StackRadar

CVE-2026-6368

Low

Advisory

Published 10 Aug 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.1
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,645
of 17,821 indexed, latest versions
Container images
2,708
deployed by those charts
Fix available
1 of 3
affected packages

CVE-2026-6368 affecting package glibc 2.38-21

Carried by container images the latest versions of 2,645 of 17,821 indexed charts deploy, on 2,708 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+63 more2.35-0ubuntu3.15, 2.39-0ubuntu8.9, 2.41-12+deb13u3+e3, 2.43-2ubuntu2.42,687
glibcrpm2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3no fix listed14
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
OSV records
DEBIAN-CVE-2026-6368UBUNTU-CVE-2026-6368AZL-95495ECHO-1dea-800f-5685
Also known as
USN-8737-1, USN-8737-2

Charts affected

2,645 by stars
ChartLatestAffected imagesRadar Score
rstmdbrstmdb0.2.01 of 1See more

rstmdb rstmdb 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
rstmdb/rstmdb:lateste5187f2aaace
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

1,023
rstudio-pmrstudioVerified publisher0.20.51 of 1See more

rstudio-pm rstudio 0.20.5

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
posit/package-manager:2026.09.0-ubuntu-24.04527493ef621b
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9

Open the chart page →

32,684
mealiertomik-helm-chartsVerified publisher0.0.21 of 1See more

mealie rtomik-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
glibc@2.41-12
no fix listed

Open the chart page →

3,940
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

5,323
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
glibc@2.27-3ubuntu1.4
no fix listed

Open the chart page →

13,604
kyoorubxkubeVerified publisher0.1.104 of 9See more

kyoo rubxkube 0.1.10

4 of the 9 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
glibc@2.36-9+deb12u9
no fix listed
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
glibc@2.36-9+deb12u9
no fix listed
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
glibc@2.36-9+deb12u9
no fix listed
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

30,550
conference-appsalaboy1.0.03 of 7See more

conference-app salaboy 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
salaboy/agenda-service-0967b907d9920c99918e2b91b91937b3digest-pinnedce9ce8293e4e
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.15
salaboy/c4p-service-a3dc0474cbfa348afcdf47a8eee70ba9digest-pinnedbb64bf14467d
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.15
salaboy/notifications-service-0e27884e01429ab7e350cb5dff61b525digest-pinned799c35f9f306
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.15

Open the chart page →

11,095
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

38,725
teamcityscalified-teamcityVerified publisher2026.2.01 of 3See more

teamcity scalified-teamcity 2026.2.0

1 of the 3 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
library/postgres:14816cf7d06ec3
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

1,272
sceptresceptreai0.1.122 of 5See more

sceptre sceptreai 0.1.12

2 of the 5 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
maponyacharles/sceptreai:mlflow-0.1.1242d418654ebd
glibc@2.41-12+deb13u3
no fix listed
maponyacharles/sceptreai:api-0.1.127b37b092130a
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

4,527
schemaheroschemahero1.4.01 of 1See more

schemahero schemahero 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
schemahero/schemahero-manager:0.22.11609e1a05cd3
glibc@2.39-0ubuntu8.5
2.39-0ubuntu8.9

Open the chart page →

2,208
searxngsearxngVerified publisher0.1.111 of 3See more

searxng searxng 0.1.11

1 of the 3 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
valkey/valkey:9.1.1-trixie64e361b630ec
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

780
seatsurfingseatsurfing0.1.21 of 1See more

seatsurfing seatsurfing 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
seatsurfing/backend:1.119.39952e80048b0
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

552
securosecuroVerified publisher0.16.02 of 4See more

securo securo 0.16.0

2 of the 4 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
pgvector/pgvector:pg16ccc6e83d6e35
glibc@2.36-9+deb12u14
no fix listed
ghcr.io/securo-finance/securo-backend:0.16.0f452147e07f1
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

3,597
immichsecustorVerified publisher2.0.61 of 1See more

immich secustor 2.0.6

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.279cc1623323d
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

3,151
viya4-home-dir-builderselerityVerified publisher1.1.01 of 2See more

viya4-home-dir-builder selerity 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
library/python:3.12-slim2f17fc044b57
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

628
sentry-k8ssentry-k8sVerified publisher1.4.16 of 11See more

sentry-k8s sentry-k8s 1.4.1

6 of the 11 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
glibc@2.35-0ubuntu3.10
2.35-0ubuntu3.15
library/postgres:16f1c3376c26f2
glibc@2.41-12+deb13u3
no fix listed
ghcr.io/getsentry/relay:26.7.2cd29b88c1d72
glibc@2.41-12+deb13u3
no fix listed
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
glibc@2.36-9+deb12u14
no fix listed
ghcr.io/getsentry/snuba:26.7.210f8d164109b
glibc@2.41-12+deb13u3
no fix listed
ghcr.io/getsentry/taskbroker:26.7.264d0da74a578
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

17,006
seq-input-gelfseq-input-gelfVerified publisher0.3.11 of 2See more

seq-input-gelf seq-input-gelf 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
datalust/seq-input-gelf:3.0.441-x643de34aed5642
glibc@2.31-0ubuntu9.9
no fix listed

Open the chart page →

3,427
vuiseriohub1.0.62 of 3See more

vui seriohub 1.0.6

2 of the 3 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
dserio83/velero-api:0.3.16b3d9115fee2
glibc@2.36-9+deb12u10
no fix listed
dserio83/velero-watchdog:0.1.8d5deae589229
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

11,518
sigscale-csesigscale-cseOfficialVerified publisher1.4.221 of 1See more

sigscale-cse sigscale-cse 1.4.22

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
sigscale/cse:latest67d0c886516b
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

2,327
sigscale-ocssigscale-ocsOfficialVerified publisher1.1.171 of 1See more

sigscale-ocs sigscale-ocs 1.1.17

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
sigscale/ocs:latest3c1bdc9732e2
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

2,327
mssqlserver-2019simcube1.2.31 of 1See more

mssqlserver-2019 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
glibc@2.31-0ubuntu9.7
no fix listed

Open the chart page →

6,926
clickhousesinextraVerified publisher0.22.01 of 1See more

clickhouse sinextra 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.3.1092098d3b31dd
glibc@2.35-0ubuntu3.13
2.35-0ubuntu3.15

Open the chart page →

2,036
mongodb-backupsinextraVerified publisher1.1.01 of 1See more

mongodb-backup sinextra 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

4,565
postgresql-singlesinextraVerified publisher1.15.11 of 1See more

postgresql-single sinextra 1.15.1

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

4,875
registry-mirrorssinextraVerified publisher2.0.191 of 1See more

registry-mirrors sinextra 2.0.19

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
ghcr.io/project-zot/zot:v2.1.216b69512c00dc
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

374
gitlab-omnibusslamdev0.1.61 of 2See more

gitlab-omnibus slamdev 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
daedalusproject/base_kubectl:latest6f72b5119eda
glibc@2.31-0ubuntu9.1
no fix listed

Open the chart page →

2,872
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

2,915
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
glibc@2.31-0ubuntu9.9
no fix listed
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
glibc@2.31-0ubuntu9.9
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
glibc@2.31-0ubuntu9.9
no fix listed

Open the chart page →

251,257
snappasssnappassVerified publisher0.4.32 of 3See more

snappass snappass 0.4.3

2 of the 3 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
glibc@2.41-12+deb13u1
no fix listed
valkey/valkey:8.1.61f84517eca8e
glibc@2.41-12+deb13u2
no fix listed

Open the chart page →

2,946
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
glibc@2.41-12
no fix listed

Open the chart page →

14,542
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
library/redis:8.10.18a1efc5f4795
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

1,936
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
glibc@2.41-12+deb13u1
no fix listed

Open the chart page →

7,365
postgresql-ha-chartsoldevelo-postgresql-ha-chart16.3.42 of 2See more

postgresql-ha-chart soldevelo-postgresql-ha-chart 16.3.4

2 of the 2 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
soldevelo/pgpool:4.6.3-debian-12-r0044d16a65129
glibc@2.36-9+deb12u13
no fix listed
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

4,703
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
glibc@2.36-9+deb12u7
no fix listed

Open the chart page →

5,689
speckle-serverspeckleVerified publisher2.26.34 of 4See more

speckle-server speckle 2.26.3

4 of the 4 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
speckle/speckle-monitor-deployment:2.26.3d51e1b0cf231
glibc@2.36-9+deb12u7
no fix listed
speckle/speckle-preview-service:2.26.3092384dba45d
glibc@2.36-9+deb12u7
no fix listed
speckle/speckle-server:2.26.379f14a2bf931
glibc@2.36-9+deb12u10
no fix listed
speckle/speckle-webhook-service:2.26.3c58eb372c488
glibc@2.36-9+deb12u7
no fix listed

Open the chart page →

10,239
squidsquid-helmVerified publisher0.1.01 of 1See more

squid squid-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
ubuntu/squid:5.2-22.04_beta723891b5bc74
glibc@2.35-0ubuntu3.11
2.35-0ubuntu3.15

Open the chart page →

2,671
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
graphprotocol/graph-node:v0.37.0f4452cdedd68
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

4,660
multusstartechnicaVerified publisher0.1.21 of 1See more

multus startechnica 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:stableec4e5dfe12b6
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

446
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
glibc@2.31-0ubuntu9.9
no fix listed

Open the chart page →

13,622
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

102,725
stornxstornxVerified publisher1.1.13 of 9See more

stornx stornx 1.1.1

3 of the 9 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.9
alazidis/stornx:1.1.1602d4f7f090c
glibc@2.36-9+deb12u13
no fix listed
istio/pilot:1.29.1f8b0e412ac4a
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.9

Open the chart page →

11,773
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.9

Open the chart page →

2,941
supabasesupabse0.8.06 of 11See more

supabase supabse 0.8.0

6 of the 11 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.30.13b709e4a0e5e
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.9
kong/kong:3.9.16addf50e6bd8
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.9
supabase/edge-runtime:v1.74.02781daf92394
glibc@2.36-9+deb12u13
no fix listed
supabase/postgres-meta:v0.96.6a84cc713585e
glibc@2.36-9+deb12u13
no fix listed
supabase/realtime:v2.102.3aa1c92c0cf32
glibc@2.36-9+deb12u14
no fix listed
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

17,986
supersonicsupersonicVerified publisher0.3.11 of 2See more

supersonic supersonic 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.92956bd9de830
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.15

Open the chart page →

2,162
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
glibc@2.41-12+deb13u2
no fix listed

Open the chart page →

3,304
mumblesyntaxerror404Verified publisher1.0.51 of 1See more

mumble syntaxerror404 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.9

Open the chart page →

2,176
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

1,593
headscaleszpadel-chartsVerified publisher0.30.22 of 3See more

headscale szpadel-charts 0.30.2

2 of the 3 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:0.29.18453e47ea6bf
glibc@2.41-12+deb13u3
no fix listed
ghcr.io/tale/headplane:0.6.39476cc5adb12
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

1,748
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-6368.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

1,593

Container images carrying it

2,708 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
glibc@2.41-12
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
glibc@2.36-9+deb12u3
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
glibc@2.36-9+deb12u8
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
glibc@2.36-9+deb12u13
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
glibc@2.36-9+deb12u10
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
glibc@2.36-9+deb12u14
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
glibc@2.36-9+deb12u10
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.