StackRadar

CVE-2026-6791

Critical

Advisory

Published 2 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.0
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,625
of 17,821 indexed, latest versions
Container images
2,680
deployed by those charts
Fix available
2 of 4
affected packages

CVE-2026-6791 affecting package glibc 2.38-21

Carried by container images the latest versions of 2,625 of 17,821 indexed charts deploy, on 2,680 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+63 more2.35-0ubuntu3.15, 2.39-0ubuntu8.9, 2.41-12+deb13u3+e2, 2.43-2ubuntu2.42,630
glibcapk2.37-r6, 2.38-r6, 2.39-r7, 2.40-r1+10 more2.43-r1030
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibcrpm2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3no fix listed13
OSV records
CGA-pg7p-jc78-5qw9DEBIAN-CVE-2026-6791UBUNTU-CVE-2026-6791AZL-95492ECHO-9658-3093-2999
Also known as
CGA-q9rx-85qf-q76x, USN-8737-1, USN-8737-2

Charts affected

2,625 by stars
ChartLatestAffected imagesRadar Score
sample-bookinfokubesphere-testVerified publisher1.0.01 of 4See more

sample-bookinfo kubesphere-test 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
kubesphere/examples-bookinfo-reviews-v2:1.13.06d93129beb32
glibc@2.23-0ubuntu11
no fix listed

Open the chart page →

9,424
xenondbkubesphere-testVerified publisher1.0.01 of 3See more

xenondb kubesphere-test 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

7,406
vector-controllerkubevela0.2.31 of 2See more

vector-controller kubevela 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
oamdev/vector-controller:v0.2.39dd8be44ffc9
glibc@2.27-3ubuntu1.6
no fix listed

Open the chart page →

4,820
kubevirtkubevirtVerified publisher0.2.01 of 1See more

kubevirt kubevirt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
quay.io/kubevirt/virt-operator:v1.8.465d23c9ad917
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

648
kubevoipkubevoipOfficialVerified publisher0.6.81 of 1See more

kubevoip kubevoip 0.6.8

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/kubevoip/kubevoip:v0.6.841c603a93642
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,129
network-enforcerkubewardenVerified publisher0.1.21 of 3See more

network-enforcer kubewarden 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0.4ca08b7d2df5b
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

2,694
kube-wordpress-mysqlkube-wordpress-mysql0.1.01 of 2See more

kube-wordpress-mysql kube-wordpress-mysql 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/wordpress:php8.1-apachef73396626d2f
glibc@2.41-12
no fix listed

Open the chart page →

8,931
penpotkubitodevVerified publisher1.2.12 of 5See more

penpot kubitodev 1.2.1

2 of the 5 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.15
penpotapp/exporter:2.2.15c835ffd87ab
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.15

Open the chart page →

17,074
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.43 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

3 of the 9 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
grafana/alloy:v1.5.101a63f4e032c
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.9
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
glibc@2.41-12
no fix listed
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

20,582
ctrlmeshkusionstackVerified publisher0.2.01 of 1See more

ctrlmesh kusionstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
glibc@2.31-0ubuntu9.16
no fix listed

Open the chart page →

3,489
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.15

Open the chart page →

63,775
sample-operatorkusionstackVerified publisher0.1.21 of 1See more

sample-operator kusionstack 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
chaerr/kridge:demo-operator-v0.1.266833deec017
glibc@2.31-0ubuntu9.9
no fix listed

Open the chart page →

2,523
kustomize-patcherkustomize-patcher1.0.21 of 2See more

kustomize-patcher kustomize-patcher 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/themesama/kubernetes-kustomize-patcher:latestb1bf0669e3a0
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

908
fstyr-ddp-keycloak-application-platform-configkvalitetsitVerified publisher0.1.131 of 1See more

fstyr-ddp-keycloak-application-platform-config kvalitetsit 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.9

Open the chart page →

3,172
keycloak-application-platform-configkvalitetsitVerified publisher0.0.291 of 1See more

keycloak-application-platform-config kvalitetsit 0.0.29

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
glibc@2.39-0ubuntu8.2
2.39-0ubuntu8.9

Open the chart page →

3,403
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
glibc@2.27-3ubuntu1.4
no fix listed

Open the chart page →

16,733
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
glibc@2.35-0ubuntu3.8
2.35-0ubuntu3.15

Open the chart page →

7,863
nginx-chartkyb-nginx0.1.01 of 1See more

nginx-chart kyb-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,956
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
glibc@2.27-3ubuntu1
no fix listed

Open the chart page →

26,562
pageslatif-pages1.0.02 of 3See more

pages latif-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
glibc@2.31-0ubuntu9.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
glibc@2.27-3ubuntu1
no fix listed

Open the chart page →

20,285
pageslavanya-pages1.0.02 of 3See more

pages lavanya-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
glibc@2.31-0ubuntu9.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
glibc@2.27-3ubuntu1
no fix listed

Open the chart page →

20,285
homebridgelbenicio-communityVerified publisher0.1.151 of 1See more

homebridge lbenicio-community 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
glibc@2.39-0ubuntu8.8
2.39-0ubuntu8.9

Open the chart page →

34,371
smtplbenicio-communityVerified publisher0.1.31 of 1See more

smtp lbenicio-community 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,387
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

33,925
jenkinsleechistest2.7.11 of 2See more

jenkins leechistest 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

4,496
kinesaliteleprechaun-charts0.1.21 of 1See more

kinesalite leprechaun-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
instructure/kinesalite:latest34400d82f28f
glibc@2.31-0ubuntu9.17
no fix listed

Open the chart page →

4,297
owntracks-exporterleprechaun-charts0.1.111 of 1See more

owntracks-exporter leprechaun-charts 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
glibc@2.36-9+deb12u1
no fix listed

Open the chart page →

4,094
vaultwardenleprechaun-charts0.1.281 of 1See more

vaultwarden leprechaun-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.1ebdfe70701c6
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

2,084
jackettlib42Verified publisher1.1.01 of 1See more

jackett lib42 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
lib42/jackett:latesta55596cda383
glibc@2.36-9+deb12u3
no fix listed

Open the chart page →

4,677
librenmslibrenms10.1.21 of 5See more

librenms librenms 10.1.2

1 of the 5 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/redis:8.10.1602d361c4da9
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

2,748
kube-iptables-tailerlifen0.2.31 of 1See more

kube-iptables-tailer lifen 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
glibc@2.31-0ubuntu9.7
no fix listed

Open the chart page →

4,481
lightlyticslightlytics0.1.212 of 2See more

lightlytics lightlytics 0.1.21

2 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
glibc@2.36-9+deb12u9
no fix listed
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

5,471
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

38,692
weblinzhengen0.1.71 of 1See more

web linzhengen 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,956
listmonklistmonk-chartVerified publisher2.0.11 of 2See more

listmonk listmonk-chart 2.0.1

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/postgres:15dfbbb0ad8cab
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

3,143
pocketbase-halitesql0.0.31 of 1See more

pocketbase-ha litesql 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/litesql/pocketbase-ha:latestc5b28608958b
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,170
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.15

Open the chart page →

10,844
pagesliviu884422-pages1.0.02 of 3See more

pages liviu884422-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
glibc@2.31-0ubuntu9.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
glibc@2.27-3ubuntu1
no fix listed

Open the chart page →

20,285
web-chartljw-ktcloudlab0.1.01 of 1See more

web-chart ljw-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,956
llmarinerllmariner1.53.11 of 21See more

llmariner llmariner 1.53.1

1 of the 21 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
glibc@2.41-12
no fix listed

Open the chart page →

12,185
jellyfinlmatfyVerified publisher0.1.31 of 1See more

jellyfin lmatfy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11aefb67e6a7ff
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

2,672
mt-mcp-grafanaloafoe0.10.01 of 2See more

mt-mcp-grafana loafoe 0.10.0

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
grafana/mcp-grafana:0.14.042f541f22063
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

1,988
mt-mcp-proxyloafoe0.3.01 of 2See more

mt-mcp-proxy loafoe 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/github/github-mcp-server:latest508a0857ec76
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

505
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
locustio/locust:2.24.151d866285170
glibc@2.36-9+deb12u4
no fix listed

Open the chart page →

7,581
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

33,925
vnode-runtimeloftVerified publisher0.3.31 of 1See more

vnode-runtime loft 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
glibc@2.35-0ubuntu3.14
2.35-0ubuntu3.15

Open the chart page →

2,546
nightingalelogic3579Verified publisher0.3.13 of 6See more

nightingale logic3579 0.3.1

3 of the 6 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.9
flashcatcloud/nightingale:8.5.1421acb36181b
glibc@2.41-12+deb13u1
no fix listed
library/redis:6.2e7b96daa9a18
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

9,172
rocketmq-exporterlogic3579Verified publisher0.0.21 of 1See more

rocketmq-exporter logic3579 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
apache/rocketmq-exporter:0.0.2c8fb51195444
glibc@2.35-0ubuntu3.6
2.35-0ubuntu3.15

Open the chart page →

6,692
login-test-backendlogin-test-backend0.1.01 of 2See more

login-test-backend login-test-backend 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
aboogie/login_test_backend:new9c41a4483ac8
glibc@2.36-9+deb12u7
no fix listed

Open the chart page →

6,610
apica-ascentlogiqai2.0.41 of 19See more

apica-ascent logiqai 2.0.4

1 of the 19 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
logiqai/flash:v3.10.265b996bc7bdc
glibc@2.36-9+deb12u8
no fix listed

Open the chart page →

23,806

Container images carrying it

2,680 by charts deploying them

A fixed version is listed for 2 of the 4 affected packages.

No deployed image carries CVE-2026-6791.

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.