CVE-2026-5928
HighAdvisory
Published 20 Apr 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.004
- 31st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,416
- of 17,792 indexed, latest versions
- Container images
- 2,430
- deployed by those charts
- Fix available
- 2 of 4
- affected packages
CVE-2026-5928 affecting package glibc 2.38-21
Carried by container images the latest versions of 2,416 of 17,792 indexed charts deploy, on 2,430 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| glibcdeb | 2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+59 more | 2.35-0ubuntu3.14, 2.39-0ubuntu8.8, 2.41-12+deb13u2+e4, 2.41-12+deb13u4+1 more | 2,378 |
| glibcapk | 2.37-r7, 2.38-r6, 2.39-r7, 2.40-r1+8 more | 2.43-r7 | 22 |
| eglibcdeb | 2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 more | no fix listed | 7 |
| glibcrpm | 2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3 | no fix listed | 23 |
- OSV records
- CGA-2gxw-5ffj-x2phDEBIAN-CVE-2026-5928UBUNTU-CVE-2026-5928AZL-83087ECHO-c634-adb4-1dbe
- Also known as
- CGA-482r-2xq8-f4x9, CGA-52fm-fh87-3chx, CGA-7rhh-qh9f-p756, CGA-8q82-f5j8-fh3w, CGA-cr8c-r5h5-5gc4, CGA-fwmr-xqf9-976q, CGA-h6w5-gmvw-7p3j, CGA-h8hx-28hx-583g, CGA-mff9-49w3-8vxq, CGA-q7rf-9pqj-g4hq, CGA-r747-wj6f-v7p4, CGA-vrh7-vv5q-5295, CGA-wxh3-3r3r-49wr, CGA-x688-wmjw-qhpm, CGA-xqv8-j654-32r2, USN-8611-1
Charts affected
2,416 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| wordpress-alpinewordpress-alpine | 1.5.18 | 2 of 6See more | 4,063 |
| Wordpresswordpress-mariadb | 1.0.2 | 1 of 2See more | 5,676 |
| playwright-synthetic-monitoringwork-adventure | 1.0.1 | 1 of 1See more | 14,173 |
| workshop-pipelinesworkshop-pipelines | 0.1.6 | 1 of 2See more | 11,603 |
| tabbyxdVerified publisher | 1.0.6 | 1 of 2See more | 7,697 |
| xkopsxkops | 0.1.0 | 3 of 5See more | 13,783 |
| xlinexline | 0.0.1 | 1 of 1See more | 2,142 |
| nginx-chartxxoznge-nginx | 0.1.0 | 1 of 1See more | 1,849 |
| helm-demoyahoon-helm-demoVerified publisher | 1.0.0 | 1 of 1See more | 1,304 |
| my-nginx-appyasser-nginx-app | 0.1.0 | 1 of 1See more | 1,849 |
| api-snapyoukadevVerified publisher | 0.1.1 | 1 of 1See more | 2,684 |
| zahori-schedulerzahoriVerified publisher | 1.0.1 | 1 of 1See more | 2,467 |
| changedetection-iozekker6Verified publisher | 1.99.0 | 1 of 1See more | 2,612 |
| endlessh-gozekker6Verified publisher | 0.4.0 | 1 of 1See more | 478 |
| NEW_APPzekker6Verified publisher | 0.0.0 | 1 of 1See more | 1,849 |
| clickhousezloi-space | 1.2.0 | 2 of 3See more | 9,256 |
Container images carrying it
2,430 by charts deploying them
A fixed version is listed for 2 of the 4 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| continuoussecuritytooling/ | f04ecefab64e | glibc | no fix listed | 1 |
| cortezaproject/ | 0bcdcbcd3c63 | glibc | 2.35-0ubuntu3.14 | 1 |
| cortezaproject/ | 8eb7a26605c9 | glibc | no fix listed | 1 |
| cortezaproject/ | cb9f200de5d2 | glibc | 2.35-0ubuntu3.14 | 1 |
| cortezaproject/ | 4ea78dfe5364 | glibc | no fix listed | 1 |
| coturn/ | f4c2af06c3c5 | glibc | 2.41-12+deb13u4 | 1 |
| countly/ | e3c238248f99 | glibc | no fix listed | 1 |
| cradlepoint/ | 8f5720b0cd03 | glibc | no fix listed | 1 |
| cribl/ | 762747cb6796 | glibc | no fix listed | 1 |
| csiplugin/ | 1fa83d45417f | glibc | no fix listed | 1 |
| cspconsole/ | 5524a26a6c23 | glibc | no fix listed | 1 |
| cspconsole/ | 46dda4a31bd6 | glibc | no fix listed | 1 |
| cspconsole/ | 39750248193b | glibc | no fix listed | 1 |
| cspconsole/ | 9a2d8840bfdf | glibc | no fix listed | 1 |
| cubejs/ | 34ac523a9bab | glibc | no fix listed | 1 |
| cybrarist/ | e9e2447ac666 | glibc | 2.41-12+deb13u4 | 1 |
| cyfershepard/ | c4e2dfa8bddf | glibc | no fix listed | 1 |
| cznic/ | fe71c5214fdc | glibc | 2.41-12+deb13u4 | 1 |
| dachichang/ | 7ccac90a935e | glibc | no fix listed | 1 |
| daedalusproject/ | 6f72b5119eda | glibc | no fix listed | 1 |
| danialnabiyan1382/ | f96a7ebf1f42 | glibc | no fix listed | 1 |
| dannielkil/ | 937993927694 | glibc | no fix listed | 1 |
| dariomader/ | d2f4a8c5e690 | glibc | 2.43-r7 | 1 |
| darthsim/ | 3b709e4a0e5e | glibc | 2.39-0ubuntu8.8 | 1 |
| darthsim/ | 476cb08c816a | glibc | 2.39-0ubuntu8.8 | 1 |
| darthsim/ | 7d12c7c8fc66 | glibc | 2.39-0ubuntu8.8 | 1 |
| daskdev/ | 052630f5ca04 | glibc | no fix listed | 1 |
| dasmeta/ | fa657960dfec | glibc | no fix listed | 1 |
| datadog/ | aad9994de6a7 | glibc | 2.39-0ubuntu8.8 | 1 |
| datafuselabs/ | ba877ee6cb4d | glibc | no fix listed | 1 |
| datafuselabs/ | a936843b85b4 | glibc | no fix listed | 1 |
| datalayers/ | 17b292079239 | glibc | 2.35-0ubuntu3.14 | 1 |
| datalust/ | 9c731bb207a6 | glibc | no fix listed | 1 |
| datalust/ | 3de34aed5642 | glibc | no fix listed | 1 |
| datamate/ | 2dd66b722464 | glibc | 2.35-0ubuntu3.14 | 1 |
| dbeaver/ | 87ab86d00f8c | glibc | 2.39-0ubuntu8.8 | 1 |
| dbgate/ | f2dc7423ea88 | glibc | no fix listed | 1 |
| dblaci/ | eea697611af4 | glibc | 2.35-0ubuntu3.14 | 1 |
| ddosify/ | ea602056d9ce | glibc | no fix listed | 1 |
| ddosify/ | a43c5155fa1c | glibc | no fix listed | 1 |
| ddosify/ | 3c11e3182652 | glibc | no fix listed | 1 |
| ddosify/ | ac323d52bfb4 | glibc | no fix listed | 1 |
| ddosify/ | b796b8c73011 | glibc | no fix listed | 1 |
| decisionrules/ | 38c377e7c01e | glibc | 2.41-12+deb13u4 | 1 |
| deconzcommunity/ | 062de2362641 | glibc | no fix listed | 1 |
| deepflowce/ | bc1882f75c18 | glibc | no fix listed | 1 |
| deepflowce/ | 29332fee7fc2 | glibc | 2.35-0ubuntu3.14 | 1 |
| defactops/ | 07b663c0092a | glibc | no fix listed | 1 |
| defectdojo/ | c597abdbb535 | glibc | 2.41-12+deb13u4 | 1 |
| deimosfr/ | 284c4040fc6d | glibc | 2.41-12+deb13u4 | 1 |