CVE-2026-5435
HighAdvisory
Published 28 Apr 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.3
- base score, highest
- EPSS
- 0.002
- 15th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,504
- of 17,821 indexed, latest versions
- Container images
- 2,538
- deployed by those charts
- Fix available
- 1 of 3
- affected packages
CVE-2026-5435 affecting package glibc 2.38-21
Carried by container images the latest versions of 2,504 of 17,821 indexed charts deploy, on 2,538 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| glibcdeb | 2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+61 more | 2.35-0ubuntu3.14, 2.39-0ubuntu8.8, 2.41-12+deb13u2+e5, 2.43-2ubuntu2.3 | 2,517 |
| eglibcdeb | 2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 more | no fix listed | 7 |
| glibcrpm | 2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3 | no fix listed | 14 |
- OSV records
- DEBIAN-CVE-2026-5435UBUNTU-CVE-2026-5435AZL-84599ECHO-53d2-a97b-142d
- Also known as
- USN-8611-1
Charts affected
2,504 by stars
Container images carrying it
2,538 by charts deploying them
A fixed version is listed for 1 of the 3 affected packages.