StackRadar

CVE-2026-41989

High

Advisory

Published 23 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,959
of 17,787 indexed, latest versions
Container images
2,170
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libgcrypt security update

Carried by container images the latest versions of 1,959 of 17,787 indexed charts deploy, on 2,170 images.

Affected packageAffected versionsFixed inImages
libgcryptrpm1.8.3-2.el8, 1.8.3-4.el8, 1.8.5-4.el8, 1.8.5-6.el8+7 more0:1.8.5-8.el8_10, 0:1.10.0-13.el9_8, 1.11.0-150700.5.10.1, 1.12.1-160000.3.1379
libgcrypt20deb1.6.5-2ubuntu0.2, 1.6.5-2ubuntu0.3, 1.6.5-2ubuntu0.4, 1.6.5-2ubuntu0.5+18 more1.9.4-3ubuntu3.2, 1.10.1-3+deb12u1, 1.10.3-2ubuntu0.1, 1.11.0-7+deb13u1+4 more1,791
OSV records
RHSA-2026:47117RHSA-2026:50147RLSA-2026:47117RLSA-2026:50147DEBIAN-CVE-2026-41989UBUNTU-CVE-2026-41989ECHO-afba-f32f-e1d7SUSE-SU-2026:22826-1SUSE-SU-2026:3182-1
Also known as
RHSA-2026:52950, RHSA-2026:52952, RHSA-2026:52953, RHSA-2026:58977, RHSA-2026:58978, RHSA-2026:58979, USN-8319-1

Charts affected

1,959 by stars
ChartLatestAffected imagesRadar Score
freeradiusopencord1.0.41 of 1See more

freeradius opencord 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

15,722
mcord-cdn-remoteopencord0.1.62 of 2See more

mcord-cdn-remote opencord 0.1.6

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
woojoong/wowza:latestec230db19652
libgcrypt20@1.8.1-4ubuntu1.1
no fix listed

Open the chart page →

42,662
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed

Open the chart page →

29,158
mcord-control-planeopencord0.2.22 of 5See more

mcord-control-plane opencord 0.2.2

2 of the 5 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
libgcrypt20@1.8.1-4ubuntu1
no fix listed

Open the chart page →

15,660
oaisimopencord0.1.72 of 3See more

oaisim opencord 0.1.7

2 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

14,550
omec-control-planeopencord0.1.315 of 8See more

omec-control-plane opencord 0.1.31

5 of the 8 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
omecproject/c3po-hss:master-latest638671ef4842
libgcrypt20@1.6.5-2ubuntu0.6
no fix listed
omecproject/c3po-hssdb:master-latest28a90cc26716
libgcrypt20@1.8.5-5ubuntu1
no fix listed
omecproject/mme-exporter:paging-latestbcc5f19fd676
libgcrypt20@1.8.1-4ubuntu1.1
no fix listed
omecproject/ngic-cp:central-cp-multi-upfs-latest24a389a0a4fe
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
omecproject/openmme:master-latest64776cb9edb3
libgcrypt20@1.6.5-2ubuntu0.6
no fix listed

Open the chart page →

40,795
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
libgcrypt20@1.8.1-4ubuntu1.1
no fix listed

Open the chart page →

12,939
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
libgcrypt20@1.6.5-2ubuntu0.3
no fix listed

Open the chart page →

38,889
ovspluginopencord1.0.21 of 1See more

ovsplugin opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gopinatht/ovs-plugin-installer:latest632cb2e9c399
libgcrypt20@1.6.5-2ubuntu0.4
no fix listed

Open the chart page →

4,170
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed

Open the chart page →

12,631
sebaopencord1.0.05 of 17See more

seba opencord 1.0.0

5 of the 17 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
tpdock/freeradius:2.2.93da600c95a49
libgcrypt20@1.6.5-2ubuntu0.3
no fix listed
voltha/voltha-cli:1.6.0c4e41e92f046
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
voltha/voltha-netconf:1.6.037f80524c207
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
voltha/voltha-ofagent:1.6.09ee8c1f4428c
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed
voltha/voltha-voltha:1.6.0ff596b62de59
libgcrypt20@1.6.5-2ubuntu0.5
no fix listed

Open the chart page →

93,965
voltha-infraopencord2.14.04 of 10See more

voltha-infra opencord 2.14.0

4 of the 10 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed
library/ubuntu:16.041f1a2d56de1d
libgcrypt20@1.6.5-2ubuntu0.6
no fix listed
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
libgcrypt20@1.8.1-4ubuntu1.3
no fix listed
voltha/voltha-onos:5.1.8e038acb950d3
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

41,088
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

11,003
dokuopenlit0.1.41 of 3See more

doku openlit 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latestfa394da808cc
libgcrypt20@1.9.4-3ubuntu3.2
no fix listed

Open the chart page →

1,735
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.4.12e6587b81a26
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed

Open the chart page →

5,056
minioopenobserve5.0.72 of 2See more

minio openobserve 5.0.7

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

7,457
openpanelopenpanel0.9.01 of 6See more

openpanel openpanel 0.9.0

1 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

3,462
llm-stackopenproject-helm-chartsVerified publisher1.1.01 of 2See more

llm-stack openproject-helm-charts 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
apache/apisix:3.16.0-ubuntu5e47692cac00
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1

Open the chart page →

1,977
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

11,795
alquimia-studioopenshift0.2.01 of 1See more

alquimia-studio openshift 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
alquimiaai/studio:certification38a1f0341982
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

2,386
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
andrianrf/backoffice-be:latest6036614803d4
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8
andrianrf/iso-server:latest7da47f525c7d
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8

Open the chart page →

34,721
canvas-oamportalopenshift4.0.01 of 1See more

canvas-oamportal openshift 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/oam:4.0.0ed8fd2062548
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

7,519
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8

Open the chart page →

18,991
dify-enterpriseopenshift3.9.810 of 13See more

dify-enterprise openshift 3.9.8

10 of the 13 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
langgenius/dify-ee-audit:3.9.8-ubi9e99aed151fc5
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-collector:3.9.8-ubi9a9b91fd62c94
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-enterprise:3.9.8-ubi9c392a36a4ef7
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-gateway:3.9.8-ubi99e314c29a61f
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-plugin-crd:3.9.8-ubi96f4e0e5f6e5a
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-plugin-manager:3.9.8-ubi9207b343013a0
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

4,846
exporteropenshift1.0.473 of 3See more

exporter openshift 1.0.47

3 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

13,034
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/mariadb:11.4611a2fcc5fa7
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

7,848
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

9,968
fsmopenshift0.1.8-ubi.66 of 6See more

fsm openshift 0.1.8-ubi.6

6 of the 6 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/toolbox-ubi8:1.2.01f5e3161cb84
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

16,554
harikubeopenshift0.16.31 of 3See more

harikube openshift 0.16.3

1 of the 3 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

2,543
kb-cloud-installeropenshift2.1.351 of 1See more

kb-cloud-installer openshift 2.1.35

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

4,145
kite-agentopenshift1.0.01 of 1See more

kite-agent openshift 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

5,863
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi87 of 7See more

osm-edge openshift 1.2.1-ubi8

7 of the 7 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

19,449
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
libgcrypt@1.10.0-10.el9_2
0:1.10.0-13.el9_8

Open the chart page →

8,634
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

13,608
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

11,740
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

13,570
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

13,553
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

13,457
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

13,101
openshift-integration-operatoropenshift-integration-operatorVerified publisher0.8.21 of 2See more

openshift-integration-operator openshift-integration-operator 0.8.2

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8

Open the chart page →

2,063
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

15,607
openvscode-serveropenvscode-server-helmVerified publisher2.7.371 of 2See more

openvscode-server openvscode-server-helm 2.7.37

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
antiantiops/vscode-browser-docker:1.137.0eeff80a99d92
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

4,284
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
libgcrypt20@1.8.1-4ubuntu1.2
no fix listed

Open the chart page →

36,230
opslevelopslevelVerified publisher2025.1.221 of 10See more

opslevel opslevel 2025.1.22

1 of the 10 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10

Open the chart page →

5,609
hiveopstty0.1.91 of 4See more

hive opstty 0.1.9

1 of the 4 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

4,539
grrosdfir-infrastructureVerified publisher1.0.32 of 5See more

grr osdfir-infrastructure 1.0.3

2 of the 5 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
library/mariadb:11.3.2e101f9db3191
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

10,965
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.020 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

20 of the 40 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
bitnamilegacy/git:latest4b08d0c5af8d
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
library/mariadb:11.3.2e101f9db3191
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11

Open the chart page →

72,154
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2

Open the chart page →

3,660
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41989.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1

Open the chart page →

3,133

Container images carrying it

2,170 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
2
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
2
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
2
ghcr.io/openunison/openunison-kubernetes-operator:1.0.1392bd6c526c50
libgcrypt20@1.10.3-2ubuntu0.2
1.12.0-2ubuntu0.1~Fips1~rc11
2
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
2
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
2
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
2
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2:latestb53a854bd7c1
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
2
quay.io/cilium/cilium-envoy:v1.37.5-1786810558-766ccfb37260a43e9d228837aa84ce3faf9f64e775b8094c7127
libgcrypt20@1.10.3-2ubuntu0.1
1.12.0-2ubuntu0.1~Fips1~rc11
2
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
libgcrypt@1.8.5-6.el8
0:1.8.5-8.el8_10
2
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
2
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
2
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
2
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
2
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
libgcrypt@1.8.5-4.el8
0:1.8.5-8.el8_10
2
quay.io/strimzi/drain-cleaner:1.6.15fb28e9f30d0
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
2
quay.io/strimzi/operator:0.39.002f6f143fc6d
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
2
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
2
1dev/server:11.9.0cd5b12fe5471
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
5200710/hadoop:3.2.3-java8092d3088a5fb
libgcrypt20@1.8.5-5ubuntu1.1
no fix listed
1
a10networks/acos-prometheus-exporter:latest8dc58d434d71
libgcrypt20@1.8.1-4ubuntu1.1
no fix listed
1
aboogie/login_test_backend:new9c41a4483ac8
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
actualbudget/actual-server:25.3.158fecd9088b7
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
adeptiainc/adeptia-connect-migration:4.8.1f1087da3da0b
libgcrypt@1.10.0-11.el9
0:1.10.0-13.el9_8
1
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
libgcrypt20@1.9.4-3ubuntu3
1.9.4-3ubuntu3.2
1
aibrix/metadata-service:v0.7.063fb81a64377
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
airbyte/manifest-server:7.23.73b3a670af168
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
airbyte/pod-sweeper:1.5.198d2c39d512e
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libgcrypt20@1.8.5-5ubuntu1
no fix listed
1
akaunting/akaunting:3.0.1552811b36ec3a
libgcrypt20@1.10.1-3
1.10.1-3+deb12u1
1
akeyless/base:latest759e4289fae8
libgcrypt20@1.10.3-2build1
1.10.3-2ubuntu0.1
1
akeyless/base-rhel:0.0.14ba8900a0061
libgcrypt@1.8.5-7.el8_6
0:1.8.5-8.el8_10
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.