StackRadar

CVE-2026-56392

Medium

Advisory

Published 24 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,756
of 17,792 indexed, latest versions
Container images
1,748
deployed by those charts
Fix available
1 of 2
affected packages

Red Hat Bug Fix Advisory: coreutils bug fix and enhancement update

Carried by container images the latest versions of 1,756 of 17,792 indexed charts deploy, on 1,748 images.

Affected packageAffected versionsFixed inImages
coreutilsdeb9.1-1, 9.7-3, 9.7-3+dhi3, 9.7-3+dhi4no fix listed1,258
coreutilsrpm8.30-6.el8, 8.30-6.el8_1.1, 8.30-7.el8_2.1, 8.30-8.el8+11 more0:8.30-20.el8_10, 0:8.32-41.el9_8.1490
OSV records
DEBIAN-CVE-2026-56392RHBA-2026:47115RHSA-2026:66403RLSA-2026:66403

Charts affected

1,756 by stars
ChartLatestAffected imagesRadar Score
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.12 of 2See more

stackgres-operator stackgres-charts 1.19.1

2 of the 2 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
coreutils@8.30-17.el8_10
0:8.30-20.el8_10
quay.io/stackgres/operator:1.19.1f241b0b20326
coreutils@8.32-41.el9_8
0:8.32-41.el9_8.1

Open the chart page →

2,139
pxc-operatorpercona1.20.11 of 1See more

pxc-operator percona 1.20.1

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
coreutils@8.32-40.el9
0:8.32-41.el9_8.1

Open the chart page →

417
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
coreutils@9.1-1
no fix listed

Open the chart page →

6,960
difydify-helmVerified publisher0.38.05 of 11See more

dify dify-helm 0.38.0

5 of the 11 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
coreutils@9.1-1
no fix listed
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
coreutils@9.1-1
no fix listed
langgenius/dify-api:1.16.1dcefa5f7c47c
coreutils@9.1-1
no fix listed
langgenius/dify-sandbox:0.2.15750e1111426e
coreutils@9.7-3
no fix listed
library/nginx:latest05b8cb60c354
coreutils@9.7-3
no fix listed

Open the chart page →

22,214
eclipse-cheeclipse-cheVerified publisher7.122.01 of 1See more

eclipse-che eclipse-che 7.122.0

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
quay.io/eclipse/che-operator:7.122.0d752a1c2a7b7
coreutils@8.30-15.el8
0:8.30-20.el8_10

Open the chart page →

931
operatorminio-operator7.1.11 of 1See more

operator minio-operator 7.1.1

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
quay.io/minio/operator:v7.1.1cd587f60c43d
coreutils@8.32-36.el9
0:8.32-41.el9_8.1

Open the chart page →

874
stacks-blockchainhirosystemsVerified publisher2.2.21 of 1See more

stacks-blockchain hirosystems 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
coreutils@9.1-1
no fix listed

Open the chart page →

1,396
oktetooktetoOfficialVerified publisher0.0.0-2026-08-171 of 10See more

okteto okteto 0.0.0-2026-08-17

1 of the 10 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-173e56bdd1b90d
coreutils@9.7-3
no fix listed

Open the chart page →

5,532
apisix-ingress-controllerapisix1.3.11 of 2See more

apisix-ingress-controller apisix 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
coreutils@9.1-1
no fix listed

Open the chart page →

1,661
volsyncbackube-helm-chartsVerified publisher0.16.01 of 1See more

volsync backube-helm-charts 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
quay.io/backube/volsync:0.16.00d03a6aad575
coreutils@8.32-40.el9
0:8.32-41.el9_8.1

Open the chart page →

1,386
actualbudgetcommunity-chartsVerified publisher1.9.41 of 1See more

actualbudget community-charts 1.9.4

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
coreutils@9.1-1
no fix listed

Open the chart page →

1,112
concourseconcourseVerified publisher20.3.01 of 2See more

concourse concourse 20.3.0

1 of the 2 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
coreutils@9.7-3
no fix listed

Open the chart page →

2,054
dynatrace-operatordynatraceVerified publisher1.10.21 of 1See more

dynatrace-operator dynatrace 1.10.2

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.10.252281db48c93
coreutils@8.32-41.el9_8
0:8.32-41.el9_8.1

Open the chart page →

172
openprojectopenproject-helm-chartsOfficialVerified publisher13.12.04See more

openproject openproject-helm-charts 13.12.0

4 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
bitnamilegacy/memcached:1.6.24-debian-12-r01d80b6a96f00
coreutils@9.1-1
no fix listed
library/postgres:16f1c3376c26f2
coreutils@9.7-3
no fix listed
openproject/hocuspocus:release-338001b288dc1359dfb5
coreutils@9.1-1
no fix listed
openproject/openproject:17.8.0-slim48952034215d
coreutils@9.7-3
no fix listed

Open the chart page →

sftpgosftpgoOfficialVerified publisher0.47.01 of 1See more

sftpgo sftpgo 0.47.0

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
ghcr.io/drakkan/sftpgo:v2.7.46cb60f08fede
coreutils@9.7-3
no fix listed

Open the chart page →

1,262
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
coreutils@9.1-1
no fix listed

Open the chart page →

11,431
lemmyananace-chartsVerified publisher0.6.152 of 5See more

lemmy ananace-charts 0.6.15

2 of the 5 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
dessalines/lemmy:0.19.2079e9f02c286c
coreutils@9.1-1
no fix listed
dessalines/lemmy-ui:0.19.20ee4c620d8e93
coreutils@9.7-3
no fix listed

Open the chart page →

7,255
zabbixcetic3.1.31 of 5See more

zabbix cetic 3.1.3

1 of the 5 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
coreutils@9.7-3
no fix listed

Open the chart page →

33,928
csi-driver-smbcsi-driver-smbVerified publisher1.20.31 of 6See more

csi-driver-smb csi-driver-smb 1.20.3

1 of the 6 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
coreutils@9.1-1
no fix listed

Open the chart page →

3,005
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
coreutils@9.1-1
no fix listed

Open the chart page →

4,310
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
coreutils@9.1-1
no fix listed

Open the chart page →

6,562
stacks-blockchain-apihirosystemsVerified publisher6.5.12 of 5See more

stacks-blockchain-api hirosystems 6.5.1

2 of the 5 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
coreutils@9.1-1
no fix listed
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
coreutils@9.1-1
no fix listed

Open the chart page →

8,409
hpe-csi-driverhpe-storageVerified publisher3.3.08 of 14See more

hpe-csi-driver hpe-storage 3.3.0

8 of the 14 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
quay.io/hpestorage/alletra-9000-primera-and-3par-csp:v3.3.0046215e41416
coreutils@8.32-41.el9_8
0:8.32-41.el9_8.1
quay.io/hpestorage/alletrastoragemp-b10000-nfs-csp:v1.3.0efaca660f9f0
coreutils@8.32-41.el9_8
0:8.32-41.el9_8.1
quay.io/hpestorage/alletrastoragemp-x10000-nfs-csp:v1.1.0043bb2ddb642
coreutils@8.32-41.el9_8
0:8.32-41.el9_8.1
quay.io/hpestorage/csi-driver:v3.3.0e58e22427b38
coreutils@8.32-41.el9_8
0:8.32-41.el9_8.1
quay.io/hpestorage/csi-extensions:v1.3.0df65cea35805
coreutils@8.32-41.el9_8
0:8.32-41.el9_8.1
quay.io/hpestorage/volume-group-provisioner:v1.1.09ba017780f80
coreutils@8.32-41.el9_8
0:8.32-41.el9_8.1
quay.io/hpestorage/volume-group-snapshotter:v1.1.0b26660528928
coreutils@8.32-41.el9_8
0:8.32-41.el9_8.1
quay.io/hpestorage/volume-mutator:v1.4.03890d0b3aa89
coreutils@8.32-41.el9_8
0:8.32-41.el9_8.1

Open the chart page →

1,700
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
coreutils@9.1-1
no fix listed

Open the chart page →

6,049
factorio-server-chartsfactorio-server-chartsVerified publisher2.5.21 of 1See more

factorio-server-charts factorio-server-charts 2.5.2

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
factoriotools/factorio:lateste9227748c507
coreutils@9.7-3
no fix listed

Open the chart page →

1,459
netbirdjaconiVerified publisher0.15.11 of 4See more

netbird jaconi 0.15.1

1 of the 4 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
library/golang:latest512690a56605
coreutils@9.7-3
no fix listed

Open the chart page →

8,567
litellm-helmlitellm1.101.01 of 2See more

litellm-helm litellm 1.101.0

1 of the 2 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
coreutils@9.1-1
no fix listed

Open the chart page →

4,991
localstacklocalstack0.7.01 of 1See more

localstack localstack 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest4aef81c53168
coreutils@9.7-3
no fix listed

Open the chart page →

2,228
gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
coreutils@9.7-3
no fix listed

Open the chart page →

9,747
oneuptimeoneuptimeOfficialVerified publisher13.0.61See more

oneuptime oneuptime 13.0.6

1 container image this version deploys carries CVE-2026-56392.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
coreutils@9.7-3
no fix listed

Open the chart page →

openclawopenclaw-helmVerified publisher1.5.402 of 2See more

openclaw openclaw-helm 1.5.40

2 of the 2 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
chromedp/headless-shell:148.0.7778.97313ed7255ae1
coreutils@9.7-3
no fix listed
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
coreutils@9.1-1
no fix listed

Open the chart page →

5,710
stalwart-mailstalwart-mailVerified publisher2.0.101 of 1See more

stalwart-mail stalwart-mail 2.0.10

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
stalwartlabs/stalwart:v0.16.2074ca4f7f6885
coreutils@9.7-3
no fix listed

Open the chart page →

1,425
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
coreutils@8.30-8.el8
0:8.30-20.el8_10

Open the chart page →

6,853
plugin-barman-cloudcloudnative-pgVerified publisher0.8.01 of 1See more

plugin-barman-cloud cloudnative-pg 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/plugin-barman-cloud:v0.15.0563c680fe7fd
coreutils@8.32-41.el9_8
0:8.32-41.el9_8.1

Open the chart page →

77
glasskube-operatorglasskubeOfficialVerified publisher0.12.22 of 3See more

glasskube-operator glasskube 0.12.2

2 of the 3 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
coreutils@8.30-15.el8
0:8.30-20.el8_10
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
coreutils@8.30-15.el8
0:8.30-20.el8_10

Open the chart page →

11,987
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
coreutils@9.1-1
no fix listed

Open the chart page →

5,375
plane-cemakeplaneOfficialVerified publisher1.8.12 of 11See more

plane-ce makeplane 1.8.1

2 of the 11 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
coreutils@8.32-39.el9
0:8.32-41.el9_8.1
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
coreutils@8.32-39.el9
0:8.32-41.el9_8.1

Open the chart page →

4,885
milvusmilvus-helm5.0.281 of 4See more

milvus milvus-helm 5.0.28

1 of the 4 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
coreutils@8.32-36.el9
0:8.32-41.el9_8.1

Open the chart page →

10,782
prefect-serverprefectVerified publisher2026.9.141419102 of 2See more

prefect-server prefect 2026.9.14141910

2 of the 2 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
coreutils@9.1-1
no fix listed
prefecthq/prefect:3.8.6-python3.11f518ebb9c353
coreutils@9.7-3
no fix listed

Open the chart page →

5,556
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
coreutils@8.32-39.el9
0:8.32-41.el9_8.1

Open the chart page →

6,400
apicurio-registryapicurio-registry-helmVerified publisher3.8.01 of 2See more

apicurio-registry apicurio-registry-helm 3.8.0

1 of the 2 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
coreutils@8.30-15.el8
0:8.30-20.el8_10

Open the chart page →

6,675
codefreshcodefresh-onpremOfficialVerified publisher2.12.144 of 42See more

codefresh codefresh-onprem 2.12.14

4 of the 42 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
coreutils@9.1-1
no fix listed
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
coreutils@9.1-1
no fix listed
bitnamilegacy/rabbitmq:4.1.39e635efba431
coreutils@9.1-1
no fix listed
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
coreutils@9.1-1
no fix listed

Open the chart page →

15,093
gitlab-operatorgitlabVerified publisher3.3.21 of 1See more

gitlab-operator gitlab 3.3.2

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:3.3.242dd426130a9
coreutils@8.32-41.el9_8
0:8.32-41.el9_8.1

Open the chart page →

152
apim3graviteeioVerified publisher4.12.192 of 4See more

apim3 graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
coreutils@9.7-3
no fix listed
graviteeio/apim-management-api:4.12.19-debian27374522cd04
coreutils@9.7-3
no fix listed

Open the chart page →

4,852
redisgroundhog2k2.4.71 of 1See more

redis groundhog2k 2.4.7

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
coreutils@9.7-3
no fix listed

Open the chart page →

978
wordpressgroundhog2k0.16.41 of 1See more

wordpress groundhog2k 0.16.4

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
coreutils@9.7-3
no fix listed

Open the chart page →

3,752
supabasetokens-studioVerified publisher1.0.04 of 14See more

supabase tokens-studio 1.0.0

4 of the 14 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
supabase/edge-runtime:v1.59.0eff9c554d649
coreutils@9.1-1
no fix listed
supabase/postgres-meta:v0.84.2d0a96973e9f1
coreutils@9.1-1
no fix listed
supabase/realtime:v2.33.8d207e6e23ad3
coreutils@9.1-1
no fix listed
supabase/studio:20241021-9f9b08326d8070c55e9
coreutils@9.1-1
no fix listed

Open the chart page →

23,365
wekanwekanVerified publisher11.83.02 of 3See more

wekan wekan 11.83.0

2 of the 3 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
ghcr.io/wekan/ferretdb:latest6cb94aa01999
coreutils@9.7-3
no fix listed
ghcr.io/wekan/wekan:v11.83137951e3fb40
coreutils@9.7-3
no fix listed

Open the chart page →

1,619
polarisapache-polarisOfficialVerified publisher1.3.0-incubating1 of 1See more

polaris apache-polaris 1.3.0-incubating

1 of the 1 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
apache/polaris:lateste66366e783f1
coreutils@8.32-41.el9_8
0:8.32-41.el9_8.1

Open the chart page →

473
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-56392.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
coreutils@9.1-1
no fix listed
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
coreutils@9.1-1
no fix listed

Open the chart page →

8,586

Container images carrying it

1,748 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-56392.

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.