StackRadar

CVE-2026-23903

Medium

Advisory

Published 9 Feb 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
6
deployed by those charts
Fix available
1 of 1
affected package

Apache Shiro has an Authentication Bypass

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 6 images.

Affected packageAffected versionsFixed inImages
shiro-springmaven1.4.0, 1.7.0, 1.8.0, 1.10.1+1 more2.1.06
OSV records
GHSA-c244-p6m5-vqj6

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-23903.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
shiro-spring@1.4.0
2.1.0

Open the chart page →

11,553
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-23903.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
shiro-spring@1.4.0
2.1.0

Open the chart page →

11,553
shenyuerdeng2.4.211 of 2See more

shenyu erdeng 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-23903.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
shiro-spring@1.7.0
2.1.0

Open the chart page →

12,513
my-chartfleet-web-app0.1.01 of 6See more

my-chart fleet-web-app 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-23903.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
shiro-spring@1.10.1
2.1.0

Open the chart page →

24,296
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-23903.

Container imageDigestPackageFixed in
ladeit/ladeit:latest962b665ffe82
shiro-spring@1.4.0
2.1.0

Open the chart page →

26,356
activemqmicroboxlabs3.8.01 of 1See more

activemq microboxlabs 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-23903.

Container imageDigestPackageFixed in
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
shiro-spring@1.13.0
2.1.0

Open the chart page →

1,494
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-23903.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.5.1e2be712fc4f4
shiro-spring@1.8.0
2.1.0

Open the chart page →

8,804
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2026-23903.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
shiro-spring@1.7.0
2.1.0

Open the chart page →

12,513
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-23903.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
shiro-spring@1.7.0
2.1.0

Open the chart page →

12,513

Container images carrying it

6 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/shenyu-admin:2.4.2e8b7c4ddd069
shiro-spring@1.7.0
2.1.0
3
mbentley/omada-controller:4.3f4e682274bed
shiro-spring@1.4.0
2.1.0
2
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
shiro-spring@1.13.0
2.1.0
1
apache/shenyu-admin:2.5.1e2be712fc4f4
shiro-spring@1.8.0
2.1.0
1
ladeit/ladeit:latest962b665ffe82
shiro-spring@1.4.0
2.1.0
1
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
shiro-spring@1.10.1
2.1.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.