CVE-2026-41254
HighAdvisory
Published 18 Apr 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.004
- 30th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 303
- of 17,781 indexed, latest versions
- Container images
- 299
- deployed by those charts
- Fix available
- 7 of 7
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 303 of 17,781 indexed charts deploy, on 299 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| lcms2deb | 2.5-0ubuntu4, 2.5-0ubuntu4.1, 2.6-3ubuntu2, 2.6-3ubuntu2.1+6 more | 2.5-0ubuntu4.2+esm1, 2.6-3ubuntu2.1+esm1, 2.9-1ubuntu0.1+esm1, 2.9-4ubuntu0.1~esm1+5 more | 235 |
| lcms2apk | 2.16-r0, 2.17-r0 | 2.19-r0 | 40 |
| javabitnami | 11.0.15-150, 11.0.18-10-1, 11.0.18-10-2, 11.0.20-8-3+12 more | 1.8.0 | 16 |
| Javabitnami | 11.0.20-8, 11.0.21-10, 17.0.8-7, 17.0.10-13-1+2 more | 1.8.0 | 7 |
| openjdk-17deb | 17.0.10+7-1~deb12u1, 17.0.13+11-2~deb12u1, 17.0.16+8-1~deb12u1, 17.0.17+10-1~deb12u1+2 more | 17.0.20+8-1~deb12u1 | 7 |
| jrebitnami | 17.0.16-12-0, 17.0.19-11-2, 21.0.8-12-0, 21.0.9-15-0+1 more | 1.8.0 | 5 |
| openjdk-21deb | 21.0.11+10-1~deb13u2 | 21.0.12+8-1~deb13u1 | 2 |
- OSV records
- ALPINE-CVE-2026-41254BIT-java-2026-41254BIT-jre-2026-41254DEBIAN-CVE-2026-41254UBUNTU-CVE-2026-41254
- Also known as
- BIT-java-min-2026-41254, GHSA-4xp6-rcgg-m9qq, USN-8209-1, USN-8209-2
Charts affected
303 by stars
Container images carrying it
299 by charts deploying them
A fixed version is listed for 7 of the 7 affected packages.