StackRadar

CVE-2026-97399

Low

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.003
20th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,805
of 17,966 indexed, latest versions
Container images
2,827
deployed by those charts
Fix available
None
affected packages

CVE-2026-97399 affecting package glibc 2.38-21

Carried by container images the latest versions of 2,805 of 17,966 indexed charts deploy, on 2,827 images.

Affected packageAffected versionsFixed inImages
glibcrpm2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3no fix listed13
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+65 moreno fix listed2,807
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
OSV records
DEBIAN-CVE-2026-97399UBUNTU-CVE-2026-97399AZL-104976
Trending
Rank 1 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

2,805 by stars
ChartLatestAffected imagesRadar Score
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-97399.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

1,765
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97399.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

4,916
zimagizimagi2.7.171 of 6See more

zimagi zimagi 2.7.17

1 of the 6 container images this version deploys carry CVE-2026-97399.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.15.331407c0e8e32
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

2,085
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-97399.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
glibc@2.27-3ubuntu1.4
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
glibc@2.31-0ubuntu9.2
no fix listed

Open the chart page →

9,589
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-97399.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
glibc@2.35-0ubuntu3.14
no fix listed

Open the chart page →

8,586

Container images carrying it

2,827 by charts deploying them

A fixed version is listed for 0 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
technitium/dns-server:15.5.1b8efe03a5e3b
glibc@2.39-0ubuntu8.9
no fix listed
2
testinprod/op-erigon:latest0a125bd77a2d
glibc@2.36-9+deb12u9
no fix listed
2
thiagoguaru/alerthawk.monitoring:3.3.9e739b7f178ec
glibc@2.41-12+deb13u4+dhi1
no fix listed
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
glibc@2.35-0ubuntu3.1
no fix listed
2
uffizzi/controller:latest0344805f267b
glibc@2.36-9+deb12u4
no fix listed
2
valkey/valkey:9.0.1546304417fea
glibc@2.41-12
no fix listed
2
valkey/valkey:8640c5e62cea0
glibc@2.41-12+deb13u4
no fix listed
2
valkey/valkey:8.1.481db6d39e1bb
glibc@2.41-12
no fix listed
2
valkey/valkey:9.1.08e8d64b405ce
glibc@2.41-12+deb13u3
no fix listed
2
valkey/valkey:9.1.2:latestc123e3715db6
glibc@2.41-12+deb13u3
no fix listed
2
vdiogov/glpi-conteiner:latest6945f84f0058
glibc@2.36-9+deb12u7
no fix listed
2
velero/velero:v1.18.237396519f399
glibc@2.35-0ubuntu3.13
no fix listed
2
wolveix/satisfactory-server:latest:v1.9.10e103700ae6ae
glibc@2.35-0ubuntu3.10
no fix listed
2
wurstmeister/zookeeper:latest7a7fd44a7210
eglibc@2.19-0ubuntu6.3
no fix listed
2
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
glibc@2.39-0ubuntu8.3
no fix listed
2
gcr.io/cloud-tagging-10302018/gtm-cloud-image:stable688d35c6c544
glibc@2.41-12+deb13u3
no fix listed
2
gcr.io/google_containers/kubernetes-dashboard-init-amd64:v1.0.0fbe12aa24de6
glibc@2.23-0ubuntu9
no fix listed
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
glibc@2.35-0ubuntu3.11
no fix listed
2
ghcr.io/astriaorg/conductor:latest3ea8164b0eae
glibc@2.36-9+deb12u13
no fix listed
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
glibc@2.39-0ubuntu8.8
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
glibc@2.39-0ubuntu8.4
no fix listed
2
ghcr.io/chroma-core/chroma:1.5.91e0b73a187a2
glibc@2.41-12+deb13u2
no fix listed
2
ghcr.io/cloudnative-pg/postgresql:18.4-system-trixie42708a75345b
glibc@2.41-12+deb13u3
no fix listed
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
glibc@2.35-0ubuntu3.1
no fix listed
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
glibc@2.35-0ubuntu3.1
no fix listed
2
ghcr.io/donkie/spoolman:0.27.07aba565eff77
glibc@2.36-9+deb12u14
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
glibc@2.36-9+deb12u13
no fix listed
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
glibc@2.31-0ubuntu9.2
no fix listed
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
glibc@2.31-0ubuntu9.2
no fix listed
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
glibc@2.31-0ubuntu9.2
no fix listed
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
glibc@2.36-9+deb12u7
no fix listed
2
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
glibc@2.36-9+deb12u14
no fix listed
2
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
glibc@2.41-12+deb13u2
no fix listed
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
glibc@2.36-9+deb12u10
no fix listed
2
ghcr.io/kubedb/kubedb-webhook-server:v0.42.0e0f4431c4704
glibc@2.36-9+deb12u14
no fix listed
2
ghcr.io/kubedb/kubedb-webhook-server:v0.42.0f7dcade6523b
glibc@2.36-9+deb12u14
no fix listed
2
ghcr.io/libredb/libredb-studio:0.17.0ce4d58724e25
glibc@2.41-12+deb13u4
no fix listed
2
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
glibc@2.27-3ubuntu1.2
no fix listed
2
ghcr.io/lissy93/web-check:latest7e2ef5261764
glibc@2.36-9+deb12u14
no fix listed
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
glibc@2.36-9+deb12u8
no fix listed
2
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
glibc@2.36-9+deb12u10
no fix listed
2
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
glibc@2.36-9+deb12u10
no fix listed
2
ghcr.io/openunison/openunison-kubernetes-operator:1.0.13a0178e08639a
glibc@2.39-0ubuntu8.9
no fix listed
2
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
glibc@2.36-9+deb12u3
no fix listed
2
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
glibc@2.36-9+deb12u7
no fix listed
2
ghcr.io/project-zot/zot:v2.1.216b69512c00dc
glibc@2.41-12+deb13u3
no fix listed
2
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
glibc@2.36-9+deb12u9
no fix listed
2
ghcr.io/salaboy/fmtok8s-agenda-service:v0.0.1-native6c5efe150958
glibc@2.27-3ubuntu1.6
no fix listed
2
ghcr.io/salaboy/fmtok8s-c4p-service:v0.0.1-native3f7cc45fd20b
glibc@2.27-3ubuntu1.6
no fix listed
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
glibc@2.35-0ubuntu3
no fix listed
2

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.