StackRadar

CVE-2026-41989

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,944
of 17,790 indexed, latest versions
Container images
2,156
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libgcrypt security update

Carried by container images the latest versions of 1,944 of 17,790 indexed charts deploy, on 2,156 images.

Affected packageAffected versionsFixed inImages
libgcryptrpm1.8.3-2.el8, 1.8.3-4.el8, 1.8.5-4.el8, 1.8.5-6.el8+7 more0:1.8.5-8.el8_10, 0:1.10.0-13.el9_8, 1.11.0-150700.5.10.1, 1.12.1-160000.3.1378
libgcrypt20deb1.6.5-2ubuntu0.2, 1.6.5-2ubuntu0.3, 1.6.5-2ubuntu0.4, 1.6.5-2ubuntu0.5+18 more1.9.4-3ubuntu3.2, 1.10.1-3+deb12u1, 1.10.3-2ubuntu0.1, 1.11.0-7+deb13u1+4 more1,778
OSV records
RHSA-2026:47117RHSA-2026:50147RLSA-2026:47117RLSA-2026:50147DEBIAN-CVE-2026-41989UBUNTU-CVE-2026-41989ECHO-afba-f32f-e1d7SUSE-SU-2026:22826-1SUSE-SU-2026:3182-1
Also known as
RHSA-2026:52950, RHSA-2026:52952, RHSA-2026:52953, RHSA-2026:58977, RHSA-2026:58978, RHSA-2026:58979, USN-8319-1

Charts affected

1,944 by stars
ChartLatestAffected imagesRadar Score
grayloggroundhog2k0.13.101 of 1See more

graylog groundhog2k 0.13.10

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
graylog/graylog:7.1.9598bd41fefd5
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

1,112
ilumilumOfficialVerified publisher6.7.33 of 19See more

ilum ilum 6.7.3

3 of the 19 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
bitnamilegacy/postgresql:16233f361c5819
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
ilum/marquez:0.54.06e1d709d41f8
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

23,289
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

3,434
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

7,031
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
libgcrypt20@1.11.0-7
1.11.0-7+deb13u1

Open the chart page →

4,344
netris-controllernetrisai2.8.24 of 14See more

netris-controller netrisai 2.8.2

4 of the 14 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
netrisai/controller-grpc:4.6.0.00753178bf173c2
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
netrisai/controller-telescope:4.6.0.00414d82948a8b2
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
netrisai/controller-web-session-generator:0.2.0a030a31289f4
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

30,481
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

17,306
paperless-ngxpaperless-ngxVerified publisher0.3.221 of 3See more

paperless-ngx paperless-ngx 0.3.22

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

8,510
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
platform9community/api-gateway:latest40a4970de568
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
platform9community/customers-service:latest2089811e5cc6
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
platform9community/vets-service:latestd1165c94dfb3
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
platform9community/visits-service:latest8d11b50368c6
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

41,902
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

14,276
selenium3selenium31.2.41 of 1See more

selenium3 selenium3 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
libgcrypt20@1.8.5-5ubuntu1
no fix listed

Open the chart page →

11,831
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

7,333
plexutkuozdemirVerified publisher2.1.11 of 1See more

plex utkuozdemir 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
linuxserver/plex:1.25.24a13ced2326c
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

6,386
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

2,321
istio-operatorwiremindVerified publisher1.18.21 of 1See more

istio-operator wiremind 1.18.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
istio/operator:1.18.270f9d1fe5fff
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

5,669
zabbix-serveraekondratievVerified publisher1.0.63 of 4See more

zabbix-server aekondratiev 1.0.6

3 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

30,811
crowdatlassian-data-centerVerified publisher2.0.151 of 2See more

crowd atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
atlassian/crowd:7.2.3c81cc7d6bc9e
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

1,463
wazuh-agentavistoVerified publisher4.12.21 of 1See more

wazuh-agent avisto 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

6,484
awx-operatorawx-operator-helm3.2.11 of 2See more

awx-operator awx-operator-helm 3.2.1

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

9,868
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

12,163
cluster-secretclutersecretVerified publisher0.7.01 of 1See more

cluster-secret clutersecret 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

3,039
codercoderOfficialVerified publisher1.44.62 of 2See more

coder coder 1.44.6

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
coderenvs/coder-service:1.44.61deffc4670e6
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
coderenvs/timescale:1.44.676fd37fe6830
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

6,847
convoyconvoyVerified publisher3.7.132 of 3See more

convoy convoy 3.7.13

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

5,915
grayloggraylog2OfficialVerified publisher2.0.01 of 2See more

graylog graylog2 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
graylog/graylog-enterprise:7.1.88a1f641cd7aa
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

1,539
hasurahasura-extraVerified publisher3.0.11 of 1See more

hasura hasura-extra 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.34.0-ce0111b0204136
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

4,951
mongooseimmongoose0.4.111 of 1See more

mongooseim mongoose 0.4.11

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
erlangsolutions/mongooseim:6.6.0cc5bf032931f
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

1,302
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

8,685
nessienessie0.108.41 of 1See more

nessie nessie 0.108.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/projectnessie/nessie:0.108.4c0f42874c810
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

222
technitium-dnsserverobeoneVerified publisher1.13.01 of 1See more

technitium-dnsserver obeone 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
technitium/dns-server:15.4.0df7d90ef0f7b
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

1,225
passboltpassbolt2.1.14 of 6See more

passbolt passbolt 2.1.1

4 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
bitnamilegacy/redis-sentinel:8.2.1-debian-12-r00ca3ea1d2f82
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
library/mariadb:latestdd9b303aed4f
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

13,455
redis-enterprise-operatorredis-enterprise-operator-officialOfficialVerified publisher8.0.18-111 of 1See more

redis-enterprise-operator redis-enterprise-operator-official 8.0.18-11

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
redislabs/operator:8.0.18-119078e713bb6a
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

914
reposilitereposilite1.4.21 of 1See more

reposilite reposilite 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
dzikoysk/reposilite:3.6.390de4c8e6c0e
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

1,028
selenium-gridselenium-grid0.59.13 of 4See more

selenium-grid selenium-grid 0.59.1

3 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
selenium/hub:4.48.0-20260905d47c27474cb4
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11
selenium/node-chrome:4.48.0-202609055ac71fd8dd1e
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11
selenium/node-firefox:4.48.0-2026090574a5c1c90f95
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

7,168
mssqlserver-2022simcube1.2.31 of 1See more

mssqlserver-2022 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed

Open the chart page →

2,927
swo-k8s-collectorsolarwindsOfficialVerified publisher5.3.01 of 3See more

swo-k8s-collector solarwinds 5.3.0

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
solarwinds/solarwinds-otel-collector:0.152.3-k8s3c1110e8bdfb
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

2,347
thehivestrangebee-helmOfficialVerified publisher1.0.73See more

thehive strangebee-helm 1.0.7

3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

truenas-csptruenas-cspVerified publisher1.2.45 of 11See more

truenas-csp truenas-csp 1.2.4

5 of the 11 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/hpestorage/csi-driver:v3.2.0ef7f4e1544fa
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
quay.io/hpestorage/csi-extensions:v1.2.1189146672a7ac
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
quay.io/hpestorage/volume-group-provisioner:v1.0.107bf9d8f16a5d
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
quay.io/hpestorage/volume-group-snapshotter:v1.0.10caeaaffe7e2b
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
quay.io/hpestorage/volume-mutator:v1.3.109e98b2e697bd
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

5,851
uffizzi-controlleruffizzi-controller2.4.61 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

1 of the 11 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

14,266
abcdesktopabcdesktopOfficialVerified publisher4.4.121 of 9See more

abcdesktop abcdesktop 4.4.12

1 of the 9 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/abcdesktopio/mongo:safe8.0c4c1938a973b
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

806
openvpn-asas-helm-chartOfficialVerified publisher0.2.11 of 1See more

openvpn-as as-helm-chart 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
openvpn/openvpn-as:latest2253c10ec652
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

2,716
bambooatlassian-data-centerVerified publisher2.0.151 of 2See more

bamboo atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
atlassian/bamboo:12.1.114af4bb6c8d46
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

2,079
baserowbaserow-chartVerified publisher1.0.563 of 6See more

baserow baserow-chart 1.0.56

3 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
bitnamilegacy/redis:7.2.5-debian-12-r05261cae9e407
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

17,346
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
libgcrypt20@1.8.5-5ubuntu1
no fix listed
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
libgcrypt20@1.8.5-5ubuntu1
no fix listed

Open the chart page →

53,012
headwind-mdmchristianhuthVerified publisher5.10.22See more

headwind-mdm christianhuth 5.10.2

2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
headwindmdm/hmdm:0.1.93550b4840840
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed

Open the chart page →

dolibarrcowboysysopVerified publisher9.0.32 of 3See more

dolibarr cowboysysop 9.0.3

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
dolibarr/dolibarr:22.0.47ad88fc9b13c
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

9,154
daskhubdask2024.1.11 of 9See more

daskhub dask 2024.1.1

1 of the 9 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
pangeo/base-notebook:2024.01.155fbe688a4f80
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

14,134
seafiledatamateVerified publisher0.6.04 of 6See more

seafile datamate 0.6.0

4 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb-galera:11.4.3-debian-12-r0cb8beb6dbb58
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
bitnamilegacy/memcached:1.6.29-debian-12-r4ff0e7239c17c
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
datamate/seafile-professional:11.0.202dd66b722464
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

27,358
plexgabe565Verified publisher0.5.11 of 1See more

plex gabe565 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:version-1.41.4.9463-630c9f557e6d2775e77ec
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

2,578
geonode-k8sgeonode-k8sVerified publisher2.0.03 of 10See more

geonode-k8s geonode-k8s 2.0.0

3 of the 10 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
geopython/pycsw:3.0.0-beta284662ea6b78b
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
library/redis:8.4.03906b477e4b6
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

14,043
glpiglpi-conteiner0.1.02 of 3See more

glpi glpi-conteiner 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/mariadb:latestdd9b303aed4f
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
vdiogov/glpi-conteiner:latest6945f84f0058
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

12,270

Container images carrying it

2,156 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10
1
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10
1
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
1
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/enderdash-com/enderdash-agent:latest8525a1a67958
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
libgcrypt20@1.11.0-7
1.11.0-7+deb13u1
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/flanksource/mission-control-ai-assistant:1.0.1229a635cbeeb5
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
libgcrypt20@1.11.0-7
1.11.0-7+deb13u1
1
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
ghcr.io/grafana/alloy-operator:1.12.14ee4b71cf16a
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
ghcr.io/grycap/im:latest06a16d4f279f
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
ghcr.io/hemslo/chat-search:latest39d48995a5bd
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.