StackRadar

CVE-2026-41697

Medium

Advisory

Published 10 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,781 indexed, latest versions
Container images
15
deployed by those charts
Fix available
1 of 1
affected package

Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference

Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
spring-data-relationalmaven2.1.13, 2.2.5, 2.3.1, 2.4.1+6 more3.5.1215
OSV records
GHSA-8r2h-xh92-gq57

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
cert-vaultcert-vaultOfficialVerified publisher2.12.01 of 7See more

cert-vault cert-vault 2.12.0

1 of the 7 container images this version deploys carry CVE-2026-41697.

Container imageDigestPackageFixed in
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
spring-data-relational@3.5.6
3.5.12

Open the chart page →

15,863
amgraviteeioVerified publisher4.12.62 of 3See more

am graviteeio 4.12.6

2 of the 3 container images this version deploys carry CVE-2026-41697.

Container imageDigestPackageFixed in
graviteeio/am-gateway:4.12.607b7f6dc267a
spring-data-relational@3.4.5
no fix listed
graviteeio/am-management-api:4.12.6a8eb04ee0c70
spring-data-relational@3.4.5
no fix listed

Open the chart page →

2,088
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-41697.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
spring-data-relational@2.4.6
no fix listed

Open the chart page →

13,486
url-shortenerbeastob1.0.21 of 3See more

url-shortener beastob 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-41697.

Container imageDigestPackageFixed in
beastob/url-shortener:1.0.299a49885ab33
spring-data-relational@2.1.13
no fix listed

Open the chart page →

3,607
kf-app-eaiit-at-mOfficialVerified publisher0.1.71 of 1See more

kf-app-eai it-at-m 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-41697.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
spring-data-relational@3.5.3
3.5.12

Open the chart page →

1,947
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2026-41697.

Container imageDigestPackageFixed in
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
spring-data-relational@3.3.0
no fix listed

Open the chart page →

7,802
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41697.

Container imageDigestPackageFixed in
vlebediantsev/file-system-ms-final:latest10393a89b4a8
spring-data-relational@2.4.1
no fix listed

Open the chart page →

5,875
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41697.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
spring-data-relational@2.4.1
no fix listed

Open the chart page →

6,852
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41697.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
spring-data-relational@2.4.1
no fix listed

Open the chart page →

5,916
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41697.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
spring-data-relational@2.4.1
no fix listed

Open the chart page →

5,873
unifiqaoruVerified publisher1.1.21 of 2See more

unifi qaoru 1.1.2

1 of the 2 container images this version deploys carry CVE-2026-41697.

Container imageDigestPackageFixed in
linuxserver/unifi-network-application:10.6.101-ls144b6ce6968ee45
spring-data-relational@3.5.11
3.5.12

Open the chart page →

3,642
business-serviceredestroyder0.2.11 of 1See more

business-service redestroyder 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-41697.

Container imageDigestPackageFixed in
redestroyder/business-service:0.0.1db03499a0726
spring-data-relational@2.3.1
no fix listed

Open the chart page →

2,600
hetzner-iroboslamdev0.0.51 of 1See more

hetzner-irobo slamdev 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-41697.

Container imageDigestPackageFixed in
slamdev/hetzner-irobo:0.0.13ca20c184c55
spring-data-relational@2.2.5
no fix listed

Open the chart page →

3,754
retail-store-sample-orders-chartstacksimplifyVerified publisher2.0.01 of 1See more

retail-store-sample-orders-chart stacksimplify 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-41697.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-orders:1.3.0e85f034bcf48
spring-data-relational@3.5.3
3.5.12

Open the chart page →

1,223

Container images carrying it

15 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
beastob/url-shortener:1.0.299a49885ab33
spring-data-relational@2.1.13
no fix listed
1
graviteeio/am-gateway:4.12.607b7f6dc267a
spring-data-relational@3.4.5
no fix listed
1
graviteeio/am-management-api:4.12.6a8eb04ee0c70
spring-data-relational@3.4.5
no fix listed
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
spring-data-relational@3.3.0
no fix listed
1
linuxserver/unifi-network-application:10.6.101-ls144b6ce6968ee45
spring-data-relational@3.5.11
3.5.12
1
redestroyder/business-service:0.0.1db03499a0726
spring-data-relational@2.3.1
no fix listed
1
slamdev/hetzner-irobo:0.0.13ca20c184c55
spring-data-relational@2.2.5
no fix listed
1
vlebediantsev/file-system-ms-final:latest10393a89b4a8
spring-data-relational@2.4.1
no fix listed
1
vlebediantsev/logic-ms:latestdf8bf38c535b
spring-data-relational@2.4.1
no fix listed
1
vlebediantsev/registration-ms-final:latest427af418b75e
spring-data-relational@2.4.1
no fix listed
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
spring-data-relational@2.4.1
no fix listed
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
spring-data-relational@3.5.6
3.5.12
1
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
spring-data-relational@3.5.3
3.5.12
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
spring-data-relational@2.4.6
no fix listed
1
public.ecr.aws/aws-containers/retail-store-sample-orders:1.3.0e85f034bcf48
spring-data-relational@3.5.3
3.5.12
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.