StackRadar

CVE-2026-1002

Medium

Advisory

Published 15 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.004
32nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
102
of 17,781 indexed, latest versions
Container images
90
deployed by those charts
Fix available
1 of 1
affected package

Vert.x Web static handler component cache can be manipulated to deny the access to static files

Carried by container images the latest versions of 102 of 17,781 indexed charts deploy, on 90 images.

Affected packageAffected versionsFixed inImages
vertx-coremaven3.4.1, 3.5.0, 3.5.3, 3.5.4+36 more4.5.24, 5.0.790
OSV records
GHSA-cphf-4846-3xx9

Charts affected

102 by stars
ChartLatestAffected imagesRadar Score
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1002.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
vertx-core@3.9.3
4.5.24

Open the chart page →

3,424
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-1002.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
vertx-core@4.3.4
4.5.24

Open the chart page →

6,016

Container images carrying it

90 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
codeurjc/server:v1.0310bea5b1ee7
vertx-core@4.3.4
4.5.24
8
mastercloudapps/server:v2.23f3d24dfe2686
vertx-core@4.3.4
4.5.24
4
quay.io/strimzi/operator:0.37.052f376e64b9b
vertx-core@4.4.4
4.5.24
4
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
vertx-core@4.2.7
4.5.24
2
quay.io/keycloak/keycloak:26.1.4044a457e0498
vertx-core@4.5.11
4.5.24
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
vertx-core@4.3.4
4.5.24
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
vertx-core@4.2.1
4.5.24
2
quay.io/strimzi/operator:0.39.002f6f143fc6d
vertx-core@4.5.0
4.5.24
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
vertx-core@4.5.14
4.5.24
2
aktosecurity/akto-threat-detection-backend:latest15ebb75b94dc
vertx-core@4.5.11
4.5.24
1
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
vertx-core@4.5.11
4.5.24
1
anguda/ant-media:2.5c435285fc241
vertx-core@4.2.3
4.5.24
1
apache/bookkeeper:4.14.5a7d9970c148f
vertx-core@3.9.8
4.5.24
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
vertx-core@4.3.8
4.5.24
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
vertx-core@3.9.8
4.5.24
1
apachepulsar/pulsar:2.6.14db6ff0b4045
vertx-core@3.4.1
4.5.24
1
apachepulsar/pulsar:3.0.79c9947de139d
vertx-core@4.5.10
4.5.24
1
apachepulsar/pulsar:2.9.0d056c89b7131
vertx-core@3.9.8
4.5.24
1
apachepulsar/pulsar:2.8.2d538416d5afe
vertx-core@3.9.8
4.5.24
1
apache/shenyu-admin:2.5.1e2be712fc4f4
vertx-core@4.3.2
4.5.24
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
vertx-core@4.3.2
4.5.24
1
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
vertx-core@3.9.3
4.5.24
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
vertx-core@3.9.6
4.5.24
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
vertx-core@4.3.7
4.5.24
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
vertx-core@4.3.7
4.5.24
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
vertx-core@4.3.7
4.5.24
1
assistiot/identity-manager_kc:latest0df4b4fa899a
vertx-core@4.2.1
4.5.24
1
atomix/atomix:3.1.127738ff4f5c63
vertx-core@3.5.0
4.5.24
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
vertx-core@4.3.4
4.5.24
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
vertx-core@4.5.7
4.5.24
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
vertx-core@4.5.18
4.5.24
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
vertx-core@3.9.1
4.5.24
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
vertx-core@4.3.8
4.5.24
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
vertx-core@3.9.1
4.5.24
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
vertx-core@3.9.1
4.5.24
1
consensys/teku:25.4.1bf6ecd2ea716
vertx-core@4.5.14
4.5.24
1
esperotech/yaade:latest24d2d692d948
vertx-core@4.5.1
4.5.24
1
folioci/edge-oai-pmh:latesteedfcbc29792
vertx-core@5.0.5
5.0.7
1
folioci/edge-patron:latest682b852e056d
vertx-core@5.0.5
5.0.7
1
folioci/mod-aes:latest6d67e9564270
vertx-core@4.0.3
4.5.24
1
folioci/mod-authtoken:latest995a25a33133
vertx-core@4.5.13
4.5.24
1
folioci/mod-codex-ekb:latest235a3fa4adc9
vertx-core@4.3.3
4.5.24
1
folioci/mod-codex-inventory:latest6d53ed758fd1
vertx-core@4.1.0.CR1
4.5.24
1
folioci/mod-codex-mux:latestd4138abfd30d
vertx-core@4.3.4
4.5.24
1
folioci/mod-courses:latest68ca414f5596
vertx-core@5.0.6
5.0.7
1
folioci/mod-data-import-converter-storage:latest3028f333778f
vertx-core@4.3.4
4.5.24
1
folioci/mod-email:latest79ea8e2e7ebf
vertx-core@5.0.6
5.0.7
1
folioci/mod-feesfines:latestfe3a7049f2fb
vertx-core@5.0.5
5.0.7
1
folioci/mod-inventory-update:latestba84812b4d58
vertx-core@5.0.4
5.0.7
1
folioci/mod-login:latest88de493f86db
vertx-core@4.5.23
4.5.24
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.