StackRadar

CVE-2026-22748

Medium

Advisory

Published 22 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.002
10th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
22
of 17,781 indexed, latest versions
Container images
23
deployed by those charts
Fix available
1 of 1
affected package

Spring Security has Potential Security Misconfiguration when Using withIssuerLocation

Carried by container images the latest versions of 22 of 17,781 indexed charts deploy, on 23 images.

Affected packageAffected versionsFixed inImages
spring-security-oauth2-josemaven6.3.3, 6.3.5, 6.3.6, 6.3.8+12 more6.5.10, 7.0.523
OSV records
GHSA-cvc6-q2cp-2xhw

Charts affected

22 by stars
ChartLatestAffected imagesRadar Score
kafka-uikafka-uiVerified publisher1.6.51 of 1See more

kafka-ui kafka-ui 1.6.5

1 of the 1 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
spring-security-oauth2-jose@6.5.9
6.5.10

Open the chart page →

729
thingsboardcetic0.1.21 of 2See more

thingsboard cetic 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
thingsboard/tb-postgres:latest2d17e4e36edc
spring-security-oauth2-jose@6.4.11
no fix listed

Open the chart page →

5,235
hazelcasthazelcastVerified publisher5.10.21 of 2See more

hazelcast hazelcast 5.10.2

1 of the 2 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
spring-security-oauth2-jose@6.3.3
no fix listed

Open the chart page →

2,634
cbioportalcbioportalOfficialVerified publisher1.1.01 of 1See more

cbioportal cbioportal 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
spring-security-oauth2-jose@6.5.5
6.5.10

Open the chart page →

3,674
cert-vaultcert-vaultOfficialVerified publisher2.12.01 of 7See more

cert-vault cert-vault 2.12.0

1 of the 7 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
spring-security-oauth2-jose@6.5.7
6.5.10

Open the chart page →

15,863
enavenav-service-architectureVerified publisher0.0.75 of 10See more

enav enav-service-architecture 0.0.7

5 of the 10 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
spring-security-oauth2-jose@7.0.4
7.0.5
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
spring-security-oauth2-jose@7.0.4
7.0.5
ghcr.io/gla-rad/enav-eureka:latest05002092c621
spring-security-oauth2-jose@7.0.4
7.0.5
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
spring-security-oauth2-jose@7.0.4
7.0.5
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
spring-security-oauth2-jose@7.0.4
7.0.5

Open the chart page →

15,860
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
treskon/portrait:DEV-latest88e813f22347
spring-security-oauth2-jose@6.3.5
no fix listed

Open the chart page →

31,844
kafka-uiappscodeVerified publisher2026.3.301 of 1See more

kafka-ui appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
spring-security-oauth2-jose@6.5.9
6.5.10

Open the chart page →

729
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
spring-security-oauth2-jose@6.4.5
no fix listed

Open the chart page →

1,816
kafka-uidoubanVerified publisher1.5.21 of 1See more

kafka-ui douban 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-security-oauth2-jose@6.4.3
no fix listed

Open the chart page →

1,269
eximeebpmseximeebpms-k8sOfficialVerified publisher0.3.01 of 1See more

eximeebpms eximeebpms-k8s 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.3.0acb8dbce38fd
spring-security-oauth2-jose@7.0.3
7.0.5

Open the chart page →

727
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
spring-security-oauth2-jose@6.4.4
no fix listed

Open the chart page →

7,792
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
openbas/platform:2.0.5d986d80b0a75
spring-security-oauth2-jose@6.3.6
no fix listed

Open the chart page →

25,017
appswitcher-serverit-at-mOfficialVerified publisher2.0.21 of 1See more

appswitcher-server it-at-m 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
spring-security-oauth2-jose@6.4.5
no fix listed

Open the chart page →

3,774
kf-app-eaiit-at-mOfficialVerified publisher0.1.71 of 1See more

kf-app-eai it-at-m 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
spring-security-oauth2-jose@6.5.3
6.5.10

Open the chart page →

1,947
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
spring-security-oauth2-jose@6.4.1
no fix listed

Open the chart page →

3,131
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
spring-security-oauth2-jose@6.4.4
no fix listed

Open the chart page →

7,792
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
spring-security-oauth2-jose@6.4.4
no fix listed

Open the chart page →

2,003
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
spring-security-oauth2-jose@6.3.8
no fix listed

Open the chart page →

1,827
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
spring-security-oauth2-jose@6.5.5
6.5.10

Open the chart page →

1,527
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
spring-security-oauth2-jose@6.5.2
6.5.10

Open the chart page →

1,689
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2026-22748.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
spring-security-oauth2-jose@6.3.3
no fix listed

Open the chart page →

2,634

Container images carrying it

23 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/fineract:1.12.1a83cf1980609
spring-security-oauth2-jose@6.4.4
no fix listed
2
hazelcast/management-center:5.5.2991ddb27c251
spring-security-oauth2-jose@6.3.3
no fix listed
2
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
spring-security-oauth2-jose@6.5.9
6.5.10
2
2martens/timetable:latestbd1ba6ab84c9
spring-security-oauth2-jose@6.5.5
6.5.10
1
2martens/wahlrecht:latestba2c3040dab0
spring-security-oauth2-jose@6.5.2
6.5.10
1
bluerange/bluerange:26.1.307c8f73b55df
spring-security-oauth2-jose@6.4.5
no fix listed
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
spring-security-oauth2-jose@6.5.5
6.5.10
1
gotson/komga:1.22.0ba892ab3e082
spring-security-oauth2-jose@6.4.1
no fix listed
1
openbas/platform:2.0.5d986d80b0a75
spring-security-oauth2-jose@6.3.6
no fix listed
1
operaton/operaton:1.0.0-beta-4b35867ffe4d8
spring-security-oauth2-jose@6.4.4
no fix listed
1
streamnative/private-cloud-console:v2.3.27-all91e54375e154
spring-security-oauth2-jose@6.3.8
no fix listed
1
thingsboard/tb-postgres:latest2d17e4e36edc
spring-security-oauth2-jose@6.4.11
no fix listed
1
treskon/portrait:DEV-latest88e813f22347
spring-security-oauth2-jose@6.3.5
no fix listed
1
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.3.0acb8dbce38fd
spring-security-oauth2-jose@7.0.3
7.0.5
1
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
spring-security-oauth2-jose@7.0.4
7.0.5
1
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
spring-security-oauth2-jose@7.0.4
7.0.5
1
ghcr.io/gla-rad/enav-eureka:latest05002092c621
spring-security-oauth2-jose@7.0.4
7.0.5
1
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
spring-security-oauth2-jose@7.0.4
7.0.5
1
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
spring-security-oauth2-jose@7.0.4
7.0.5
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
spring-security-oauth2-jose@6.5.7
6.5.10
1
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
spring-security-oauth2-jose@6.4.5
no fix listed
1
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
spring-security-oauth2-jose@6.5.3
6.5.10
1
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-security-oauth2-jose@6.4.3
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.