StackRadar

CVE-2026-3260

Medium

Advisory

Published 24 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
27
of 17,781 indexed, latest versions
Container images
25
deployed by those charts
Fix available
None
affected package

Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests

Carried by container images the latest versions of 27 of 17,781 indexed charts deploy, on 25 images.

Affected packageAffected versionsFixed inImages
undertow-coremaven1.3.15.Final, 1.4.0.Final, 2.2.4.Final, 2.2.5.Final+13 moreno fix listed25
OSV records
GHSA-3x3v-w654-m28m

Charts affected

27 by stars
ChartLatestAffected imagesRadar Score
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
undertow-core@2.2.14.Final
no fix listed

Open the chart page →

7,713
penpotpenpotOfficialVerified publisher1.9.01 of 4See more

penpot penpot 1.9.0

1 of the 4 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
penpotapp/backend:2.17.2770b55f6e51b
undertow-core@2.4.0.Final
no fix listed

Open the chart page →

4,314
kafdroplsst-sqre0.1.31 of 1See more

kafdrop lsst-sqre 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
undertow-core@2.2.16.Final
no fix listed

Open the chart page →

7,901
activemq-artemisactivemq-artemis-helm0.3.61 of 1See more

activemq-artemis activemq-artemis-helm 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
vromero/activemq-artemis:2.16.0408d6a46b153
undertow-core@1.3.15.Final
no fix listed

Open the chart page →

4,419
arcadedbarcadedb26.9.11 of 1See more

arcadedb arcadedb 26.9.1

1 of the 1 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
arcadedata/arcadedb:26.9.102a1a74fcef3
undertow-core@2.4.3.Final
no fix listed

Open the chart page →

39
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
undertow-core@2.2.8.Final
no fix listed

Open the chart page →

3,958
signserver-cesignserverOfficialVerified publisher2.3.51 of 1See more

signserver-ce signserver 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.3.2798fbbe00283
undertow-core@2.3.18.Final
no fix listed

Open the chart page →

2,406
stardogstardog3.1.01 of 3See more

stardog stardog 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
stardog/stardog:latest2714e5c4b3c1
undertow-core@2.3.21.Final
no fix listed

Open the chart page →

293
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
undertow-core@2.2.14.Final
no fix listed

Open the chart page →

7,713
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
undertow-core@2.2.17.Final
no fix listed

Open the chart page →

13,352
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
undertow-core@2.2.19.Final
no fix listed

Open the chart page →

9,722
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
undertow-core@2.2.16.Final
no fix listed

Open the chart page →

13,459
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
undertow-core@2.3.18.Final
no fix listed

Open the chart page →

1,816
mod-agreementsfolio-org0.1.321 of 1See more

mod-agreements folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
folioci/mod-agreements:latest29c3f233a498
undertow-core@2.2.39.Final
no fix listed

Open the chart page →

1,874
mod-licensesfolio-org0.1.321 of 1See more

mod-licenses folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
folioci/mod-licenses:latestcfd6109bf477
undertow-core@2.2.39.Final
no fix listed

Open the chart page →

1,760
mod-oafolio-org0.1.21 of 1See more

mod-oa folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
folioci/mod-oa:latestae3b069d4ba5
undertow-core@2.2.39.Final
no fix listed

Open the chart page →

1,733
mod-serials-managementfolio-org0.1.11 of 1See more

mod-serials-management folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
folioci/mod-serials-management:latest571fa1ffe8c9
undertow-core@2.2.39.Final
no fix listed

Open the chart page →

1,733
mod-service-interactionfolio-org0.1.61 of 1See more

mod-service-interaction folio-org 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
folioci/mod-service-interaction:latestf53c327a48e8
undertow-core@2.2.39.Final
no fix listed

Open the chart page →

1,733
dinsrokronkltdVerified publisher0.1.71 of 2See more

dinsro kronkltd 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
duck1123/dinsro:latest9568c5961d5d
undertow-core@2.2.4.Final
no fix listed

Open the chart page →

1,628
penpotkubitodevVerified publisher1.2.11 of 5See more

penpot kubitodev 1.2.1

1 of the 5 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
undertow-core@2.3.10.Final
no fix listed

Open the chart page →

16,877
ma1sdnetsocVerified publisher0.2.11 of 1See more

ma1sd netsoc 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
ma1uta/ma1sd:2.5.0ee2a56d8b8ca
undertow-core@2.2.7.Final
no fix listed

Open the chart page →

3,582
management-portalradar-baseVerified publisher1.7.01 of 1See more

management-portal radar-base 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
undertow-core@2.2.35.Final
no fix listed

Open the chart page →

3,182
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
undertow-core@2.2.19.Final
no fix listed

Open the chart page →

5,856
digdagskyoo20030.5.21 of 4See more

digdag skyoo2003 0.5.2

1 of the 4 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
undertow-core@1.4.0.Final
no fix listed

Open the chart page →

6,949
orchestratremolo3.1.551 of 5See more

orchestra tremolo 3.1.55

1 of the 5 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
undertow-core@2.4.0.Final
no fix listed

Open the chart page →

7,637
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
undertow-core@2.2.5.Final
no fix listed

Open the chart page →

28,605
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-3260.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
undertow-core@2.3.10.Final
no fix listed

Open the chart page →

11,577

Container images carrying it

25 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
undertow-core@2.2.16.Final
no fix listed
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
undertow-core@2.2.14.Final
no fix listed
2
arcadedata/arcadedb:26.9.102a1a74fcef3
undertow-core@2.4.3.Final
no fix listed
1
assistiot/identity-manager_kc:latest0df4b4fa899a
undertow-core@2.2.17.Final
no fix listed
1
bluerange/bluerange:26.1.307c8f73b55df
undertow-core@2.3.18.Final
no fix listed
1
duck1123/dinsro:latest9568c5961d5d
undertow-core@2.2.4.Final
no fix listed
1
folioci/mod-agreements:latest29c3f233a498
undertow-core@2.2.39.Final
no fix listed
1
folioci/mod-licenses:latestcfd6109bf477
undertow-core@2.2.39.Final
no fix listed
1
folioci/mod-oa:latestae3b069d4ba5
undertow-core@2.2.39.Final
no fix listed
1
folioci/mod-serials-management:latest571fa1ffe8c9
undertow-core@2.2.39.Final
no fix listed
1
folioci/mod-service-interaction:latestf53c327a48e8
undertow-core@2.2.39.Final
no fix listed
1
jhipster/jhipster-registry:latest7184525acd4d
undertow-core@2.2.19.Final
no fix listed
1
keyfactor/signserver-ce:7.3.2798fbbe00283
undertow-core@2.3.18.Final
no fix listed
1
ma1uta/ma1sd:2.5.0ee2a56d8b8ca
undertow-core@2.2.7.Final
no fix listed
1
penpotapp/backend:2.2.147853d9bb9dd
undertow-core@2.3.10.Final
no fix listed
1
penpotapp/backend:2.17.2770b55f6e51b
undertow-core@2.4.0.Final
no fix listed
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
undertow-core@2.2.19.Final
no fix listed
1
remche/shinyproxy:2.6.18bcda8a04d3b
undertow-core@2.2.8.Final
no fix listed
1
stardog/stardog:latest2714e5c4b3c1
undertow-core@2.3.21.Final
no fix listed
1
vromero/activemq-artemis:2.16.0408d6a46b153
undertow-core@1.3.15.Final
no fix listed
1
ghcr.io/openunison/openunison-k8s:1.0.509ad450220ab9
undertow-core@2.4.0.Final
no fix listed
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
undertow-core@2.2.35.Final
no fix listed
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
undertow-core@1.4.0.Final
no fix listed
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
undertow-core@2.2.5.Final
no fix listed
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
undertow-core@2.3.10.Final
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.