StackRadar

CVE-2026-41254

High

Advisory

Published 18 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
303
of 17,781 indexed, latest versions
Container images
299
deployed by those charts
Fix available
7 of 7
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 303 of 17,781 indexed charts deploy, on 299 images.

Affected packageAffected versionsFixed inImages
lcms2deb2.5-0ubuntu4, 2.5-0ubuntu4.1, 2.6-3ubuntu2, 2.6-3ubuntu2.1+6 more2.5-0ubuntu4.2+esm1, 2.6-3ubuntu2.1+esm1, 2.9-1ubuntu0.1+esm1, 2.9-4ubuntu0.1~esm1+5 more235
lcms2apk2.16-r0, 2.17-r02.19-r040
javabitnami11.0.15-150, 11.0.18-10-1, 11.0.18-10-2, 11.0.20-8-3+12 more1.8.016
Javabitnami11.0.20-8, 11.0.21-10, 17.0.8-7, 17.0.10-13-1+2 more1.8.07
openjdk-17deb17.0.10+7-1~deb12u1, 17.0.13+11-2~deb12u1, 17.0.16+8-1~deb12u1, 17.0.17+10-1~deb12u1+2 more17.0.20+8-1~deb12u17
jrebitnami17.0.16-12-0, 17.0.19-11-2, 21.0.8-12-0, 21.0.9-15-0+1 more1.8.05
openjdk-21deb21.0.11+10-1~deb13u221.0.12+8-1~deb13u12
OSV records
ALPINE-CVE-2026-41254BIT-java-2026-41254BIT-jre-2026-41254DEBIAN-CVE-2026-41254UBUNTU-CVE-2026-41254
Also known as
BIT-java-min-2026-41254, GHSA-4xp6-rcgg-m9qq, USN-8209-1, USN-8209-2

Charts affected

303 by stars
ChartLatestAffected imagesRadar Score
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-41254.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
lcms2@2.9-4
2.9-4ubuntu0.1~esm1

Open the chart page →

28,605
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-41254.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
jre@21.0.9-15-0
1.8.0

Open the chart page →

7,624
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-41254.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
lcms2@2.12~rc1-2build2
2.12~rc1-2ubuntu0.1

Open the chart page →

14,100

Container images carrying it

299 by charts deploying them

A fixed version is listed for 7 of the 7 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
lcms2@2.9-4
2.9-4ubuntu0.1~esm1
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
lcms2@2.9-4
2.9-4ubuntu0.1~esm1
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
lcms2@2.9-4
2.9-4ubuntu0.1~esm1
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
lcms2@2.16-r0
2.19-r0
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
lcms2@2.16-r0
2.19-r0
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
lcms2@2.17-r0
2.19-r0
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
lcms2@2.9-4
2.9-4ubuntu0.1~esm1
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
lcms2@2.9-4
2.9-4ubuntu0.1~esm1
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
lcms2@2.9-4
2.9-4ubuntu0.1~esm1
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
lcms2@2.9-4
2.9-4ubuntu0.1~esm1
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
lcms2@2.9-4
2.9-4ubuntu0.1~esm1
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
lcms2@2.9-1ubuntu0.1
2.9-1ubuntu0.1+esm1
1
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
lcms2@2.17-r0
2.19-r0
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/open-telemetry/demo:3.0.0-fraud-detection1cdfd1bcf476
lcms2@2.14-2
openjdk-17@17.0.18+8-1~deb12u1
2.14-2+deb12u1
17.0.20+8-1~deb12u1
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
lcms2@2.9-4
2.9-4ubuntu0.1~esm1
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
lcms2@2.16-2
2.16-2+deb13u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
lcms2@2.16-2
2.16-2+deb13u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
lcms2@2.16-2
2.16-2+deb13u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
lcms2@2.16-2
2.16-2+deb13u2
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
lcms2@2.9-4
2.9-4ubuntu0.1~esm1
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
lcms2@2.9-4
2.9-4ubuntu0.1~esm1
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
lcms2@2.9-4
2.9-4ubuntu0.1~esm1
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
lcms2@2.14-2build1
2.14-2ubuntu0.1
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
lcms2@2.12~rc1-2build2
2.12~rc1-2ubuntu0.1
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
lcms2@2.12~rc1-2build2
2.12~rc1-2ubuntu0.1
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
lcms2@2.12~rc1-2build2
2.12~rc1-2ubuntu0.1
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
jre@21.0.9-15-0
1.8.0
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
lcms2@2.14-2
2.14-2+deb12u1
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
lcms2@2.14-2
2.14-2+deb12u1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
lcms2@2.14-2
2.14-2+deb12u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
lcms2@2.14-2
2.14-2+deb12u1
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
lcms2@2.14-2
2.14-2+deb12u1
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
lcms2@2.14-2
2.14-2+deb12u1
1
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
lcms2@2.17-r0
2.19-r0
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
lcms2@2.6-3ubuntu2.1
2.6-3ubuntu2.1+esm1
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
lcms2@2.14-2
2.14-2+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.