StackRadar

CVE-2026-41254

High

Advisory

Published 18 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
303
of 17,781 indexed, latest versions
Container images
299
deployed by those charts
Fix available
7 of 7
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 303 of 17,781 indexed charts deploy, on 299 images.

Affected packageAffected versionsFixed inImages
lcms2deb2.5-0ubuntu4, 2.5-0ubuntu4.1, 2.6-3ubuntu2, 2.6-3ubuntu2.1+6 more2.5-0ubuntu4.2+esm1, 2.6-3ubuntu2.1+esm1, 2.9-1ubuntu0.1+esm1, 2.9-4ubuntu0.1~esm1+5 more235
lcms2apk2.16-r0, 2.17-r02.19-r040
javabitnami11.0.15-150, 11.0.18-10-1, 11.0.18-10-2, 11.0.20-8-3+12 more1.8.016
Javabitnami11.0.20-8, 11.0.21-10, 17.0.8-7, 17.0.10-13-1+2 more1.8.07
openjdk-17deb17.0.10+7-1~deb12u1, 17.0.13+11-2~deb12u1, 17.0.16+8-1~deb12u1, 17.0.17+10-1~deb12u1+2 more17.0.20+8-1~deb12u17
jrebitnami17.0.16-12-0, 17.0.19-11-2, 21.0.8-12-0, 21.0.9-15-0+1 more1.8.05
openjdk-21deb21.0.11+10-1~deb13u221.0.12+8-1~deb13u12
OSV records
ALPINE-CVE-2026-41254BIT-java-2026-41254BIT-jre-2026-41254DEBIAN-CVE-2026-41254UBUNTU-CVE-2026-41254
Also known as
BIT-java-min-2026-41254, GHSA-4xp6-rcgg-m9qq, USN-8209-1, USN-8209-2

Charts affected

303 by stars
ChartLatestAffected imagesRadar Score
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-41254.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
lcms2@2.9-4
2.9-4ubuntu0.1~esm1

Open the chart page →

28,605
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-41254.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
jre@21.0.9-15-0
1.8.0

Open the chart page →

7,624
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-41254.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
lcms2@2.12~rc1-2build2
2.12~rc1-2ubuntu0.1

Open the chart page →

14,100

Container images carrying it

299 by charts deploying them

A fixed version is listed for 7 of the 7 affected packages.

Container imageDigestPackageFixed inUsed by
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
lcms2@2.12~rc1-2build2
2.12~rc1-2ubuntu0.1
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
lcms2@2.12~rc1-2build2
2.12~rc1-2ubuntu0.1
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
lcms2@2.12~rc1-2build2
2.12~rc1-2ubuntu0.1
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
lcms2@2.12~rc1-2build2
2.12~rc1-2ubuntu0.1
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
lcms2@2.6-3ubuntu2
2.6-3ubuntu2.1+esm1
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
lcms2@2.16-2
2.16-2+deb13u2
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
lcms2@2.14-2
2.14-2+deb12u1
1
trueosiris/vrising:latest9356f98ad561
lcms2@2.12~rc1-2build2
2.12~rc1-2ubuntu0.1
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
lcms2@2.14-2
2.14-2+deb12u1
1
vlebediantsev/notes-admin-front:latest007c6670ff48
lcms2@2.14-2
2.14-2+deb12u1
1
vlebediantsev/notes-project-front:latest945675fd2636
lcms2@2.14-2
2.14-2+deb12u1
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
lcms2@2.14-2
2.14-2+deb12u1
1
wavefronthq/proxy:9.2d1064d28f6eb
lcms2@2.9-1ubuntu0.1
2.9-1ubuntu0.1+esm1
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
lcms2@2.12~rc1-2build2
2.12~rc1-2ubuntu0.1
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
lcms2@2.14-2
2.14-2+deb12u1
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
lcms2@2.14-2
2.14-2+deb12u1
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
lcms2@2.16-r0
2.19-r0
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
lcms2@2.16-r0
2.19-r0
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
lcms2@2.16-r0
2.19-r0
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
lcms2@2.16-r0
2.19-r0
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
lcms2@2.14-2build1
2.14-2ubuntu0.1
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
lcms2@2.12~rc1-2build2
2.12~rc1-2ubuntu0.1
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
lcms2@2.17-r0
2.19-r0
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
lcms2@2.16-2
2.16-2+deb13u2
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
openjdk-17@17.0.19+10-1~deb12u2
17.0.20+8-1~deb12u1
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
lcms2@2.14-2
openjdk-17@17.0.16+8-1~deb12u1
2.14-2+deb12u1
17.0.20+8-1~deb12u1
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
lcms2@2.16-2
2.16-2+deb13u2
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
lcms2@2.16-2
2.16-2+deb13u2
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
lcms2@2.16-2
2.16-2+deb13u2
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/ellite/wallos:2.46.09ce55520e7bd
lcms2@2.16-r0
2.19-r0
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
lcms2@2.16-r0
2.19-r0
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
lcms2@2.16-r0
2.19-r0
1
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
lcms2@2.16-r0
2.19-r0
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
lcms2@2.17-r0
2.19-r0
1
ghcr.io/home-operations/lidarr:3.1.29df1e14c8e09
lcms2@2.17-r0
2.19-r0
1
ghcr.io/home-operations/lidarr:3.1.2.4902dab0e07502a3
lcms2@2.17-r0
2.19-r0
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
lcms2@2.16-2
2.16-2+deb13u2
1
ghcr.io/jeremylong/open-vulnerability-data-mirror:v9.0.49a69aa14dc3e
lcms2@2.17-r0
2.19-r0
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
lcms2@2.9-1ubuntu0.1
2.9-1ubuntu0.1+esm1
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
lcms2@2.14-2build1
2.14-2ubuntu0.1
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
lcms2@2.14-2build1
2.14-2ubuntu0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.