StackRadar

CVE-2026-22746

Low

Advisory

Published 22 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
75
of 17,781 indexed, latest versions
Container images
73
deployed by those charts
Fix available
1 of 1
affected package

Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider

Carried by container images the latest versions of 75 of 17,781 indexed charts deploy, on 73 images.

Affected packageAffected versionsFixed inImages
spring-security-coremaven5.7.1, 5.7.2, 5.7.3, 5.7.4+33 more6.5.10, 7.0.573
OSV records
GHSA-vxf7-qj7q-83fh

Charts affected

75 by stars
ChartLatestAffected imagesRadar Score
appswitcher-serverit-at-mOfficialVerified publisher2.0.21 of 1See more

appswitcher-server it-at-m 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
spring-security-core@6.4.5
no fix listed

Open the chart page →

3,774
kf-app-eaiit-at-mOfficialVerified publisher0.1.71 of 1See more

kf-app-eai it-at-m 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
spring-security-core@6.5.3
6.5.10

Open the chart page →

1,947
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
spring-security-core@6.4.1
no fix listed

Open the chart page →

3,131
nacosnacos-yunyeVerified publisher1.0.31 of 1See more

nacos nacos-yunye 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.130a39cb0c54d
spring-security-core@6.4.4
no fix listed

Open the chart page →

1,783
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
vlebediantsev/file-system-ms-final:latest10393a89b4a8
spring-security-core@5.7.2
no fix listed

Open the chart page →

5,875
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
spring-security-core@5.7.2
no fix listed

Open the chart page →

6,852
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
spring-security-core@5.7.2
no fix listed

Open the chart page →

5,916
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
spring-security-core@5.7.2
no fix listed

Open the chart page →

5,873
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
spring-security-core@5.8.14
no fix listed

Open the chart page →

5,826
bpjstk-serviceopenshift1.0.01 of 6See more

bpjstk-service openshift 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
andrianrf/backoffice-be:latest6036614803d4
spring-security-core@5.7.8
no fix listed

Open the chart page →

34,671
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
spring-security-core@6.4.4
no fix listed

Open the chart page →

7,792
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
spring-security-core@6.4.4
no fix listed

Open the chart page →

2,003
management-portalradar-baseVerified publisher1.7.01 of 1See more

management-portal radar-base 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
spring-security-core@5.7.12
no fix listed

Open the chart page →

3,182
smartquerysearchhub0.1.01 of 1See more

smartquery searchhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
commerceexperts/smartquery-service:2.2.09e33ad89baf6
spring-security-core@5.7.10
no fix listed

Open the chart page →

1,528
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
spring-security-core@5.7.11
no fix listed

Open the chart page →

4,245
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
spring-security-core@5.7.3
no fix listed

Open the chart page →

5,856
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
spring-security-core@5.7.5
no fix listed

Open the chart page →

13,646
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
spring-security-core@6.3.8
no fix listed

Open the chart page →

1,827
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
spring-security-core@6.3.9
no fix listed

Open the chart page →

4,674
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
spring-security-core@5.8.3
no fix listed

Open the chart page →

18,756
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
thingsboard/tb-node:3.4.1645f43b688f7
spring-security-core@5.7.1
no fix listed

Open the chart page →

25,394
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
spring-security-core@6.5.5
6.5.10

Open the chart page →

1,527
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
spring-security-core@6.5.2
6.5.10

Open the chart page →

1,689
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
spring-security-core@6.3.3
no fix listed

Open the chart page →

2,634
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-22746.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-security-core@5.7.6
no fix listed

Open the chart page →

5,846

Container images carrying it

73 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/fineract:1.12.1a83cf1980609
spring-security-core@6.4.4
no fix listed
2
apache/nifi-registry:1.26.07cdfd8deec92
spring-security-core@5.8.11
no fix listed
2
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
spring-security-core@6.4.5
no fix listed
2
hazelcast/management-center:5.5.2991ddb27c251
spring-security-core@6.3.3
no fix listed
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
spring-security-core@5.8.7
no fix listed
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
spring-security-core@6.5.7
6.5.10
2
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
spring-security-core@6.5.9
6.5.10
2
2martens/timetable:latestbd1ba6ab84c9
spring-security-core@6.5.5
6.5.10
1
2martens/wahlrecht:latestba2c3040dab0
spring-security-core@6.5.2
6.5.10
1
andrianrf/backoffice-be:latest6036614803d4
spring-security-core@5.7.8
no fix listed
1
apache/nifi-registry:1.27.063b8e3e40742
spring-security-core@5.8.13
no fix listed
1
apache/ranger:2.7.076c176e8a0e4
spring-security-core@5.7.12
no fix listed
1
apimap/api:v1.8.11ae2b3ab00177
spring-security-core@5.7.4
no fix listed
1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
spring-security-core@5.7.1
no fix listed
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
spring-security-core@6.3.10
no fix listed
1
bluerange/bluerange:26.1.307c8f73b55df
spring-security-core@6.4.5
no fix listed
1
castlemock/castlemock:latestb7f3f1527ba9
spring-security-core@6.4.4
no fix listed
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
spring-security-core@6.5.5
6.5.10
1
commerceexperts/smartquery-service:2.2.09e33ad89baf6
spring-security-core@5.7.10
no fix listed
1
conductoross/conductor:3.31.09fba127693e6
spring-security-core@6.3.9
no fix listed
1
dannielkil/book-backend:lateste3b479a55a69
spring-security-core@5.7.3
no fix listed
1
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
spring-security-core@5.7.5
no fix listed
1
flowable/flowable-rest:7.1.0b7ae287502cd
spring-security-core@6.3.3
no fix listed
1
folioci/mod-agreements:latest29c3f233a498
spring-security-core@5.8.16
no fix listed
1
folioci/mod-data-export-spring:latestf1d7caf4544b
spring-security-core@7.0.2
7.0.5
1
folioci/mod-licenses:latestcfd6109bf477
spring-security-core@5.8.16
no fix listed
1
folioci/mod-oa:latestae3b069d4ba5
spring-security-core@5.8.16
no fix listed
1
folioci/mod-serials-management:latest571fa1ffe8c9
spring-security-core@5.8.16
no fix listed
1
folioci/mod-service-interaction:latestf53c327a48e8
spring-security-core@5.8.16
no fix listed
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
spring-security-core@5.8.16
no fix listed
1
gotson/komga:1.22.0ba892ab3e082
spring-security-core@6.4.1
no fix listed
1
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
spring-security-core@5.7.4
no fix listed
1
gresearchdev/siembol-storm-topology-manager:latest8dad36a05ebf
spring-security-core@5.7.4
no fix listed
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
spring-security-core@6.5.7
6.5.10
1
hazelcast/management-center:5.3.2f9d34300d330
spring-security-core@5.7.10
no fix listed
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
spring-security-core@5.8.14
no fix listed
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
spring-security-core@5.8.11
no fix listed
1
jhipster/jhipster-registry:latest7184525acd4d
spring-security-core@5.7.3
no fix listed
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
spring-security-core@5.7.11
no fix listed
1
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
spring-security-core@6.3.3
no fix listed
1
nacos/nacos-server:v3.0.20e951a1d07bb
spring-security-core@6.4.4
no fix listed
1
nacos/nacos-server:v3.0.130a39cb0c54d
spring-security-core@6.4.4
no fix listed
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
spring-security-core@5.8.14
no fix listed
1
openbas/platform:2.0.5d986d80b0a75
spring-security-core@6.3.6
no fix listed
1
operaton/operaton:1.0.0-beta-4b35867ffe4d8
spring-security-core@6.4.4
no fix listed
1
seataio/seata-server:latest703b5de7f1a6
spring-security-core@5.7.11
no fix listed
1
streamnative/private-cloud-console:v2.3.27-all91e54375e154
spring-security-core@6.3.8
no fix listed
1
structurizr/onpremises:2025.11.094b5ffb5119c8
spring-security-core@6.4.6
no fix listed
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
spring-security-core@5.8.3
no fix listed
1
thingsboard/tb-node:3.4.1645f43b688f7
spring-security-core@5.7.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.