StackRadar

CVE-2026-41989

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,953
of 17,803 indexed, latest versions
Container images
2,164
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libgcrypt security update

Carried by container images the latest versions of 1,953 of 17,803 indexed charts deploy, on 2,164 images.

Affected packageAffected versionsFixed inImages
libgcryptrpm1.8.3-2.el8, 1.8.3-4.el8, 1.8.5-4.el8, 1.8.5-6.el8+7 more0:1.8.5-8.el8_10, 0:1.10.0-13.el9_8, 1.11.0-150700.5.10.1, 1.12.1-160000.3.1378
libgcrypt20deb1.6.5-2ubuntu0.2, 1.6.5-2ubuntu0.3, 1.6.5-2ubuntu0.4, 1.6.5-2ubuntu0.5+18 more1.9.4-3ubuntu3.2, 1.10.1-3+deb12u1, 1.10.3-2ubuntu0.1, 1.11.0-7+deb13u1+4 more1,786
OSV records
RHSA-2026:47117RHSA-2026:50147RLSA-2026:47117RLSA-2026:50147DEBIAN-CVE-2026-41989UBUNTU-CVE-2026-41989ECHO-afba-f32f-e1d7SUSE-SU-2026:22826-1SUSE-SU-2026:3182-1
Also known as
RHSA-2026:52950, RHSA-2026:52952, RHSA-2026:52953, RHSA-2026:58977, RHSA-2026:58978, RHSA-2026:58979, USN-8319-1

Charts affected

1,953 by stars
ChartLatestAffected imagesRadar Score
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

3,697
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

9,272
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed

Open the chart page →

7,936

Container images carrying it

2,164 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/astriaorg/auctioneer:pr-18391386b7b5e555
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/astriaorg/conductor:1.1.01f97d131b1d1
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/astriaorg/evm-bridge-withdrawer:1.0.29c88e1aff357
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/astriaorg/hermes:0.5.04f33a0a9f75e
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
ghcr.io/astriaorg/sequencer:latest44f82ee0b24c
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/astriaorg/sequencer-relayer:latest5f6c74993f08
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/atuinsh/atuin:18.12.0e953fa9e36ef
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/base/node-reth:v1.1.18eb6e492fe3c
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/blockscout/smart-contract-verifier:main9a43f0cc5797
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
1
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
ghcr.io/caninehq/canine:latesta058034ca006
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.7.211cdbbc479b3
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.0e7f9e8f1d565
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/chmouel/gosmee:v0.32.060b8db1f68cc
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
ghcr.io/cleanuparr/cleanuparr:2.10.68136c3beda7a
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11
1
ghcr.io/cobbler/cobbler-tftp:v0.1.0a7fef3ca80baa4
libgcrypt@1.12.1-160000.1.1
1.12.1-160000.3.1
1
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/containers/kubernetes-mcp-server:v0.0.666d650f4bd6ac
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
libgcrypt20@1.11.0-7
1.11.0-7+deb13u1
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/ctfd/ctfd:3.8.2870e396fddf8
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10
1
ghcr.io/ctron/kubectl:1.25e37d61b5277c
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
1
ghcr.io/damap-org/damap-backend:5.0.0f3d0c7d35498
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
ghcr.io/dask/dask:2024.1.0080150de7d86
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
libgcrypt20@1.11.0-7
1.11.0-7+deb13u1
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.