StackRadar

CVE-2026-5419

Low

Advisory

Published 30 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,057
of 17,787 indexed, latest versions
Container images
1,141
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,057 of 17,787 indexed charts deploy, on 1,141 images.

Affected packageAffected versionsFixed inImages
gnutls28deb3.7.9-2, 3.7.9-2+deb12u1, 3.7.9-2+deb12u2, 3.7.9-2+deb12u3+14 more3.7.9-2+deb12u7, 3.8.3-1.1ubuntu3.6, 3.8.3-1.1ubuntu3.6+Fips1.2, 3.8.9-3+deb13u4+2 more1,100
gnutlsapk3.8.5-r0, 3.8.8-r0, 3.8.11-r0, 3.8.12-r03.8.13-r041
OSV records
ALPINE-CVE-2026-5419DEBIAN-CVE-2026-5419UBUNTU-CVE-2026-5419
Also known as
USN-8284-1

Charts affected

1,057 by stars
ChartLatestAffected imagesRadar Score
wordpress-alpinewordpress-alpine1.5.181 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

1 of the 6 container images this version deploys carry CVE-2026-5419.

Container imageDigestPackageFixed in
library/mariadb:12.3.2628f228f0fd5
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

4,032
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-5419.

Container imageDigestPackageFixed in
library/mariadb:ltsdd9b303aed4f
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

5,635
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-5419.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-5419.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7

Open the chart page →

7,685
xkopsxkops0.1.04 of 5See more

xkops xkops 0.1.0

4 of the 5 container images this version deploys carry CVE-2026-5419.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
hamzaarshad10/querypodpy:1.7154f38e8668e
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
library/mongo:latest5211c51171f5
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
murtazashah46/helmfile:latest4d11726cf803
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7

Open the chart page →

13,197
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-5419.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
gnutls28@3.8.3-1.1ubuntu3.1
3.8.3-1.1ubuntu3.6

Open the chart page →

2,136
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-5419.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7

Open the chart page →

2,674

Container images carrying it

1,141 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hassroutyyoussef/accountservice:latest1f01edf1ee0c
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
hassroutyyoussef/orderservice:latest2fc3d1617928
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
hassroutyyoussef/userservice:lateste0392e2b4a90
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1
hazegoodlife/haaze:milksite8d4c63169e14
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1
hecrom/myweatherangularclient:1.3.11bb0372939c19
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
gnutls28@3.7.9-2
3.7.9-2+deb12u7
1
helmforge/fastmcp-server:0.2.061f759a1421f
gnutls28@3.8.9-3+deb13u2
3.8.9-3+deb13u4
1
helmforge/fastmcp-server:0.11.2fcb7017327d6
gnutls28@3.8.9-3+deb13u2
3.8.9-3+deb13u4
1
hiboxsystems/marge-bot:0.16.0b59f01bc0418
gnutls28@3.8.9-3
3.8.9-3+deb13u4
1
hiboxsystems/marge-bot:0.14.0dcffb926e563
gnutls28@3.7.9-2+deb12u1
3.7.9-2+deb12u7
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
1
hivemq/hivemq-edge:2026.13aba306d1f089
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
1
hivemq/hivemq-swarm:4.54.0f9746d5d70fa
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
1
hjacobs/kube-janitor:23.7.0fbb303ed463c
gnutls28@3.7.9-2
3.7.9-2+deb12u7
1
hjacobs/kube-web-view:23.8.0431f1bf013d0
gnutls28@3.7.9-2
3.7.9-2+deb12u7
1
hyperledger/besu:latest6f3f21ce5333
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
gnutls28@3.7.9-2
3.7.9-2+deb12u7
1
improwised/proxysql:master-6b26e59-171765063828940522e8b7
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7
1
instill/artifact-backend:b28766ac4a393e601ed
gnutls28@3.8.9-3+deb13u1
3.8.9-3+deb13u4
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
gnutls28@3.8.9-3+deb13u1
3.8.9-3+deb13u4
1
instill/model-backend:611f0f2e980125e5ba5
gnutls28@3.8.9-3+deb13u1
3.8.9-3+deb13u4
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
gnutls28@3.7.9-2+deb12u1
3.7.9-2+deb12u7
1
iomesh/node-disk-manager:1.8.0-2292ad270082e
gnutls28@3.8.3-1.1ubuntu3.1
3.8.3-1.1ubuntu3.6
1
iomesh/node-disk-operator:1.8.0-1de4aa40684ad
gnutls28@3.8.3-1.1ubuntu3.1
3.8.3-1.1ubuntu3.6
1
istio/examples-helloworld-v1:latest328b237e4fb1
gnutls28@3.7.9-2+deb12u1
3.7.9-2+deb12u7
1
istio/examples-helloworld-v2:latest0a7f02b2c7c9
gnutls28@3.7.9-2+deb12u1
3.7.9-2+deb12u7
1
istio/install-cni:1.23.6ab34c4740f44
gnutls28@3.8.3-1.1ubuntu3.3
3.8.3-1.1ubuntu3.6
1
istio/install-cni:1.29.0ce27c9ce43c8
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6
1
istio/pilot:1.29.0325156535773
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6
1
istio/pilot:1.23.69c3d6a218181
gnutls28@3.8.3-1.1ubuntu3.3
3.8.3-1.1ubuntu3.6
1
istio/pilot:1.29.1f8b0e412ac4a
gnutls28@3.8.3-1.1ubuntu3.5
3.8.3-1.1ubuntu3.6
1
istio/ztunnel:1.25.005f3972d80a9
gnutls28@3.8.3-1.1ubuntu3.3
3.8.3-1.1ubuntu3.6
1
itzg/minecraft-server:2026.9.04e29d14082d9
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
1
itzg/minecraft-server:latest8672e335dbef
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
1
ixsystems/truecommand:3.2.019c218455cd2
gnutls28@3.8.9-3
3.8.9-3+deb13u4
1
jaedb/iris:latest048cfbf58d57
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1
janzo83/serviceexample:latestfb3c4ac36f3e
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
1
jellyfin/jellyfin:10.11.81694ff069f0c
gnutls28@3.8.9-3+deb13u2
3.8.9-3+deb13u4
1
jellyfin/jellyfin:10.11.717285f9cce63
gnutls28@3.8.9-3+deb13u2
3.8.9-3+deb13u4
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
jellyfin/jellyfin:10.11.6333b64771663
gnutls28@3.8.9-3+deb13u1
3.8.9-3+deb13u4
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
jellyfin/jellyfin:10.10.77ae36aab93ef
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1
jellyfin/jellyfin:10.10.696b09723b22f
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
gnutls28@3.7.9-2+deb12u1
3.7.9-2+deb12u7
1
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
jlesage/firefox:v25.03.1055c28defe31
gnutls@3.8.8-r0
3.8.13-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.