StackRadar

CVE-2026-40458

Medium

Advisory

Published 17 Apr 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
7
of 17,781 indexed, latest versions
Container images
6
deployed by those charts
Fix available
1 of 1
affected package

PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability

Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 6 images.

Affected packageAffected versionsFixed inImages
pac4j-coremaven4.3.0, 4.5.7, 5.4.5, 5.7.1+2 more5.7.106
OSV records
GHSA-xw5c-jc7x-gf75

Charts affected

7 by stars
ChartLatestAffected imagesRadar Score
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2026-40458.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
pac4j-core@5.7.3
5.7.10

Open the chart page →

3,812
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2026-40458.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
pac4j-core@4.5.7
5.7.10

Open the chart page →

7,930
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2026-40458.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
pac4j-core@5.4.5
5.7.10

Open the chart page →

9,722
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2026-40458.

Container imageDigestPackageFixed in
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
pac4j-core@5.7.1
5.7.10

Open the chart page →

11,160
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2026-40458.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
pac4j-core@5.7.3
5.7.10

Open the chart page →

8,541
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-40458.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
pac4j-core@5.7.2
5.7.10

Open the chart page →

5,826
apache-knox-helmpfisterer-knox0.1.111 of 1See more

apache-knox-helm pfisterer-knox 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-40458.

Container imageDigestPackageFixed in
farberg/apache-knox-docker:1.6.14b4a22487394
pac4j-core@4.3.0
5.7.10

Open the chart page →

6,237

Container images carrying it

6 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/druid:37.0.00116fb802786
pac4j-core@5.7.3
5.7.10
2
apache/druid:29.0.10cef139b6bf1
pac4j-core@4.5.7
5.7.10
1
farberg/apache-knox-docker:1.6.14b4a22487394
pac4j-core@4.3.0
5.7.10
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
pac4j-core@5.7.2
5.7.10
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
pac4j-core@5.4.5
5.7.10
1
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
pac4j-core@5.7.1
5.7.10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.