StackRadar

CVE-2026-77117

Medium

Advisory

Published 27 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,796
of 17,911 indexed, latest versions
Container images
2,825
deployed by those charts
Fix available
1 of 4
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 2,796 of 17,911 indexed charts deploy, on 2,825 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+63 more2.35-0ubuntu3.15, 2.39-0ubuntu8.9, 2.41-12+deb13u3+e6, 2.43-2ubuntu2.42,674
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibc-2.44apk2.44-r1, 2.44-r4, 2.44-r5, 2.44-r6no fix listed143
glibc-2.43apk2.43-r14no fix listed1
OSV records
DEBIAN-CVE-2026-77117UBUNTU-CVE-2026-77117CGA-26xq-9jxj-rw6fCGA-3mpj-r23j-gqxpCGA-6rxh-7rcg-6vm6CGA-86q6-jgw4-4qvqCGA-gm49-5xmv-9mwgCGA-gvr8-r35v-jwr6CGA-p9hr-458p-2fj5ECHO-52f8-53b9-ae20
Also known as
CGA-58cc-vw33-fmgw, CGA-965p-4jfr-2ph7, CGA-h2mc-94cg-jh7f, CGA-h7q9-f494-wj26, CGA-h9gc-g4cr-r6c4, CGA-hcvr-63qq-w73g, CGA-hm69-mxvx-ff6j, CGA-jjr2-x4j3-gqwr, CGA-jvq4-83m5-3qqg, CGA-m5f2-g9g8-q69p, CGA-qwjw-qj9j-qrf5, CGA-xxjm-mj25-24q2, USN-8737-1, USN-8737-2

Charts affected

2,796 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,825 by charts deploying them

A fixed version is listed for 1 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
speckle/speckle-webhook-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb107c63336ab5
glibc@2.36-9+deb12u7
no fix listed
1
speckle/speckle-webhook-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e14828aee2277c
glibc@2.36-9+deb12u7
no fix listed
1
speckle/speckle-webhook-service:2.20.2-branch.testing4.134160-9fad4b270f5167d1d4d
glibc@2.36-9+deb12u7
no fix listed
1
speckle/speckle-webhook-service:2.18.12-branch.testing3.88744-f55b341771f872cfa63
glibc@2.36-9+deb12u4
no fix listed
1
speckle/speckle-webhook-service:2.18.11-branch.testing2.88634-335d469902b98ad5327
glibc@2.36-9+deb12u4
no fix listed
1
speckle/speckle-webhook-service:2.17.14-branch.testing.72707.921a5f899913052b72e
glibc@2.36-9+deb12u3
no fix listed
1
speckle/speckle-webhook-service:2.26.3c58eb372c488
glibc@2.36-9+deb12u7
no fix listed
1
speckle/speckle-webhook-service:2.20.6-branch.testing1.154030-9b09114cf1d99bad89a
glibc@2.36-9+deb12u7
no fix listed
1
speckle/speckle-webhook-service:2.25.10-branch.testing6.645-b125c1edd9db6cbe9bb
glibc@2.36-9+deb12u7
no fix listed
1
spy86/rabbitmq-stomp:latestea649101b9fb
glibc@2.31-0ubuntu9.9
no fix listed
1
sslhep/servicex_app:v1.8.6c935e123030d
glibc@2.41-12+deb13u4
no fix listed
1
sslhep/servicex_code_gen_atlas_xaod:v1.8.67827e689caa5
glibc@2.41-12+deb13u4
no fix listed
1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.62d6843be2d8d
glibc@2.41-12+deb13u4
no fix listed
1
sslhep/servicex_code_gen_python:v1.8.696805be717ff
glibc@2.41-12+deb13u4
no fix listed
1
sslhep/servicex_code_gen_raw_uproot:v1.8.61494a81a474b
glibc@2.41-12+deb13u4
no fix listed
1
sslhep/servicex_code_gen_topcp:v1.8.6f7faf8c6c3e4
glibc@2.41-12+deb13u4
no fix listed
1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.6bd738c952e72
glibc@2.41-12+deb13u4
no fix listed
1
sslhep/servicex-did-finder-cernopendata:v1.8.623a80e40ab18
glibc@2.41-12+deb13u4
no fix listed
1
sslhep/servicex-did-finder-xrootd:v1.8.69a9fb17458f1
glibc@2.41-12+deb13u4
no fix listed
1
stackstorm/st2actionrunner:3.888235ba70cad
glibc@2.31-0ubuntu9.12
no fix listed
1
stackstorm/st2api:3.86f56d239d280
glibc@2.31-0ubuntu9.12
no fix listed
1
stackstorm/st2auth:3.833ecfda16608
glibc@2.31-0ubuntu9.12
no fix listed
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
glibc@2.31-0ubuntu9.12
no fix listed
1
stackstorm/st2notifier:3.8f190a6212195
glibc@2.31-0ubuntu9.12
no fix listed
1
stackstorm/st2rulesengine:3.8259503496ff9
glibc@2.31-0ubuntu9.12
no fix listed
1
stackstorm/st2scheduler:3.8b1de2055c362
glibc@2.31-0ubuntu9.12
no fix listed
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
glibc@2.31-0ubuntu9.12
no fix listed
1
stackstorm/st2stream:3.81c8904a3bf67
glibc@2.31-0ubuntu9.12
no fix listed
1
stackstorm/st2timersengine:3.81bf35bfaf00c
glibc@2.31-0ubuntu9.12
no fix listed
1
stackstorm/st2web:3.809989a26c8b7
glibc@2.31-0ubuntu9.12
no fix listed
1
stackstorm/st2workflowengine:3.819fdfffdbba8
glibc@2.31-0ubuntu9.12
no fix listed
1
stalwartlabs/stalwart:v0.16.1425001929f36a
glibc@2.41-12+deb13u3
no fix listed
1
stalwartlabs/stalwart:v0.15.5dcf575db2d53
glibc@2.41-12+deb13u1
no fix listed
1
stardog/stardog:latest2714e5c4b3c1
glibc-2.44@2.44-r4
no fix listed
1
stashapp/stash:latest24dbd7607174
glibc@2.31-0ubuntu9.2
no fix listed
1
stashapp/stash-box:latesta534c8afdf39
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.9
1
statcan/ckan:2.93921305425b8
glibc@2.31-0ubuntu9.2
no fix listed
1
statusim/nimbus-eth2:multiarch-latest6ccd9d382885
glibc@2.36-9+deb12u14
no fix listed
1
strangebee/thehive:5.8.0-1a7f7b05fba24
glibc@2.36-9+deb12u14
no fix listed
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
glibc@2.31-0ubuntu9.2
no fix listed
1
structurizr/onpremises:2025.11.094b5ffb5119c8
glibc@2.39-0ubuntu8.4
2.39-0ubuntu8.9
1
substratusai/verba:v0.4.0-baseURL261695be635eb
glibc@2.36-9+deb12u6
no fix listed
1
supabase/edge-runtime:v1.74.02781daf92394
glibc@2.36-9+deb12u13
no fix listed
1
supabase/edge-runtime:v1.59.0eff9c554d649
glibc@2.36-9+deb12u8
no fix listed
1
supabase/logflare:latesta82f96c8845c
glibc@2.41-12+deb13u4
no fix listed
1
supabase/postgres-meta:v0.96.6a84cc713585e
glibc@2.36-9+deb12u13
no fix listed
1
supabase/postgres-meta:v0.84.2d0a96973e9f1
glibc@2.36-9+deb12u8
no fix listed
1
supabase/realtime:latest7a6d995635f7
glibc@2.41-12+deb13u3
no fix listed
1
supabase/realtime:v2.102.3aa1c92c0cf32
glibc@2.36-9+deb12u14
no fix listed
1
supabase/realtime:v2.33.8d207e6e23ad3
glibc@2.36-9+deb12u8
no fix listed
1

syft 1.42.1 · advisories as of 26 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.