StackRadar

CVE-2026-4738

Critical

Advisory

Published 24 Mar 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.4
base score, highest
EPSS
0.003
20th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
gdaldeb2.4.0+10-0bionic1, 3.0.4+dfsg-1build3, 3.4.1+dfsg-1build4, 3.6.2+dfsg-1+b2+4 moreno fix listed18
OSV records
DEBIAN-CVE-2026-4738UBUNTU-CVE-2026-4738

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
nominatimrobjuz6.4.11 of 4See more

nominatim robjuz 6.4.1

1 of the 4 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
mediagis/nominatim:5.3.27923a8e67197
gdal@3.8.4+dfsg-3ubuntu3
no fix listed

Open the chart page →

8,690
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg16d7db8f1085a3
gdal@3.4.1+dfsg-1build4
no fix listed

Open the chart page →

12,930
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
gdal@3.4.1+dfsg-1build4
no fix listed

Open the chart page →

32,501
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
gdal@3.4.1+dfsg-1build4
no fix listed

Open the chart page →

20,900
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
gdal@2.4.0+10-0bionic1
no fix listed

Open the chart page →

27,728
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
gdal@2.4.0+10-0bionic1
no fix listed

Open the chart page →

22,405
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
gdal@2.4.0+10-0bionic1
no fix listed

Open the chart page →

24,335
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
gdal@3.10.3+dfsg-1
no fix listed

Open the chart page →

7,459
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
gdal@3.4.1+dfsg-1build4
no fix listed

Open the chart page →

24,917
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
gdal@3.4.1+dfsg-1build4
no fix listed

Open the chart page →

30,699
dawarichhelmforgeVerified publisher1.0.01 of 4See more

dawarich helmforge 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
postgis/postgis:18-3.67e00e8c3539f
gdal@3.13.2+dfsg-1.pgdg13+1
no fix listed

Open the chart page →

4,742
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
gdal@3.4.1+dfsg-1build4
no fix listed

Open the chart page →

14,290
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
gdal@3.8.4+dfsg-3ubuntu3
no fix listed

Open the chart page →

45,239
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
gdal@3.0.4+dfsg-1build3
no fix listed

Open the chart page →

22,658
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
gdal@3.6.2+dfsg-1+b2
no fix listed

Open the chart page →

11,636
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
gdal@3.8.4+dfsg-3ubuntu3
no fix listed

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
gdal@3.8.4+dfsg-3ubuntu3
no fix listed

Open the chart page →

12,460
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
gdal@3.8.4+dfsg-3ubuntu3
no fix listed

Open the chart page →

45,239
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
gdal@3.4.1+dfsg-1build4
no fix listed

Open the chart page →

13,459
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-4738.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
gdal@3.8.4+dfsg-1~jammy0
no fix listed

Open the chart page →

7,849

Container images carrying it

18 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/tika:2.9.2.1-fullae0b86d3c4d0
gdal@3.8.4+dfsg-3ubuntu3
no fix listed
2
kurento/kurento-media-server:latest03c0d34d0828
gdal@3.8.4+dfsg-3ubuntu3
no fix listed
2
mediagis/nominatim:5.3.27923a8e67197
gdal@3.8.4+dfsg-3ubuntu3
no fix listed
1
mediagis/nominatim:3.7c15e941485ef
gdal@3.0.4+dfsg-1build3
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
gdal@3.4.1+dfsg-1build4
no fix listed
1
opendatacube/pipelines:wofs-1.225d810e8504b8
gdal@2.4.0+10-0bionic1
no fix listed
1
opendatacube/restcube:latest91870111837c
gdal@2.4.0+10-0bionic1
no fix listed
1
opendatacube/wms:latest1b90cdf68831
gdal@2.4.0+10-0bionic1
no fix listed
1
postgis/postgis:18-3.67e00e8c3539f
gdal@3.13.2+dfsg-1.pgdg13+1
no fix listed
1
signalen/backend:2.50.14760256000738
gdal@3.6.2+dfsg-1+b2
no fix listed
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
gdal@3.4.1+dfsg-1build4
no fix listed
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
gdal@3.4.1+dfsg-1build4
no fix listed
1
timescale/timescaledb-ha:pg16d7db8f1085a3
gdal@3.4.1+dfsg-1build4
no fix listed
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
gdal@3.4.1+dfsg-1build4
no fix listed
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
gdal@3.4.1+dfsg-1build4
no fix listed
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
gdal@3.4.1+dfsg-1build4
no fix listed
1
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
gdal@3.8.4+dfsg-1~jammy0
no fix listed
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
gdal@3.10.3+dfsg-1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.