StackRadar

CVE-2026-11500

Medium

Advisory

Published 8 Jun 2026In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
5.0
base score, highest
EPSS
0.003
27th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5
of 17,781 indexed, latest versions
Container images
2
deployed by those charts
Fix available
1 of 1
affected package

Weaviate has an Improper Authorization issue

Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 2 images.

Affected packageAffected versionsFixed inImages
github.com/weaviate/weaviategolangv1.35.21.38.0-rc.02
OSV records
GHSA-jqpm-wf57-qx5c
Also known as
GO-2026-6140

Charts affected

5 by stars
ChartLatestAffected imagesRadar Score
kubedbappscodeVerified publisher2026.7.102 of 8See more

kubedb appscode 2026.7.10

2 of the 8 container images this version deploys carry CVE-2026-11500.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
github.com/weaviate/weaviate@v1.35.2
1.38.0-rc.0
ghcr.io/kubedb/kubedb-provisioner:v0.66.0824d6d78d451
github.com/weaviate/weaviate@v1.35.2
1.38.0-rc.0

Open the chart page →

4,016
kubedb-provisionerappscodeVerified publisher0.66.01 of 1See more

kubedb-provisioner appscode 0.66.0

1 of the 1 container images this version deploys carry CVE-2026-11500.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-provisioner:v0.66.0824d6d78d451
github.com/weaviate/weaviate@v1.35.2
1.38.0-rc.0

Open the chart page →

500
kubedb-certifiedappscodeVerified publisher2026.7.102 of 8See more

kubedb-certified appscode 2026.7.10

2 of the 8 container images this version deploys carry CVE-2026-11500.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
github.com/weaviate/weaviate@v1.35.2
1.38.0-rc.0
ghcr.io/kubedb/kubedb-provisioner:v0.66.0824d6d78d451
github.com/weaviate/weaviate@v1.35.2
1.38.0-rc.0

Open the chart page →

4,016
kubedb-ops-managerappscodeVerified publisher0.53.01 of 1See more

kubedb-ops-manager appscode 0.53.0

1 of the 1 container images this version deploys carry CVE-2026-11500.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
github.com/weaviate/weaviate@v1.35.2
1.38.0-rc.0

Open the chart page →

549
kubedb-certifiedopenshift2026.7.102 of 8See more

kubedb-certified openshift 2026.7.10

2 of the 8 container images this version deploys carry CVE-2026-11500.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
github.com/weaviate/weaviate@v1.35.2
1.38.0-rc.0
ghcr.io/kubedb/kubedb-provisioner:v0.66.0824d6d78d451
github.com/weaviate/weaviate@v1.35.2
1.38.0-rc.0

Open the chart page →

4,016

Container images carrying it

2 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
github.com/weaviate/weaviate@v1.35.2
1.38.0-rc.0
4
ghcr.io/kubedb/kubedb-provisioner:v0.66.0824d6d78d451
github.com/weaviate/weaviate@v1.35.2
1.38.0-rc.0
4

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.