StackRadar

CVE-2026-41989

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,955
of 17,797 indexed, latest versions
Container images
2,167
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libgcrypt security update

Carried by container images the latest versions of 1,955 of 17,797 indexed charts deploy, on 2,167 images.

Affected packageAffected versionsFixed inImages
libgcryptrpm1.8.3-2.el8, 1.8.3-4.el8, 1.8.5-4.el8, 1.8.5-6.el8+7 more0:1.8.5-8.el8_10, 0:1.10.0-13.el9_8, 1.11.0-150700.5.10.1, 1.12.1-160000.3.1378
libgcrypt20deb1.6.5-2ubuntu0.2, 1.6.5-2ubuntu0.3, 1.6.5-2ubuntu0.4, 1.6.5-2ubuntu0.5+18 more1.9.4-3ubuntu3.2, 1.10.1-3+deb12u1, 1.10.3-2ubuntu0.1, 1.11.0-7+deb13u1+4 more1,789
OSV records
RHSA-2026:47117RHSA-2026:50147RLSA-2026:47117RLSA-2026:50147DEBIAN-CVE-2026-41989UBUNTU-CVE-2026-41989ECHO-afba-f32f-e1d7SUSE-SU-2026:22826-1SUSE-SU-2026:3182-1
Also known as
RHSA-2026:52950, RHSA-2026:52952, RHSA-2026:52953, RHSA-2026:58977, RHSA-2026:58978, RHSA-2026:58979, USN-8319-1

Charts affected

1,955 by stars
ChartLatestAffected imagesRadar Score
devtron-enterprisedevtron-labs48.0.08 of 28See more

devtron-enterprise devtron-labs 48.0.0

8 of the 28 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
libgcrypt20@1.6.5-2ubuntu0.6
no fix listed
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
quay.io/devtron/postgres:14.91b594392f7cb
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

68,765
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

4,979
devtron-operatordevtron-labs0.23.35 of 11See more

devtron-operator devtron-labs 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
quay.io/devtron/postgres:14.91b594392f7cb
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

33,219
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
libgcrypt20@1.8.5-5ubuntu1
no fix listed

Open the chart page →

11,981
migration-incluster-cddevtron-labs0.10.01 of 1See more

migration-incluster-cd devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

3,927
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.03 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
library/rabbitmq:3-managemente582c0bc7766
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
oscarsotosanchez/weatherservice:v1.0911ec961d10b
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

27,676
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

4,083
difydify1.0.03 of 4See more

dify dify 1.0.0

3 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
langgenius/dify-plugin-daemon:main-localda995c129e2f
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
langgenius/dify-sandbox:0.2.009b7e8705673
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

19,513
pagesdipak1.0.02 of 3See more

pages dipak 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libgcrypt20@1.8.5-5ubuntu1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

20,262
alertifydjjudas21Verified publisher0.1.01 of 1See more

alertify djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
djjudas21/alertify:0.1.0ba22be670c37
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

2,402
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

7,322
ownclouddjjudas21Verified publisher0.3.232 of 3See more

owncloud djjudas21 0.3.23

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
owncloud/server:10.16.3b3f9efdcd7f7
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed

Open the chart page →

10,199
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

17,129
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

14,713
dnation-kubernetes-jsonnet-translatordnationcloud2.0.11 of 1See more

dnation-kubernetes-jsonnet-translator dnationcloud 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

3,845
dnation-kubernetes-monitoringdnationcloud3.0.21 of 1See more

dnation-kubernetes-monitoring dnationcloud 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

3,845
dnation-kubernetes-monitoring-stackdnationcloud4.0.23 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

3 of the 17 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

21,767
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
libgcrypt20@1.8.1-4ubuntu1.1
no fix listed

Open the chart page →

9,003
dominodomino-iisasVerified publisher0.3.12 of 3See more

domino domino-iisas 0.3.1

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
libgcrypt20@1.11.0-7
1.11.0-7+deb13u1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

10,393
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

3,195
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

24,986
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
libgcrypt20@1.8.5-5ubuntu1
no fix listed

Open the chart page →

11,848
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.03 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
library/rabbitmq:3-managemente582c0bc7766
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
oscarsotosanchez/weatherservice:v1.0911ec961d10b
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

24,781
drogue-cloud-coredrogue-iotVerified publisher0.7.1120 of 22See more

drogue-cloud-core drogue-iot 0.7.11

20 of the 22 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
libgcrypt@1.10.0-8.el9_0
0:1.10.0-13.el9_8
quay.io/keycloak/keycloak:20.0054ef67eb7da
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

55,991
drogue-cloud-examplesdrogue-iotVerified publisher0.7.114 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

4 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
ghcr.io/ctron/kubectl:1.25e37d61b5277c
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10

Open the chart page →

30,778
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

6,916
duckdb-uiduckdb-ui0.5.21 of 1See more

duckdb-ui duckdb-ui 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

4,465
postgres-backup-localduck-helm0.1.51 of 1See more

postgres-backup-local duck-helm 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:latestf70742ebe42b
libgcrypt20@1.11.0-7
1.11.0-7+deb13u1

Open the chart page →

3,490
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
libgcrypt20@1.6.5-2ubuntu0.6
no fix listed

Open the chart page →

19,859
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

9,364
base-consensusdysnixVerified publisher0.2.01 of 1See more

base-consensus dysnix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/base/node-reth:v1.1.18eb6e492fe3c
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

1,768
bitcoinddysnixVerified publisher0.4.31 of 2See more

bitcoind dysnix 0.4.3

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

1,987
gcp-local-nvme-raiddysnixVerified publisher0.2.01 of 2See more

gcp-local-nvme-raid dysnix 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/ubuntu:24.0433ceb71981b6
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

688
gcp-local-ssd-raiddysnixVerified publisher0.1.71 of 2See more

gcp-local-ssd-raid dysnix 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

2,417
rethdysnixVerified publisher0.0.111 of 2See more

reth dysnix 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/paradigmxyz/reth:v2.2.0505fca5e87d6
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

1,082
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

4,623
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
libgcrypt20@1.11.0-7
1.11.0-7+deb13u1

Open the chart page →

13,613
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10

Open the chart page →

11,483
orion-ldeclipse-aeriosVerified publisher1.0.02 of 2See more

orion-ld eclipse-aerios 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
fiware/orion-ld:1.10.03c490a746f65
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
library/mongo:7.0.12ae1cf99fa7bf
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

9,815
self-orchestratoreclipse-aeriosVerified publisher1.2.01 of 1See more

self-orchestrator eclipse-aerios 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
eclipseaerios/self-orchestrator:1.2.08b123bec5679
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

2,416
marblerunedgelesssysVerified publisher1.9.21 of 1See more

marblerun edgelesssys 1.9.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed

Open the chart page →

1,860
marblerun-coordinatoredgelesssysVerified publisher0.5.01 of 1See more

marblerun-coordinator edgelesssys 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

11,019
pagesedgwarepages1.0.02 of 3See more

pages edgwarepages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libgcrypt20@1.8.5-5ubuntu1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

20,262
deploy-elibraryeducative-helm-bookapp0.5.01 of 1See more

deploy-elibrary educative-helm-bookapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

5,163
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

7,407
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

30,529
egeria-baseegeria-charts4.3.01 of 5See more

egeria-base egeria-charts 4.3.0

1 of the 5 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

4,047
egeria-ctsegeria-charts4.3.01 of 3See more

egeria-cts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

4,034
egeria-ptsegeria-charts4.3.01 of 3See more

egeria-pts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

4,034
odpi-egeria-labegeria-charts4.3.01 of 4See more

odpi-egeria-lab egeria-charts 4.3.0

1 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

4,034

Container images carrying it

2,167 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
quay.io/maximilianopizarro/nfl-api-bills:1.0.1b596a4687bb0
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/maximilianopizarro/nfl-wallet-api-customers:1.0.1d50c80a85b35
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/maximilianopizarro/nfl-wallet-api-raiders:1.0.1f9c71dc2bc5f
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
libgcrypt@1.8.3-4.el8
0:1.8.5-8.el8_10
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
quay.io/minio/directpv:v4.0.84560083eb77d
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
quay.io/mittwald/kube-mail:latest04f1099241fc
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
libgcrypt20@1.6.5-2ubuntu0.6
no fix listed
1
quay.io/mongodb/mongodb-enterprise-operator-ubi:1.33.0b05101723412
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
1
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/netobserv/network-observability-operator:1.12.0-communityb05d21a015b0
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
quay.io/nmstate/kubernetes-nmstate-operator:v0.87.04dce694f01ea
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
quay.io/open-cluster-management/multicluster-controlplane:latest9888240f644b
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/openshift/origin-cli:4.66722d5041b47
libgcrypt@1.8.3-4.el8
0:1.8.5-8.el8_10
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
libgcrypt@1.8.3-4.el8
0:1.8.5-8.el8_10
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/projectquay/clair:4.9.023329c3368e4
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8
1
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
quay.io/strimzi/operator:0.45.158c727cd2e68
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.