StackRadar

CVE-2026-19654

High

Advisory

Published 12 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
rsyslogdeb7.4.4-1ubuntu2.3, 7.4.4-1ubuntu2.5, 7.4.4-1ubuntu2.6, 7.4.4-1ubuntu2.7+6 more8.2112.0-2ubuntu2.4, 8.2312.0-3ubuntu9.3, 8.2504.0-1+deb13u114
OSV records
DEBIAN-CVE-2026-19654UBUNTU-CVE-2026-19654

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-19654.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
rsyslog@8.2504.0-1
8.2504.0-1+deb13u1

Open the chart page →

5,366
akeyless-api-gatewayakeyless-services-helmVerified publisher1.62.221 of 1See more

akeyless-api-gateway akeyless-services-helm 1.62.22

1 of the 1 container images this version deploys carry CVE-2026-19654.

Container imageDigestPackageFixed in
akeyless/base:latest759e4289fae8
rsyslog@8.2312.0-3ubuntu9.2
8.2312.0-3ubuntu9.3

Open the chart page →

2,358
kafka-devwikimedia0.2.01 of 1See more

kafka-dev wikimedia 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-19654.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
rsyslog@7.4.4-1ubuntu2.3
no fix listed

Open the chart page →

41,427
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-19654.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
rsyslog@8.32.0-1ubuntu4.2
no fix listed

Open the chart page →

12,779
opensipschetan-opensips0.1.01 of 1See more

opensips chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-19654.

Container imageDigestPackageFixed in
chetangautamm/repo:Opensips_Buildb4b94155ff5a
rsyslog@7.4.4-1ubuntu2.7
no fix listed

Open the chart page →

30,140
guestbookcloudnativeapp0.2.01 of 3See more

guestbook cloudnativeapp 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-19654.

Container imageDigestPackageFixed in
resouer/redis-slave:v2e2f198b49ba7
rsyslog@7.4.4-1ubuntu2.5
no fix listed

Open the chart page →

36,839
galaxy-stablecloudve2.0.02 of 5See more

galaxy-stable cloudve 2.0.0

2 of the 5 container images this version deploys carry CVE-2026-19654.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
rsyslog@7.4.4-1ubuntu2.7
no fix listed
galaxy/galaxy-stable:v18.018e577a626dfd
rsyslog@7.4.4-1ubuntu2.7
no fix listed

Open the chart page →

70,895
mongodb-bi-connectordasmeta1.0.31 of 1See more

mongodb-bi-connector dasmeta 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-19654.

Container imageDigestPackageFixed in
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
rsyslog@8.32.0-1ubuntu4.2
no fix listed

Open the chart page →

5,832
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-19654.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
rsyslog@8.2302.0-1+deb12u1
no fix listed

Open the chart page →

64,489
ibexaibexaVerified publisher3.11.11 of 10See more

ibexa ibexa 3.11.1

1 of the 10 container images this version deploys carry CVE-2026-19654.

Container imageDigestPackageFixed in
boky/postfix:4.4.0f3f247fd4252
rsyslog@8.2302.0-1
no fix listed

Open the chart page →

5,959
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-19654.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
rsyslog@7.4.4-1ubuntu2.3
no fix listed

Open the chart page →

41,427
sebaopencord1.0.01 of 17See more

seba opencord 1.0.0

1 of the 17 container images this version deploys carry CVE-2026-19654.

Container imageDigestPackageFixed in
voltha/voltha-envoy:1.6.059ab2a00f712
rsyslog@7.4.4-1ubuntu2.6
no fix listed

Open the chart page →

93,855
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-19654.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
rsyslog@7.4.4-1ubuntu2.7
no fix listed

Open the chart page →

26,339
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-19654.

Container imageDigestPackageFixed in
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
rsyslog@8.2112.0-2ubuntu2.2
8.2112.0-2ubuntu2.4

Open the chart page →

5,841

Container images carrying it

14 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
wurstmeister/zookeeper:latest7a7fd44a7210
rsyslog@7.4.4-1ubuntu2.3
no fix listed
2
akeyless/base:latest759e4289fae8
rsyslog@8.2312.0-3ubuntu9.2
8.2312.0-3ubuntu9.3
1
boky/postfix:5.1.0aafc77238423
rsyslog@8.2504.0-1
8.2504.0-1+deb13u1
1
boky/postfix:4.4.0f3f247fd4252
rsyslog@8.2302.0-1
no fix listed
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
rsyslog@7.4.4-1ubuntu2.7
no fix listed
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
rsyslog@8.32.0-1ubuntu4.2
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
rsyslog@8.2302.0-1+deb12u1
no fix listed
1
galaxy/galaxy-init:v18.010267bad550e6
rsyslog@7.4.4-1ubuntu2.7
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
rsyslog@7.4.4-1ubuntu2.7
no fix listed
1
openthread/otbr:latestf307f59f6432
rsyslog@8.32.0-1ubuntu4.2
no fix listed
1
opsmx11/issuegen:v2.1.05c50ca123d88
rsyslog@7.4.4-1ubuntu2.7
no fix listed
1
resouer/redis-slave:v2e2f198b49ba7
rsyslog@7.4.4-1ubuntu2.5
no fix listed
1
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
rsyslog@8.2112.0-2ubuntu2.2
8.2112.0-2ubuntu2.4
1
voltha/voltha-envoy:1.6.059ab2a00f712
rsyslog@7.4.4-1ubuntu2.6
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.