StackRadar

CVE-2026-5450

Critical

Advisory

Published 20 Apr 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,717
of 17,781 indexed, latest versions
Container images
2,882
deployed by those charts
Fix available
3 of 4
affected packages

Red Hat Security Advisory: glibc security, bug fix, and enhancement update

Carried by container images the latest versions of 2,717 of 17,781 indexed charts deploy, on 2,882 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+59 more2.35-0ubuntu3.14, 2.39-0ubuntu8.8, 2.41-12+deb13u2+e4, 2.41-12+deb13u4+1 more2,414
glibcapk2.37-r7, 2.38-r6, 2.39-r7, 2.40-r1+8 more2.43-r722
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibcrpm2.17-260.el7_6.4, 2.17-260.el7_6.6, 2.17-292.el7, 2.17-307.el7.1+59 more0:2.17-326.el7_9.6, 0:2.28-251.el8_10.38, 0:2.34-272.el9_8, 0:2.39-126.el10_2439
OSV records
CGA-3qwq-5w83-3j3qDEBIAN-CVE-2026-5450UBUNTU-CVE-2026-5450RHSA-2026:33092RHSA-2026:33126RHSA-2026:33226RHSA-2026:34211RLSA-2026:33126RLSA-2026:33226AZL-83093ECHO-56eb-505f-7a61
Also known as
CGA-76f7-m58j-73wj, CGA-7x3v-c6pf-4v43, CGA-88p4-5g7h-3xrh, CGA-g425-f69f-xj8j, CGA-hq3x-5xh3-92jc, CGA-j9xg-mq3r-jh83, CGA-jgfr-5wmr-hfpc, CGA-mvj4-3q5f-wmwg, CGA-p427-94gh-pr7p, CGA-p7rp-4rm4-hg9q, CGA-qj6g-5h8p-677v, CGA-vc3j-8vcq-8pqc, CGA-vv29-hp4w-2hrw, CGA-wxx7-6vh7-9qhv, CGA-xrvh-57r4-pjhh, RHSA-2026:33227, RHSA-2026:33228, RHSA-2026:33229, RHSA-2026:33230, RHSA-2026:33231, RHSA-2026:36643, USN-8611-1

Charts affected

2,717 by stars
ChartLatestAffected imagesRadar Score
stalwart-mailstalwart-mailVerified publisher2.0.101 of 1See more

stalwart-mail stalwart-mail 2.0.10

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
stalwartlabs/stalwart:v0.16.2074ca4f7f6885
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

1,403
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
glibc@2.27-3ubuntu1.2
no fix listed

Open the chart page →

15,592
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
glibc@2.31-0ubuntu9.7
no fix listed

Open the chart page →

7,880
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
glibc@2.28-151.el8
0:2.28-251.el8_10.38

Open the chart page →

6,854
glasskube-operatorglasskubeOfficialVerified publisher0.12.23 of 3See more

glasskube-operator glasskube 0.12.2

3 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
glibc@2.35-0ubuntu3.4
2.35-0ubuntu3.14
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
glibc@2.28-225.el8
0:2.28-251.el8_10.38
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
glibc@2.28-225.el8
0:2.28-251.el8_10.38

Open the chart page →

11,933
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

5,352
plane-cemakeplaneOfficialVerified publisher1.8.12 of 11See more

plane-ce makeplane 1.8.1

2 of the 11 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
glibc@2.34-168.el9_6.23
0:2.34-272.el9_8
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
glibc@2.34-168.el9_6.23
0:2.34-272.el9_8

Open the chart page →

4,854
milvusmilvus-helm5.0.273 of 4See more

milvus milvus-helm 5.0.27

3 of the 4 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.14
milvusdb/etcd:3.5.25-r1fededb2f2d63
glibc@2.35-0ubuntu3.11
2.35-0ubuntu3.14
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
glibc@2.34-125.el9_5.1
0:2.34-272.el9_8

Open the chart page →

10,670
prefect-serverprefectVerified publisher2026.9.32126052 of 2See more

prefect-server prefect 2026.9.3212605

2 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
glibc@2.36-9+deb12u9
no fix listed
prefecthq/prefect:3.8.5-python3.110018d02259bc
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

5,786
rocketmqrocketmq12.6.02 of 2See more

rocketmq rocketmq 12.6.0

2 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
glibc@2.34-168.el9_6.23
0:2.34-272.el9_8

Open the chart page →

6,328
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
glibc@2.31-0ubuntu9.9
no fix listed

Open the chart page →

18,509
apicurio-registryapicurio-registry-helmVerified publisher3.8.01 of 2See more

apicurio-registry apicurio-registry-helm 3.8.0

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
glibc@2.28-236.el8.7
0:2.28-251.el8_10.38

Open the chart page →

6,675
codefreshcodefresh-onpremOfficialVerified publisher2.12.134 of 42See more

codefresh codefresh-onprem 2.12.13

4 of the 42 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
glibc@2.36-9+deb12u10
no fix listed
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
glibc@2.36-9+deb12u8
no fix listed
bitnamilegacy/rabbitmq:4.1.39e635efba431
glibc@2.36-9+deb12u10
no fix listed
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

14,956
apim3graviteeioVerified publisher4.12.192 of 4See more

apim3 graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
glibc@2.41-12+deb13u3
2.41-12+deb13u4
graviteeio/apim-management-api:4.12.19-debian27374522cd04
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

4,806
redisgroundhog2k2.4.71 of 1See more

redis groundhog2k 2.4.7

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

955
wordpressgroundhog2k0.16.41 of 1See more

wordpress groundhog2k 0.16.4

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

3,685
velero-uiotwldVerified publisher0.15.01 of 1See more

velero-ui otwld 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
otwld/velero-ui:0.10.2d1954b759e47
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

1,332
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
glibc@2.31-0ubuntu9.12
no fix listed
stackstorm/st2api:3.86f56d239d280
glibc@2.31-0ubuntu9.12
no fix listed
stackstorm/st2auth:3.833ecfda16608
glibc@2.31-0ubuntu9.12
no fix listed
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
glibc@2.31-0ubuntu9.12
no fix listed
stackstorm/st2notifier:3.8f190a6212195
glibc@2.31-0ubuntu9.12
no fix listed
stackstorm/st2rulesengine:3.8259503496ff9
glibc@2.31-0ubuntu9.12
no fix listed
stackstorm/st2scheduler:3.8b1de2055c362
glibc@2.31-0ubuntu9.12
no fix listed
stackstorm/st2sensorcontainer:3.8b1a338f64773
glibc@2.31-0ubuntu9.12
no fix listed
stackstorm/st2stream:3.81c8904a3bf67
glibc@2.31-0ubuntu9.12
no fix listed
stackstorm/st2timersengine:3.81bf35bfaf00c
glibc@2.31-0ubuntu9.12
no fix listed
stackstorm/st2web:3.809989a26c8b7
glibc@2.31-0ubuntu9.12
no fix listed
stackstorm/st2workflowengine:3.819fdfffdbba8
glibc@2.31-0ubuntu9.12
no fix listed

Open the chart page →

96,419
supabasetokens-studioVerified publisher1.0.05 of 14See more

supabase tokens-studio 1.0.0

5 of the 14 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
supabase/edge-runtime:v1.59.0eff9c554d649
glibc@2.36-9+deb12u8
no fix listed
supabase/postgres-meta:v0.84.2d0a96973e9f1
glibc@2.36-9+deb12u8
no fix listed
supabase/realtime:v2.33.8d207e6e23ad3
glibc@2.36-9+deb12u8
no fix listed
supabase/studio:20241021-9f9b08326d8070c55e9
glibc@2.36-9+deb12u8
no fix listed

Open the chart page →

23,123
wekanwekanVerified publisher11.76.01 of 3See more

wekan wekan 11.76.0

1 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/wekan/ferretdb:latest6cb94aa01999
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

1,576
polarisapache-polarisOfficialVerified publisher1.3.0-incubating1 of 1See more

polaris apache-polaris 1.3.0-incubating

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
apache/polaris:lateste66366e783f1
glibc@2.34-270.el9_8
0:2.34-272.el9_8

Open the chart page →

455
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
glibc@2.36-9+deb12u7
no fix listed
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

8,493
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8

Open the chart page →

1,710
budibasebudibase0.0.0-master4 of 7See more

budibase budibase 0.0.0-master

4 of the 7 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
glibc@2.36-9+deb12u13
no fix listed
budibase/proxy:3.41.38d780b6ee602
glibc@2.41-12+deb13u3
2.41-12+deb13u4
library/redis:latest298e5b3bc566
glibc@2.41-12+deb13u3
2.41-12+deb13u4
minio/minio:latest14cea493d9a3
glibc@2.34-168.el9_6.23
0:2.34-272.el9_8

Open the chart page →

10,775
csi-secrets-store-provider-azurecsi-secrets-store-provider-azureVerified publisher1.8.25 of 5See more

csi-secrets-store-provider-azure csi-secrets-store-provider-azure 1.8.2

5 of the 5 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.8.2f21fca343428
glibc@2.38-20.azl3
no fix listed
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.14.06cb172e3de7e
glibc@2.38-20.azl3
no fix listed
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.15.059b9d0348428
glibc@2.38-18.azl3
no fix listed
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.65f91243cfd60
glibc@2.38-20.azl3
no fix listed
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver-crds:v1.5.6cb0112636dc4
glibc@2.38-20.azl3
no fix listed

Open the chart page →

2,235
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

3,812
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14

Open the chart page →

3,454
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

3,025
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14

Open the chart page →

7,857
cassandrakubelauncherVerified publisher0.1.271 of 1See more

cassandra kubelauncher 0.1.27

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/cassandradigest-pinnedb66aba320083
glibc@2.43-2ubuntu2
2.43-2ubuntu2.3

Open the chart page →

1,442
mongodbkubelauncherVerified publisher0.4.51 of 1See more

mongodb kubelauncher 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mongodbdigest-pinned9bc37ed78a8b
glibc@2.43-2ubuntu2
2.43-2ubuntu2.3

Open the chart page →

1,342
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.8

Open the chart page →

1,240
rediskubelauncherVerified publisher0.5.11 of 1See more

redis kubelauncher 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/redisdigest-pinnedbcd8e9a6224f
glibc@2.43-2ubuntu2
2.43-2ubuntu2.3

Open the chart page →

770
purelbpurelb0.0.0-106-ipv6-lbip-052cedab1 of 2See more

purelb purelb 0.0.0-106-ipv6-lbip-052cedab

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
glibc@2.28-164.el8_5.3
0:2.28-251.el8_10.38

Open the chart page →

4,413
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
glibc@2.36-9+deb12u7
no fix listed

Open the chart page →

3,480
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

11,405
zillazillaOfficialVerified publisher2.4.21 of 1See more

zilla zilla 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/aklivity/zilla:2.4.289c4a2e74863
glibc@2.35-0ubuntu3.13
2.35-0ubuntu3.14

Open the chart page →

1,698
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

2,938
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
glibc@2.35-0ubuntu3.5
2.35-0ubuntu3.14

Open the chart page →

4,244
yopasscloudhippieVerified publisher9.15.91 of 1See more

yopass cloudhippie 9.15.9

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
jhaals/yopass:14.9.0934e4f2c016f
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

421
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

3,012
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
glibc@2.36-9+deb12u3
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
quay.io/devtron/postgres:14.91b594392f7cb
glibc@2.36-9+deb12u3
no fix listed

Open the chart page →

32,902
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.8

Open the chart page →

3,606
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
glibc@2.39-0ubuntu8.1
2.39-0ubuntu8.8

Open the chart page →

5,357
nextcloudgroundhog2k0.22.51 of 3See more

nextcloud groundhog2k 0.22.5

1 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

4,507
envoy-gatewayhelmforgeVerified publisher2.1.02 of 3See more

envoy-gateway helmforge 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
envoyproxy/gateway:v1.9.10049bcb384c5
glibc@2.41-12+deb13u3
2.41-12+deb13u4
mccutchen/go-httpbin:v2.15.024528cf5229d
glibc@2.36-9+deb12u8
no fix listed

Open the chart page →

2,379
ilumilumOfficialVerified publisher6.7.35 of 19See more

ilum ilum 6.7.3

5 of the 19 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
glibc@2.36-9+deb12u9
no fix listed
bitnamilegacy/postgresql:16233f361c5819
glibc@2.36-9+deb12u9
no fix listed
ilum/api:6.7.3624fd09528c8
glibc@2.41-12+deb13u3
2.41-12+deb13u4
ilum/marquez:0.54.06e1d709d41f8
glibc@2.36-9+deb12u13
no fix listed
minio/mc:RELEASE.2025-04-16T18-13-26Zaead63c77f9d
glibc@2.34-125.el9_5.3
0:2.34-272.el9_8

Open the chart page →

23,228
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8

Open the chart page →

3,395
lakekeeperlakekeeperVerified publisher0.12.02 of 2See more

lakekeeper lakekeeper 0.12.0

2 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
glibc@2.41-12+deb13u3
2.41-12+deb13u4
quay.io/lakekeeper/catalog:v0.13.3db2ba6168eb1
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

1,918
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
glibc@2.36-9+deb12u10
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

7,007

Container images carrying it

2,882 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
apache/nifi-registry:1.27.063b8e3e40742
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.14
1
apache/polaris:lateste66366e783f1
glibc@2.34-270.el9_8
0:2.34-272.el9_8
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
glibc@2.31-0ubuntu9.2
no fix listed
1
apachepulsar/pulsar:3.0.79c9947de139d
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.14
1
apachepulsar/pulsar:2.9.0d056c89b7131
glibc@2.31-0ubuntu9.2
no fix listed
1
apachepulsar/pulsar:2.8.2d538416d5afe
glibc@2.31-0ubuntu9.2
no fix listed
1
apache/ranger:2.7.076c176e8a0e4
glibc@2.35-0ubuntu3.10
2.35-0ubuntu3.14
1
apache/rocketmq:5.3.0434d8398f996
glibc@2.39-0ubuntu8.2
2.39-0ubuntu8.8
1
apache/rocketmq-exporter:0.0.2c8fb51195444
glibc@2.35-0ubuntu3.6
2.35-0ubuntu3.14
1
apache/skywalking-oap-server:9.2.0133d35d2c263
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
glibc@2.31-0ubuntu9.2
no fix listed
1
apache/skywalking-ui:9.2.0295f1dc87d98
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14
1
apache/skywalking-ui:8.9.180530f0308a5
glibc@2.31-0ubuntu9.2
no fix listed
1
apache/superset:4.0.1ab9467fd712c
glibc@2.36-9+deb12u6
no fix listed
1
apache/tika:3.3.1.090b7fa1dc018
glibc@2.43-2ubuntu2
2.43-2ubuntu2.3
1
apache/tika:2.9.0.092d055a84e9e
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
glibc@2.41-12
2.41-12+deb13u4
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
glibc@2.34-231.el9_7.2
0:2.34-272.el9_8
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
glibc@2.28-225.el8_8.6
0:2.28-251.el8_10.38
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
glibc@2.28-151.el8
0:2.28-251.el8_10.38
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
glibc@2.28-225.el8
0:2.28-251.el8_10.38
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
glibc@2.28-225.el8
0:2.28-251.el8_10.38
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
glibc@2.28-225.el8
0:2.28-251.el8_10.38
1
archivebox/archivebox:0.7.41a5a37331091
glibc@2.36-9+deb12u14
no fix listed
1
arilot/docker-bitcoind:0.17.127a4f7e0f9f1
glibc@2.23-0ubuntu10
no fix listed
1
aristidetm/basic-notebook:3.6.5469dbc951224
glibc@2.36-9+deb12u7
no fix listed
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
glibc@2.36-9+deb12u7
no fix listed
1
artifacthub/tracker:v1.23.05368d21a6e5c
glibc@2.41-12+deb13u3
2.41-12+deb13u4
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
glibc@2.36-9+deb12u7
no fix listed
1
arunvelsriram/utils:latest655ad18fd8d6
glibc@2.39-0ubuntu8.5
2.39-0ubuntu8.8
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
glibc@2.31-0ubuntu9.12
no fix listed
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
glibc@2.31-0ubuntu9.9
no fix listed
1
assistiot/identity-manager_db:latest0d3e6d35f168
glibc@2.36-9+deb12u3
no fix listed
1
assistiot/identity-manager_kc:latest0df4b4fa899a
glibc@2.28-189.5.el8_6
0:2.28-251.el8_10.38
1
assistiot/location_processing:lateste9bae124095f
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14
1
assistiot/open_api_backend:1.1.230812ba93555
glibc@2.35-0ubuntu3.5
2.35-0ubuntu3.14
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
glibc@2.31-0ubuntu9.9
no fix listed
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
glibc@2.36-9+deb12u4
no fix listed
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
glibc@2.36-9+deb12u4
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
glibc@2.36-9+deb12u1
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
glibc@2.31-0ubuntu9.9
no fix listed
1
athou/commafeed:6.2.0-postgresql5e388351df1a
glibc@2.41-12+deb13u1
2.41-12+deb13u4
1
atlassian/confluence-server:7.10.03b9222ab32ef
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14
1
atlassian/jira-software:8.14.037bc46cbec1a
glibc@2.35-0ubuntu3.6
2.35-0ubuntu3.14
1
atlassian/jira-software:9.7.264a75aa4ec4e
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.8
1
avaprotocol/ap-avs:1.2.0c430ea5c37d6
glibc@2.36-9+deb12u7
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
glibc@2.36-9
no fix listed
1
avzini/web-app:latestf40b30210ed0
glibc@2.36-9+deb12u3
no fix listed
1
baserow/backend:2.3.37c00549b3a6f
glibc@2.41-12+deb13u3
2.41-12+deb13u4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.