StackRadar

CVE-2026-6791

Critical

Advisory

Published 2 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.0
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,584
of 17,792 indexed, latest versions
Container images
2,622
deployed by those charts
Fix available
2 of 4
affected packages

CVE-2026-6791 affecting package glibc 2.38-21

Carried by container images the latest versions of 2,584 of 17,792 indexed charts deploy, on 2,622 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+62 more2.35-0ubuntu3.15, 2.39-0ubuntu8.9, 2.41-12+deb13u3+e2, 2.43-2ubuntu2.42,562
glibcapk2.37-r6, 2.38-r6, 2.39-r7, 2.40-r1+10 more2.43-r1030
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibcrpm2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3no fix listed23
OSV records
CGA-pg7p-jc78-5qw9DEBIAN-CVE-2026-6791UBUNTU-CVE-2026-6791AZL-95492ECHO-9658-3093-2999
Also known as
CGA-q9rx-85qf-q76x, USN-8737-1, USN-8737-2

Charts affected

2,584 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,622 by charts deploying them

A fixed version is listed for 2 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
consensys/teku:latest3a4f5761ae1c
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9
1
consensys/teku:25.4.1bf6ecd2ea716
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.9
1
consensys/web3signer:latestf146a51a1ba3
glibc@2.43-2ubuntu2.3
2.43-2ubuntu2.4
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
glibc@2.36-9+deb12u8
no fix listed
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
glibc@2.36-9+deb12u14
no fix listed
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
glibc@2.35-0ubuntu3.11
2.35-0ubuntu3.15
1
cortezaproject/corteza:2024.9.08eb7a26605c9
glibc@2.31-0ubuntu9.16
no fix listed
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
glibc@2.35-0ubuntu3.10
2.35-0ubuntu3.15
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
glibc@2.36-9+deb12u10
no fix listed
1
coturn/coturn:4.10.0-r1f4c2af06c3c5
glibc@2.41-12+deb13u2
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
glibc@2.31-0ubuntu9.7
no fix listed
1
cradlepoint/pgbouncer:1.0.18f5720b0cd03
glibc@2.27-3ubuntu1
no fix listed
1
cribl/cribl:3.0.2762747cb6796
glibc@2.27-3ubuntu1.4
no fix listed
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
glibc@2.23-0ubuntu11.3
no fix listed
1
cspconsole/config-provider:1.0.365524a26a6c23
glibc@2.36-9+deb12u13
no fix listed
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
glibc@2.36-9+deb12u13
no fix listed
1
cspconsole/report-collector:1.0.15839750248193b
glibc@2.36-9+deb12u13
no fix listed
1
cspconsole/report-processor:1.0.279a2d8840bfdf
glibc@2.36-9+deb12u13
no fix listed
1
cubejs/cubestore:v1.5.334ac523a9bab
glibc@2.36-9+deb12u13
no fix listed
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
glibc@2.41-12
no fix listed
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
glibc@2.36-9+deb12u14
no fix listed
1
cyverse/irods-csi-driver:v0.12.0aa69d105b292
glibc@2.35-0ubuntu3.14
2.35-0ubuntu3.15
1
cznic/knot-resolver:v6.4.2fe71c5214fdc
glibc@2.41-12+deb13u3
no fix listed
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
glibc@2.36-9+deb12u3
no fix listed
1
daedalusproject/base_kubectl:latest6f72b5119eda
glibc@2.31-0ubuntu9.1
no fix listed
1
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
glibc@2.36-9+deb12u13
no fix listed
1
dannielkil/book-frontend:latest937993927694
glibc@2.36-9+deb12u8
no fix listed
1
dariomader/twampy:v0.0.2d2f4a8c5e690
glibc@2.38-r6
2.43-r10
1
darthsim/imgproxy:v3.30.13b709e4a0e5e
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.9
1
darthsim/imgproxy:v3.26476cb08c816a
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.9
1
darthsim/imgproxy:v3.29.17d12c7c8fc66
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.9
1
darthsim/imgproxy:latestf247c72df1d7
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9
1
daskdev/dask-notebook:1.1.0052630f5ca04
glibc@2.27-3ubuntu1
no fix listed
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
glibc@2.27-3ubuntu1.6
no fix listed
1
datadog/agent:6aad9994de6a7
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.9
1
datafuselabs/databend-meta:v1.2.279ba877ee6cb4d
glibc@2.36-9+deb12u3
no fix listed
1
datafuselabs/databend-query:v1.2.279a936843b85b4
glibc@2.36-9+deb12u3
no fix listed
1
datalayers/datalayers:v2.2.1017b292079239
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.15
1
datalust/seq:5.0.832-pre9c731bb207a6
glibc@2.23-0ubuntu10
no fix listed
1
datalust/seq-input-gelf:3.0.441-x643de34aed5642
glibc@2.31-0ubuntu9.9
no fix listed
1
datamate/seafile-professional:11.0.202dd66b722464
glibc@2.35-0ubuntu3.10
2.35-0ubuntu3.15
1
dbeaver/cloudbeaver:26.1.287ab86d00f8c
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.9
1
dbgate/dbgate:7.2.3f2dc7423ea88
glibc@2.36-9+deb12u14
no fix listed
1
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
glibc@2.35-0ubuntu3.4
2.35-0ubuntu3.15
1
ddosify/alaz:v0.12.0ea602056d9ce
glibc@2.36-9+deb12u7
no fix listed
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
glibc@2.36-9+deb12u4
no fix listed
1
ddosify/selfhosted_backend:3.2.93c11e3182652
glibc@2.36-9+deb12u4
no fix listed
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
glibc@2.36-9+deb12u4
no fix listed
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
glibc@2.36-9+deb12u4
no fix listed
1
decisionrules/ai-engine:latest38c377e7c01e
glibc@2.41-12+deb13u3
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.