StackRadar

CVE-2026-42012

High

Advisory

Published 30 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,754
of 17,790 indexed, latest versions
Container images
1,836
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,754 of 17,790 indexed charts deploy, on 1,836 images.

Affected packageAffected versionsFixed inImages
gnutls28deb3.4.10-4ubuntu1.3, 3.4.10-4ubuntu1.4, 3.4.10-4ubuntu1.5, 3.4.10-4ubuntu1.7+47 more3.4.10-4ubuntu1.9+esm4, 3.5.18-1ubuntu1.6+esm4, 3.6.13-2ubuntu1.12+esm3, 3.7.3-4ubuntu1.9+6 more1,795
gnutlsapk3.8.5-r0, 3.8.8-r0, 3.8.11-r0, 3.8.12-r03.8.13-r041
OSV records
ALPINE-CVE-2026-42012DEBIAN-CVE-2026-42012UBUNTU-CVE-2026-42012
Also known as
USN-8284-1, USN-8539-1

Charts affected

1,754 by stars
ChartLatestAffected imagesRadar Score
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42012.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
gnutls28@3.8.3-1.1ubuntu3.1
3.8.3-1.1ubuntu3.6

Open the chart page →

2,136
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42012.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7

Open the chart page →

2,674
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-42012.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
gnutls28@3.5.18-1ubuntu1.5
3.5.18-1ubuntu1.6+esm4
yandex/clickhouse-server:21.3.204eccfffb01d7
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.12+esm3

Open the chart page →

9,250
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-42012.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
gnutls28@3.7.3-4ubuntu1.9
no fix listed

Open the chart page →

7,916

Container images carrying it

1,836 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
istio/install-cni:1.10.32232f365aed6
gnutls28@3.5.18-1ubuntu1.4
3.5.18-1ubuntu1.6+esm4
1
istio/install-cni:1.23.6ab34c4740f44
gnutls28@3.8.3-1.1ubuntu3.3
3.8.3-1.1ubuntu3.6
1
istio/install-cni:1.29.0ce27c9ce43c8
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6
1
istio/node-agent-k8s:1.2.9268ab879ea51
gnutls28@3.4.10-4ubuntu1.5
3.4.10-4ubuntu1.9+esm4
1
istio/operator:1.10.3655eefa11c84
gnutls28@3.5.18-1ubuntu1.4
3.5.18-1ubuntu1.6+esm4
1
istio/operator:1.12.06cfce8a071b9
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.12+esm3
1
istio/operator:1.18.270f9d1fe5fff
gnutls28@3.7.3-4ubuntu1.2
3.7.3-4ubuntu1.9
1
istio/pilot:1.10.0294ca55bd1cc
gnutls28@3.5.18-1ubuntu1.4
3.5.18-1ubuntu1.6+esm4
1
istio/pilot:1.29.0325156535773
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6
1
istio/pilot:1.23.69c3d6a218181
gnutls28@3.8.3-1.1ubuntu3.3
3.8.3-1.1ubuntu3.6
1
istio/pilot:1.16.0ac0284d75ec9
gnutls28@3.7.3-4ubuntu1.1
3.7.3-4ubuntu1.9
1
istio/pilot:1.2.9c09319753454
gnutls28@3.4.10-4ubuntu1.5
3.4.10-4ubuntu1.9+esm4
1
istio/pilot:1.17.1ce9d87606701
gnutls28@3.7.3-4ubuntu1.1
3.7.3-4ubuntu1.9
1
istio/pilot:1.15.2db08d6963975
gnutls28@3.7.3-4ubuntu1.1
3.7.3-4ubuntu1.9
1
istio/pilot:1.10.3e7e110a421c2
gnutls28@3.5.18-1ubuntu1.4
3.5.18-1ubuntu1.6+esm4
1
istio/pilot:1.29.1f8b0e412ac4a
gnutls28@3.8.3-1.1ubuntu3.5
3.8.3-1.1ubuntu3.6
1
istio/proxyv2:1.2.90c78be035e98
gnutls28@3.4.10-4ubuntu1.5
3.4.10-4ubuntu1.9+esm4
1
istio/proxyv2:1.9.687a9db561d2e
gnutls28@3.5.18-1ubuntu1.4
3.5.18-1ubuntu1.6+esm4
1
istio/proxyv2:1.10.088c6c693e67a
gnutls28@3.5.18-1ubuntu1.4
3.5.18-1ubuntu1.6+esm4
1
istio/proxyv2:1.14.1df69c1a7af7c
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.12+esm3
1
istio/ztunnel:1.25.005f3972d80a9
gnutls28@3.8.3-1.1ubuntu3.3
3.8.3-1.1ubuntu3.6
1
itzg/minecraft-server:latest8672e335dbef
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
1
ixsystems/truecommand:3.2.019c218455cd2
gnutls28@3.8.9-3
3.8.9-3+deb13u4
1
jacobalberty/unifi:v7.1.664a3616625dda
gnutls28@3.5.18-1ubuntu1.5
3.5.18-1ubuntu1.6+esm4
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
gnutls28@3.5.18-1ubuntu1.6
3.5.18-1ubuntu1.6+esm4
1
jacobalberty/unifi:5.10.19c409924e2463
gnutls28@3.4.10-4ubuntu1.4
3.4.10-4ubuntu1.9+esm4
1
jaedb/iris:latest048cfbf58d57
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1
jakowenko/double-take:1.6.0b858bac9e32a
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.12+esm3
1
janzo83/serviceexample:latestfb3c4ac36f3e
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
1
jedi132000/nextapp:latestdc2a81e92f23
gnutls28@3.6.13-2ubuntu1.7
3.6.13-2ubuntu1.12+esm3
1
jellyfin/jellyfin:10.11.81694ff069f0c
gnutls28@3.8.9-3+deb13u2
3.8.9-3+deb13u4
1
jellyfin/jellyfin:10.11.717285f9cce63
gnutls28@3.8.9-3+deb13u2
3.8.9-3+deb13u4
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
jellyfin/jellyfin:10.11.6333b64771663
gnutls28@3.8.9-3+deb13u1
3.8.9-3+deb13u4
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
jellyfin/jellyfin:10.10.77ae36aab93ef
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1
jellyfin/jellyfin:10.10.696b09723b22f
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7
1
jhipster/jhipster-registry:latest7184525acd4d
gnutls28@3.6.13-2ubuntu1.12
3.6.13-2ubuntu1.12+esm3
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
gnutls28@3.7.9-2+deb12u1
3.7.9-2+deb12u7
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
gnutls28@3.6.13-2ubuntu1.10
3.6.13-2ubuntu1.12+esm3
1
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
jlesage/firefox:v25.03.1055c28defe31
gnutls@3.8.8-r0
3.8.13-r0
1
jmferrer/azure-devops-agent:latest030f68ec6998
gnutls28@3.4.10-4ubuntu1.7
3.4.10-4ubuntu1.9+esm4
1
josh5/unmanic:0.2.64d49c4816260
gnutls28@3.7.3-4ubuntu1.2
3.7.3-4ubuntu1.9
1
jpgouin/openldap:2.6.9-fixbfdd0088c776
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1
jupyterhub/jupyterhub:5.4.63974ba945e65
gnutls28@3.8.3-1.1ubuntu3.5
3.8.3-1.1ubuntu3.6
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
gnutls28@3.6.13-2ubuntu1.3
3.6.13-2ubuntu1.12+esm3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.