StackRadar

CVE-2026-4438

Medium

Advisory

Published 20 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.4
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
996
of 17,787 indexed, latest versions
Container images
1,167
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-4438 affecting package glibc for versions less than 2.38-19

Carried by container images the latest versions of 996 of 17,787 indexed charts deploy, on 1,167 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.36-9, 2.36-9+deb12u1, 2.36-9+deb12u3, 2.36-9+deb12u4+19 more2.36-9+deb12u14, 2.39-0ubuntu8.8, 2.41-12+deb13u2+e2, 2.41-12+deb13u31,137
glibcapk2.37-r7, 2.38-r6, 2.39-r7, 2.40-r1+7 more2.43-r420
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibcrpm2.38-16.azl3, 2.38-18.azl32.38-193
OSV records
CGA-3jvw-cpqx-f8w2DEBIAN-CVE-2026-4438UBUNTU-CVE-2026-4438AZL-80282ECHO-49d5-1f6e-5068
Also known as
CGA-44m8-5gw6-5qvv, CGA-4w93-3fmj-w88c, CGA-5h5q-3r3v-xr9g, CGA-722r-222x-hhhf, CGA-7fmh-pg32-8pv7, CGA-c53j-fx2j-57cf, CGA-c8r4-qhfx-5jqj, CGA-fg6j-4w5q-pjf3, CGA-j3f7-h2g8-xp9q, CGA-p954-rwjw-2p5h, CGA-pfmv-47h7-9x9v, CGA-q89h-5j3w-f3m5, CGA-wf74-v63j-cxxf, CGA-wrpj-h6wm-4267, CGA-x9rq-r5hh-4fjj, USN-8611-1

Charts affected

996 by stars
ChartLatestAffected imagesRadar Score
sentry-relaydasmeta0.1.21 of 1See more

sentry-relay dasmeta 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
getsentry/relay:24.10.0ba7bf9163219
glibc@2.36-9+deb12u8
2.36-9+deb12u14

Open the chart page →

3,401
monitoring-stackdata354-helmVerified publisher1.4.21 of 4See more

monitoring-stack data354-helm 1.4.2

1 of the 4 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
grafana/fluent-plugin-loki:latest8a3882e8c28b
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

3,189
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8

Open the chart page →

6,177
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8

Open the chart page →

6,028
private-action-runnerdatadogVerified publisher1.28.11 of 1See more

private-action-runner datadog 1.28.1

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
gcr.io/datadoghq/private-action-runner:v1.21.05f5918f843a4
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8

Open the chart page →

2,164
db-connection-testdb-connection-testVerified publisher0.1.01 of 1See more

db-connection-test db-connection-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
felipecs8/app-db-connection-test:v129e06c9c6385
glibc@2.36-9+deb12u9
2.36-9+deb12u14

Open the chart page →

10,116
defactopsdefactops1.0.91 of 2See more

defactops defactops 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
defactops/defactops-backend:1.0.2307b663c0092a
glibc@2.36-9+deb12u7
2.36-9+deb12u14

Open the chart page →

4,353
linkdingdeimosfr-charts1.0.31 of 1See more

linkding deimosfr-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.35.00c5dddf0b37c
glibc@2.36-9+deb12u8
2.36-9+deb12u14

Open the chart page →

5,656
technitiumdeimosfr-charts15.4.01 of 1See more

technitium deimosfr-charts 15.4.0

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
technitium/dns-server:15.4.0df7d90ef0f7b
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8

Open the chart page →

1,225
dell-fan-controllerdell-fan-controllerVerified publisher1.0.71 of 1See more

dell-fan-controller dell-fan-controller 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8

Open the chart page →

2,560
deployhubdeployhubVerified publisher10.0.4154 of 11See more

deployhub deployhub 10.0.415

4 of the 11 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
glibc@2.42-r4
2.43-r4
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
glibc@2.42-r4
2.43-r4
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
glibc@2.42-r4
2.43-r4
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
glibc@2.42-r4
2.43-r4

Open the chart page →

11,161
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
glibc@2.36-9+deb12u8
2.36-9+deb12u14

Open the chart page →

9,152
devtron-enterprisedevtron48.0.07 of 28See more

devtron-enterprise devtron 48.0.0

7 of the 28 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
glibc@2.36-9+deb12u3
2.36-9+deb12u14
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
glibc@2.36-9+deb12u13
2.36-9+deb12u14
quay.io/devtron/postgres:14.91b594392f7cb
glibc@2.36-9+deb12u3
2.36-9+deb12u14

Open the chart page →

66,542
migration-incluster-cddevtron0.10.01 of 1See more

migration-incluster-cd devtron 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
glibc@2.36-9+deb12u9
2.36-9+deb12u14

Open the chart page →

3,699
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
glibc@2.36-9+deb12u8
2.36-9+deb12u14

Open the chart page →

9,152
devtron-enterprisedevtron-labs48.0.07 of 28See more

devtron-enterprise devtron-labs 48.0.0

7 of the 28 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
glibc@2.36-9+deb12u3
2.36-9+deb12u14
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
glibc@2.36-9+deb12u13
2.36-9+deb12u14
quay.io/devtron/postgres:14.91b594392f7cb
glibc@2.36-9+deb12u3
2.36-9+deb12u14

Open the chart page →

66,542
devtron-operatordevtron-labs0.23.35 of 11See more

devtron-operator devtron-labs 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
glibc@2.36-9+deb12u3
2.36-9+deb12u14
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
quay.io/devtron/postgres:14.91b594392f7cb
glibc@2.36-9+deb12u3
2.36-9+deb12u14

Open the chart page →

31,447
migration-incluster-cddevtron-labs0.10.01 of 1See more

migration-incluster-cd devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
glibc@2.36-9+deb12u9
2.36-9+deb12u14

Open the chart page →

3,699
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.01 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.8

Open the chart page →

27,608
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

4,053
difydify1.0.02 of 4See more

dify dify 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
glibc@2.36-9+deb12u9
2.36-9+deb12u14
langgenius/dify-sandbox:0.2.009b7e8705673
glibc@2.36-9+deb12u6
2.36-9+deb12u14

Open the chart page →

19,063
alertifydjjudas21Verified publisher0.1.01 of 1See more

alertify djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
djjudas21/alertify:0.1.0ba22be670c37
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

2,384
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
glibc@2.36-9+deb12u9
2.36-9+deb12u14

Open the chart page →

7,167
ownclouddjjudas21Verified publisher0.3.232 of 3See more

owncloud djjudas21 0.3.23

2 of the 3 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
glibc@2.36-9+deb12u7
2.36-9+deb12u14
valkey/valkey:8.1.481db6d39e1bb
glibc@2.41-12
2.41-12+deb13u3

Open the chart page →

10,129
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
glibc@2.39-0ubuntu8.2
2.39-0ubuntu8.8

Open the chart page →

17,053
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
glibc@2.41-12
2.41-12+deb13u3

Open the chart page →

5,144
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
glibc@2.36-9+deb12u3
2.36-9+deb12u14

Open the chart page →

13,031
dnation-kubernetes-jsonnet-translatordnationcloud2.0.11 of 1See more

dnation-kubernetes-jsonnet-translator dnationcloud 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
glibc@2.36-9+deb12u8
2.36-9+deb12u14

Open the chart page →

3,626
dnation-kubernetes-monitoringdnationcloud3.0.21 of 1See more

dnation-kubernetes-monitoring dnationcloud 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
glibc@2.36-9+deb12u8
2.36-9+deb12u14

Open the chart page →

3,626
dnation-kubernetes-monitoring-stackdnationcloud4.0.23 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

3 of the 17 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
glibc@2.36-9+deb12u8
2.36-9+deb12u14
grafana/loki:3.2.0882e30c20683
glibc@2.36-9+deb12u8
2.36-9+deb12u14
grafana/loki-canary:3.2.049e03f80d361
glibc@2.36-9+deb12u8
2.36-9+deb12u14

Open the chart page →

21,455
dnsmasq-k8sdnsmasq-k8s1.4.11 of 1See more

dnsmasq-k8s dnsmasq-k8s 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
glibc@2.41-12
2.41-12+deb13u3

Open the chart page →

3,030
dominodomino-iisasVerified publisher0.3.13 of 3See more

domino domino-iisas 0.3.1

3 of the 3 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
glibc@2.41-12
2.41-12+deb13u3
ghcr.io/iisas/domino-frontend:k8s8e53861be292
glibc@2.36-9+deb12u13
2.36-9+deb12u14
ghcr.io/iisas/domino-rest:latest3009350bfc11
glibc@2.41-12+deb13u1
2.41-12+deb13u3

Open the chart page →

10,307
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.8

Open the chart page →

24,714
duckdb-uiduckdb-ui0.5.21 of 1See more

duckdb-ui duckdb-ui 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
glibc@2.36-9+deb12u13
2.36-9+deb12u14

Open the chart page →

4,283
cloudflaredduck-helm1.1.31 of 1See more

cloudflared duck-helm 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
glibc@2.41-12+deb13u1
2.41-12+deb13u3

Open the chart page →

1,442
postgres-backup-localduck-helm0.1.51 of 1See more

postgres-backup-local duck-helm 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:latestf70742ebe42b
glibc@2.41-12
2.41-12+deb13u3

Open the chart page →

3,426
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
glibc@2.36-9+deb12u7
2.36-9+deb12u14

Open the chart page →

9,251
base-consensusdysnixVerified publisher0.2.01 of 1See more

base-consensus dysnix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
ghcr.io/base/node-reth:v1.1.18eb6e492fe3c
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8

Open the chart page →

1,743
bitcoinddysnixVerified publisher0.4.31 of 2See more

bitcoind dysnix 0.4.3

1 of the 2 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.8

Open the chart page →

1,970
gcp-local-ssd-raiddysnixVerified publisher0.1.71 of 2See more

gcp-local-ssd-raid dysnix 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

2,399
rethdysnixVerified publisher0.0.111 of 2See more

reth dysnix 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
ghcr.io/paradigmxyz/reth:v2.2.0505fca5e87d6
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8

Open the chart page →

1,067
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
glibc@2.36-9+deb12u9
2.36-9+deb12u14

Open the chart page →

4,593
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
glibc@2.41-12
2.41-12+deb13u3

Open the chart page →

13,422
self-awarenesseclipse-aeriosVerified publisher1.4.41 of 2See more

self-awareness eclipse-aerios 1.4.4

1 of the 2 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
eclipseaerios/self-awareness-hardware-info:1.4.434b72f45b46a
glibc@2.41-12
2.41-12+deb13u3

Open the chart page →

2,195
self-orchestratoreclipse-aeriosVerified publisher1.2.01 of 1See more

self-orchestrator eclipse-aerios 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
eclipseaerios/self-orchestrator:1.2.08b123bec5679
glibc@2.36-9+deb12u9
2.36-9+deb12u14

Open the chart page →

2,397
trustmanagereclipse-aeriosVerified publisher1.0.01 of 1See more

trustmanager eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
eclipseaerios/trust-manager:1.0.0f55442e2c0ed
glibc@2.41-12
2.41-12+deb13u3

Open the chart page →

1,907
egressgatewayegressgateway0.6.92 of 2See more

egressgateway egressgateway 0.6.9

2 of the 2 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.8
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.8

Open the chart page →

3,944
netobserv-flowelastiflowVerified publisher0.11.01 of 1See more

netobserv-flow elastiflow 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
elastiflow/flow-collector:7.26.0fee67842e16b
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8

Open the chart page →

1,474
redisemberstackVerified publisher1.0.211 of 1See more

redis emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
library/redis:8.0.2b43d2dcbbdb1
glibc@2.36-9+deb12u10
2.36-9+deb12u14

Open the chart page →

1,902
kube-ecp-stackemqx-operator2.5.12 of 16See more

kube-ecp-stack emqx-operator 2.5.1

2 of the 16 container images this version deploys carry CVE-2026-4438.

Container imageDigestPackageFixed in
emqx/ecp-ui:2.5.1e33e9816f147
glibc@2.36-9+deb12u9
2.36-9+deb12u14
library/telegraf:1.27507a3eecf809
glibc@2.36-9+deb12u4
2.36-9+deb12u14

Open the chart page →

22,845

Container images carrying it

1,167 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
glibc@2.36-9+deb12u9
2.36-9+deb12u14
1
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
glibc@2.36-9+deb12u9
2.36-9+deb12u14
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
glibc@2.36-9+deb12u9
2.36-9+deb12u14
1
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8
1
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v5.2.0afdfa3da79df
glibc@2.38-16.azl3
2.38-19
1
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v1.13.2fa8eba9843ff
glibc@2.38-18.azl3
2.38-19
1
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.15.059b9d0348428
glibc@2.38-18.azl3
2.38-19
1
public.ecr.aws/aktosecurity/redis47200b041382
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
public.ecr.aws/aktosecurity/redis:latestV8.6.2832d7785830f
glibc@2.41-12+deb13u2
2.41-12+deb13u3
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.8
1
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
glibc@2.41-12
2.41-12+deb13u3
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
glibc@2.36-9+deb12u10
2.36-9+deb12u14
1
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
glibc@2.41-12+deb13u1+e2
2.41-12+deb13u2+e2
1
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
glibc@2.41-12+deb13u1+e2
2.41-12+deb13u2+e2
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
glibc@2.36-9+deb12u8
2.36-9+deb12u14
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
glibc@2.36-9+deb12u8
2.36-9+deb12u14
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
glibc@2.36-9+deb12u7
2.36-9+deb12u14
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
glibc@2.36-9+deb12u4
2.36-9+deb12u14
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
glibc@2.36-9+deb12u3
2.36-9+deb12u14
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
glibc@2.36-9+deb12u9
2.36-9+deb12u14
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
glibc@2.36-9+deb12u9
2.36-9+deb12u14
1
public.ecr.aws/opslevel/kubectl-opslevel:v2024.9.571697b5ff713
glibc@2.36-9+deb12u8
2.36-9+deb12u14
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
glibc@2.36-9+deb12u9
2.36-9+deb12u14
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
glibc@2.36-9+deb12u3
2.36-9+deb12u14
1
public.ecr.aws/zinclabs/openobserve:v0.8.127f8de509169
glibc@2.36-9+deb12u4
2.36-9+deb12u14
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.8
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
glibc@2.39-0ubuntu8.5
2.39-0ubuntu8.8
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
glibc@2.39-0ubuntu8.5
2.39-0ubuntu8.8
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8
1
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
glibc@2.39-0ubuntu8.5
2.39-0ubuntu8.8
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
glibc@2.36-9+deb12u9
2.36-9+deb12u14
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
glibc@2.36-9+deb12u10
2.36-9+deb12u14
1
quay.io/heubeck/examiner:1.14.61154472ff8c4
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
quay.io/kubevirt/virt-operator:v1.7.037d2ef21e3e5
glibc@2.36-9+deb12u10
2.36-9+deb12u14
1
quay.io/kubevirt/virt-operator:v1.8.465d23c9ad917
glibc@2.36-9+deb12u13
2.36-9+deb12u14
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
glibc@2.36-9+deb12u10
2.36-9+deb12u14
1
quay.io/mittwald/kube-mail:latest04f1099241fc
glibc@2.36-9+deb12u10
2.36-9+deb12u14
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.8
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
glibc@2.41-12
2.41-12+deb13u3
1
quay.io/opstree/fluent-bit:5.0.3391eef5a68ff
glibc@2.41-12+deb13u2
2.41-12+deb13u3
1
quay.io/opstree/grafana:12.4.3b61c1ed2f015
glibc@2.41-12+deb13u2
2.41-12+deb13u3
1
quay.io/opstree/k8s-sidecar:2.7.126aa9bb3386b
glibc@2.41-12+deb13u2
2.41-12+deb13u3
1
quay.io/opstree/k8s-sidecar:2.7.37075d455b219
glibc@2.41-12+deb13u2
2.41-12+deb13u3
1
quay.io/opstree/memcached:1.6.38-alpine3.22cabbdfd2c3fe
glibc@2.41-12+deb13u2
2.41-12+deb13u3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.