StackRadar

CVE-2026-41989

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,955
of 17,797 indexed, latest versions
Container images
2,167
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libgcrypt security update

Carried by container images the latest versions of 1,955 of 17,797 indexed charts deploy, on 2,167 images.

Affected packageAffected versionsFixed inImages
libgcryptrpm1.8.3-2.el8, 1.8.3-4.el8, 1.8.5-4.el8, 1.8.5-6.el8+7 more0:1.8.5-8.el8_10, 0:1.10.0-13.el9_8, 1.11.0-150700.5.10.1, 1.12.1-160000.3.1378
libgcrypt20deb1.6.5-2ubuntu0.2, 1.6.5-2ubuntu0.3, 1.6.5-2ubuntu0.4, 1.6.5-2ubuntu0.5+18 more1.9.4-3ubuntu3.2, 1.10.1-3+deb12u1, 1.10.3-2ubuntu0.1, 1.11.0-7+deb13u1+4 more1,789
OSV records
RHSA-2026:47117RHSA-2026:50147RLSA-2026:47117RLSA-2026:50147DEBIAN-CVE-2026-41989UBUNTU-CVE-2026-41989ECHO-afba-f32f-e1d7SUSE-SU-2026:22826-1SUSE-SU-2026:3182-1
Also known as
RHSA-2026:52950, RHSA-2026:52952, RHSA-2026:52953, RHSA-2026:58977, RHSA-2026:58978, RHSA-2026:58979, USN-8319-1

Charts affected

1,955 by stars
ChartLatestAffected imagesRadar Score
oaisimopencord0.1.72 of 3See more

oaisim opencord 0.1.7

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

14,574
omec-control-planeopencord0.1.315 of 8See more

omec-control-plane opencord 0.1.31

5 of the 8 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
omecproject/c3po-hss:master-latest638671ef4842
libgcrypt20@1.6.5-2ubuntu0.6
no fix listed
omecproject/c3po-hssdb:master-latest28a90cc26716
libgcrypt20@1.8.5-5ubuntu1
no fix listed
omecproject/mme-exporter:paging-latestbcc5f19fd676
libgcrypt20@1.8.1-4ubuntu1.1
no fix listed
omecproject/ngic-cp:central-cp-multi-upfs-latest24a389a0a4fe
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
omecproject/openmme:master-latest64776cb9edb3
libgcrypt20@1.6.5-2ubuntu0.6
no fix listed

Open the chart page →

40,941
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
libgcrypt20@1.8.1-4ubuntu1.1
no fix listed

Open the chart page →

12,953
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
libgcrypt20@1.6.5-2ubuntu0.3
no fix listed

Open the chart page →

38,966
ovspluginopencord1.0.21 of 1See more

ovsplugin opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gopinatht/ovs-plugin-installer:latest632cb2e9c399
libgcrypt20@1.6.5-2ubuntu0.4
no fix listed

Open the chart page →

4,180
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed

Open the chart page →

12,646
sebaopencord1.0.05 of 17See more

seba opencord 1.0.0

5 of the 17 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
tpdock/freeradius:2.2.93da600c95a49
libgcrypt20@1.6.5-2ubuntu0.3
no fix listed
voltha/voltha-cli:1.6.0c4e41e92f046
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
voltha/voltha-netconf:1.6.037f80524c207
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
voltha/voltha-ofagent:1.6.09ee8c1f4428c
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
voltha/voltha-voltha:1.6.0ff596b62de59
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed

Open the chart page →

94,117
voltha-infraopencord2.14.04 of 10See more

voltha-infra opencord 2.14.0

4 of the 10 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
library/ubuntu:16.041f1a2d56de1d
libgcrypt20@1.6.5-2ubuntu0.6
no fix listed
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
voltha/voltha-onos:5.1.8e038acb950d3
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

41,148
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

11,064
dokuopenlit0.1.41 of 3See more

doku openlit 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latestfa394da808cc
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed

Open the chart page →

1,744
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.4.12e6587b81a26
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

5,083
minioopenobserve5.0.72 of 2See more

minio openobserve 5.0.7

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

7,472
openpanelopenpanel0.9.01 of 6See more

openpanel openpanel 0.9.0

1 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

3,472
llm-stackopenproject-helm-chartsVerified publisher1.1.01 of 2See more

llm-stack openproject-helm-charts 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
apache/apisix:3.16.0-ubuntu5e47692cac00
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

2,009
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

12,185
alquimia-studioopenshift0.2.01 of 1See more

alquimia-studio openshift 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
alquimiaai/studio:certification38a1f0341982
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

2,388
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
andrianrf/backoffice-be:latest6036614803d4
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8
andrianrf/iso-server:latest7da47f525c7d
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8

Open the chart page →

35,119
canvas-oamportalopenshift4.0.01 of 1See more

canvas-oamportal openshift 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/oam:4.0.0ed8fd2062548
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

7,519
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8

Open the chart page →

19,093
dify-enterpriseopenshift3.9.810 of 13See more

dify-enterprise openshift 3.9.8

10 of the 13 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
langgenius/dify-ee-audit:3.9.8-ubi9e99aed151fc5
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-collector:3.9.8-ubi9a9b91fd62c94
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-enterprise:3.9.8-ubi9c392a36a4ef7
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-gateway:3.9.8-ubi99e314c29a61f
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-plugin-crd:3.9.8-ubi96f4e0e5f6e5a
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-plugin-manager:3.9.8-ubi9207b343013a0
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

4,903
exporteropenshift1.0.473 of 3See more

exporter openshift 1.0.47

3 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

13,041
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/mariadb:11.4611a2fcc5fa7
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

7,889
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

9,979
fsmopenshift0.1.8-ubi.66 of 6See more

fsm openshift 0.1.8-ubi.6

6 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/toolbox-ubi8:1.2.01f5e3161cb84
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

16,563
harikubeopenshift0.16.31 of 3See more

harikube openshift 0.16.3

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

2,566
kb-cloud-installeropenshift2.1.351 of 1See more

kb-cloud-installer openshift 2.1.35

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

4,170
kite-agentopenshift1.0.01 of 1See more

kite-agent openshift 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

5,863
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi87 of 7See more

osm-edge openshift 1.2.1-ubi8

7 of the 7 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

19,471
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8

Open the chart page →

8,643
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

13,612
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

11,741
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

13,574
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

13,557
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

13,461
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

13,105
openshift-integration-operatoropenshift-integration-operatorVerified publisher0.8.21 of 2See more

openshift-integration-operator openshift-integration-operator 0.8.2

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

2,063
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

15,622
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

36,335
opslevelopslevelVerified publisher2025.1.221 of 10See more

opslevel opslevel 2025.1.22

1 of the 10 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

5,658
hiveopstty0.1.91 of 4See more

hive opstty 0.1.9

1 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

4,569
grrosdfir-infrastructureVerified publisher1.0.32 of 5See more

grr osdfir-infrastructure 1.0.3

2 of the 5 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/mariadb:11.3.2e101f9db3191
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

11,020
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.020 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

20 of the 40 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/git:latest4b08d0c5af8d
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
library/mariadb:11.3.2e101f9db3191
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

72,857
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

3,679
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

3,335
k3p2p-avs0.1.51 of 2See more

k3 p2p-avs 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

2,351
mishtip2p-avs0.1.01 of 2See more

mishti p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

4,052
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

12,426
ungatep2p-avs0.1.03 of 3See more

ungate p2p-avs 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

27,579
p4p40.1.06 of 7See more

p4 p4 0.1.0

6 of the 7 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
library/mongo:5.0-focal5e15a3f014ed
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
library/rabbitmq:3.11-managementc3f70098e01d
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
mastercloudapps/planner:v1.2340a950b311b2
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
mastercloudapps/server:v2.23f3d24dfe2686
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
mastercloudapps/weatherservice:v1.23de859d29c116
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

27,784

Container images carrying it

2,167 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
vlebediantsev/notes-project-front:latest945675fd2636
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
voltha/bbsim:1.16.7d90403d58016
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
1
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
1
voltha/bbsim-sadis-server:0.4.0762b272d439e
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
1
voltha/voltha-cli:1.6.0c4e41e92f046
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
1
voltha/voltha-netconf:1.6.037f80524c207
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
1
voltha/voltha-onos:5.1.8e038acb950d3
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
voltha/voltha-tester:1.7.0655c3048a602
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
1
voltha/voltha-voltha:1.6.0ff596b62de59
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
1
wallarm/api-gateway:0.2.0a3d4d2f780e8
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
wasmcloud/wasmcloud:0.81.05c7acfe7e8e1
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
wateim/lighthouse-launch:latest2520149ee574
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
wavefronthq/proxy:9.2d1064d28f6eb
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
wazuh/wazuh-dashboard:4.4.11787550d2358
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
wazuh/wazuh-manager:4.4.121994f40e0da
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
wekanteam/wekan:v4.2268a51f0327df
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
wger/server:2.6997ead43aabd
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
wistefan/mvf:lateste0887302b2d8
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
wolveix/satisfactory-server:v1.9.1199be1064b18
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
wolveix/satisfactory-server:v1.9.9464d11e36e10
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
woojoong/wowza:latestec230db19652
libgcrypt20@1.8.1-4ubuntu1.1
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
worthnl/notifynl-omc:2.2.009fca4ed1c71
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11
1
xeladock/mysql_dns:latest4baf531453f1
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
xeladock/nginx2:latestc259a67b1dff
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
xeotek/kadeck:6.3.439a3b37a17c5
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
xeotek/kadeck:4.2.94c6b04d9ce55
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
libgcrypt20@1.6.5-2ubuntu0.6
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
yandex/clickhouse-client:21.3863f94a0f607
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
1
yandex/clickhouse-server:latest1cbf75aabe1e
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
yandex/clickhouse-server:21.3.204eccfffb01d7
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
yandex/clickhouse-server:19.17ab1738a64b70
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
yandex/clickhouse-server:19.14ccf9c2b5e3f2
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
yandex/clickhouse-server:19.16d210dc69321e
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
youkadev/api-snap:0.1.14db0f9428e67
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.