StackRadar

CVE-2026-5435

High

Advisory

Published 28 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,490
of 17,813 indexed, latest versions
Container images
2,522
deployed by those charts
Fix available
1 of 3
affected packages

CVE-2026-5435 affecting package glibc 2.38-21

Carried by container images the latest versions of 2,490 of 17,813 indexed charts deploy, on 2,522 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+61 more2.35-0ubuntu3.14, 2.39-0ubuntu8.8, 2.41-12+deb13u2+e5, 2.43-2ubuntu2.32,496
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibcrpm2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3no fix listed19
OSV records
DEBIAN-CVE-2026-5435UBUNTU-CVE-2026-5435AZL-84599ECHO-53d2-a97b-142d
Also known as
USN-8611-1

Charts affected

2,490 by stars
ChartLatestAffected imagesRadar Score
quarterdeckrotationalVerified publisher0.16.01 of 1See more

quarterdeck rotational 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
rotationalio/quarterdeck:0.16.00e7ad3a031dc
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

1,193
rotational-apirotationalVerified publisher1.3.11 of 1See more

rotational-api rotational 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
rotationalio/rotational-api:1.3.0f1a2d05d8fff
glibc@2.41-12+deb13u1
no fix listed

Open the chart page →

1,620
vanityrotationalVerified publisher1.2.21 of 1See more

vanity rotational 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
rotationalio/vanity:1.2.0d77350f69b45
glibc@2.41-12+deb13u1
no fix listed

Open the chart page →

1,250
routehub-serverroutehub-helm1.0.12 of 3See more

routehub-server routehub-helm 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
glibc@2.31-0ubuntu9.12
no fix listed
library/postgres:latest4ef4dbc939d6
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

7,023
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

3,597
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

4,804
prepull-daemonsetrstudioVerified publisher0.0.51 of 2See more

prepull-daemonset rstudio 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/ubuntu:bionic152dc042452c
glibc@2.27-3ubuntu1.6
no fix listed

Open the chart page →

1,740
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
glibc@2.35-0ubuntu3.13
2.35-0ubuntu3.14

Open the chart page →

7,820
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
glibc@2.41-12
no fix listed

Open the chart page →

10,845
cloudflare-tunnelrubxkubeVerified publisher0.3.31 of 1See more

cloudflare-tunnel rubxkube 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.6.16d91c121b803
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

638
flaresolverrrubxkubeVerified publisher0.1.11 of 1See more

flaresolverr rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

27,938
jellyfinrubxkubeVerified publisher1.3.11 of 1See more

jellyfin rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

2,672
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

7,518
linkdingrubxkubeVerified publisher1.2.41 of 1See more

linkding rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.47.0e35cb50e0581
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

2,101
simple-coffeerubxkubeVerified publisher0.1.01 of 1See more

simple-coffee rubxkube 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

2,596
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8

Open the chart page →

6,346
trmnl-serverrubxkubeVerified publisher0.1.01 of 2See more

trmnl-server rubxkube 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/python:3.14-slimcad9a2c87176
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

2,959
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

30,899
vaultwardenrubxkubeVerified publisher1.2.41 of 1See more

vaultwarden rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,792
your-spotifyrubxkubeVerified publisher1.0.11 of 3See more

your-spotify rubxkube 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:latestb0652af9c8d0
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

5,476
runwhen-localrunwhen-contribVerified publisher0.6.171 of 3See more

runwhen-local runwhen-contrib 0.6.17

1 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

3,842
rybbitrybbit-helm1.3.21 of 7See more

rybbit rybbit-helm 1.3.2

1 of the 7 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
valkey/valkey:9.1.164e361b630ec
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

6,225
janitorrryuunosukeds30.1.31 of 1See more

janitorr ryuunosukeds3 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/schaka/janitorr:native-stable7cfe1e0c41da
glibc@2.39-0ubuntu8.5
2.39-0ubuntu8.8

Open the chart page →

1,012
nadekobotryuunosukeds30.1.21 of 2See more

nadekobot ryuunosukeds3 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.14

Open the chart page →

8,822
orbitalryuunosukeds30.2.01 of 1See more

orbital ryuunosukeds3 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ryuunosukeds3/orbital:latest0879f7261b10
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

2,706
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
glibc@2.41-12
no fix listed

Open the chart page →

9,879
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
glibc@2.35-0ubuntu3.13
2.35-0ubuntu3.14

Open the chart page →

7,496
test-helm-app1saam-helm-test0.1.01 of 1See more

test-helm-app1 saam-helm-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
hamidyousefi93/saam-test:latestc34f071f6ed0
glibc@2.36-9+deb12u3
no fix listed

Open the chart page →

3,957
hivechart-1sabryp3-charts0.2.01 of 2See more

hivechart-1 sabryp3-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
valkey/valkey:latestc123e3715db6
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

861
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,637
safe-stacksafe-global0.1.03 of 9See more

safe-stack safe-global 0.1.0

3 of the 9 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
glibc@2.36-9
no fix listed
safeglobal/safe-config-service:latest09a5e495c219
glibc@2.41-12+deb13u3
no fix listed
safeglobal/safe-transaction-service:latest80db836cc5d5
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

19,929
safe-transaction-servicesafe-global0.1.02 of 6See more

safe-transaction-service safe-global 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
glibc@2.36-9
no fix listed
safeglobal/safe-transaction-service:latest80db836cc5d5
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

16,923
sagawisesagawiseVerified publisher0.1.01 of 3See more

sagawise sagawise 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
venturenox/redis:latest83b471c193ba
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

4,395
fmtok8s-agenda-servicesalaboy0.1.21 of 2See more

fmtok8s-agenda-service salaboy 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-agenda-service:v0.0.1-native6c5efe150958
glibc@2.27-3ubuntu1.6
no fix listed

Open the chart page →

2,615
fmtok8s-c4p-servicesalaboy0.1.11 of 2See more

fmtok8s-c4p-service salaboy 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-c4p-service:v0.0.1-native3f7cc45fd20b
glibc@2.27-3ubuntu1.6
no fix listed

Open the chart page →

2,615
fmtok8s-conference-chartsalaboy0.1.44 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

4 of the 6 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-agenda-service:v0.0.1-native6c5efe150958
glibc@2.27-3ubuntu1.6
no fix listed
ghcr.io/salaboy/fmtok8s-c4p-service:v0.0.1-native3f7cc45fd20b
glibc@2.27-3ubuntu1.6
no fix listed
ghcr.io/salaboy/fmtok8s-email-service:v0.1.0-nativecf28472bc460
glibc@2.27-3ubuntu1.6
no fix listed
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
glibc@2.35-0ubuntu3
2.35-0ubuntu3.14

Open the chart page →

16,312
fmtok8s-email-servicesalaboy0.2.01 of 1See more

fmtok8s-email-service salaboy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-email-service:v0.2.0-nativeb52d5dbac2ca
glibc@2.27-3ubuntu1.6
no fix listed

Open the chart page →

2,917
fmtok8s-frontendsalaboy0.1.31 of 1See more

fmtok8s-frontend salaboy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
glibc@2.35-0ubuntu3
2.35-0ubuntu3.14

Open the chart page →

8,165
pagessamanvithkaranth1.0.02 of 3See more

pages samanvithkaranth 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
glibc@2.31-0ubuntu9.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
glibc@2.27-3ubuntu1
no fix listed

Open the chart page →

20,285
evsantisbon0.2.02 of 5See more

ev santisbon 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
santisbon/evwatcher:latestc4e994ca4540
glibc@2.36-9+deb12u1
no fix listed
santisbon/evworker:lateste807283f8d69
glibc@2.36-9+deb12u1
no fix listed

Open the chart page →

14,532
speedtestsantisbon0.1.02 of 3See more

speedtest santisbon 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
glibc@2.36-9+deb12u13
no fix listed
santisbon/speedtest:latest8ee3a1697227
glibc@2.36-9+deb12u1
no fix listed

Open the chart page →

12,923
pagessarubits-pages1.0.02 of 3See more

pages sarubits-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
glibc@2.31-0ubuntu9.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
glibc@2.27-3ubuntu1
no fix listed

Open the chart page →

20,285
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
glibc@2.36-9+deb12u4
no fix listed

Open the chart page →

10,308
jellyfinsb-helm-charts0.4.01 of 1See more

jellyfin sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.317c3a8d9dddb
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

4,179
mlflowsb-helm-charts0.3.01 of 1See more

mlflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/python:3.11-slim9534e5a8e315
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

942
mongodbsb-helm-charts0.4.01 of 1See more

mongodb sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/mongo:7.0.140032d2ca20db
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.14

Open the chart page →

4,118
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
glibc@2.41-12
no fix listed

Open the chart page →

10,002
phpmyadminsb-helm-charts0.3.01 of 1See more

phpmyadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

5,455
postgresqlsb-helm-charts0.4.01 of 1See more

postgresql sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
library/postgres:16.11468e1f126ca5
glibc@2.41-12+deb13u1
no fix listed

Open the chart page →

2,448
promtailsb-helm-charts0.4.01 of 1See more

promtail sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-5435.

Container imageDigestPackageFixed in
grafana/promtail:3.6.18dcfdf466da0
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.8

Open the chart page →

2,295

Container images carrying it

2,522 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.0696d798a5c85
glibc@2.41-12+deb13u3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabdc1a8972c640
glibc@2.36-9+deb12u14
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.26645e014f75d
glibc@2.41-12+deb13u4
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-kas:v19.4.08ae8be4645ce
glibc@2.41-12+deb13u4
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
glibc@2.41-12+deb13u3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3aca1bb3d5b7e
glibc@2.41-12+deb13u3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.02256b49461fa
glibc@2.41-12+deb13u3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
glibc@2.41-12+deb13u3
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
glibc@2.31-0ubuntu9.2
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
glibc@2.36-9+deb12u3
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
glibc@2.36-9+deb12u13
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
glibc@2.36-9+deb12u7
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
glibc@2.41-12
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
glibc@2.36-9+deb12u3
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
glibc@2.36-9+deb12u8
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
glibc@2.36-9+deb12u13
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
glibc@2.36-9+deb12u10
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
glibc@2.36-9+deb12u10
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.