of 17,803 indexed, latest versions
Container images
2,164
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libgcrypt security update

Carried by container images the latest versions of 1,953 of 17,803 indexed charts deploy, on 2,164 images.

Affected packageAffected versionsFixed inImages
libgcryptrpm1.8.3-2.el8, 1.8.3-4.el8, 1.8.5-4.el8, 1.8.5-6.el8+7 more0:1.8.5-8.el8_10, 0:1.10.0-13.el9_8, 1.11.0-150700.5.10.1, 1.12.1-160000.3.1378
libgcrypt20deb1.6.5-2ubuntu0.2, 1.6.5-2ubuntu0.3, 1.6.5-2ubuntu0.4, 1.6.5-2ubuntu0.5+18 more1.9.4-3ubuntu3.2, 1.10.1-3+deb12u1, 1.10.3-2ubuntu0.1, 1.11.0-7+deb13u1+4 more1,786
OSV records
RHSA-2026:47117RHSA-2026:50147RLSA-2026:47117RLSA-2026:50147DEBIAN-CVE-2026-41989UBUNTU-CVE-2026-41989ECHO-afba-f32f-e1d7SUSE-SU-2026:22826-1SUSE-SU-2026:3182-1
Also known as
RHSA-2026:52950, RHSA-2026:52952, RHSA-2026:52953, RHSA-2026:58977, RHSA-2026:58978, RHSA-2026:58979, USN-8319-1

Charts affected

1,953 by stars
ChartLatestAffected imagesRadar Score
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

3,697
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

9,272
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed

Open the chart page →

7,936

Container images carrying it

2,164 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
tensorflow/serving:latest8a208c232297
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
libgcrypt20@1.6.5-2ubuntu0.3
no fix listed
1
testinprod/op-erigon:latest0a125bd77a2d
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
thecampagnards/trafficlight-api:main7dca9d973837
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
themoah/klag:0.2.16610579160052
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11
1
theradius/loggia:0.463ba348546ec
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
thesisrobot/bitcoind:v23.016b368e4d52c
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
thingsboard/tb-postgres:latest2d17e4e36edc
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
thmmniii/fbs-core:v1.27.15438517d9fc2
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
thongngo3301/stakefish:latesta341af5976e3
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
tibyandocker/serviceexample:latesta4ad592cea84
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
timescale/timescaledb-ha:pg16d7db8f1085a3
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libgcrypt20@1.6.5-2ubuntu0.3
no fix listed
1
tpdock/freeradius:2.2.93da600c95a49
libgcrypt20@1.6.5-2ubuntu0.3
no fix listed
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
trinodb/trino:45038c6f24ab1a4
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8
1
trinodb/trino:405ee80ab5eeab2
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
trueosiris/vrising:latest9356f98ad561
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
typesense/typesense:0.25.1035ccfbc3fd8
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
typesense/typesense:0.23.03accb727cbe2
libgcrypt20@1.6.5-2ubuntu0.6
no fix listed
1
typesense/typesense:30.191604dc128e2
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
typesense/typesense:28.0.rc35dea1b62b7b6e
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
ubuntu/squid:5.2-22.04_beta723891b5bc74
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
unitbuilds/velocity-workflow:1.0.0f85a34f5bb28
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
v3xl/kubesend:0.1.06f62ca96be82
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
valkey/valkey:8.0.1c5d4f082b76d
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
vaultwarden/server:1.34.384fd8a47f58d
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
vcnngr/telegram-login:latest1a849a997b6d
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
vcnngr/telegram-rebot:latest30f1f05e57a6
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
veecode/devportala72cf5cb47b8
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
venturenox/redis:latest83b471c193ba
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
vexorian/dizquetv:1.4.37e2b99844a5c
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
vlebediantsev/notes-admin-front:latest007c6670ff48
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
vlebediantsev/notes-project-front:latest945675fd2636
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
voltha/bbsim:1.16.7d90403d58016
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.