StackRadar

CVE-2026-5450

Critical

Advisory

Published 20 Apr 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,712
of 17,813 indexed, latest versions
Container images
2,893
deployed by those charts
Fix available
3 of 4
affected packages

Red Hat Security Advisory: glibc security, bug fix, and enhancement update

Carried by container images the latest versions of 2,712 of 17,813 indexed charts deploy, on 2,893 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+59 more2.35-0ubuntu3.14, 2.39-0ubuntu8.8, 2.41-12+deb13u2+e4, 2.41-12+deb13u4+1 more2,433
glibcapk2.37-r7, 2.38-r6, 2.39-r7, 2.40-r1+8 more2.43-r722
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibcrpm2.17-260.el7_6.4, 2.17-260.el7_6.6, 2.17-292.el7, 2.17-307.el7.1+60 more0:2.17-326.el7_9.6, 0:2.28-251.el8_10.38, 0:2.34-272.el9_8, 0:2.39-126.el10_2431
OSV records
CGA-3qwq-5w83-3j3qDEBIAN-CVE-2026-5450UBUNTU-CVE-2026-5450RHSA-2026:33092RHSA-2026:33126RHSA-2026:33226RHSA-2026:34211RLSA-2026:33126RLSA-2026:33226AZL-83093ECHO-56eb-505f-7a61
Also known as
CGA-76f7-m58j-73wj, CGA-7x3v-c6pf-4v43, CGA-88p4-5g7h-3xrh, CGA-g425-f69f-xj8j, CGA-hq3x-5xh3-92jc, CGA-j9xg-mq3r-jh83, CGA-jgfr-5wmr-hfpc, CGA-mvj4-3q5f-wmwg, CGA-p427-94gh-pr7p, CGA-p7rp-4rm4-hg9q, CGA-qj6g-5h8p-677v, CGA-vc3j-8vcq-8pqc, CGA-vv29-hp4w-2hrw, CGA-wxx7-6vh7-9qhv, CGA-xrvh-57r4-pjhh, RHSA-2026:33227, RHSA-2026:33228, RHSA-2026:33229, RHSA-2026:33230, RHSA-2026:33231, RHSA-2026:36643, USN-8611-1

Charts affected

2,712 by stars
ChartLatestAffected imagesRadar Score
pgcatxxl-job-adminVerified publisher0.3.31 of 1See more

pgcat xxl-job-admin 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
glibc@2.36-9+deb12u7
no fix listed

Open the chart page →

3,196
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

1,956
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

1,338
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

1,956
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
glibc@2.36-9+deb12u4
no fix listed

Open the chart page →

2,718
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
glibc@2.27-3ubuntu1.6
no fix listed

Open the chart page →

2,485
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
glibc@2.28-211.el8
0:2.28-251.el8_10.38

Open the chart page →

6,026
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
glibc@2.28-211.el8
0:2.28-251.el8_10.38

Open the chart page →

3,700
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

2,697
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

493
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

1,956
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
glibc@2.27-3ubuntu1.4
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

9,296

Container images carrying it

2,893 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
glibc@2.35-0ubuntu3.9
2.35-0ubuntu3.14
1
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
glibc@2.34-270.el9_8
0:2.34-272.el9_8
1
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
glibc@2.34-270.el9_8
0:2.34-272.el9_8
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
glibc@2.34-231.el9_7.2
0:2.34-272.el9_8
1
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
glibc@2.34-270.el9_8
0:2.34-272.el9_8
1
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
glibc@2.34-270.el9_8
0:2.34-272.el9_8
1
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
glibc@2.34-270.el9_8
0:2.34-272.el9_8
1
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal:10.0.0d352df1b94b6
glibc@2.34-270.el9_8
0:2.34-272.el9_8
1
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
glibc@2.34-168.el9_6.23
0:2.34-272.el9_8
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
glibc@2.34-83.el9_3.12
0:2.34-272.el9_8
1
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
glibc@2.34-270.el9_8
0:2.34-272.el9_8
1
ghcr.io/itobey/playlist-mirror:1.0.0601082677a46
glibc@2.41-12+deb13u3
2.41-12+deb13u4
1
ghcr.io/jaydee94/kubeseal-webgui/api:4.5.33cceb9462ae1
glibc@2.36-9+deb12u10
no fix listed
1
ghcr.io/jellyfin/jellyfin:10.11.1145f648c382a0
glibc@2.41-12+deb13u3
2.41-12+deb13u4
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
glibc@2.28-101.el8
0:2.28-251.el8_10.38
1
ghcr.io/jensholdgaard/ourios:latest3d87d932391d
glibc@2.36-9+deb12u14
no fix listed
1
ghcr.io/jeremylvln/shulker-operator:0.13.027c55706c126
glibc@2.36-9+deb12u10
no fix listed
1
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
glibc@2.27-3ubuntu1.6
no fix listed
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
1
ghcr.io/jlclx/runtimeclass-controller:latestb3a87f92a963
glibc@2.36-9+deb12u8
no fix listed
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
glibc@2.36-9+deb12u9
no fix listed
1
ghcr.io/jossware/node-provider-labeler:v0.8.0f80e85291439
glibc@2.36-9+deb12u7
no fix listed
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
glibc@2.31-0ubuntu9.2
no fix listed
1
ghcr.io/juanfont/headscale:0.29.3-debug842cd94b754b
glibc@2.41-12+deb13u3
2.41-12+deb13u4
1
ghcr.io/juanfont/headscale:0.29.18453e47ea6bf
glibc@2.41-12+deb13u3
2.41-12+deb13u4
1
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
glibc@2.36-9+deb12u9
no fix listed
1
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
glibc@2.36-9+deb12u9
no fix listed
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
glibc@2.31-0ubuntu9.9
no fix listed
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
glibc@2.31-0ubuntu9.2
no fix listed
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
glibc@2.31-0ubuntu9.2
no fix listed
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
glibc@2.31-0ubuntu9.2
no fix listed
1
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
glibc@2.31-0ubuntu9.9
no fix listed
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
glibc@2.31-0ubuntu9.2
no fix listed
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
glibc@2.31-0ubuntu9.2
no fix listed
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
glibc@2.31-0ubuntu9.2
no fix listed
1
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
glibc@2.31-0ubuntu9.9
no fix listed
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
glibc@2.31-0ubuntu9.7
no fix listed
1
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
glibc@2.31-0ubuntu9.7
no fix listed
1
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14
1
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
glibc@2.31-0ubuntu9.2
no fix listed
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
glibc@2.31-0ubuntu9.2
no fix listed
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
glibc@2.31-0ubuntu9.2
no fix listed
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
glibc@2.31-0ubuntu9.9
no fix listed
1
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
glibc@2.31-0ubuntu9.2
no fix listed
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
glibc@2.31-0ubuntu9.7
no fix listed
1
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
glibc@2.31-0ubuntu9.9
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.