StackRadar

CVE-2026-5435

High

Advisory

Published 28 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,438
of 17,805 indexed, latest versions
Container images
2,431
deployed by those charts
Fix available
1 of 3
affected packages

CVE-2026-5435 affecting package glibc 2.38-21

Carried by container images the latest versions of 2,438 of 17,805 indexed charts deploy, on 2,431 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+61 more2.35-0ubuntu3.14, 2.39-0ubuntu8.8, 2.41-12+deb13u2+e5, 2.43-2ubuntu2.32,404
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibcrpm2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3no fix listed20
OSV records
DEBIAN-CVE-2026-5435UBUNTU-CVE-2026-5435AZL-84599ECHO-53d2-a97b-142d
Also known as
USN-8611-1

Charts affected

2,438 by stars
ChartLatestAffected imagesRadar Score
hello-worldsikalabs0.17.01 of 1See more

hello-world sikalabs 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/sikalabs/hello-world-server:latestcf8538bf6489
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,215
hello-world-examplesikalabs0.1.31 of 1See more

hello-world-example sikalabs 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
sikalabs/hello-world-server:latest5f49bf889a64
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,215
kubernetes-dashboard-gatewaysikalabs0.1.01 of 1See more

kubernetes-dashboard-gateway sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,879
wordpress-mysqlsikalabs0.1.21 of 2See more

wordpress-mysql sikalabs 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

3,939
simple-websimple-webVerified publisher1.1.11 of 1See more

simple-web simple-web 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,879
bitwardensinextraVerified publisher0.10.21 of 1See more

bitwarden sinextra 0.10.2

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,785
clickhouse-keepersinextraVerified publisher0.7.21 of 1See more

clickhouse-keeper sinextra 0.7.2

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.12.6a65ca89ddbe8
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.14

Open the chart page →

2,234
fluentdsinextraVerified publisher1.4.51 of 1See more

fluentd sinextra 1.4.5

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/fluentd:1.19.33273d13f1e75
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,134
headscalesinextraVerified publisher0.1.01 of 1See more

headscale sinextra 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.29.30e7f1c6e4ce6
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

573
infisicalsinextraVerified publisher0.6.01 of 1See more

infisical sinextra 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.602082bf13163
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

3,085
mongosqldsinextraVerified publisher0.3.71 of 1See more

mongosqld sinextra 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
glibc@2.35-0ubuntu3.10
2.35-0ubuntu3.14

Open the chart page →

2,613
mongosyncsinextraVerified publisher0.4.01 of 1See more

mongosync sinextra 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
glibc@2.39-0ubuntu8.5
2.39-0ubuntu8.8

Open the chart page →

2,874
pgbouncersinextraVerified publisher0.17.01 of 1See more

pgbouncer sinextra 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/pgbouncer:16.1518f1121ba0a4
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

1,969
service-commonsinextraVerified publisher0.3.161 of 1See more

service-common sinextra 0.3.16

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/haproxy:2.8.288baa7d29a27a
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

872
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
glibc@2.31-0ubuntu9.17
no fix listed

Open the chart page →

5,912
yopasssky-sailVerified publisher1.3.12 of 2See more

yopass sky-sail 1.3.1

2 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
jhaals/yopass:12.5.0916a1cf45d36
glibc@2.36-9+deb12u13
no fix listed
library/memcached:1.6.409ae868852d0b
glibc@2.41-12
no fix listed

Open the chart page →

3,065
envoyslamdev0.0.171 of 2See more

envoy slamdev 0.0.17

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.18.2e8b37c1d7578
glibc@2.27-3ubuntu1.4
no fix listed

Open the chart page →

4,719
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
glibc@2.31-0ubuntu9.9
no fix listed

Open the chart page →

9,261
slothsloth0.16.01 of 2See more

sloth sloth 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
glibc@2.41-12
no fix listed

Open the chart page →

4,007
oi-slurm-cluster-chartslurm-cluster-chart0.25.11 of 4See more

oi-slurm-cluster-chart slurm-cluster-chart 0.25.1

1 of the 4 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
glibc@2.35-0ubuntu3.6
2.35-0ubuntu3.14

Open the chart page →

4,390
slurm-cluster-chartslurm-cluster-chart0.25.01 of 4See more

slurm-cluster-chart slurm-cluster-chart 0.25.0

1 of the 4 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
glibc@2.35-0ubuntu3.6
2.35-0ubuntu3.14

Open the chart page →

4,390
amt-configuresmarthallVerified publisher0.1.11 of 1See more

amt-configure smarthall 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
boxcutter/meshcmd:1.1.384e13f01bcab
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14

Open the chart page →

2,773
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
glibc@2.36-9+deb12u4
no fix listed

Open the chart page →

5,621
aafsmo-helm-chart6.0.01 of 14See more

aaf smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
glibc@2.23-0ubuntu11
no fix listed

Open the chart page →

79,246
aaismo-helm-chart6.0.01 of 14See more

aai smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
glibc@2.23-0ubuntu11
no fix listed

Open the chart page →

79,280
dgbuildersmo-helm-chart6.0.01 of 3See more

dgbuilder smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
glibc@2.23-0ubuntu9
no fix listed

Open the chart page →

83,918
dmaap-listenersmo-helm-chart6.0.01 of 3See more

dmaap-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
glibc@2.23-0ubuntu11
no fix listed

Open the chart page →

79,246
elasticsearchsmo-helm-chart6.0.01 of 5See more

elasticsearch smo-helm-chart 6.0.0

1 of the 5 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
glibc@2.23-0ubuntu11
no fix listed

Open the chart page →

78,253
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
glibc@2.23-0ubuntu9
no fix listed

Open the chart page →

84,670
mariadb-initsmo-helm-chart6.0.01 of 2See more

mariadb-init smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
glibc@2.23-0ubuntu11
no fix listed

Open the chart page →

78,253
msbsmo-helm-chart6.0.01 of 6See more

msb smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
glibc@2.23-0ubuntu9
no fix listed

Open the chart page →

82,925
multicloudsmo-helm-chart6.0.01 of 14See more

multicloud smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/ubuntu-init:1.0.03adf3d21ad3b
glibc@2.23-0ubuntu7
no fix listed

Open the chart page →

9,577
pndasmo-helm-chart6.0.01 of 3See more

pnda smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
glibc@2.23-0ubuntu9
no fix listed

Open the chart page →

82,925
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
glibc@2.23-0ubuntu9
no fix listed

Open the chart page →

84,670
portalsmo-helm-chart6.0.01 of 8See more

portal smo-helm-chart 6.0.0

1 of the 8 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
glibc@2.23-0ubuntu9
no fix listed

Open the chart page →

82,925
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
glibc@2.23-0ubuntu11
no fix listed

Open the chart page →

79,246
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
glibc@2.23-0ubuntu11
no fix listed

Open the chart page →

79,246
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
glibc@2.23-0ubuntu11
no fix listed

Open the chart page →

79,246
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
glibc@2.23-0ubuntu11
no fix listed

Open the chart page →

78,253
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
glibc@2.23-0ubuntu11
no fix listed

Open the chart page →

78,253
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
glibc@2.23-0ubuntu11
no fix listed

Open the chart page →

79,246
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

7,628
daemonsetsnowplow-devopsVerified publisher0.6.01 of 1See more

daemonset snowplow-devops 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,879
service-deploymentsnowplow-devopsVerified publisher0.43.01 of 1See more

service-deployment snowplow-devops 0.43.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:stablecb92301e719d
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,861
space-engineerssoblivionscall1.0.21 of 2See more

space-engineers soblivionscall 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/ubuntu:xenial1f1a2d56de1d
glibc@2.23-0ubuntu11.3
no fix listed

Open the chart page →

2,785
bootzookasoftwaremillVerified publisher0.2.11 of 2See more

bootzooka softwaremill 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
softwaremill/bootzooka:latest845b5e8f8056
glibc@2.43-2ubuntu2
2.43-2ubuntu2.3

Open the chart page →

3,117
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14

Open the chart page →

13,670
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
glibc@2.35-0ubuntu3.6
2.35-0ubuntu3.14

Open the chart page →

13,142
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
glibc@2.31-0ubuntu9.7
no fix listed

Open the chart page →

97,304
nginx-chartsongduckbae-nginx0.1.01 of 1See more

nginx-chart songduckbae-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,879

Container images carrying it

2,431 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/opstree/memcached:1.6.38-alpine3.22cabbdfd2c3fe
glibc@2.41-12+deb13u2
no fix listed
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
glibc@2.36-9+deb12u14
no fix listed
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
glibc@2.36-9+deb12u14
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
glibc@2.36-9+deb12u1
no fix listed
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
glibc@2.27-3ubuntu1.5
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8
1
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
glibc@2.36-9+deb12u14
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
glibc@2.36-9+deb12u14
no fix listed
1
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
glibc@2.36-9+deb12u14
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
glibc@2.36-9+deb12u14
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
glibc@2.41-12+deb13u3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
glibc@2.41-12+deb13u3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
glibc@2.41-12+deb13u2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
glibc@2.36-9+deb12u14
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
glibc@2.41-12+deb13u3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
glibc@2.36-9+deb12u7
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
glibc@2.41-12+deb13u3
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
glibc@2.31-0ubuntu9.2
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
glibc@2.36-9+deb12u3
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
glibc@2.36-9+deb12u13
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
glibc@2.36-9+deb12u7
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
glibc@2.41-12
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
glibc@2.36-9+deb12u3
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
glibc@2.36-9+deb12u8
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
glibc@2.36-9+deb12u13
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
glibc@2.36-9+deb12u10
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
glibc@2.36-9+deb12u10
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.