CVE-2026-6791
CriticalAdvisory
Published 2 Jul 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.0
- base score, highest
- EPSS
- 0.002
- 11th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,625
- of 17,821 indexed, latest versions
- Container images
- 2,680
- deployed by those charts
- Fix available
- 2 of 4
- affected packages
CVE-2026-6791 affecting package glibc 2.38-21
Carried by container images the latest versions of 2,625 of 17,821 indexed charts deploy, on 2,680 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| glibcdeb | 2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+63 more | 2.35-0ubuntu3.15, 2.39-0ubuntu8.9, 2.41-12+deb13u3+e2, 2.43-2ubuntu2.4 | 2,630 |
| glibcapk | 2.37-r6, 2.38-r6, 2.39-r7, 2.40-r1+10 more | 2.43-r10 | 30 |
| eglibcdeb | 2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 more | no fix listed | 7 |
| glibcrpm | 2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3 | no fix listed | 13 |
- OSV records
- CGA-pg7p-jc78-5qw9DEBIAN-CVE-2026-6791UBUNTU-CVE-2026-6791AZL-95492ECHO-9658-3093-2999
- Also known as
- CGA-q9rx-85qf-q76x, USN-8737-1, USN-8737-2
Charts affected
2,625 by stars
| Chart | Latest | Affected images | Radar Score |
|---|
Container images carrying it
2,680 by charts deploying them
A fixed version is listed for 2 of the 4 affected packages.
No deployed image carries CVE-2026-6791.