StackRadar

CVE-2026-22740

Medium

Advisory

Published 29 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
55
of 17,781 indexed, latest versions
Container images
67
deployed by those charts
Fix available
1 of 1
affected package

Spring Framework DoS with Multipart Temp Files in WebFlux

Carried by container images the latest versions of 55 of 17,781 indexed charts deploy, on 67 images.

Affected packageAffected versionsFixed inImages
spring-webfluxmaven5.2.2.RELEASE, 5.2.7.RELEASE, 5.2.8.RELEASE, 5.3.1+27 more6.2.18, 7.0.767
OSV records
GHSA-5843-p793-ghmm

Charts affected

55 by stars
ChartLatestAffected imagesRadar Score
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-22740.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
spring-webflux@6.1.19
no fix listed

Open the chart page →

4,674
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-22740.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-webflux@5.2.2.RELEASE
no fix listed

Open the chart page →

12,513
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-22740.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-webflux@5.3.15
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-22740.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-webflux@5.3.15
no fix listed

Open the chart page →

28,605
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-22740.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-webflux@5.3.25
no fix listed

Open the chart page →

5,846

Container images carrying it

67 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
streamnative/private-cloud-console:v2.3.27-all91e54375e154
spring-webflux@6.1.19
no fix listed
1
thingsboard/tb-postgres:latest2d17e4e36edc
spring-webflux@6.2.11
6.2.18
1
thmmniii/fbs-core:v1.27.15438517d9fc2
spring-webflux@5.3.27
no fix listed
1
treskon/portrait:DEV-latest88e813f22347
spring-webflux@6.1.15
no fix listed
1
vlebediantsev/logic-ms:latestdf8bf38c535b
spring-webflux@5.3.21
no fix listed
1
vrijbrp/haal-centraal-brp-bevragen:develop5c770c2ae48c
spring-webflux@5.3.27
no fix listed
1
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-webflux@5.3.25
no fix listed
1
zbalogh/reservation-api-server:1.0.97c247e399a1f
spring-webflux@5.3.23
no fix listed
1
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
spring-webflux@7.0.6
7.0.7
1
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
spring-webflux@7.0.6
7.0.7
1
ghcr.io/gla-rad/enav-eureka:latest05002092c621
spring-webflux@7.0.6
7.0.7
1
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
spring-webflux@7.0.6
7.0.7
1
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-webflux@6.2.3
6.2.18
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
spring-webflux@6.1.1
no fix listed
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
spring-webflux@5.3.24
no fix listed
1
public.ecr.aws/aws-containers/retail-store-sample-ui:1.3.0ce3f2e935eb3
spring-webflux@6.2.10
6.2.18
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
spring-webflux@5.3.24
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.