StackRadar

CVE-2026-5450

Critical

Advisory

Published 20 Apr 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,639
of 17,828 indexed, latest versions
Container images
2,901
deployed by those charts
Fix available
3 of 4
affected packages

Red Hat Security Advisory: glibc security, bug fix, and enhancement update

Carried by container images the latest versions of 2,639 of 17,828 indexed charts deploy, on 2,901 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+59 more2.35-0ubuntu3.14, 2.39-0ubuntu8.8, 2.41-12+deb13u2+e4, 2.41-12+deb13u4+1 more2,445
glibcapk2.37-r7, 2.38-r6, 2.39-r7, 2.40-r1+8 more2.43-r722
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibcrpm2.17-260.el7_6.4, 2.17-260.el7_6.6, 2.17-292.el7, 2.17-307.el7.1+60 more0:2.17-326.el7_9.6, 0:2.28-251.el8_10.38, 0:2.34-272.el9_8, 0:2.39-126.el10_2427
OSV records
CGA-3qwq-5w83-3j3qDEBIAN-CVE-2026-5450UBUNTU-CVE-2026-5450RHSA-2026:33092RHSA-2026:33126RHSA-2026:33226RHSA-2026:34211RLSA-2026:33126RLSA-2026:33226AZL-83093ECHO-56eb-505f-7a61
Also known as
CGA-76f7-m58j-73wj, CGA-7x3v-c6pf-4v43, CGA-88p4-5g7h-3xrh, CGA-g425-f69f-xj8j, CGA-hq3x-5xh3-92jc, CGA-j9xg-mq3r-jh83, CGA-jgfr-5wmr-hfpc, CGA-mvj4-3q5f-wmwg, CGA-p427-94gh-pr7p, CGA-p7rp-4rm4-hg9q, CGA-qj6g-5h8p-677v, CGA-vc3j-8vcq-8pqc, CGA-vv29-hp4w-2hrw, CGA-wxx7-6vh7-9qhv, CGA-xrvh-57r4-pjhh, RHSA-2026:33227, RHSA-2026:33228, RHSA-2026:33229, RHSA-2026:33230, RHSA-2026:33231, RHSA-2026:36643, USN-8611-1

Charts affected

2,639 by stars
ChartLatestAffected imagesRadar Score
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

13,827
redminemt1905027.3.41 of 3See more

redmine mt190502 7.3.4

1 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/redmine:6.1.204ac44a2595b
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

7,204
n3uronn3uronVerified publisher0.3.51 of 1See more

n3uron n3uron 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
n3uronhub/n3uron:v1.22.4423a0bdd9cb9
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

1,929
satisfactorynaj981.1.11 of 1See more

satisfactory naj98 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.1199be1064b18
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.14

Open the chart page →

3,775
clowder2ncsaVerified publisher1.9.75 of 12See more

clowder2 ncsa 1.9.7

5 of the 12 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
glibc@2.36-9+deb12u4
no fix listed
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
glibc@2.36-9+deb12u4
no fix listed
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
glibc@2.36-9+deb12u13
no fix listed
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
glibc@2.36-9+deb12u13
no fix listed
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

37,915
netobserv-operatornetobservOfficialVerified publisher1.12.01 of 1See more

netobserv-operator netobserv 1.12.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
quay.io/netobserv/network-observability-operator:1.12.0-communityb05d21a015b0
glibc@2.34-270.el9_8
0:2.34-272.el9_8

Open the chart page →

370
cloud9nicholaswildeVerified publisher1.0.01 of 1See more

cloud9 nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
linuxserver/cloud9:version-1.29.245c5fe102ff3
glibc@2.27-3ubuntu1.5
no fix listed

Open the chart page →

11,757
papermergenicholaswildeVerified publisher1.0.21 of 1See more

papermerge nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/papermerge:version-v2.0.198ba2dd3f0bd
glibc@2.31-0ubuntu9.7
no fix listed

Open the chart page →

20,368
writefreelynicholaswildeVerified publisher1.0.01 of 1See more

writefreely nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/writefreely:version-0.13.1c3c8481b7e56
glibc@2.27-3ubuntu1.4
no fix listed

Open the chart page →

8,130
node-provider-labelernode-provider-labelerVerified publisher0.20.01 of 1See more

node-provider-labeler node-provider-labeler 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/jossware/node-provider-labeler:v0.8.0f80e85291439
glibc@2.36-9+deb12u7
no fix listed

Open the chart page →

1,118
helm-composenousefreakVerified publisher0.1.31 of 2See more

helm-compose nousefreak 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/mariadb:10.8.2-focal490f01279be1
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

13,684
nvidia-gpu-exporternvidia-gpu-exporterVerified publisher2.15.11 of 1See more

nvidia-gpu-exporter nvidia-gpu-exporter 2.15.1

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
utkuozdemir/nvidia_gpu_exporter:1.15.17aee2d42836a
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

279
octopuso7studios-octopus-helm-chartsOfficialVerified publisher1.2.31 of 5See more

octopus o7studios-octopus-helm-charts 1.2.3

1 of the 5 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
percona/percona-server-mongodb-operator:1.20.1d09453ce7886
glibc@2.34-168.el9_6.14
0:2.34-272.el9_8

Open the chart page →

6,142
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
glibc@2.36-9+deb12u8
no fix listed

Open the chart page →

5,115
growthbookone-acre-fundVerified publisher0.3.01 of 3See more

growthbook one-acre-fund 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
growthbook/growthbook:latestcbf1bc59e9a9
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

1,161
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
glibc@2.36-9
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
glibc@2.36-9+deb12u8
no fix listed

Open the chart page →

14,990
dhcp-serveropencord1.0.21 of 1See more

dhcp-server opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
networkboot/dhcpd:lateste99bbfbd6fb2
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14

Open the chart page →

4,398
opencveopencve1.2.01 of 3See more

opencve opencve 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
cleveritcz/opencve:1.5.0c75c1636e0b7
glibc@2.34-83.el9.12
0:2.34-272.el9_8

Open the chart page →

2,133
librechatopenshift1.9.02 of 3See more

librechat openshift 1.9.0

2 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

5,943
opentelemetry-demoopentelemetry-helmOfficialVerified publisher0.42.05 of 34See more

opentelemetry-demo opentelemetry-helm 0.42.0

5 of the 34 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
glibc@2.41-12+deb13u3
2.41-12+deb13u4
ghcr.io/open-telemetry/demo:3.1.0-payment10d6bd20d8a0
glibc@2.36-9+deb12u13
no fix listed
ghcr.io/open-telemetry/demo:3.1.0-fraud-detectiona07ee694304b
glibc@2.36-9+deb12u13
no fix listed
ghcr.io/open-telemetry/demo:3.1.0-load-generatorb130d6cee6cb
glibc@2.36-9+deb12u14
no fix listed
ghcr.io/open-telemetry/demo:3.1.0-addfd7a4697116
glibc@2.39-0ubuntu8.5
2.39-0ubuntu8.8

Open the chart page →

20,236
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

7,011
rustfs-operatoroperatorVerified publisher0.7.01 of 1See more

rustfs-operator operator 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
rustfs/operator:0.07b96f986e5991
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

1,015
opikopikOfficialVerified publisher2.2.722 of 13See more

opik opik 2.2.72

2 of the 13 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/zookeeper:3.9.4dfa9ba46d14b
glibc@2.35-0ubuntu3.13
2.35-0ubuntu3.14
redis/redis-stack-server:7.2.0-v10e44b2b49d059
glibc@2.35-0ubuntu3.6
2.35-0ubuntu3.14

Open the chart page →

14,981
opsopsVerified publisher1.2.01 of 2See more

ops ops 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
shaowenchen/ops-server:latest6bac5cebd125
glibc@2.35-0ubuntu3.10
2.35-0ubuntu3.14

Open the chart page →

91,111
ouriosouriosVerified publisher0.4.81 of 1See more

ourios ourios 0.4.8

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/jensholdgaard/ourios:latest3d87d932391d
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

360
palworldpalworld-server-chartVerified publisher2.7.11 of 1See more

palworld palworld-server-chart 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
glibc@2.41-12+deb13u1
2.41-12+deb13u4

Open the chart page →

3,780
paperless-ngxpaperlessVerified publisher0.4.03 of 3See more

paperless-ngx paperless 0.4.0

3 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
bitnamilegacy/postgresqldigest-pinned926356130b77
glibc@2.36-9+deb12u10
no fix listed
valkey/valkey:9.0.54c64dfeae602
glibc@2.41-12+deb13u3
2.41-12+deb13u4
ghcr.io/paperless-ngx/paperless-ngxdigest-pinnedaa810a36942c
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

8,685
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

6,976
patch-operatorpatch-operator0.1.112 of 2See more

patch-operator patch-operator 0.1.11

2 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
glibc@2.28-164.el8
0:2.28-251.el8_10.38
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
glibc@2.34-100.el9
0:2.34-272.el9_8

Open the chart page →

7,861
fahclientpcktdmp2.6.01 of 2See more

fahclient pcktdmp 2.6.0

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
foldingathome/fah-gpu:latest5ef7742d1eb4
glibc@2.27-3ubuntu1.4
no fix listed

Open the chart page →

4,629
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

7,122
periscopeperiscopeVerified publisher1.1.61 of 1See more

periscope periscope 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/gnana997/periscope:1.1.621b284fb00f2
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

862
spring-boot-api-apppiominVerified publisher0.3.111 of 1See more

spring-boot-api-app piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14

Open the chart page →

7,667
matomopockostVerified publisher1.3.02 of 3See more

matomo pockost 1.3.0

2 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
glibc@2.41-12+deb13u3
2.41-12+deb13u4
pockost/matomo:5.13.07f5d293cbe4e
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

5,355
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
glibc@2.31-0ubuntu9.2
no fix listed
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

32,167
JenkinsprasoonjenkinsVerified publisher0.1.01 of 1See more

Jenkins prasoonjenkins 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

2,545
privacyideaprivacyidea1.0.62 of 2See more

privacyidea privacyidea 1.0.6

2 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
gpappsoft/privacyidea-docker:3.12.2af7841adad26
glibc@2.42-r4
2.43-r7
library/mariadb:11.7.2fcc7fcd7114a
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.8

Open the chart page →

5,597
prowlerprowler-appVerified publisher0.0.92 of 5See more

prowler prowler-app 0.0.9

2 of the 5 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/neo4j:2026.02.25ab4ab0358cf
glibc@2.41-12+deb13u2
2.41-12+deb13u4
prowlercloud/prowler-api:5.31.14f252d579be2
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

8,493
pzserverpzserver0.1.171 of 2See more

pzserver pzserver 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
lis314/project-zomboid-docker:latestaa2089c37920
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

3,270
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8

Open the chart page →

56,167
minecraft-serverqumine0.1.15001 of 1See more

minecraft-server qumine 0.1.1500

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
qumine/minecraft-server:v0.1.15c0b650d51132
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14

Open the chart page →

6,967
rabbitmqrabbitmq-magefleet1.2.01 of 1See more

rabbitmq rabbitmq-magefleet 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/rabbitmq:4.1.0-management935b3f84c1e4
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.8

Open the chart page →

2,889
velero-s3-deploymentradar-baseVerified publisher0.4.31 of 4See more

velero-s3-deployment radar-base 0.4.3

1 of the 4 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
glibc@2.34-125.el9_5.1
0:2.34-272.el9_8

Open the chart page →

4,821
redis-enterprise-operatorredis-enterprise-operatorVerified publisher7.13.4-121 of 1See more

redis-enterprise-operator redis-enterprise-operator 7.13.4-12

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
redislabs/operator:7.4.2-2ecb101af0506
glibc@2.34-83.el9_3.7
0:2.34-272.el9_8

Open the chart page →

2,638
napcatredish101Verified publisher0.1.31 of 1See more

napcat redish101 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
mlikiowa/napcat-docker:latest2cc70b45244a
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.14

Open the chart page →

66,280
redis-sentinel-gatewayredis-sentinel-gatewayVerified publisher1.0.21 of 1See more

redis-sentinel-gateway redis-sentinel-gateway 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
promzeus/redis-sentinel-gateway:v182f6d56e280b
glibc@2.36-9+deb12u8
no fix listed

Open the chart page →

2,700
redmineredmine-helm-chartVerified publisher0.2.61 of 1See more

redmine redmine-helm-chart 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

4,278
reportportalreportportal-ioOfficialVerified publisher26.8.123 of 15See more

reportportal reportportal-io 26.8.12

3 of the 15 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
glibc@2.36-9+deb12u10
no fix listed
library/postgres:18.4a02db8cac496
glibc@2.41-12+deb13u3
2.41-12+deb13u4
reportportal/service-auto-analyzer:5.15.5c449b93629a5
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

12,327
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
glibc@2.35-0ubuntu3.9
2.35-0ubuntu3.14

Open the chart page →

7,283
retyc-csiretyc-csi0.2.01 of 3See more

retyc-csi retyc-csi 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/retyc/retyc-k8s-csi:v0.2.01521d4baeb85
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

1,416

Container images carrying it

2,901 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
glibc@2.36-9+deb12u10
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.