StackRadar

CVE-2026-78408

High

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.9
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,738
of 17,828 indexed, latest versions
Container images
2,748
deployed by those charts
Fix available
2 of 3
affected packages

CVE-2026-78408 affecting package util-linux 2.40.2-5

Carried by container images the latest versions of 2,738 of 17,828 indexed charts deploy, on 2,748 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:2.41.5-0+deb13u1+dhi3, 1:4.16.0-2+really2.41-5+47 more2.41.5-0+deb13u1+e22,488
util-linuxapk2.41-r9, 2.41.2-r0, 2.41.4-r0, 2.42-r0+1 more2.41.6-r1, 2.42.3-r1259
util-linuxrpm2.40.2-4.azl3no fix listed1
OSV records
ALPINE-CVE-2026-78408DEBIAN-CVE-2026-78408UBUNTU-CVE-2026-78408AZL-99393ECHO-3f6d-9602-8caa

Charts affected

2,738 by stars
ChartLatestAffected imagesRadar Score
rpc-snooperethereum-helm-chartsVerified publisher0.0.21 of 1See more

rpc-snooper ethereum-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ethpandaops/rpc-snooper:latestc0b30fcf64bc
util-linux@2.41-5
no fix listed

Open the chart page →

1,540
smart-contract-verifier-httpethereum-helm-chartsVerified publisher0.1.41 of 1See more

smart-contract-verifier-http ethereum-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/blockscout/smart-contract-verifier:main9a43f0cc5797
util-linux@2.39.3-9ubuntu6.5
no fix listed

Open the chart page →

633
syncoor-webethereum-helm-chartsVerified publisher0.0.11 of 1See more

syncoor-web ethereum-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/syncoor-web:master60d7c38d6062
util-linux@2.42.1-r0
2.42.3-r1

Open the chart page →

371
web3signerethereum-helm-chartsVerified publisher1.0.61 of 4See more

web3signer ethereum-helm-charts 1.0.6

1 of the 4 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
consensys/web3signer:latestf146a51a1ba3
util-linux@2.41.3-3ubuntu2
no fix listed

Open the chart page →

2,093
beeethersphereVerified publisher0.17.41 of 1See more

bee ethersphere 0.17.4

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ethersphere/bee:2.2.0a884fd84b72f
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

3,437
beekeeperethersphereVerified publisher0.4.141 of 1See more

beekeeper ethersphere 0.4.14

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ethersphere/beekeeper:lateste3bc0da9ffde
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,586
bee-overlay-exporterethersphereVerified publisher0.1.01 of 1See more

bee-overlay-exporter ethersphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/python:3.12-slim2f17fc044b57
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

628
beeport-uiethersphereVerified publisher0.76.22 of 3See more

beeport-ui ethersphere 0.76.2

2 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
util-linux@2.41.5-0+deb13u1
no fix listed
library/node:lts64af3819f927
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

6,985
multichain-uiethersphereVerified publisher0.73.12 of 3See more

multichain-ui ethersphere 0.73.1

2 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
util-linux@2.41.5-0+deb13u1
no fix listed
library/node:lts64af3819f927
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

6,985
nethermindethersphereVerified publisher0.2.11 of 1See more

nethermind ethersphere 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
nethermind/nethermind:1.14.615517708c3b6
util-linux@2.37.2-4ubuntu3
no fix listed

Open the chart page →

89,035
static-siteethersphereVerified publisher0.73.11 of 2See more

static-site ethersphere 0.73.1

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

7,259
snyk-farcaster-agenteugen1.0.11 of 1See more

snyk-farcaster-agent eugen 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
probely/farcaster-onprem-agent:v3741b34e8166f
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,128
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

21,016
evobotevobotVerified publisher0.1.11 of 1See more

evobot evobot 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/evobot:3.0.04ddbb244c82f
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

2,965
spring-boot-adminevryfs-ossVerified publisher0.1.101 of 1See more

spring-boot-admin evryfs-oss 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
util-linux@2.37.2-4ubuntu3
no fix listed

Open the chart page →

6,065
express-ts-app-helm-chartsexpress-ts-app-helm-chartsVerified publisher1.0.01 of 4See more

express-ts-app-helm-charts express-ts-app-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
grafana/promtail:3.5.165bfae480b57
util-linux@2.39.3-9ubuntu6.2
no fix listed

Open the chart page →

5,844
extended-ceph-exporterextended-ceph-exporterVerified publisher1.10.01 of 2See more

extended-ceph-exporter extended-ceph-exporter 1.10.0

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
galexrt/extended-ceph-exporter:v1.8.05373078a3a08
util-linux@2.41-5
no fix listed

Open the chart page →

2,966
external-secrets-reloaderexternal-secrets-reloader0.1.01 of 1See more

external-secrets-reloader external-secrets-reloader 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/bensoer/external-secrets-reloader:v0.1.38e31b5a81853
util-linux@2.41-r9
2.41.6-r1

Open the chart page →

1,035
datadog-apmfairwinds-incubator2.0.11 of 1See more

datadog-apm fairwinds-incubator 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
util-linux@2.39.3-9ubuntu6.3
no fix listed

Open the chart page →

2,898
oom-event-generatorfairwinds-incubator0.2.21 of 1See more

oom-event-generator fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
util-linux@2.27.1-6ubuntu3.10
no fix listed

Open the chart page →

4,668
yelbfairwinds-incubator0.1.11 of 5See more

yelb fairwinds-incubator 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

5,084
fairwinds-insightsfairwinds-stableVerified publisher10.2.01See more

fairwinds-insights fairwinds-stable 10.2.0

1 container image this version deploys carries CVE-2026-78408.

Container imageDigestPackageFixed in
swaggerapi/swagger-ui:v5.32.159ae209e3791e
util-linux@2.42.1-r0
2.42.3-r1

Open the chart page →

event-generatorfalcosecurity0.4.01 of 1See more

event-generator falcosecurity 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
falcosecurity/event-generator:latest932956d86c99
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

3,859
farm-observabilityfarm-observabilityOfficialVerified publisher0.27.24 of 18See more

farm-observability farm-observability 0.27.2

4 of the 18 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
grafana/alloy:v1.16.384b76d56c594
util-linux@2.39.3-9ubuntu6.5
no fix listed
grafana/alloy:v1.12.2f94b1c82957a
util-linux@2.39.3-9ubuntu6.4
no fix listed
quay.io/kiwigrid/k8s-sidecar:2.7.3694950d736c8
util-linux@2.41-r9
2.41.6-r1
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
util-linux@2.41-r9
2.41.6-r1

Open the chart page →

13,610
jenkinsfatihtepe-jenkins1.0.01 of 1See more

jenkins fatihtepe-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

2,451
quickstartfeatureformVerified publisher0.1.12 of 3See more

quickstart featureform 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
util-linux@2.41.5-0+deb13u1
no fix listed
library/redis:latest298e5b3bc566
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

3,496
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
util-linux@2.37.2-4ubuntu3
no fix listed

Open the chart page →

13,541
rospoferama0.4.31 of 1See more

rospo ferama 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

6,246
vipienferama0.2.81 of 1See more

vipien ferama 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
util-linux@2.34-0.1ubuntu9.3
no fix listed

Open the chart page →

7,546
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
util-linux@2.27.1-6ubuntu3.10
no fix listed

Open the chart page →

14,730
ferriscompanyferriscompany0.1.01 of 1See more

ferriscompany ferriscompany 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

10,975
fibfibonacci-cluster-appsVerified publisher1.0.03 of 5See more

fib fibonacci-cluster-apps 1.0.0

3 of the 5 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
util-linux@2.38.1-5+b1
no fix listed
golenski/fibonacci-task-manager:2.0.03a2b36df247b
util-linux@2.38.1-5+b1
no fix listed
golenski/fibonacci-worker:2.0.0954caf4aaf6a
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

16,911
infrafibonacci-cluster-infraVerified publisher1.0.03 of 4See more

infra fibonacci-cluster-infra 1.0.0

3 of the 4 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.37.0bae523439ee3
util-linux@2.39.3-9ubuntu6
no fix listed
library/postgres:16.4e62fbf9d3e2b
util-linux@2.38.1-5+deb12u2
no fix listed
library/redis:7.4.1bb142a9c18ac
util-linux@2.38.1-5+deb12u2
no fix listed

Open the chart page →

12,518
fineractfineract-openshift0.1.12 of 4See more

fineract fineract-openshift 0.1.1

2 of the 4 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/mariadb:11.4611a2fcc5fa7
util-linux@2.39.3-9ubuntu6.5
no fix listed
library/nginx:latest05b8cb60c354
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

7,914
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
util-linux@2.41-5
no fix listed

Open the chart page →

5,308
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
util-linux@2.41-5
no fix listed
fireflyiii/data-importer:version-2.2.3ab52bf932546
util-linux@2.41-5
no fix listed

Open the chart page →

10,799
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
util-linux@2.41-5
no fix listed

Open the chart page →

5,098
flask-contactsfirst-idror-chart1.0.12 of 3See more

flask-contacts first-idror-chart 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/phpmyadmin:latest9e915766488a
util-linux@2.41.5-0+deb13u1
no fix listed
shashkist/flask-contacts-app:latest581de1fd6084
util-linux@2.38.1-5+deb12u2
no fix listed

Open the chart page →

5,841
business-api-ecosystemfiware1.1.02 of 4See more

business-api-ecosystem fiware 1.1.0

2 of the 4 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
util-linux@2.34-0.1ubuntu9.6
no fix listed
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

113,233
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,917
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,558
apm-hubflanksourceVerified publisher0.0.472 of 2See more

apm-hub flanksource 0.0.47

2 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
flanksource/apm-hub:v0.0.471dacc3195bf9
util-linux@2.37.2-4ubuntu3
no fix listed
library/postgres:14816cf7d06ec3
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

5,794
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
util-linux@2.39.3-9ubuntu6.3
no fix listed

Open the chart page →

5,545
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

4,633
facetflanksourceVerified publisher0.1.721 of 1See more

facet flanksource 0.1.72

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/flanksource/facet:0.1.7237237038be15
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

21,582
flanksource-uiflanksourceVerified publisher1.4.3191 of 1See more

flanksource-ui flanksource 1.4.319

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.319953948a194c9
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,617
mission-controlflanksourceVerified publisher0.1.3382 of 8See more

mission-control flanksource 0.1.338

2 of the 8 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
util-linux@2.38.1-5+deb12u3
no fix listed
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

9,061
mission-control-ai-assistantflanksourceVerified publisher1.0.121 of 1See more

mission-control-ai-assistant flanksource 1.0.12

1 of the 1 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
ghcr.io/flanksource/mission-control-ai-assistant:1.0.1229a635cbeeb5
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,266
flask-contactsflask-contacts-generic1.0.12 of 3See more

flask-contacts flask-contacts-generic 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
library/phpmyadmin:latest9e915766488a
util-linux@2.41.5-0+deb13u1
no fix listed
shashkist/flask-contacts-app:latest581de1fd6084
util-linux@2.38.1-5+deb12u2
no fix listed

Open the chart page →

5,841
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-78408.

Container imageDigestPackageFixed in
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

4,045

Container images carrying it

2,748 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

No deployed image carries CVE-2026-78408.

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.