StackRadar

CVE-2026-22741

Low

Advisory

Published 29 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.1
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
312
of 17,787 indexed, latest versions
Container images
269
deployed by those charts
Fix available
2 of 2
affected packages

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

Carried by container images the latest versions of 312 of 17,787 indexed charts deploy, on 269 images.

Affected packageAffected versionsFixed inImages
spring-webmvcmaven2.5.6.SEC03, 3.2.18.RELEASE, 4.3.1.RELEASE, 4.3.2.RELEASE+85 more6.2.18, 7.0.7242
spring-webfluxmaven5.2.2.RELEASE, 5.2.7.RELEASE, 5.2.8.RELEASE, 5.3.1+27 more6.2.18, 7.0.767
OSV records
GHSA-wg35-8jpf-2xv3

Charts affected

312 by stars
ChartLatestAffected imagesRadar Score
querysiakhooiVerified publisher1.0.01 of 1See more

query siakhooi 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
siakhooi/query:1.0.0f1f4b5b1b870
spring-webmvc@7.0.6
7.0.7

Open the chart page →

1,792
ocean-metric-exporterspot1.1.11 of 1See more

ocean-metric-exporter spot 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
spring-webmvc@6.2.10
6.2.18

Open the chart page →

1,482
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
spring-webflux@5.3.24
spring-webmvc@5.3.24
no fix listed
no fix listed

Open the chart page →

13,532
migrationadeptia-automate-migration5.2.91 of 1See more

migration adeptia-automate-migration 5.2.9

1 of the 1 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
spring-webmvc@6.2.15
6.2.18

Open the chart page →

414
airsonic-advancedairsonic-advancedVerified publisher0.3.11 of 1See more

airsonic-advanced airsonic-advanced 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
spring-webmvc@6.1.12
no fix listed

Open the chart page →

1,748
pagesalstom-pages-app1.0.01 of 3See more

pages alstom-pages-app 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

20,233
amorphieamorphie0.1.23 of 18See more

amorphie amorphie 0.1.2

3 of the 18 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
camunda/zeebe:8.4.5ab5abc09e407
spring-webflux@6.1.4
no fix listed
hazelcast/management-center:5.3.2f9d34300d330
spring-webmvc@5.3.29
no fix listed
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
spring-webmvc@6.1.2
no fix listed

Open the chart page →

28,212
pagesandrei-pages1.0.01 of 3See more

pages andrei-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

20,233
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
spring-webmvc@5.1.6.RELEASE
no fix listed

Open the chart page →

11,579
apache-iotdbapache-iotdb-single-nodeVerified publisher0.1.01 of 1See more

apache-iotdb apache-iotdb-single-node 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
apache/iotdb:0.11.28647309f95d1
spring-webmvc@4.3.18.RELEASE
no fix listed

Open the chart page →

5,277
apimap-apiapimapOfficialVerified publisher1.8.111 of 1See more

apimap-api apimap 1.8.11

1 of the 1 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
apimap/api:v1.8.11ae2b3ab00177
spring-webflux@5.3.23
no fix listed

Open the chart page →

2,231
apispringbootHelmapispringboot0.1.01 of 1See more

apispringbootHelm apispringboot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
rabeh/apibootspring:1.0941007b6946e
spring-webmvc@6.1.1
no fix listed

Open the chart page →

6,227
kafka-uiappscodeVerified publisher2026.3.301 of 1See more

kafka-ui appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
spring-webflux@6.2.17
6.2.18

Open the chart page →

729
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
spring-webmvc@5.2.9.RELEASE
no fix listed

Open the chart page →

8,904
dashboard-pui9assist-iot-tactile-dashboard0.2.01 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
spring-webmvc@5.3.20
no fix listed

Open the chart page →

4,145
url-shortenerbeastob1.0.21 of 3See more

url-shortener beastob 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
beastob/url-shortener:1.0.299a49885ab33
spring-webmvc@5.3.10
no fix listed

Open the chart page →

3,607
pagesberrutig-pages1.0.01 of 3See more

pages berrutig-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

20,233
blackduck-alertblackduck8.4.01 of 4See more

blackduck-alert blackduck 8.4.0

1 of the 4 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
spring-webmvc@6.1.21
no fix listed

Open the chart page →

4,295
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
spring-webmvc@5.3.18
no fix listed

Open the chart page →

13,499
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
spring-webflux@6.2.6
spring-webmvc@6.2.6
6.2.18
6.2.18

Open the chart page →

1,816
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-agg:logbc25b152d88e
spring-webmvc@6.2.1
6.2.18

Open the chart page →

26,266
pagesbrian-pages1.0.01 of 3See more

pages brian-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

20,233
pagesbrixton-mayuribhavsar23-pages1.0.01 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

20,233
pagesbrixton-pages1.0.01 of 3See more

pages brixton-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

20,233
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/category:distributed02fc234353a9
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

11,947
pagescamden-pages1.0.01 of 3See more

pages camden-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

20,233
geoservercamptocamp20.0.36 of 12See more

geoserver camptocamp2 0.0.3

6 of the 12 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
spring-webflux@5.2.8.RELEASE
no fix listed
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
spring-webflux@5.2.8.RELEASE
spring-webmvc@5.2.8.RELEASE
no fix listed
no fix listed
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
spring-webflux@5.2.8.RELEASE
spring-webmvc@5.2.8.RELEASE
no fix listed
no fix listed
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
spring-webflux@5.2.8.RELEASE
spring-webmvc@5.2.8.RELEASE
no fix listed
no fix listed
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
spring-webflux@5.2.8.RELEASE
spring-webmvc@5.2.8.RELEASE
no fix listed
no fix listed
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
spring-webflux@5.2.8.RELEASE
spring-webmvc@5.2.8.RELEASE
no fix listed
no fix listed

Open the chart page →

88,377
pagescarina-pages1.0.01 of 3See more

pages carina-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

20,233
pagescarmel-pages-dell1.0.01 of 3See more

pages carmel-pages-dell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

20,233
Chart-Oracle-Host-Appchart-oracle-host-appVerified publisher0.1.21 of 1See more

Chart-Oracle-Host-App chart-oracle-host-app 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
stanislovesid/oracle-host-app:14fe1ed26e194
spring-webmvc@5.3.12
no fix listed

Open the chart page →

2,434
event-store-servicechoerodon0.8.01 of 2See more

event-store-service choerodon 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
choerodon/event-store-service:0.8.03c94c97f6f69
spring-webmvc@4.3.8.RELEASE
no fix listed

Open the chart page →

9,808
gocdcloudnativeapp1.9.21 of 2See more

gocd cloudnativeapp 1.9.2

1 of the 2 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
gocd/gocd-server:v19.3.02da45cb09d57
spring-webmvc@4.3.22.RELEASE
no fix listed

Open the chart page →

9,144
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
spring-webmvc@4.3.18.RELEASE
no fix listed

Open the chart page →

23,683
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
robotshop/rs-shipping:latest89753ab48919
spring-webmvc@5.2.8.RELEASE
no fix listed

Open the chart page →

29,594
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
spring-webmvc@6.2.5
6.2.18

Open the chart page →

4,616
clamapicnieg2.0.51 of 2See more

clamapi cnieg 2.0.5

1 of the 2 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
audig/clamapi:2.1.62c3fe34ee430
spring-webmvc@5.2.8.RELEASE
no fix listed

Open the chart page →

4,672
ganttcnieg2.1.01 of 1See more

gantt cnieg 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
cnieg/gantt:1.1.2d4b478d76f2a
spring-webmvc@5.3.23
no fix listed

Open the chart page →

2,390
pulsarcnieg1.0.81 of 2See more

pulsar cnieg 1.0.8

1 of the 2 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
spring-webmvc@5.0.6.RELEASE
no fix listed

Open the chart page →

16,860
consumer-helmconsumer-app-helm-chart0.1.01 of 1See more

consumer-helm consumer-app-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
j4ckhunter/consumer:1.00bb7a429e3e75
spring-webmvc@5.3.22
no fix listed

Open the chart page →

2,564
pagescrypticcode-helmchart1.0.01 of 3See more

pages crypticcode-helmchart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

20,233
nifi-registryd4nVerified publisher1.0.01 of 2See more

nifi-registry d4n 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
spring-webmvc@5.3.34
no fix listed

Open the chart page →

5,438
pagesdalston-pages1.0.01 of 3See more

pages dalston-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

20,233
pagesdaman-dell-kuber1.0.01 of 3See more

pages daman-dell-kuber 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

20,233
dara-chartsdara-charts0.1.01 of 2See more

dara-charts dara-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
razzy10/product-service:latest702e411956db
spring-webmvc@6.2.10
6.2.18

Open the chart page →

3,576
pagesdavid-pages1.0.01 of 3See more

pages david-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

20,233
pagesdebasish-pages1.0.01 of 3See more

pages debasish-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

20,233
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.01 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
oscarsotosanchez/toposervice:v1.0d4d020e9f272
spring-webflux@5.3.1
no fix listed

Open the chart page →

27,608
pagesdipak1.0.01 of 3See more

pages dipak 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-webmvc@5.2.7.RELEASE
no fix listed

Open the chart page →

20,233
kafka-uidoubanVerified publisher1.5.21 of 1See more

kafka-ui douban 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-webflux@6.2.3
6.2.18

Open the chart page →

1,269
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-22741.

Container imageDigestPackageFixed in
oscarsotosanchez/toposervice:v1.0d4d020e9f272
spring-webflux@5.3.1
no fix listed

Open the chart page →

24,714

Container images carrying it

269 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
salaboy/fmtok8s-monolith:v0.1.0f225568e6d03
spring-webflux@5.2.8.RELEASE
no fix listed
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
spring-webflux@5.3.13
spring-webmvc@5.3.13
no fix listed
no fix listed
1
sdandey/dandey-apps:kanban-board-kanban-appbef0f599737b
spring-webmvc@5.1.8.RELEASE
no fix listed
1
seataio/seata-server:latest703b5de7f1a6
spring-webmvc@5.3.31
no fix listed
1
seataio/seata-server:1.5.1ee1ed55f4144
spring-webmvc@5.3.13
no fix listed
1
seldonio/apife:0.2.7ba81b17f00eb
spring-webmvc@4.3.20.RELEASE
no fix listed
1
seldonio/apife:0.3.1eea0d3f578ca
spring-webmvc@4.3.20.RELEASE
no fix listed
1
seldonio/cluster-manager:0.2.729e362bb1ba2
spring-webmvc@4.3.20.RELEASE
no fix listed
1
siakhooi/query:1.0.0f1f4b5b1b870
spring-webmvc@7.0.6
7.0.7
1
slagattollas/toposervice-practica:latestdc63973dae0d
spring-webflux@5.3.1
no fix listed
1
slamdev/hetzner-irobo:0.0.13ca20c184c55
spring-webmvc@5.3.10
no fix listed
1
someblackmagic/smtp-fake-server:latest0d63ba37a560
spring-webmvc@5.3.2
no fix listed
1
stanislovesid/oracle-host-app:14fe1ed26e194
spring-webmvc@5.3.12
no fix listed
1
streamnative/private-cloud-console:v2.3.27-all91e54375e154
spring-webflux@6.1.19
spring-webmvc@6.2.10
no fix listed
6.2.18
1
structurizr/onpremises:2025.11.094b5ffb5119c8
spring-webmvc@6.2.7
6.2.18
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
spring-webmvc@5.3.27
no fix listed
1
sysnet4admin/colosseum-agg:logbc25b152d88e
spring-webmvc@6.2.1
6.2.18
1
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
spring-webmvc@5.3.20
no fix listed
1
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
spring-webmvc@5.3.20
no fix listed
1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
spring-webmvc@5.3.20
no fix listed
1
thingsboard/tb-node:3.4.1645f43b688f7
spring-webmvc@5.3.20
no fix listed
1
thingsboard/tb-node:3.6.0f40a542832c4
spring-webmvc@5.3.26
no fix listed
1
thingsboard/tb-postgres:latest2d17e4e36edc
spring-webflux@6.2.11
spring-webmvc@6.2.11
6.2.18
6.2.18
1
thmmniii/fbs-core:v1.27.15438517d9fc2
spring-webflux@5.3.27
spring-webmvc@5.3.27
no fix listed
no fix listed
1
treskon/portrait:DEV-latest88e813f22347
spring-webflux@6.1.15
spring-webmvc@6.1.15
no fix listed
no fix listed
1
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
spring-webmvc@5.3.9
no fix listed
1
vincentgwzhang/k8sforjava:latesta9139f2cd98f
spring-webmvc@6.2.1
6.2.18
1
vlebediantsev/config-server-another:lateste7f20450d2ae
spring-webmvc@5.3.22
no fix listed
1
vlebediantsev/file-system-ms-final:latest10393a89b4a8
spring-webmvc@5.3.21
no fix listed
1
vlebediantsev/logic-ms:latestdf8bf38c535b
spring-webflux@5.3.21
spring-webmvc@5.3.21
no fix listed
no fix listed
1
vlebediantsev/registration-ms-final:latest427af418b75e
spring-webmvc@5.3.21
no fix listed
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
spring-webmvc@5.3.21
no fix listed
1
vrijbrp/haal-centraal-brp-bevragen:develop5c770c2ae48c
spring-webflux@5.3.27
spring-webmvc@5.3.27
no fix listed
no fix listed
1
xuxueli/xxl-job-admin:2.4.0640093c35fd6
spring-webmvc@5.3.25
no fix listed
1
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-webflux@5.3.25
spring-webmvc@5.3.25
no fix listed
no fix listed
1
zbalogh/reservation-api-server:1.0.97c247e399a1f
spring-webflux@5.3.23
no fix listed
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
spring-webmvc@5.2.3.RELEASE
no fix listed
1
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
spring-webmvc@6.2.10
6.2.18
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
spring-webmvc@6.1.2
no fix listed
1
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.3.0acb8dbce38fd
spring-webmvc@7.0.5
7.0.7
1
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
spring-webflux@7.0.6
7.0.7
1
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
spring-webflux@7.0.6
spring-webmvc@7.0.6
7.0.7
7.0.7
1
ghcr.io/gla-rad/enav-eureka:latest05002092c621
spring-webflux@7.0.6
spring-webmvc@7.0.6
7.0.7
7.0.7
1
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
spring-webflux@7.0.6
spring-webmvc@7.0.6
7.0.7
7.0.7
1
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
spring-webmvc@7.0.6
7.0.7
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
spring-webmvc@6.2.14
6.2.18
1
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
spring-webmvc@6.2.6
6.2.18
1
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
spring-webmvc@6.2.10
6.2.18
1
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
spring-webmvc@6.2.1
6.2.18
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
spring-webmvc@6.2.0
6.2.18
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.