StackRadar

CVE-2026-5450

Critical

Advisory

Published 20 Apr 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,639
of 17,828 indexed, latest versions
Container images
2,901
deployed by those charts
Fix available
3 of 4
affected packages

Red Hat Security Advisory: glibc security, bug fix, and enhancement update

Carried by container images the latest versions of 2,639 of 17,828 indexed charts deploy, on 2,901 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+59 more2.35-0ubuntu3.14, 2.39-0ubuntu8.8, 2.41-12+deb13u2+e4, 2.41-12+deb13u4+1 more2,445
glibcapk2.37-r7, 2.38-r6, 2.39-r7, 2.40-r1+8 more2.43-r722
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibcrpm2.17-260.el7_6.4, 2.17-260.el7_6.6, 2.17-292.el7, 2.17-307.el7.1+60 more0:2.17-326.el7_9.6, 0:2.28-251.el8_10.38, 0:2.34-272.el9_8, 0:2.39-126.el10_2427
OSV records
CGA-3qwq-5w83-3j3qDEBIAN-CVE-2026-5450UBUNTU-CVE-2026-5450RHSA-2026:33092RHSA-2026:33126RHSA-2026:33226RHSA-2026:34211RLSA-2026:33126RLSA-2026:33226AZL-83093ECHO-56eb-505f-7a61
Also known as
CGA-76f7-m58j-73wj, CGA-7x3v-c6pf-4v43, CGA-88p4-5g7h-3xrh, CGA-g425-f69f-xj8j, CGA-hq3x-5xh3-92jc, CGA-j9xg-mq3r-jh83, CGA-jgfr-5wmr-hfpc, CGA-mvj4-3q5f-wmwg, CGA-p427-94gh-pr7p, CGA-p7rp-4rm4-hg9q, CGA-qj6g-5h8p-677v, CGA-vc3j-8vcq-8pqc, CGA-vv29-hp4w-2hrw, CGA-wxx7-6vh7-9qhv, CGA-xrvh-57r4-pjhh, RHSA-2026:33227, RHSA-2026:33228, RHSA-2026:33229, RHSA-2026:33230, RHSA-2026:33231, RHSA-2026:36643, USN-8611-1

Charts affected

2,639 by stars
ChartLatestAffected imagesRadar Score
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/nginx:1.27.409369da6b103
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

5,526
repoflowrepoflow-helm-public0.9.13 of 8See more

repoflow repoflow-helm-public 0.9.1

3 of the 8 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.48.10f6c1c4b957d2
glibc@2.35-0ubuntu3.10
2.35-0ubuntu3.14
library/elasticsearch:8.15.0310b9fc03b06
glibc@2.31-0ubuntu9.16
no fix listed
library/postgres:16.24aea012537ed
glibc@2.36-9+deb12u6
no fix listed

Open the chart page →

12,747
nominatimrobjuz6.4.22 of 4See more

nominatim robjuz 6.4.2

2 of the 4 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
glibc@2.36-9+deb12u8
no fix listed
mediagis/nominatim:5.3.27923a8e67197
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8

Open the chart page →

50,212
rocketmq-clusterrocketmq12.6.02 of 2See more

rocketmq-cluster rocketmq 12.6.0

2 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
glibc@2.34-168.el9_6.23
0:2.34-272.el9_8

Open the chart page →

6,471
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

98,242
satisfactory-serversatisfactoryVerified publisher0.1.61 of 1See more

satisfactory-server satisfactory 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.10e103700ae6ae
glibc@2.35-0ubuntu3.10
2.35-0ubuntu3.14

Open the chart page →

3,512
seldon-core-operatorseldon1.19.01 of 1See more

seldon-core-operator seldon 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
glibc@2.34-231.el9_7.2
0:2.34-272.el9_8

Open the chart page →

875
lldapself-hosters-by-nightVerified publisher0.5.21 of 2See more

lldap self-hosters-by-night 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
glibc@2.41-12+deb13u1
2.41-12+deb13u4

Open the chart page →

3,471
skypilotskypilotOfficialVerified publisher0.13.01 of 3See more

skypilot skypilot 0.13.0

1 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

6,005
kafka-chartsoldevelo-kafka-chart32.4.41 of 1See more

kafka-chart soldevelo-kafka-chart 32.4.4

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

2,406
freeradiusstartechnicaVerified publisher1.2.01 of 1See more

freeradius startechnica 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.2.8af6fd34a5b78
glibc@2.35-0ubuntu3.10
2.35-0ubuntu3.14

Open the chart page →

5,995
sn-platformstreamnative1.11.451 of 9See more

sn-platform streamnative 1.11.45

1 of the 9 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
glibc@2.31-0ubuntu9.16
no fix listed

Open the chart page →

69,821
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/nginx:1.27.3fb197595ebe7
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

7,141
pretixtechwolf12Verified publisher2026.7.03 of 3See more

pretix techwolf12 2026.7.0

3 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
glibc@2.41-12+deb13u3
2.41-12+deb13u4
pretix/standalone:2026.7.05df3b7aa852e
glibc@2.41-12+deb13u3
2.41-12+deb13u4
valkey/valkey:9.1.08e8d64b405ce
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

9,989
mealieth-chartsVerified publisher0.5.11 of 1See more

mealie th-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
glibc@2.41-12
2.41-12+deb13u4

Open the chart page →

3,892
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
thmmniii/fbs-core:v1.27.15438517d9fc2
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14

Open the chart page →

28,904
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
glibc@2.35-0ubuntu3.4
2.35-0ubuntu3.14

Open the chart page →

10,461
crossplaneupbound-stable2.4.1-up.11 of 5See more

crossplane upbound-stable 2.4.1-up.1

1 of the 5 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

1,696
huginnutkuozdemirVerified publisher2.2.11 of 4See more

huginn utkuozdemir 2.2.1

1 of the 4 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
glibc@2.27-3ubuntu1.4
no fix listed

Open the chart page →

80,756
structurizrvirtualrootVerified publisher0.5.01 of 1See more

structurizr virtualroot 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
structurizr/onpremises:2025.11.094b5ffb5119c8
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.8

Open the chart page →

4,561
wasmcloud-chartwasmcloud-chartVerified publisher0.7.21 of 2See more

wasmcloud-chart wasmcloud-chart 0.7.2

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
wasmcloud/wasmcloud:0.81.05c7acfe7e8e1
glibc@2.36-9+deb12u3
no fix listed

Open the chart page →

3,509
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
glibc@2.28-164.el8
0:2.28-251.el8_10.38

Open the chart page →

6,090
wgerwgerOfficialVerified publisher2.0.03 of 7See more

wger wger 2.0.0

3 of the 7 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latest413a0c813e96
glibc@2.41-12+deb13u3
2.41-12+deb13u4
library/postgres:15.186eb0add3b77c
glibc@2.41-12+deb13u3
2.41-12+deb13u4
library/redis:8.8.0234c902a2db4
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

7,076
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
glibc@2.28-164.el8_5.3
0:2.28-251.el8_10.38

Open the chart page →

4,718
zeroclawzeroclawVerified publisher0.2.11 of 2See more

zeroclaw zeroclaw 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/zeroclaw-labs/zeroclaw:v0.1.7497893753e16
glibc@2.41-12+deb13u1
2.41-12+deb13u4

Open the chart page →

807
kubernetes-etcd-backupadfinisVerified publisher1.6.21 of 1See more

kubernetes-etcd-backup adfinis 1.6.2

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
glibc@2.34-168.el9_6.14
0:2.34-272.el9_8

Open the chart page →

1,875
paperless-ngxadnoctemVerified publisher0.4.23 of 5See more

paperless-ngx adnoctem 0.4.2

3 of the 5 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
apache/tika:2.9.0.092d055a84e9e
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14
gotenberg/gotenberg:8.36.087c16b9f3642
glibc@2.41-12+deb13u3
2.41-12+deb13u4
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

20,504
github-actions-runneradwerx0.10.31 of 1See more

github-actions-runner adwerx 0.10.3

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
glibc@2.31-0ubuntu9.1
no fix listed

Open the chart page →

13,693
agentareaagentareaVerified publisher0.0.192 of 16See more

agentarea agentarea 0.0.19

2 of the 16 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
agentarea/agentarea-mcp-runner:latest615da5917632
glibc@2.36-9+deb12u14
no fix listed
valkey/valkey:9.0.1546304417fea
glibc@2.41-12
2.41-12+deb13u4

Open the chart page →

13,039
akeyless-api-gatewayakeyless-services-helmVerified publisher1.62.261 of 1See more

akeyless-api-gateway akeyless-services-helm 1.62.26

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
akeyless/base:latest759e4289fae8
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8

Open the chart page →

2,497
icat-k8salba-helm-chartsVerified publisher1.1.01 of 4See more

icat-k8s alba-helm-charts 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
payara/server-full:7.2026.2-jdk2531f1253f0cf8
glibc@2.35-0ubuntu3.13
2.35-0ubuntu3.14

Open the chart page →

3,805
cloudflaredalekcVerified publisher1.8.11 of 1See more

cloudflared alekc 1.8.1

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.9.1b269e8abd07a
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

352
jellyfinalekcVerified publisher0.9.01 of 1See more

jellyfin alekc 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

2,681
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.02 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
glibc@2.41-12+deb13u1
2.41-12+deb13u4
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
glibc@2.41-12+deb13u1
2.41-12+deb13u4

Open the chart page →

12,332
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
glibc@2.27-3ubuntu1.6
no fix listed

Open the chart page →

69,570
mariadbalphani-helm-chartsVerified publisher10.10.31 of 1See more

mariadb alphani-helm-charts 10.10.3

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
library/mariadb:10.10.2bfc25a68e113
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.14

Open the chart page →

8,448
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
glibc@2.41-12+deb13u3
2.41-12+deb13u4

Open the chart page →

5,932
alazanteonVerified publisher0.12.01 of 1See more

alaz anteon 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ddosify/alaz:v0.12.0ea602056d9ce
glibc@2.36-9+deb12u7
no fix listed

Open the chart page →

3,428
anteonanteonVerified publisher2.6.42 of 13See more

anteon anteon 2.6.4

2 of the 13 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ddosify/selfhosted_backend:3.2.93c11e3182652
glibc@2.36-9+deb12u4
no fix listed
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
glibc@2.36-9+deb12u4
no fix listed

Open the chart page →

22,669
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
glibc@2.35-0ubuntu3.10
2.35-0ubuntu3.14

Open the chart page →

7,867
kubedb-provisionerappscodeVerified publisher0.66.01 of 1See more

kubedb-provisioner appscode 0.66.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-provisioner:v0.66.0824d6d78d451
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

656
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

5,274
s3dartur9010Verified publisher1.0.11 of 1See more

s3d artur9010 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

1,758
arvancloud-webhookarvancloud-webhookVerified publisher1.0.01 of 1See more

arvancloud-webhook arvancloud-webhook 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.00b97452674a3
glibc@2.41-12
2.41-12+deb13u4

Open the chart page →

2,366
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
glibc@2.31-0ubuntu9.12
no fix listed

Open the chart page →

18,082
dltbrokerassist-iot-distributed-broker0.2.03 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
glibc@2.35-0ubuntu3.13
2.35-0ubuntu3.14
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
glibc@2.23-0ubuntu10
no fix listed
hyperledger/fabric-couchdb:0.4.15f6c724592abf
glibc@2.23-0ubuntu11
no fix listed

Open the chart page →

188,990
dltloggingassist-iot-logging-auditing0.2.03 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
glibc@2.35-0ubuntu3.13
2.35-0ubuntu3.14
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
glibc@2.23-0ubuntu10
no fix listed
hyperledger/fabric-couchdb:0.4.15f6c724592abf
glibc@2.23-0ubuntu11
no fix listed

Open the chart page →

188,970
astradnsastradnsVerified publisher0.2.91 of 2See more

astradns astradns 0.2.9

1 of the 2 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

2,708
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
glibc@2.27-3ubuntu1.4
no fix listed

Open the chart page →

4,324
kube-image-webhookav1o-chartsVerified publisher0.1.31 of 1See more

kube-image-webhook av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-5450.

Container imageDigestPackageFixed in
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
glibc@2.27-3ubuntu1.5
no fix listed

Open the chart page →

3,748

Container images carrying it

2,901 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
glibc@2.36-9+deb12u10
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.