StackRadar

CVE-2026-10517

Medium

Advisory

Published 1 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.8
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
5
deployed by those charts
Fix available
None
affected package

Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 5 images.

Affected packageAffected versionsFixed inImages
github.com/quay/claircoregolangv1.2.0, v1.3.1, v1.5.35, v1.5.48no fix listed5
OSV records
GHSA-698x-9w2p-7vvp
Also known as
GO-2026-5939

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
kubescape-operatorkubescape1.40.41 of 6See more

kubescape-operator kubescape 1.40.4

1 of the 6 container images this version deploys carry CVE-2026-10517.

Container imageDigestPackageFixed in
quay.io/kubescape/kubescape:v4.0.1358651dce3376
github.com/quay/claircore@v1.5.35
no fix listed

Open the chart page →

920
clairdevtron0.1.141 of 2See more

clair devtron 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-10517.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
github.com/quay/claircore@v1.2.0
no fix listed

Open the chart page →

6,237
clairclair-helmVerified publisher0.12.01 of 3See more

clair clair-helm 0.12.0

1 of the 3 container images this version deploys carry CVE-2026-10517.

Container imageDigestPackageFixed in
quay.io/projectquay/clair:4.9.023329c3368e4
github.com/quay/claircore@v1.5.48
no fix listed

Open the chart page →

1,617
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-10517.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/quay/claircore@v1.3.1
no fix listed

Open the chart page →

68,240
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-10517.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
github.com/quay/claircore@v1.3.1
no fix listed

Open the chart page →

2,435
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-10517.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
github.com/quay/claircore@v1.2.0
no fix listed

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-10517.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/quay/claircore@v1.3.1
no fix listed

Open the chart page →

68,240
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-10517.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
github.com/quay/claircore@v1.3.1
no fix listed

Open the chart page →

2,435
clairromholdings0.1.141 of 2See more

clair romholdings 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-10517.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
github.com/quay/claircore@v1.2.0
no fix listed

Open the chart page →

6,237
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-10517.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/quay/claircore@v1.3.1
no fix listed

Open the chart page →

68,240
securityromholdings0.2.21 of 1See more

security romholdings 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-10517.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
github.com/quay/claircore@v1.3.1
no fix listed

Open the chart page →

2,435

Container images carrying it

5 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/clair:4.3.675fb847ac045
github.com/quay/claircore@v1.2.0
no fix listed
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
github.com/quay/claircore@v1.3.1
no fix listed
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/quay/claircore@v1.3.1
no fix listed
3
quay.io/kubescape/kubescape:v4.0.1358651dce3376
github.com/quay/claircore@v1.5.35
no fix listed
1
quay.io/projectquay/clair:4.9.023329c3368e4
github.com/quay/claircore@v1.5.48
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.