StackRadar

CVE-2026-0636

Medium

Advisory

Published 15 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
124
of 17,781 indexed, latest versions
Container images
131
deployed by those charts
Fix available
2 of 3
affected packages

Bouncy Castle has an LDAP injection

Carried by container images the latest versions of 124 of 17,781 indexed charts deploy, on 131 images.

Affected packageAffected versionsFixed inImages
bcprov-jdk18onmaven1.74, 1.75, 1.76, 1.77+9 more1.84124
bcprov-jdk15to18maven1.74, 1.75, 1.76, 1.78+4 more1.8415
bouncycastledeb1.61-1no fix listed1
OSV records
GHSA-c3fc-8qff-9hwxUBUNTU-CVE-2026-0636

Charts affected

124 by stars
ChartLatestAffected imagesRadar Score
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
bcprov-jdk18on@1.81
1.84

Open the chart page →

71,208
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
bcprov-jdk15to18@1.75
bcprov-jdk18on@1.78
1.84
1.84

Open the chart page →

1,753
keycloakpascaliskeVerified publisher0.2.01 of 1See more

keycloak pascaliske 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.74388e2379b7e
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

2,097
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
bcprov-jdk18on@1.77
1.84

Open the chart page →

5,269
radar-gatewayradar-baseVerified publisher1.9.01 of 2See more

radar-gateway radar-base 1.9.0

1 of the 2 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

2,284
radar-outputradar-baseVerified publisher1.2.101 of 1See more

radar-output radar-base 1.2.10

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

2,465
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
bcprov-jdk18on@1.76
1.84

Open the chart page →

4,203
keycloaksb-helm-charts0.3.01 of 2See more

keycloak sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

2,590
keycloaksikalabs0.1.01 of 1See more

keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.3.36a7217a100bd
bcprov-jdk18on@1.81
1.84

Open the chart page →

1,690
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
bcprov-jdk15to18@1.75
1.84

Open the chart page →

4,946
teku-validatorstakewise4.3.21 of 2See more

teku-validator stakewise 4.3.2

1 of the 2 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
consensys/teku:25.4.1bf6ecd2ea716
bcprov-jdk18on@1.80
1.84

Open the chart page →

3,153
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
bcprov-jdk18on@1.79
1.84

Open the chart page →

1,827
wonder-mesh-netstrrl-helm2026.629.01 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

1 of the 3 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.009a381c715ab
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

5,063
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

4,674
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
bcprov-jdk18on@1.78
1.84

Open the chart page →

2,144
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
bcprov-jdk18on@1.80
1.84

Open the chart page →

1,527
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
bcprov-jdk18on@1.80
1.84

Open the chart page →

1,689
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.1.4044a457e0498
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

45,239
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
bcprov-jdk15to18@1.78.1
bcprov-jdk18on@1.82
1.84
1.84

Open the chart page →

5,484
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

2,634
elasticsearchwiremindVerified publisher8.19.01 of 1See more

elasticsearch wiremind 8.19.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
bcprov-jdk18on@1.79
1.84

Open the chart page →

2,191
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
bcprov-jdk18on@1.82
1.84

Open the chart page →

7,624
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
bcprov-jdk15to18@1.78.1
bcprov-jdk18on@1.78.1
1.84
1.84

Open the chart page →

9,381
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-0636.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
bcprov-jdk18on@1.78.1
1.84

Open the chart page →

1,159

Container images carrying it

131 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/gla-rad/enav-aton-service:latest3be878690629
bcprov-jdk18on@1.81
1.84
1
ghcr.io/gla-rad/enav-eureka:latest05002092c621
bcprov-jdk18on@1.81
1.84
1
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
bcprov-jdk18on@1.81
1.84
1
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
bcprov-jdk18on@1.81
1.84
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
bcprov-jdk18on@1.80
1.84
1
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
bcprov-jdk18on@1.80.2
1.84
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
bcprov-jdk18on@1.81
1.84
1
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
bcprov-jdk18on@1.80.2
1.84
1
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal:10.0.0d352df1b94b6
bcprov-jdk18on@1.80.2
1.84
1
ghcr.io/itobey/fddb-exporter:2.4.1a824933e0f87
bcprov-jdk18on@1.81.1
1.84
1
ghcr.io/navikt/mock-oauth2-server:2.1.1065d4ed47ce09
bcprov-jdk18on@1.78.1
1.84
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
bcprov-jdk18on@1.78.1
1.84
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
bcprov-jdk18on@1.78.1
1.84
1
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
bcprov-jdk18on@1.82
1.84
1
ghcr.io/wundergraph/cosmo/keycloak:0.13.0b37408461b9b
bcprov-jdk18on@1.82
1.84
1
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
bcprov-jdk18on@1.78.1
1.84
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
bcprov-jdk18on@1.81
1.84
1
quay.io/keycloak/keycloak:26.009a381c715ab
bcprov-jdk18on@1.78.1
1.84
1
quay.io/keycloak/keycloak:26.0.74388e2379b7e
bcprov-jdk18on@1.78.1
1.84
1
quay.io/keycloak/keycloak:24.0.34d6f22991266
bcprov-jdk18on@1.77
1.84
1
quay.io/keycloak/keycloak:23.0.34f72a5b0c076
bcprov-jdk18on@1.74
1.84
1
quay.io/keycloak/keycloak:26.3.36a7217a100bd
bcprov-jdk18on@1.81
1.84
1
quay.io/keycloak/keycloak:26.5.68d44614c7479
bcprov-jdk18on@1.82
1.84
1
quay.io/keycloak/keycloak:26.49409c59bdfb6
bcprov-jdk18on@1.82
1.84
1
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
bcprov-jdk18on@1.78.1
1.84
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
bcprov-jdk15to18@1.83
1.84
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
bcprov-jdk18on@1.74
1.84
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
bcprov-jdk18on@1.74
1.84
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
bcprov-jdk18on@1.74
1.84
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
bcprov-jdk18on@1.81
1.84
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
bcprov-jdk18on@1.78.1
1.84
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.