StackRadar

CVE-2026-6238

Medium

Advisory

Published 28 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,413
of 17,813 indexed, latest versions
Container images
2,450
deployed by those charts
Fix available
1 of 3
affected packages

CVE-2026-6238 affecting package glibc 2.38-21

Carried by container images the latest versions of 2,413 of 17,813 indexed charts deploy, on 2,450 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+61 more2.35-0ubuntu3.14, 2.39-0ubuntu8.8, 2.41-12+deb13u2+e5, 2.43-2ubuntu2.32,424
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibcrpm2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3no fix listed19
OSV records
DEBIAN-CVE-2026-6238UBUNTU-CVE-2026-6238AZL-85004ECHO-916f-8705-1b52
Also known as
USN-8611-1

Charts affected

2,413 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,450 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
glibc@2.31-0ubuntu9.9
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
glibc@2.31-0ubuntu9.9
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
glibc@2.31-0ubuntu9.9
no fix listed
1
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.8
1
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.8
1
ghcr.io/spidernet-io/spiderpool/spiderpool-agent:v1.2.08bb9411e47e0
glibc@2.31-0ubuntu9.18
no fix listed
1
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
glibc@2.31-0ubuntu9.16
no fix listed
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
glibc@2.36-9+deb12u9
no fix listed
1
ghcr.io/stac-utils/stac-fastapi-pgstac:7.0.08b026c47cc1b
glibc@2.41-12+deb13u4
no fix listed
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
glibc@2.31-0ubuntu9.9
no fix listed
1
ghcr.io/steadybit/agent:2.4.6d246bfa55f63
glibc@2.41-12+deb13u4
no fix listed
1
ghcr.io/steadybit/extension-container:v1.8.1ae79f958b479
glibc@2.41-12+deb13u4
no fix listed
1
ghcr.io/steadybit/extension-host:v1.8.103a5ef26aac5
glibc@2.41-12+deb13u4
no fix listed
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8
1
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.8
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
glibc@2.39-0ubuntu8.5
2.39-0ubuntu8.8
1
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.8
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
glibc@2.39-0ubuntu8.5
2.39-0ubuntu8.8
1
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.8
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
glibc@2.31-0ubuntu9.16
no fix listed
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
glibc@2.31-0ubuntu9.16
no fix listed
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.8
1
ghcr.io/strrl/wonder-mesh-net:v2026.629.0625b140372fd
glibc@2.36-9+deb12u14
no fix listed
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
1
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
glibc@2.36-9+deb12u7
no fix listed
1
ghcr.io/sudo-kraken/3d-printing-cost-calculators:v1.1.1220c5e4e1a3d
glibc@2.36-9+deb12u13
no fix listed
1
ghcr.io/sudo-kraken/authentik-webfinger-proxy:v1.1.1e1351a977607
glibc@2.36-9+deb12u13
no fix listed
1
ghcr.io/sudo-kraken/fantasy-dice-chamber:v1.3.299fd4cb0f4fe
glibc@2.36-9+deb12u13
no fix listed
1
ghcr.io/sudo-kraken/finances-tracker:v1.1.1c73527cde81c
glibc@2.36-9+deb12u13
no fix listed
1
ghcr.io/sudo-kraken/jf-pushover-webhook:v1.1.0ee9cf22a39ab
glibc@2.36-9+deb12u13
no fix listed
1
ghcr.io/tale/headplane:0.6.39476cc5adb12
glibc@2.36-9+deb12u13
no fix listed
1
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
glibc@2.36-9+deb12u4
no fix listed
1
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/themesama/kubernetes-kustomize-patcher:latestb1bf0669e3a0
glibc@2.36-9+deb12u10
no fix listed
1
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
glibc@2.36-9+deb12u14
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.14
1
ghcr.io/trianalab/mira-operator:0.2.0c5700c191a9b
glibc@2.36-9+deb12u14
no fix listed
1
ghcr.io/trow-registry/trow:0.10.075b7d2dcdb91
glibc@2.41-12+deb13u2
no fix listed
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.8
1
ghcr.io/twigex/cospace:lateste5ecfd607e42
glibc@2.36-9+deb12u14
no fix listed
1
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
glibc@2.41-12+deb13u3
no fix listed
1
ghcr.io/utkuozdemir/nvidia_gpu_exporter:1.5.0d75967a4dd72
glibc@2.43-2ubuntu2
2.43-2ubuntu2.3
1
ghcr.io/vinny1892/octantis:latest45459c0910fc
glibc@2.41-12+deb13u2
no fix listed
1
ghcr.io/virtuos/librechat_exporter:2.0.050ea1cf0086f
glibc@2.36-9+deb12u10
no fix listed
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
glibc@2.35-0ubuntu3.6
2.35-0ubuntu3.14
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
glibc@2.35-0ubuntu3.6
2.35-0ubuntu3.14
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.14
1
ghcr.io/voyagermesh/crd-manager:v0.1.013fd0cccafe8
glibc@2.36-9+deb12u13
no fix listed
1
ghcr.io/voyagermesh/gateway:v1.6.223f4da194134
glibc@2.36-9+deb12u13
no fix listed
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.