StackRadar

CVE-2026-5419

Low

Advisory

Published 30 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,057
of 17,787 indexed, latest versions
Container images
1,141
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,057 of 17,787 indexed charts deploy, on 1,141 images.

Affected packageAffected versionsFixed inImages
gnutls28deb3.7.9-2, 3.7.9-2+deb12u1, 3.7.9-2+deb12u2, 3.7.9-2+deb12u3+14 more3.7.9-2+deb12u7, 3.8.3-1.1ubuntu3.6, 3.8.3-1.1ubuntu3.6+Fips1.2, 3.8.9-3+deb13u4+2 more1,100
gnutlsapk3.8.5-r0, 3.8.8-r0, 3.8.11-r0, 3.8.12-r03.8.13-r041
OSV records
ALPINE-CVE-2026-5419DEBIAN-CVE-2026-5419UBUNTU-CVE-2026-5419
Also known as
USN-8284-1

Charts affected

1,057 by stars
ChartLatestAffected imagesRadar Score
wordpress-alpinewordpress-alpine1.5.181 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

1 of the 6 container images this version deploys carry CVE-2026-5419.

Container imageDigestPackageFixed in
library/mariadb:12.3.2628f228f0fd5
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

4,032
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-5419.

Container imageDigestPackageFixed in
library/mariadb:ltsdd9b303aed4f
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

5,635
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-5419.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-5419.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7

Open the chart page →

7,685
xkopsxkops0.1.04 of 5See more

xkops xkops 0.1.0

4 of the 5 container images this version deploys carry CVE-2026-5419.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
hamzaarshad10/querypodpy:1.7154f38e8668e
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
library/mongo:latest5211c51171f5
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
murtazashah46/helmfile:latest4d11726cf803
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7

Open the chart page →

13,197
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-5419.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
gnutls28@3.8.3-1.1ubuntu3.1
3.8.3-1.1ubuntu3.6

Open the chart page →

2,136
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-5419.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7

Open the chart page →

2,674

Container images carrying it

1,141 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/mariadb:12.3.3:latest:ltsdd9b303aed4f
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
12
library/mongo:8:8.3.8:latest5211c51171f5
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
12
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
11
library/rabbitmq:3.13-management:3-managemente582c0bc7766
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6
8
bitnamilegacy/postgresql:17.5.0:latest42a8200d3597
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
6
bitnamilegacy/rabbitmq:4.1.3:4.1.3-debian-12-r19e635efba431
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
6
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
gnutls28@3.7.9-2
3.7.9-2+deb12u7
6
quay.io/devtron/postgres:14.91b594392f7cb
gnutls28@3.7.9-2
3.7.9-2+deb12u7
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7
5
flaresolverr/flaresolverr:latest:v3.5.0139dfee1c6f8
gnutls28@3.7.9-2+deb12u6
3.7.9-2+deb12u7
5
library/kong:3.9:latest2a8cf3b110cd
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
5
library/postgres:122f2a8c2a7d10
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
5
artifacthub/postgres:latest4fd34fa635cc
gnutls28@3.8.9-3
3.8.9-3+deb13u4
4
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
4
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
4
bitnamilegacy/postgresql:16233f361c5819
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
4
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
4
bitnamilegacy/rabbitmq:4.1.2:4.1.2-debian-12-r1fac502149c40
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
4
library/nginx:1.27.1287ff321f9e3
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
4
library/postgres:134689940c6838
gnutls28@3.8.9-3
3.8.9-3+deb13u4
4
opea/llm-tgi:1.00c25aab3f106
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
4
shashkist/flask-contacts-app:latest581de1fd6084
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
4
bitnamilegacy/kubectl:latestcd354d5b2556
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
3
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
3
gchq/hdfs:3.3.35ec58edbb2db
gnutls28@3.8.3-1.1ubuntu3.1
3.8.3-1.1ubuntu3.6
3
guacamole/guacamole:1.6.0f344085e618b
gnutls28@3.8.3-1.1ubuntu3.3
3.8.3-1.1ubuntu3.6
3
library/nginx:1.25:1.25.5a484819eb602
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7
3
library/rabbitmq:4.3.5-management:4-management:managementffd1b50c522a
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
3
library/ubuntu:24.0433ceb71981b6
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
gnutls28@3.7.9-2
3.7.9-2+deb12u7
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
3
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
gnutls28@3.7.9-2+deb12u6
3.7.9-2+deb12u7
3
ghcr.io/tremolosecurity/kube-oidc-proxy:1.0.13a89736c586ba
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
3
quay.io/devtron/ai-agent:0.0.16545dac92173
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.6
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.6
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.6
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.6
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.6
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.6
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.6
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
3
alazidis/kube-netlag:1.1.00e8c84152201
gnutls28@3.8.3-1.1ubuntu3.5
3.8.3-1.1ubuntu3.6
2
alpine/git:2.47.2062a01ad7a0e
gnutls@3.8.8-r0
3.8.13-r0
2
apache/apisix:3.18.0-ubuntu9ee5df1611f9
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
2
apache/rocketmq:5.4.0319cd8a81ed1
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.