StackRadar

CVE-2026-6791

Critical

Advisory

Published 2 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.0
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,625
of 17,821 indexed, latest versions
Container images
2,680
deployed by those charts
Fix available
2 of 4
affected packages

CVE-2026-6791 affecting package glibc 2.38-21

Carried by container images the latest versions of 2,625 of 17,821 indexed charts deploy, on 2,680 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+63 more2.35-0ubuntu3.15, 2.39-0ubuntu8.9, 2.41-12+deb13u3+e2, 2.43-2ubuntu2.42,630
glibcapk2.37-r6, 2.38-r6, 2.39-r7, 2.40-r1+10 more2.43-r1030
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibcrpm2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3no fix listed13
OSV records
CGA-pg7p-jc78-5qw9DEBIAN-CVE-2026-6791UBUNTU-CVE-2026-6791AZL-95492ECHO-9658-3093-2999
Also known as
CGA-q9rx-85qf-q76x, USN-8737-1, USN-8737-2

Charts affected

2,625 by stars
ChartLatestAffected imagesRadar Score
clickhouselohmag0.2.01 of 1See more

clickhouse lohmag 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.17ab1738a64b70
glibc@2.27-3ubuntu1
no fix listed

Open the chart page →

5,932
allure_docker_servicelovemew67Verified publisher0.0.11 of 1See more

allure_docker_service lovemew67 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.27.00815040339a9
glibc@2.27-3ubuntu1.2
no fix listed

Open the chart page →

65,433
cloudflare-tunnel-remotelovemew67Verified publisher0.1.21 of 1See more

cloudflare-tunnel-remote lovemew67 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
cloudflare/cloudflared:latestb269e8abd07a
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

356
mongo_guilovemew67Verified publisher0.0.21 of 1See more

mongo_gui lovemew67 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.1.1e3952b14ae8e
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

2,018
oncall-hobbylovemew67Verified publisher0.0.51 of 2See more

oncall-hobby lovemew67 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/redis:7.0.15352c1fdadc91
glibc@2.36-9+deb12u8
no fix listed

Open the chart page →

5,909
vulnerability-scaninglovemew67Verified publisher0.0.31 of 2See more

vulnerability-scaning lovemew67 0.0.3

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.35.14154286c0209
glibc@2.39-0ubuntu8.6
2.39-0ubuntu8.9

Open the chart page →

5,245
loxilbloxilbVerified publisher0.1.01 of 2See more

loxilb loxilb 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
glibc@2.35-0ubuntu3.14
2.35-0ubuntu3.15

Open the chart page →

4,563
lsdisklsdiskVerified publisher2.0.71 of 4See more

lsdisk lsdisk 2.0.7

1 of the 4 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

5,084
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

91,568
redislsst-sqre1.2.11 of 1See more

redis lsst-sqre 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,010
squash-apilsst-sqre0.1.61 of 3See more

squash-api lsst-sqre 0.1.6

1 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/redis:6.2143f7bfc2358
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

6,675
elastictranscoderluiscajl0.46.04 of 4See more

elastictranscoder luiscajl 0.46.0

4 of the 4 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
elastictranscoder/media:627e21dc963ab3858c6b
glibc@2.27-3ubuntu1.2
no fix listed
elastictranscoder/media-storage:f6d861a026208b8c2359
glibc@2.27-3ubuntu1.2
no fix listed
elastictranscoder/transcoder:627e21dcb4a0327029e6
glibc@2.27-3ubuntu1.2
no fix listed
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
glibc@2.27-3ubuntu1.2
no fix listed

Open the chart page →

58,348
flaresolverrluiscajl0.0.31 of 1See more

flaresolverr luiscajl 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:latest139dfee1c6f8
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

27,938
plex-rclone-wireguardluiscajl1.0.191 of 2See more

plex-rclone-wireguard luiscajl 1.0.19

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:latest7f9a1d574958
glibc@2.43-2ubuntu2.3
2.43-2ubuntu2.4

Open the chart page →

876
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
glibc@2.41-12+deb13u1
no fix listed

Open the chart page →

4,726
jellyfinm0nsterrr-jellyfinVerified publisher2.3.51 of 1See more

jellyfin m0nsterrr-jellyfin 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

2,672
kea-exporterm0nsterrr-kea-exporterVerified publisher2.2.11 of 1See more

kea-exporter m0nsterrr-kea-exporter 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,099
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
glibc@2.36-9+deb12u4
no fix listed

Open the chart page →

9,858
magistralamagistrala-devopsVerified publisher0.16.22 of 42See more

magistrala magistrala-devops 0.16.2

2 of the 42 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.31-latestcaa5b411be16
glibc@2.35-0ubuntu3.10
2.35-0ubuntu3.15
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
glibc@2.35-0ubuntu3.5
2.35-0ubuntu3.15

Open the chart page →

24,771
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
mvance/unbound:1.22.076906da36d18
glibc@2.36-9+deb12u8
no fix listed

Open the chart page →

11,554
demoshopmakaira2.4.02 of 4See more

demoshop makaira 2.4.0

2 of the 4 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
glibc@2.41-12+deb13u3
no fix listed
library/php:8.4-fpm59fa733c9af6
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

4,665
plane-mcp-servermakeplaneVerified publisher1.0.02 of 2See more

plane-mcp-server makeplane 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
makeplane/plane-mcp-server:v0.3.071b7252adef0
glibc@2.41-12+deb13u3
no fix listed
valkey/valkey:9.1.164e361b630ec
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

2,660
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
glibc@2.36-9
no fix listed

Open the chart page →

7,393
eirmargaysVerified publisher1.7.21 of 1See more

eir margays 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
margays/eir:v1.7.22883fdd06fd7
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

829
marge-botmarge-bot-helm1.3.51 of 1See more

marge-bot marge-bot-helm 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.16.0b59f01bc0418
glibc@2.41-12
no fix listed

Open the chart page →

3,627
circleci-runnermatic-insurance0.1.11 of 1See more

circleci-runner matic-insurance 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
circleci/runner:launch-agent9bdc62f02162
glibc@2.31-0ubuntu9.16
no fix listed

Open the chart page →

4,172
nginxmatic-insurance1.1.11 of 1See more

nginx matic-insurance 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,956
matrix-authentication-servicematrix-authentication-serviceVerified publisher0.1.241 of 1See more

matrix-authentication-service matrix-authentication-service 0.1.24

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/element-hq/matrix-authentication-service:1.24.052c18ffcc940
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

334
mattermost-team-editionmattermost-team-edition6.6.831 of 4See more

mattermost-team-edition mattermost-team-edition 6.6.83

1 of the 4 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

4,131
mauticmautic-chartVerified publisher1.0.22 of 3See more

mautic mautic-chart 1.0.2

2 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.2.6-debian-12-r0373c3c260571
glibc@2.36-9+deb12u8
no fix listed
mautic/mautic:7-apacheeb8cc73d97e1
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

8,526
mayastormayastorVerified publisher2.12.12 of 31See more

mayastor mayastor 2.12.1

2 of the 31 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.9
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

21,494
eoloplantmca-eoloplaner0.1.03 of 7See more

eoloplant mca-eoloplaner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
hugohg34/toposervice:0.0.2812a03b3f274
glibc@2.31-0ubuntu9.7
no fix listed
library/mongo:5.0.6-focal8e70544b6c76
glibc@2.31-0ubuntu9.7
no fix listed
library/rabbitmq:3.9-management8a279e9396a8
glibc@2.35-0ubuntu3.6
2.35-0ubuntu3.15

Open the chart page →

29,889
claude-code-apimcp-helmVerified publisher0.1.11 of 1See more

claude-code-api mcp-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
arbuzov/claude-code-api:0.1.02d7dd8070610
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

4,108
mcp-homeassistantmcp-helmVerified publisher0.2.41 of 1See more

mcp-homeassistant mcp-helm 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
voska/hass-mcp:latest7142a431e2c5
glibc@2.36-9+deb12u9
no fix listed

Open the chart page →

10,724
mcp-kubernetesmcp-helmVerified publisher0.2.71 of 1See more

mcp-kubernetes mcp-helm 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
mcp/kubernetes:latest5ffbf7f0a8aa
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

5,712
mcpomcp-helmVerified publisher0.2.81 of 1See more

mcpo mcp-helm 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/open-webui/mcpo:git-39b4867f06525afac6b
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

4,603
mcp-playwrightmcp-helmVerified publisher0.1.11 of 1See more

mcp-playwright mcp-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
mcr.microsoft.com/playwright/mcp:v0.0.43e101b832b34d
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

4,172
searchmcp-helmVerified publisher0.1.31 of 2See more

search mcp-helm 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:latestc80ae007ce2c
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

8,409
mcroutermcrouterVerified publisher0.2.02 of 2See more

mcrouter mcrouter 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
library/memcached:1.6.4226983a43c918
glibc@2.41-12+deb13u3
no fix listed
ghcr.io/dragoangel/mcrouter:v2026.06.29.0042afcffe67d0
glibc@2.39-0ubuntu8.7
2.39-0ubuntu8.9

Open the chart page →

2,363
backstagemcwarmanVerified publisher0.10.102 of 2See more

backstage mcwarman 0.10.10

2 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
glibc@2.41-12
no fix listed
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

9,918
mdai-hubmdai-hubVerified publisher0.10.12 of 14See more

mdai-hub mdai-hub 0.10.1

2 of the 14 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
envoyproxy/envoy:distroless-v1.37.283e4482fc051
glibc@2.36-9+deb12u13
no fix listed
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
glibc@2.41-12
no fix listed

Open the chart page →

4,930
applicationmediamarktsaturn1.37.01 of 1See more

application mediamarktsaturn 1.37.0

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
quay.io/heubeck/examiner:1.14.61154472ff8c4
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

829
dependency-trackmediamarktsaturn1.9.21 of 2See more

dependency-track mediamarktsaturn 1.9.2

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.14.21ba4f004e1ec
glibc@2.41-12+deb13u2
no fix listed

Open the chart page →

3,864
flaresolverrmedia-servarrVerified publisher0.18.21 of 1See more

flaresolverr media-servarr 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

6,795
tinymediamanagermedia-servarrVerified publisher1.6.31 of 2See more

tinymediamanager media-servarr 1.6.3

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
glibc@2.41-12+deb13u2
no fix listed

Open the chart page →

8,196
cameramedia-streaming-meshVerified publisher0.2.52 of 3See more

camera media-streaming-mesh 0.2.5

2 of the 3 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
glibc@2.31-0ubuntu9.9
no fix listed
ciscolabs/rtsp-server:latestb59fc10bb821
glibc@2.31-0ubuntu9.9
no fix listed

Open the chart page →

18,713
crdsmedia-streaming-meshVerified publisher0.0.11 of 2See more

crds media-streaming-mesh 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ciscolabs/msm-nc:0710202336d02faad958
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.15

Open the chart page →

3,737
msmmedia-streaming-meshVerified publisher0.1.175 of 6See more

msm media-streaming-mesh 0.1.17

5 of the 6 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.9
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
glibc@2.39-0ubuntu8.3
2.39-0ubuntu8.9
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
glibc@2.39-0ubuntu8.2
2.39-0ubuntu8.9
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
glibc@2.39-0ubuntu8.2
2.39-0ubuntu8.9
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
glibc@2.39-0ubuntu8.2
2.39-0ubuntu8.9

Open the chart page →

11,651
msm-rtspmedia-streaming-meshVerified publisher0.0.22 of 2See more

msm-rtsp media-streaming-mesh 0.0.2

2 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
glibc@2.31-0ubuntu9.9
no fix listed
ciscolabs/rtsp-server:latestb59fc10bb821
glibc@2.31-0ubuntu9.9
no fix listed

Open the chart page →

18,713
rtspmedia-streaming-meshVerified publisher0.0.142 of 2See more

rtsp media-streaming-mesh 0.0.14

2 of the 2 container images this version deploys carry CVE-2026-6791.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
glibc@2.31-0ubuntu9.9
no fix listed
ciscolabs/rtsp-server:latestb59fc10bb821
glibc@2.31-0ubuntu9.9
no fix listed

Open the chart page →

18,713

Container images carrying it

2,680 by charts deploying them

A fixed version is listed for 2 of the 4 affected packages.

No deployed image carries CVE-2026-6791.

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.