StackRadar

CVE-2026-41989

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,959
of 17,790 indexed, latest versions
Container images
2,171
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libgcrypt security update

Carried by container images the latest versions of 1,959 of 17,790 indexed charts deploy, on 2,171 images.

Affected packageAffected versionsFixed inImages
libgcryptrpm1.8.3-2.el8, 1.8.3-4.el8, 1.8.5-4.el8, 1.8.5-6.el8+7 more0:1.8.5-8.el8_10, 0:1.10.0-13.el9_8, 1.11.0-150700.5.10.1, 1.12.1-160000.3.1379
libgcrypt20deb1.6.5-2ubuntu0.2, 1.6.5-2ubuntu0.3, 1.6.5-2ubuntu0.4, 1.6.5-2ubuntu0.5+18 more1.9.4-3ubuntu3.2, 1.10.1-3+deb12u1, 1.10.3-2ubuntu0.1, 1.11.0-7+deb13u1+4 more1,792
OSV records
RHSA-2026:47117RHSA-2026:50147RLSA-2026:47117RLSA-2026:50147DEBIAN-CVE-2026-41989UBUNTU-CVE-2026-41989ECHO-afba-f32f-e1d7SUSE-SU-2026:22826-1SUSE-SU-2026:3182-1
Also known as
RHSA-2026:52950, RHSA-2026:52952, RHSA-2026:52953, RHSA-2026:58977, RHSA-2026:58978, RHSA-2026:58979, USN-8319-1

Charts affected

1,959 by stars
ChartLatestAffected imagesRadar Score
zabbixcetic3.1.34 of 5See more

zabbix cetic 3.1.3

4 of the 5 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

33,928
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

4,310
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

6,562
stacks-blockchain-apihirosystemsVerified publisher6.5.12 of 5See more

stacks-blockchain-api hirosystems 6.5.1

2 of the 5 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

8,409
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

2,373
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

6,049
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

12,838
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

3,044
netbirdjaconiVerified publisher0.15.11 of 4See more

netbird jaconi 0.15.1

1 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
netbirdio/management:0.45.10c9994b393ea
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

8,567
litellm-helmlitellm1.101.01 of 2See more

litellm-helm litellm 1.101.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

4,991
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

5,293
oneuptimeoneuptimeOfficialVerified publisher13.0.51 of 7See more

oneuptime oneuptime 13.0.5

1 of the 7 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.73b94aa2f02cd
libgcrypt20@1.9.4-3ubuntu3.3
no fix listed

Open the chart page →

11,432
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

5,710
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

3,428
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

15,602
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

7,920
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10

Open the chart page →

6,853
glasskube-operatorglasskubeOfficialVerified publisher0.12.23 of 3See more

glasskube-operator glasskube 0.12.2

3 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

11,987
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

5,375
milvusmilvus-helm5.0.282 of 4See more

milvus milvus-helm 5.0.28

2 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
milvusdb/etcd:3.5.25-r1fededb2f2d63
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

10,782
prefect-serverprefectVerified publisher2026.9.141419101 of 2See more

prefect-server prefect 2026.9.14141910

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

5,556
rocketmqrocketmq12.6.02 of 2See more

rocketmq rocketmq 12.6.0

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

6,400
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

18,589
apicurio-registryapicurio-registry-helmVerified publisher3.8.01 of 2See more

apicurio-registry apicurio-registry-helm 3.8.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

6,675
bitbucketatlassian-data-centerVerified publisher2.0.151 of 1See more

bitbucket atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
atlassian/bitbucket:10.2.705933f2b1cfd
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

1,520
zookeepercloudpirates-zookeeperVerified publisher0.13.111 of 1See more

zookeeper cloudpirates-zookeeper 0.13.11

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5cab8944a33a1
libgcrypt20@1.9.4-3ubuntu3.3
no fix listed

Open the chart page →

2,966
codefreshcodefresh-onpremOfficialVerified publisher2.12.144 of 42See more

codefresh codefresh-onprem 2.12.14

4 of the 42 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
bitnamilegacy/rabbitmq:4.1.39e635efba431
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

15,093
contourcontour0.8.01 of 2See more

contour contour 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.38.4447f857a0146
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed

Open the chart page →

1,524
memgraphmemgraphVerified publisher1.0.71 of 2See more

memgraph memgraph 1.0.7

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
memgraph/memgraph:3.13.1bd3fe13228f4
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

1,214
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
stackstorm/st2api:3.86f56d239d280
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
stackstorm/st2auth:3.833ecfda16608
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
stackstorm/st2notifier:3.8f190a6212195
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
stackstorm/st2rulesengine:3.8259503496ff9
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
stackstorm/st2scheduler:3.8b1de2055c362
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
stackstorm/st2sensorcontainer:3.8b1a338f64773
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
stackstorm/st2stream:3.81c8904a3bf67
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
stackstorm/st2timersengine:3.81bf35bfaf00c
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
stackstorm/st2web:3.809989a26c8b7
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
stackstorm/st2workflowengine:3.819fdfffdbba8
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

96,933
supabasetokens-studioVerified publisher1.0.06 of 14See more

supabase tokens-studio 1.0.0

6 of the 14 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
library/kong:3.8.0712e407b20ea
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed
supabase/edge-runtime:v1.59.0eff9c554d649
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
supabase/postgres-meta:v0.84.2d0a96973e9f1
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
supabase/realtime:v2.33.8d207e6e23ad3
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
supabase/studio:20241021-9f9b08326d8070c55e9
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

23,365
polarisapache-polarisOfficialVerified publisher1.3.0-incubating1 of 1See more

polaris apache-polaris 1.3.0-incubating

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
apache/polaris:lateste66366e783f1
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

473
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

8,586
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

1,778
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

10,856
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

3,496
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

3,048
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

7,923
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

1,284
rabbitmqkubelauncherVerified publisher0.2.111 of 1See more

rabbitmq kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/rabbitmqdigest-pinnedff5a36a457f1
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

1,124
openclawopenclawVerified publisher1.91.31 of 2See more

openclaw openclaw 1.91.3

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

3,093
purelbpurelb0.0.0-106-ipv6-lbip-052cedab1 of 2See more

purelb purelb 0.0.0-106-ipv6-lbip-052cedab

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10

Open the chart page →

4,412
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

3,503
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
libgcrypt20@1.8.5-5ubuntu1
no fix listed

Open the chart page →

11,449
zillazillaOfficialVerified publisher2.4.21 of 1See more

zilla zilla 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/aklivity/zilla:2.4.289c4a2e74863
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed

Open the chart page →

1,740
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
libgcrypt20@1.11.0-7
1.11.0-7+deb13u1

Open the chart page →

2,962
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

4,284
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

3,041
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

4,641
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
quay.io/devtron/postgres:14.91b594392f7cb
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

33,180

Container images carrying it

2,171 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/aerokube/jumphost:1.0.170fd7c00418d
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
quay.io/aerokube/keygen:1.0.1578934444f04
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
1
quay.io/backube/volsync:0.16.00d03a6aad575
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
quay.io/camel-tooling/camel-dashboard-operator:latest5e867d01846e
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
1
quay.io/eclipse/che-operator:7.122.0d752a1c2a7b7
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
quay.io/everythingascode/apishift:v0.3.08fbbcd23b902
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10
1
quay.io/fiware/orion-ld:1.10.0b7ee7569a9a8
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
1
quay.io/fiware/tmforum-account:1.18.06b25aac03414
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/tmforum-product-inventory:1.18.03a5d6dd30f1d
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/tmforum-product-ordering-management:1.18.042c81c291f6f
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/tmforum-quote:1.18.0d9ca3a334352
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/tmforum-resource-catalog:1.18.0b0d853627c59
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/tmforum-resource-function-activation:1.18.062a5acb63fd1
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/tmforum-resource-inventory:1.18.0553b4a47730b
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/fiware/tmforum-resource-order-management:1.18.0dd1778ad6203
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.