StackRadar

CVE-2026-23901

Low

Advisory

Published 10 Feb 2026In the index since 6 Sept 2026
Severity
Low
worst across findings
CVSS
1.0
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
29
of 17,781 indexed, latest versions
Container images
24
deployed by those charts
Fix available
1 of 1
affected package

Apache Shiro Affected by an Observable Timing Discrepancy Vulnerability

Carried by container images the latest versions of 29 of 17,781 indexed charts deploy, on 24 images.

Affected packageAffected versionsFixed inImages
shiro-coremaven1.2.3, 1.2.6, 1.4.0, 1.6.0+10 more2.1.024
OSV records
GHSA-c4qc-4q9p-m9q9

Charts affected

29 by stars
ChartLatestAffected imagesRadar Score
neo4jneo4j-helm4.3.2-11 of 1See more

neo4j neo4j-helm 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
shiro-core@1.7.1
2.1.0

Open the chart page →

2,640
thehivestrangebee-helmOfficialVerified publisher1.0.61 of 7See more

thehive strangebee-helm 1.0.6

1 of the 7 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
strangebee/thehive:5.7.6-1e77b713124dd
shiro-core@1.13.0
2.1.0

Open the chart page →

16,210
scm-managerscm-manager3.12.11 of 1See more

scm-manager scm-manager 3.12.1

1 of the 1 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
scmmanager/scm-manager:3.12.1bfb766050f34
shiro-core@1.13.0
2.1.0

Open the chart page →

649
neo4j-communityequinor-charts1.2.51 of 1See more

neo4j-community equinor-charts 1.2.5

1 of the 1 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
library/neo4j:4.2.4348e3f56faa2
shiro-core@1.7.1
2.1.0

Open the chart page →

2,751
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
shiro-core@1.4.0
2.1.0

Open the chart page →

11,553
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
library/neo4j:2026.02.25ab4ab0358cf
shiro-core@2.0.6
2.1.0

Open the chart page →

8,158
graylogt3n1.0.01 of 3See more

graylog t3n 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
graylog2/server:2.4.3-38ff28c66e6c1
shiro-core@1.4.0
2.1.0

Open the chart page →

8,063
zunivers-ninjaalexpressoVerified publisher1.31.21 of 2See more

zunivers-ninja alexpresso 1.31.2

1 of the 2 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
library/neo4j:5.18.18f01f7bb053e
shiro-core@1.13.0
2.1.0

Open the chart page →

1,165
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
shiro-core@1.4.0
2.1.0

Open the chart page →

11,553
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
shiro-core@1.9.1
2.1.0

Open the chart page →

9,722
cassandra-reapercloudnativeapp0.2.01 of 1See more

cassandra-reaper cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
thelastpickle/cassandra-reaper:1.3.09c53996c457d
shiro-core@1.2.3
2.1.0

Open the chart page →

5,078
neo4jcloudnativeapp1.0.01 of 1See more

neo4j cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
library/neo4j:3.4.5-enterprisea1ba477fa412
shiro-core@1.4.0
2.1.0

Open the chart page →

2,837
shenyuerdeng2.4.211 of 2See more

shenyu erdeng 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
shiro-core@1.7.0
2.1.0

Open the chart page →

12,513
my-chartfleet-web-app0.1.01 of 6See more

my-chart fleet-web-app 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
shiro-core@1.10.1
2.1.0

Open the chart page →

24,296
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
graylog/graylog:6.1.1019de1aff48c2
shiro-core@2.0.1
2.1.0

Open the chart page →

5,261
jenainseefrlab3.1.01 of 1See more

jena inseefrlab 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
stain/jena-fuseki:latestb1d0c96f19ad
shiro-core@2.0.1
2.1.0

Open the chart page →

1,262
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
shiro-core@1.6.0
2.1.0

Open the chart page →

12,856
shinsei-managerjtektVerified publisher0.2.01 of 8See more

shinsei-manager jtekt 0.2.0

1 of the 8 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
shiro-core@2.0.0
2.1.0

Open the chart page →

63,461
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
ladeit/ladeit:latest962b665ffe82
shiro-core@1.4.0
2.1.0

Open the chart page →

26,356
activemqmicroboxlabs3.8.01 of 1See more

activemq microboxlabs 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
shiro-core@1.13.0
2.1.0

Open the chart page →

1,494
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
shiro-core@1.2.6
2.1.0

Open the chart page →

43,341
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
shiro-core@2.0.0
2.1.0

Open the chart page →

30,363
neo4jneo4j-helm-old4.3.2-11 of 1See more

neo4j neo4j-helm-old 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
shiro-core@1.7.1
2.1.0

Open the chart page →

2,640
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
shiro-core@1.13.0
2.1.0

Open the chart page →

6,037
apache-knox-helmpfisterer-knox0.1.111 of 1See more

apache-knox-helm pfisterer-knox 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
farberg/apache-knox-docker:1.6.14b4a22487394
shiro-core@1.7.0
2.1.0

Open the chart page →

6,237
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.5.1e2be712fc4f4
shiro-core@1.8.0
2.1.0

Open the chart page →

8,804
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
shiro-core@1.7.0
2.1.0

Open the chart page →

12,513
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
shiro-core@1.10.0
2.1.0

Open the chart page →

4,946
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-23901.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
shiro-core@1.7.0
2.1.0

Open the chart page →

12,513

Container images carrying it

24 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/shenyu-admin:2.4.2e8b7c4ddd069
shiro-core@1.7.0
2.1.0
3
library/neo4j:5.20.052d3dec8d455
shiro-core@2.0.0
2.1.0
2
library/neo4j:4.3.2-enterprise56a9453c4064
shiro-core@1.7.1
2.1.0
2
mbentley/omada-controller:4.3f4e682274bed
shiro-core@1.4.0
2.1.0
2
1dev/server:11.9.0cd5b12fe5471
shiro-core@1.13.0
2.1.0
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
shiro-core@1.13.0
2.1.0
1
apache/shenyu-admin:2.5.1e2be712fc4f4
shiro-core@1.8.0
2.1.0
1
farberg/apache-knox-docker:1.6.14b4a22487394
shiro-core@1.7.0
2.1.0
1
graylog2/server:2.4.3-38ff28c66e6c1
shiro-core@1.4.0
2.1.0
1
graylog/graylog:6.1.1019de1aff48c2
shiro-core@2.0.1
2.1.0
1
ladeit/ladeit:latest962b665ffe82
shiro-core@1.4.0
2.1.0
1
library/neo4j:4.2.4348e3f56faa2
shiro-core@1.7.1
2.1.0
1
library/neo4j:2026.02.25ab4ab0358cf
shiro-core@2.0.6
2.1.0
1
library/neo4j:5.18.18f01f7bb053e
shiro-core@1.13.0
2.1.0
1
library/neo4j:3.4.5-enterprisea1ba477fa412
shiro-core@1.4.0
2.1.0
1
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
shiro-core@1.2.6
2.1.0
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
shiro-core@1.9.1
2.1.0
1
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
shiro-core@1.10.1
2.1.0
1
scmmanager/scm-manager:3.12.1bfb766050f34
shiro-core@1.13.0
2.1.0
1
sonatype/nexus3:3.58.1586060431b64
shiro-core@1.10.0
2.1.0
1
stain/jena-fuseki:latestb1d0c96f19ad
shiro-core@2.0.1
2.1.0
1
strangebee/thehive:5.7.6-1e77b713124dd
shiro-core@1.13.0
2.1.0
1
thelastpickle/cassandra-reaper:1.3.09c53996c457d
shiro-core@1.2.3
2.1.0
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
shiro-core@1.6.0
2.1.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.