StackRadar

CVE-2026-78410

High

Advisory

Published 2 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,580
of 17,828 indexed, latest versions
Container images
2,582
deployed by those charts
Fix available
2 of 3
affected packages

CVE-2026-78410 affecting package util-linux 2.40.2-5

Carried by container images the latest versions of 2,580 of 17,828 indexed charts deploy, on 2,582 images.

Affected packageAffected versionsFixed inImages
util-linuxdeb1:2.27.1-6ubuntu3.3, 1:2.38.1-5+deb12u1, 1:2.41.5-0+deb13u1+dhi3, 1:4.16.0-2+really2.41-5+47 more2.41.5-0+deb13u1+e22,488
util-linuxapk2.42-r0, 2.42.1-r02.42.3-r093
util-linuxrpm2.40.2-4.azl3no fix listed1
OSV records
ALPINE-CVE-2026-78410DEBIAN-CVE-2026-78410UBUNTU-CVE-2026-78410AZL-99390ECHO-5339-ad7c-f545

Charts affected

2,580 by stars
ChartLatestAffected imagesRadar Score
signozsignoz0.142.11 of 5See more

signoz signoz 0.142.1

1 of the 5 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
signoz/signoz-otel-collector:v0.144.1034ecb436b687
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

7,636
weblateweblateOfficialVerified publisher0.5.382See more

weblate weblate 0.5.38

2 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
util-linux@2.38.1-5+deb12u3
no fix listed
bitnamilegacy/redis:latest5927ff3702df
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

locustdeliveryheroVerified publisher0.35.01 of 1See more

locust deliveryhero 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

2,853
postgresgroundhog2k1.6.81 of 1See more

postgres groundhog2k 1.6.8

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
library/postgres:18.686c951e05bf5
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,272
emqxemqx-operator5.8.91 of 1See more

emqx emqx-operator 5.8.9

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
emqx/emqx:5.8.935b46f7aa7a0
util-linux@2.41-5
no fix listed

Open the chart page →

2,674
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

4,769
mariadbcloudpirates-mariadbVerified publisher0.16.151 of 1See more

mariadb cloudpirates-mariadb 0.16.15

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
library/mariadb:13.0.2d4fdec0510ad
util-linux@2.41.3-3ubuntu2.2
no fix listed

Open the chart page →

1,396
difydoubanVerified publisher0.10.03 of 6See more

dify douban 0.10.0

3 of the 6 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
util-linux@2.38.1-5+deb12u1
no fix listed
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
util-linux@2.38.1-5+deb12u1
no fix listed
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
util-linux@2.39.3-9ubuntu6.3
no fix listed

Open the chart page →

74,650
dragonflydragonflyVerified publisher1.8.51 of 3See more

dragonfly dragonfly 1.8.5

1 of the 3 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.59fe2a1d6206f
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

4,191
kubesharkkubeshark-helm-chartsOfficialVerified publisher53.4.01 of 3See more

kubeshark kubeshark-helm-charts 53.4.0

1 of the 3 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
kubeshark/front:v53.4cc7f07b99fac
util-linux@2.42.1-r0
2.42.3-r0

Open the chart page →

845
secrets-store-csi-driversecret-store-csi-driver1.6.11 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

1 of the 4 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,825
mongodbcloudpirates-mongodbVerified publisher0.18.151See more

mongodb cloudpirates-mongodb 0.18.15

1 container image this version deploys carries CVE-2026-78410.

Container imageDigestPackageFixed in
library/mongo:8.3.115d7043a4ffe0
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

code-servernicholaswildeVerified publisher1.1.11 of 1See more

code-server nicholaswilde 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/code-server:version-v3.11.1a385ba5cb161
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

16,377
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
util-linux@2.41.3-3ubuntu2
no fix listed

Open the chart page →

1,620
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
util-linux@2.39.3-9ubuntu6.2
no fix listed

Open the chart page →

3,823
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

6,943
difydify-helmVerified publisher0.38.06 of 11See more

dify dify-helm 0.38.0

6 of the 11 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
util-linux@2.38.1-5+deb12u3
no fix listed
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
util-linux@2.38.1-5+deb12u3
no fix listed
langgenius/dify-api:1.16.1dcefa5f7c47c
util-linux@2.38.1-5+deb12u3
no fix listed
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
util-linux@2.39.3-9ubuntu6.5
no fix listed
langgenius/dify-sandbox:0.2.15750e1111426e
util-linux@2.41-5
no fix listed
library/nginx:latestabe47724e466
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

63,843
pyroscopegrafana2.3.11 of 3See more

pyroscope grafana 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
grafana/alloy:v1.12.2f94b1c82957a
util-linux@2.39.3-9ubuntu6.4
no fix listed

Open the chart page →

3,275
plantumlstevehipwellVerified publisher3.49.01 of 1See more

plantuml stevehipwell 3.49.0

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

1,990
rabbitmqgroundhog2k2.3.91 of 2See more

rabbitmq groundhog2k 2.3.9

1 of the 2 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.667bad329974a
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

825
stacks-blockchainhirosystemsVerified publisher2.2.21 of 1See more

stacks-blockchain hirosystems 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,347
ingresskongOfficialVerified publisher0.24.01 of 2See more

ingress kong 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
library/kong:3.912972ce1ab63
util-linux@2.39.3-9ubuntu6.6
no fix listed

Open the chart page →

833
oktetooktetoOfficialVerified publisher0.0.0-2026-08-241See more

okteto okteto 0.0.0-2026-08-24

1 container image this version deploys carries CVE-2026-78410.

Container imageDigestPackageFixed in
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-243e56bdd1b90d
util-linux@2.41-5
no fix listed

Open the chart page →

yourlsyourlsOfficialVerified publisher8.10.21 of 2See more

yourls yourls 8.10.2

1 of the 2 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
ghcr.io/yourls/yourls:1.10.67550ff86b15f
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,992
apisix-ingress-controllerapisix1.4.01 of 2See more

apisix-ingress-controller apisix 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,556
istiocloudposse1.1.02 of 8See more

istio cloudposse 1.1.0

2 of the 8 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
util-linux@2.27.1-6ubuntu3.7
no fix listed
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
util-linux@2.27.1-6ubuntu3.7
no fix listed

Open the chart page →

137,814
actualbudgetcommunity-chartsVerified publisher1.9.41 of 1See more

actualbudget community-charts 1.9.4

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

1,066
concourseconcourseVerified publisher20.3.01 of 2See more

concourse concourse 20.3.0

1 of the 2 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,674
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
util-linux@2.31.1-0.4ubuntu3.7
no fix listed

Open the chart page →

4,188
openprojectopenproject-helm-chartsOfficialVerified publisher13.12.04 of 5See more

openproject openproject-helm-charts 13.12.0

4 of the 5 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
bitnamilegacy/memcached:1.6.24-debian-12-r01d80b6a96f00
util-linux@2.38.1-5+b1
no fix listed
library/postgres:16f1c3376c26f2
util-linux@2.41.5-0+deb13u1
no fix listed
openproject/hocuspocus:release-338001b288dc1359dfb5
util-linux@2.38.1-5+deb12u3
no fix listed
openproject/openproject:17.8.0-slim48952034215d
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

20,022
sftpgosftpgoOfficialVerified publisher0.48.01 of 1See more

sftpgo sftpgo 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
ghcr.io/drakkan/sftpgo:v2.7.59011fe608d33
util-linux@2.41-5
no fix listed

Open the chart page →

1,254
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

11,521
lemmyananace-chartsVerified publisher0.6.152 of 5See more

lemmy ananace-charts 0.6.15

2 of the 5 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
dessalines/lemmy:0.19.2079e9f02c286c
util-linux@2.38.1-5+deb12u3
no fix listed
dessalines/lemmy-ui:0.19.20ee4c620d8e93
util-linux@2.41-5
no fix listed

Open the chart page →

7,118
zabbixcetic3.1.35 of 5See more

zabbix cetic 3.1.3

5 of the 5 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
library/postgres:14816cf7d06ec3
util-linux@2.41.5-0+deb13u1
no fix listed
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
util-linux@2.37.2-4ubuntu3
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
util-linux@2.37.2-4ubuntu3
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
util-linux@2.37.2-4ubuntu3
no fix listed
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
util-linux@2.37.2-4ubuntu3
no fix listed

Open the chart page →

33,698
csi-driver-smbcsi-driver-smbVerified publisher1.20.31 of 6See more

csi-driver-smb csi-driver-smb 1.20.3

1 of the 6 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

2,957
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

4,360
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
util-linux@2.38.1-5+deb12u1
no fix listed

Open the chart page →

6,551
stacks-blockchain-apihirosystemsVerified publisher6.5.12 of 5See more

stacks-blockchain-api hirosystems 6.5.1

2 of the 5 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
util-linux@2.38.1-5+deb12u3
no fix listed
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

7,732
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
util-linux@2.39.3-9ubuntu6.3
no fix listed

Open the chart page →

2,407
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

6,091
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
util-linux@2.34-0.1ubuntu9.4
no fix listed
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
util-linux@2.37.2-4ubuntu3
no fix listed

Open the chart page →

12,948
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
util-linux@2.39.3-9ubuntu6.3
no fix listed

Open the chart page →

3,065
factorio-server-chartsfactorio-server-chartsVerified publisher2.5.21 of 1See more

factorio-server-charts factorio-server-charts 2.5.2

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
factoriotools/factorio:latest18c07a80cacc
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

1,406
netbirdjaconiVerified publisher0.15.12 of 4See more

netbird jaconi 0.15.1

2 of the 4 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
library/golang:latest3680233e3204
util-linux@2.41.5-0+deb13u1
no fix listed
netbirdio/management:0.45.10c9994b393ea
util-linux@2.39.3-9ubuntu6.2
no fix listed

Open the chart page →

7,984
litellm-helmlitellm1.102.01 of 2See more

litellm-helm litellm 1.102.0

1 of the 2 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
util-linux@2.38.1-5+b1
no fix listed

Open the chart page →

5,106
localstacklocalstack0.7.11 of 1See more

localstack localstack 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
localstack/localstack:latest4abc29e923e5
util-linux@2.41-5
no fix listed

Open the chart page →

2,192
gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
util-linux@2.41-5
no fix listed

Open the chart page →

10,276
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
util-linux@2.39.3-9ubuntu6.3
no fix listed

Open the chart page →

5,495
oneuptimeoneuptimeOfficialVerified publisher14.0.11See more

oneuptime oneuptime 14.0.1

1 container image this version deploys carries CVE-2026-78410.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
util-linux@2.41.5-0+deb13u1
no fix listed

Open the chart page →

openclawopenclaw-helmVerified publisher1.5.402 of 2See more

openclaw openclaw-helm 1.5.40

2 of the 2 container images this version deploys carry CVE-2026-78410.

Container imageDigestPackageFixed in
chromedp/headless-shell:148.0.7778.97313ed7255ae1
util-linux@2.41-5
no fix listed
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
util-linux@2.38.1-5+deb12u3
no fix listed

Open the chart page →

5,614

Container images carrying it

2,582 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

No deployed image carries CVE-2026-78410.

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.