StackRadar

CVE-2026-6791

Critical

Advisory

Published 2 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.0
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,612
of 17,828 indexed, latest versions
Container images
2,681
deployed by those charts
Fix available
2 of 4
affected packages

CVE-2026-6791 affecting package glibc 2.38-21

Carried by container images the latest versions of 2,612 of 17,828 indexed charts deploy, on 2,681 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+62 more2.35-0ubuntu3.15, 2.39-0ubuntu8.9, 2.41-12+deb13u3+e2, 2.43-2ubuntu2.42,632
glibcapk2.37-r6, 2.38-r6, 2.39-r7, 2.40-r1+10 more2.43-r1029
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibcrpm2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3no fix listed13
OSV records
CGA-pg7p-jc78-5qw9DEBIAN-CVE-2026-6791UBUNTU-CVE-2026-6791AZL-95492ECHO-9658-3093-2999
Also known as
CGA-q9rx-85qf-q76x, USN-8737-1, USN-8737-2

Charts affected

2,612 by stars
ChartLatestAffected imagesRadar Score
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
glibc@2.31-0ubuntu9.2
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
glibc@2.31-0ubuntu9.2
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
glibc@2.31-0ubuntu9.2
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
glibc@2.31-0ubuntu9.2
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

267,484
ohifkylesferrazzaVerified publisher0.1.01 of 2See more

ohif kylesferrazza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
jodogne/orthanc-plugins:latest6ff510aa29c2
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

3,577
overpass-apil4gVerified publisher0.1.21 of 1See more

overpass-api l4g 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
wiktorn/overpass-api:latest9bb5f4a9b54c
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

3,513
api-gatewaylabs64io-helm-chartsVerified publisher0.14.21See more

api-gateway labs64io-helm-charts 0.14.2

1 container image this version deploys carries CVE-2026-6791.

Container imageDigestPackageFixed in
labs64/traefik-authproxy:0.0.3dfc6086dfbce
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

auditflowlabs64io-helm-chartsVerified publisher0.15.21See more

auditflow labs64io-helm-charts 0.15.2

1 container image this version deploys carries CVE-2026-6791.

Container imageDigestPackageFixed in
labs64/auditflowdigest-pinnedc7b26d3ca11c
glibc@2.43-2ubuntu2.3
2.43-2ubuntu2.4

Open the chart page →

checkoutlabs64io-helm-chartsVerified publisher0.11.21See more

checkout labs64io-helm-charts 0.11.2

1 container image this version deploys carries CVE-2026-6791.

Container imageDigestPackageFixed in
library/postgres:1886c951e05bf5
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

payment-gatewaylabs64io-helm-chartsVerified publisher0.10.22See more

payment-gateway labs64io-helm-charts 0.10.2

2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
labs64/payment-gateway:0.0.10c66feefca17
glibc@2.43-2ubuntu2.3
2.43-2ubuntu2.4
library/postgres:1886c951e05bf5
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
langflowai/langflow-frontend:latest54f67f1961fe
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

3,959
lgtm-stacklgtm-stackVerified publisher0.1.31 of 8See more

lgtm-stack lgtm-stack 0.1.3

1 of the 8 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
grafana/alloy:v1.18.10f4434c92b3e
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9

Open the chart page →

2,527
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

35,613
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
glibc@2.31-0ubuntu9.7
no fix listed

Open the chart page →

4,481
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
glibc@2.41-r56
2.43-r10

Open the chart page →

4,539
halitesql0.1.51 of 2See more

ha litesql 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/litesql/ha:latest7376ffffc1a2
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

866
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
glibc@2.39-0ubuntu8.5
2.39-0ubuntu8.9

Open the chart page →

8,115
clickhouseliwenhe1.0.11 of 3See more

clickhouse liwenhe 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.14ccf9c2b5e3f2
glibc@2.27-3ubuntu1
no fix listed

Open the chart page →

6,787
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

7,221
locustlocustVerified publisher0.1.41 of 1See more

locust locust 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
hansehe/locust:1.1.0bc8e45262bc4
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

2,729
voice-biometricslumenvox2.0.112 of 26See more

voice-biometrics lumenvox 2.0.1

12 of the 26 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
lumenvox/cloud-assure-api:2.0.0fcb9fb54a9fd
glibc@2.31-0ubuntu9.2
no fix listed
lumenvox/cloud-assure-identity:2.0.0147854a3c916
glibc@2.31-0ubuntu9.2
no fix listed
lumenvox/cloud-audit:2.0.079428add7f38
glibc@2.31-0ubuntu9.2
no fix listed
lumenvox/cloud-binary-storage:2.0.053decadc102d
glibc@2.31-0ubuntu9.2
no fix listed
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
glibc@2.31-0ubuntu9.2
no fix listed
lumenvox/cloud-deployment:2.0.0ea8110886d38
glibc@2.31-0ubuntu9.2
no fix listed
lumenvox/cloud-engine-resource:2.0.0e2e5abe27abc
glibc@2.31-0ubuntu9.2
no fix listed
lumenvox/cloud-management-api:2.0.0b9a23345eabd
glibc@2.31-0ubuntu9.2
no fix listed
lumenvox/cloud-reporting:2.0.07a9ffdc2178a
glibc@2.31-0ubuntu9.2
no fix listed
lumenvox/cloud-reporting-api:2.0.0dbbaf5462ad6
glibc@2.31-0ubuntu9.2
no fix listed
lumenvox/cloud-transaction:2.0.08b74f9d3ba09
glibc@2.31-0ubuntu9.2
no fix listed
lumenvox/cloud-voice-verifier:2.0.014170ad34903
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

71,537
actualbudgetm0nsterrr-actualbudgetVerified publisher2.10.01 of 1See more

actualbudget m0nsterrr-actualbudget 2.10.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

1,066
flaresolverrm0nsterrr-flaresolverrVerified publisher2.4.11 of 1See more

flaresolverr m0nsterrr-flaresolverr 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

6,807
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

5,716
redismagefleet-redis0.1.01 of 1See more

redis magefleet-redis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/redis:7.20637954999d0
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

1,050
magentomagento3.2.33 of 12See more

magento magento 3.2.3

3 of the 12 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/mariadb:10.422edfe1c7834
glibc@2.31-0ubuntu9.16
no fix listed
library/rabbitmq:4.1.0-management935b3f84c1e4
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.9
library/redis:7.20637954999d0
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

13,765
mcp-orchestratormagertronVerified publisher3.8.711See more

mcp-orchestrator magertron 3.8.71

1 container image this version deploys carries CVE-2026-6791.

Container imageDigestPackageFixed in
envoyproxy/envoy:distroless-v1.33.148599dee1e6ea
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

maptiler-servermaptilerOfficialVerified publisher1.3.01 of 1See more

maptiler-server maptiler 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
maptiler/server:4.8.07e206140057b
glibc@2.31-0ubuntu9.17
no fix listed

Open the chart page →

3,039
mattermost-enterprise-editionmattermostVerified publisher2.6.1041 of 3See more

mattermost-enterprise-edition mattermost 2.6.104

1 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
mattermost/mattermost-enterprise-edition:11.11.0f0643c47b55b
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

933
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/mongo:4.2.358b25d51baa1
glibc@2.27-3ubuntu1
no fix listed

Open the chart page →

19,236
mcpmcp-chartsVerified publisher0.0.233 of 7See more

mcp mcp-charts 0.0.23

3 of the 7 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
glibc@2.41-12
no fix listed
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
glibc@2.41-12
no fix listed
ghcr.io/maritimeconnectivity/identityregistry:latest5009fd419742
glibc@2.43-2ubuntu2.3
2.43-2ubuntu2.4

Open the chart page →

7,011
jellyfinmedia-servarrVerified publisher0.17.11 of 2See more

jellyfin media-servarr 0.17.1

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

2,603
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.9

Open the chart page →

4,256
mockservermockserverOfficialVerified publisher8.0.01 of 1See more

mockserver mockserver 8.0.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
mockserver/mockserver:mockserver-8.0.0b8426e0b3c80
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

1,079
model-manager-loadermodel-manager-loader1.27.01 of 1See more

model-manager-loader model-manager-loader 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
glibc@2.41-12
no fix listed

Open the chart page →

2,745
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

13,835
redminemt1905027.3.42 of 3See more

redmine mt190502 7.3.4

2 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/postgres:1886c951e05bf5
glibc@2.41-12+deb13u4
no fix listed
library/redmine:6.1.204ac44a2595b
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

7,236
12factormyaVerified publisher24.1.21 of 1See more

12factor mya 24.1.2

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

1,593
my-react-appmy-react-app0.1.51 of 1See more

my-react-app my-react-app 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

1,593
n3uronn3uronVerified publisher0.3.51 of 1See more

n3uron n3uron 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
n3uronhub/n3uron:v1.22.4423a0bdd9cb9
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,851
satisfactorynaj981.1.11 of 1See more

satisfactory naj98 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.1199be1064b18
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.15

Open the chart page →

3,753
spring-helmnaveenalla-springboot1.0.01 of 2See more

spring-helm naveenalla-springboot 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

1,272
clowder2ncsaVerified publisher1.9.75 of 12See more

clowder2 ncsa 1.9.7

5 of the 12 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
glibc@2.36-9+deb12u4
no fix listed
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
glibc@2.36-9+deb12u4
no fix listed
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
glibc@2.36-9+deb12u13
no fix listed
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
glibc@2.36-9+deb12u13
no fix listed
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

37,558
nginx-chartnginx-chart-testVerified publisher0.1.11 of 1See more

nginx-chart nginx-chart-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

1,593
cloud9nicholaswildeVerified publisher1.0.01 of 1See more

cloud9 nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
linuxserver/cloud9:version-1.29.245c5fe102ff3
glibc@2.27-3ubuntu1.5
no fix listed

Open the chart page →

11,745
papermergenicholaswildeVerified publisher1.0.21 of 1See more

papermerge nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/papermerge:version-v2.0.198ba2dd3f0bd
glibc@2.31-0ubuntu9.7
no fix listed

Open the chart page →

20,273
writefreelynicholaswildeVerified publisher1.0.01 of 1See more

writefreely nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/writefreely:version-0.13.1c3c8481b7e56
glibc@2.27-3ubuntu1.4
no fix listed

Open the chart page →

8,107
node-provider-labelernode-provider-labelerVerified publisher0.20.01 of 1See more

node-provider-labeler node-provider-labeler 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/jossware/node-provider-labeler:v0.8.0f80e85291439
glibc@2.36-9+deb12u7
no fix listed

Open the chart page →

1,122
helm-composenousefreakVerified publisher0.1.32 of 2See more

helm-compose nousefreak 0.1.3

2 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/mariadb:10.8.2-focal490f01279be1
glibc@2.31-0ubuntu9.2
no fix listed
library/wordpress:latesta85a30d9e752
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

13,651
nvidia-gpu-exporternvidia-gpu-exporterVerified publisher2.15.11 of 1See more

nvidia-gpu-exporter nvidia-gpu-exporter 2.15.1

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
utkuozdemir/nvidia_gpu_exporter:1.15.17aee2d42836a
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

201
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
glibc@2.36-9+deb12u8
no fix listed

Open the chart page →

5,052
growthbookone-acre-fundVerified publisher0.3.01 of 3See more

growthbook one-acre-fund 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
growthbook/growthbook:latestcbf1bc59e9a9
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

1,164
onechartonechart-slVerified publisher0.76.01 of 1See more

onechart onechart-sl 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

1,593

Container images carrying it

2,681 by charts deploying them

A fixed version is listed for 2 of the 4 affected packages.

No deployed image carries CVE-2026-6791.

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.