StackRadar

CVE-2026-78409

High

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.0
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,544
of 17,813 indexed, latest versions
Container images
2,522
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 2,544 of 17,813 indexed charts deploy, on 2,522 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:2.41.5-0+deb13u1+dhi3, 1:4.16.0-2+really2.41-5+45 moreno fix listed2,429
util-linuxapk2.42-r0, 2.42.1-r02.42.3-r093
OSV records
ALPINE-CVE-2026-78409DEBIAN-CVE-2026-78409UBUNTU-CVE-2026-78409

Charts affected

2,544 by stars
ChartLatestAffected imagesRadar Score
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

5,299
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

4,797
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
util-linux@2.37.2-4ubuntu3
no fix listed

Open the chart page →

5,710
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

5,063
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

5,276
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

9,713
teitest-opea1.0.01 of 1See more

tei test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

2,330
teireranktest-opea1.0.01 of 1See more

teirerank test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

2,330
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

4,443
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

5,445
vehicle-dashboardtest-vehi-dash0.1.03 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
util-linux@2.37.2-4ubuntu3
no fix listed
library/mongo:5.0.217c81758cb295
util-linux@2.34-0.1ubuntu9.4
no fix listed
library/redis:latest298e5b3bc566
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

20,465
codeth-chartsVerified publisher0.1.01 of 1See more

code th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
collabora/code:24.04.13.2.101dc4ab83977
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

3,305
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

4,021
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

10,215
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
util-linux@2.34-0.1ubuntu9.6
no fix listed

Open the chart page →

10,130
the0the0Verified publisher0.9.83 of 9See more

the0 the0 0.9.8

3 of the 9 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
library/mongo:7-jammy406a4fdca9fc
util-linux@2.37.2-4ubuntu3.5
no fix listed
library/postgres:15-alpinefe0737ba566a
util-linux@2.42.1-r0
2.42.3-r0
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

7,528
standard-applicationthebitgram1.0.121 of 1See more

standard-application thebitgram 1.0.12

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
util-linux@1:2.27.1-6ubuntu3.3
no fix listed

Open the chart page →

11,036
trafficlight-apithecampagnards0.1.11 of 1See more

trafficlight-api thecampagnards 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
thecampagnards/trafficlight-api:main7dca9d973837
util-linux@2.34-0.1ubuntu9.1
no fix listed

Open the chart page →

4,419
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

25,562
pagesthiru-pages1.0.02 of 3See more

pages thiru-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
util-linux@2.34-0.1ubuntu9.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
util-linux@2.31.1-0.4ubuntu3.6
no fix listed

Open the chart page →

20,279
pagesthuy-pages1.0.02 of 3See more

pages thuy-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
util-linux@2.34-0.1ubuntu9.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
util-linux@2.31.1-0.4ubuntu3.6
no fix listed

Open the chart page →

20,279
voyagertibuntu1.2.01 of 1See more

voyager tibuntu 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
ghcr.io/aeharding/voyager:latest779759172676
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,885
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

4,492
joplintobiassackmann0.1.72 of 2See more

joplin tobiassackmann 0.1.7

2 of the 2 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
util-linux@2.38.1-5+deb12u3
no fix listed
joplin/server:latest3f7b852959aa
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

5,665
todoapitodoapi-appVerified publisher0.1.01 of 2See more

todoapi todoapi-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

6,877
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
util-linux@2.41-5
no fix listed

Open the chart page →

7,083
test0tohlejezkouska0.1.01 of 2See more

test0 tohlejezkouska 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

3,354
netbirdtotmicro1.8.21 of 4See more

netbird totmicro 1.8.2

1 of the 4 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
netbirdio/management:0.60.252682e5f48f9
util-linux@2.39.3-9ubuntu6.3
no fix listed

Open the chart page →

6,081
traefik-external-dns-controllertraefik-external-dns-operator2.2.01 of 1See more

traefik-external-dns-controller traefik-external-dns-operator 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-controller:2.2.08d27ad8b5f73
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,528
apptreenityVerified publisher0.1.531 of 2See more

app treenity 0.1.53

1 of the 2 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,856
treenitytreenityVerified publisher0.1.32 of 4See more

treenity treenity 0.1.3

2 of the 4 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
library/nginx:1-alpine-perl9c0cd54a2f03
util-linux@2.42.1-r0
2.42.3-r0
library/postgres:14156f0b253fd6
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

3,405
cicd-proxytremolo1.0.121 of 1See more

cicd-proxy tremolo 1.0.12

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
ghcr.io/tremolosecurity/kube-oidc-proxy:1.0.13a89736c586ba
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

419
openunison-operatortremolo3.0.311 of 1See more

openunison-operator tremolo 3.0.31

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-kubernetes-operator:1.0.1392bd6c526c50
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

1,024
orchestratremolo3.1.563 of 5See more

orchestra tremolo 3.1.56

3 of the 5 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s:1.0.51128081dae281
util-linux@2.39.3-9ubuntu6.6
no fix listed
ghcr.io/openunison/openunison-kubernetes-operator:1.0.1392bd6c526c50
util-linux@2.39.3-9ubuntu6.6
no fix listed
ghcr.io/tremolosecurity/kube-oidc-proxy:1.0.13a89736c586ba
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

3,011
orchestra-kube-oidc-proxytremolo1.0.191 of 1See more

orchestra-kube-oidc-proxy tremolo 1.0.19

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
ghcr.io/tremolosecurity/kube-oidc-proxy:1.0.13a89736c586ba
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

419
orchestra-login-portaltremolo2.3.981 of 1See more

orchestra-login-portal tremolo 2.3.98

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
util-linux@2.37.2-4ubuntu3.4
no fix listed

Open the chart page →

3,035
saleor-appstrieb-work0.6.02 of 5See more

saleor-apps trieb-work 0.6.0

2 of the 5 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
library/nginx:alpine72ba65eb42c1
util-linux@2.42.1-r0
2.42.3-r0
library/redis:8.2.2f0957bcaa75f
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

7,495
trowtrow0.13.01 of 1See more

trow trow 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
ghcr.io/trow-registry/trow:0.10.075b7d2dcdb91
util-linux@2.41-5
no fix listed

Open the chart page →

1,321
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

17,459
altinnendata-apitumogroup0.1.161 of 1See more

altinnendata-api tumogroup 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
sondresjo/altinnendata-api:v1.8.0148f173dfd9b
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

401
altinnendata-apptumogroup0.1.171 of 1See more

altinnendata-app tumogroup 0.1.17

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
sondresjo/altinnendata-app:v1.9.1c2707839d8a3
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,885
bobby-apitumogroup1.0.11 of 1See more

bobby-api tumogroup 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
sondresjo/bobby-api:latestfe534731909a
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,346
nstuning-apitumogroup0.1.201 of 1See more

nstuning-api tumogroup 0.1.20

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
sondresjo/nstuning-api:v1.6.11d32750053baa
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

401
nstuning-apptumogroup0.1.181 of 1See more

nstuning-app tumogroup 0.1.18

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
sondresjo/nstuning-app:v1.6.113a6795bf36da
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,885
twentytwenty-crm0.1.112 of 4See more

twenty twenty-crm 0.1.11

2 of the 4 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
util-linux@2.42.1-r0
2.42.3-r0
redis/redis-stack-server:7.2.0-v10e44b2b49d059
util-linux@2.37.2-4ubuntu3.3
no fix listed

Open the chart page →

5,644
simple-mongodbtyk-helm0.1.11 of 1See more

simple-mongodb tyk-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
util-linux@2.34-0.1ubuntu9.6
no fix listed

Open the chart page →

4,147
umbrella-chartumbrella-chartVerified publisher0.1.13 of 5See more

umbrella-chart umbrella-chart 0.1.1

3 of the 5 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
hassroutyyoussef/accountservice:latest1f01edf1ee0c
util-linux@2.38.1-5+deb12u2
no fix listed
hassroutyyoussef/orderservice:latest2fc3d1617928
util-linux@2.38.1-5+deb12u2
no fix listed
hassroutyyoussef/userservice:lateste0392e2b4a90
util-linux@2.38.1-5+deb12u2
no fix listed

Open the chart page →

7,602
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
util-linux@2.38.1-5+deb12u2
no fix listed

Open the chart page →

8,698
rstudiouninettsigma21.3.61 of 3See more

rstudio uninettsigma2 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
sigma2as/rstudio-proxy:20260818-1df6a44d899e81ee3eb
util-linux@2.42.1-r0
2.42.3-r0

Open the chart page →

847
sparkuninettsigma21.1.41 of 3See more

spark uninettsigma2 1.1.4

1 of the 3 container images this version deploys carry CVE-2026-78409.

Container imageDigestPackageFixed in
library/nginx:1.31.3-alpine4a73073bd557
util-linux@2.42.1-r0
2.42.3-r0

Open the chart page →

847

Container images carrying it

2,522 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/wi_stefan/consent-manager:0.0.656399619568b
util-linux@2.38.1-5+deb12u3
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
util-linux@2.38.1-5+b1
no fix listed
1
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
util-linux@2.41.3-3ubuntu2
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
util-linux@2.41-5
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
util-linux@2.38.1-5+deb12u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
util-linux@2.41.5-0+deb13u1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
util-linux@2.34-0.1ubuntu9.1
no fix listed
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-platform:prod61ff9287923a
util-linux@2.42.1-r0
2.42.3-r0
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
util-linux@2.41-5
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
util-linux@2.38.1-5+deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
util-linux@2.38.1-5+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
util-linux@2.38.1-5+deb12u3
no fix listed
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.