StackRadar

CVE-2020-26939

Medium

Advisory

Published 22 Apr 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
62
of 17,781 indexed, latest versions
Container images
58
deployed by those charts
Fix available
4 of 4
affected packages

Observable Differences in Behavior to Error Inputs in Bouncy Castle

Carried by container images the latest versions of 62 of 17,781 indexed charts deploy, on 58 images.

Affected packageAffected versionsFixed inImages
bcprov-jdk15onmaven1.50, 1.51, 1.52, 1.53+7 more1.6154
bcprov-ext-jdk15onmaven1.50, 1.59, 1.601.6113
bcprov-jdk16maven1.461.612
bc-fipsmaven1.0.11.0.21
OSV records
GHSA-72m5-fvvv-55m6

Charts affected

62 by stars
ChartLatestAffected imagesRadar Score
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2020-26939.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
bcprov-ext-jdk15on@1.50
bcprov-jdk15on@1.50
1.61
1.61

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2020-26939.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
bcprov-ext-jdk15on@1.50
bcprov-jdk15on@1.50
1.61
1.61

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2020-26939.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
bcprov-ext-jdk15on@1.50
bcprov-jdk15on@1.50
1.61
1.61

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2020-26939.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
bcprov-ext-jdk15on@1.50
bcprov-jdk15on@1.50
1.61
1.61

Open the chart page →

13,100
helloworldpauls-helm-charts2.0.01 of 1See more

helloworld pauls-helm-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2020-26939.

Container imageDigestPackageFixed in
paulczar/spring-helloworld:latestc7140cecd5f7
bcprov-jdk15on@1.60
1.61

Open the chart page →

5,596
seldon-core-oauth-gatewayseldon0.3.11 of 2See more

seldon-core-oauth-gateway seldon 0.3.1

1 of the 2 container images this version deploys carry CVE-2020-26939.

Container imageDigestPackageFixed in
seldonio/apife:0.3.1eea0d3f578ca
bcprov-ext-jdk15on@1.59
bcprov-jdk15on@1.59
1.61
1.61

Open the chart page →

8,098
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2020-26939.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
bcprov-jdk15on@1.50
1.61

Open the chart page →

13,079
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-26939.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
bcprov-jdk15on@1.60
1.61

Open the chart page →

14,493
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2020-26939.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
bcprov-jdk15on@1.53
1.61

Open the chart page →

4,303
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2020-26939.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
bcprov-jdk15on@1.57
1.61

Open the chart page →

9,397
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2020-26939.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
bcprov-jdk15on@1.60
1.61

Open the chart page →

6,213
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2020-26939.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
bcprov-jdk15on@1.58
1.61

Open the chart page →

3,480

Container images carrying it

58 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
seldonio/cluster-manager:0.2.729e362bb1ba2
bcprov-ext-jdk15on@1.59
bcprov-jdk15on@1.59
1.61
1.61
1
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
bcprov-jdk15on@1.54
1.61
1
zahoriaut/zahori-process:0.1.13351f8a220ed7
bcprov-jdk15on@1.58
1.61
1
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
bcprov-jdk15on@1.59
1.61
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
bcprov-jdk15on@1.60
1.61
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
bcprov-jdk15on@1.60
1.61
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.66.9138c8b82c398
bcprov-jdk16@1.46
1.61
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:latestf669a6eacf8c
bcprov-jdk16@1.46
1.61
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.