StackRadar

CVE-2026-41706

Medium

Advisory

Published 10 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
119
of 17,792 indexed, latest versions
Container images
142
deployed by those charts
Fix available
1 of 1
affected package

Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache

Carried by container images the latest versions of 119 of 17,792 indexed charts deploy, on 142 images.

Affected packageAffected versionsFixed inImages
spring-security-webmaven3.2.10.RELEASE, 4.1.3.RELEASE, 4.1.4.RELEASE, 4.2.2.RELEASE+57 more6.5.11, 7.0.6142
OSV records
GHSA-x2r2-rvhq-2mqv

Charts affected

119 by stars
ChartLatestAffected imagesRadar Score
kafka-uikafka-uiVerified publisher1.6.51 of 1See more

kafka-ui kafka-ui 1.6.5

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
spring-security-web@6.5.9
6.5.11

Open the chart page →

729
gocdgocdOfficialVerified publisher2.18.11 of 2See more

gocd gocd 2.18.1

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
gocd/gocd-server:v26.1.0720d1012b93f
spring-security-web@4.2.20.RELEASE
no fix listed

Open the chart page →

1,539
apim3graviteeioVerified publisher4.12.191 of 4See more

apim3 graviteeio 4.12.19

1 of the 4 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
graviteeio/apim-management-api:4.12.19-debian27374522cd04
spring-security-web@6.5.10
6.5.11

Open the chart page →

4,852
spring-petclinic-cloudplatform9-communityVerified publisher0.2.04 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

4 of the 6 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
platform9community/api-gateway:latest40a4970de568
spring-security-web@5.3.3.RELEASE
no fix listed
platform9community/customers-service:latest2089811e5cc6
spring-security-web@5.3.3.RELEASE
no fix listed
platform9community/vets-service:latestd1165c94dfb3
spring-security-web@5.3.3.RELEASE
no fix listed
platform9community/visits-service:latest8d11b50368c6
spring-security-web@5.3.3.RELEASE
no fix listed

Open the chart page →

41,926
geonode-k8sgeonode-k8sVerified publisher2.0.01 of 10See more

geonode-k8s geonode-k8s 2.0.0

1 of the 10 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
spring-security-web@5.8.16
no fix listed

Open the chart page →

14,112
flowableflowable-oss7.1.01 of 2See more

flowable flowable-oss 7.1.0

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
flowable/flowable-rest:7.1.0b7ae287502cd
spring-security-web@6.3.3
no fix listed

Open the chart page →

2,786
apimgraviteeioVerified publisher4.12.191 of 4See more

apim graviteeio 4.12.19

1 of the 4 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
graviteeio/apim-management-api:4.12.19-debian27374522cd04
spring-security-web@6.5.10
6.5.11

Open the chart page →

4,852
nacosgujunxiang0.1.51 of 1See more

nacos gujunxiang 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
spring-security-web@6.5.10
6.5.11

Open the chart page →

1,827
nzbhydra2halkeye2.30.11 of 2See more

nzbhydra2 halkeye 2.30.1

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
spring-security-web@5.3.3.RELEASE
no fix listed

Open the chart page →

6,714
hazelcasthazelcastVerified publisher5.10.31 of 2See more

hazelcast hazelcast 5.10.3

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.20095e0320623
spring-security-web@6.3.3
no fix listed

Open the chart page →

2,624
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.261 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

1 of the 6 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
thingsboard/tb-node:3.6.0f40a542832c4
spring-security-web@5.7.7
no fix listed

Open the chart page →

14,574
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
thmmniii/fbs-core:v1.27.15438517d9fc2
spring-security-web@5.7.8
no fix listed

Open the chart page →

28,634
vrijbrpvrijbrpVerified publisher0.1.51 of 5See more

vrijbrp vrijbrp 0.1.5

1 of the 5 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
vrijbrp/haal-centraal-brp-bevragen:develop5c770c2ae48c
spring-security-web@5.7.8
no fix listed

Open the chart page →

8,836
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
spring-security-web@5.7.12
no fix listed

Open the chart page →

7,794
nacosbytectl0.1.61 of 1See more

nacos bytectl 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
spring-security-web@6.5.10
6.5.11

Open the chart page →

1,827
geoserver-cloudcamptocamp20.0.55 of 11See more

geoserver-cloud camptocamp2 0.0.5

5 of the 11 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
spring-security-web@5.3.4.RELEASE
no fix listed

Open the chart page →

84,710
geoserverCloudcamptocamp20.0.65 of 11See more

geoserverCloud camptocamp2 0.0.6

5 of the 11 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
spring-security-web@5.3.4.RELEASE
no fix listed

Open the chart page →

84,710
cbioportalcbioportalOfficialVerified publisher1.1.01 of 1See more

cbioportal cbioportal 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
spring-security-web@6.5.5
6.5.11

Open the chart page →

3,745
cert-vaultcert-vaultOfficialVerified publisher2.12.01 of 7See more

cert-vault cert-vault 2.12.0

1 of the 7 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
spring-security-web@6.5.7
6.5.11

Open the chart page →

16,056
nifid4nVerified publisher2.0.01 of 5See more

nifi d4n 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
spring-security-web@5.8.11
no fix listed

Open the chart page →

5,440
spinnakerdwardu-helm-charts2.2.61 of 2See more

spinnaker dwardu-helm-charts 2.2.6

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
spring-security-web@5.2.1.RELEASE
no fix listed

Open the chart page →

8,755
nifi-registrydysnixVerified publisher1.1.51 of 2See more

nifi-registry dysnix 1.1.5

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
apache/nifi-registry:0.8.0974efa2f21da
spring-security-web@5.2.2.RELEASE
no fix listed

Open the chart page →

6,533
enavenav-service-architectureVerified publisher0.0.78 of 10See more

enav enav-service-architecture 0.0.7

8 of the 10 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
spring-security-web@7.0.4
7.0.6
ghcr.io/gla-rad/enav-aton-admin-service:latestcf85570b1324
spring-security-web@7.0.5
7.0.6
ghcr.io/gla-rad/enav-aton-service:latest3be878690629
spring-security-web@7.0.5
7.0.6
ghcr.io/gla-rad/enav-aton-service-client:latestf1629ac5f9ec
spring-security-web@7.0.5
7.0.6
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
spring-security-web@7.0.4
7.0.6
ghcr.io/gla-rad/enav-eureka:latest05002092c621
spring-security-web@7.0.4
7.0.6
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
spring-security-web@7.0.4
7.0.6
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
spring-security-web@7.0.4
7.0.6

Open the chart page →

15,881
seata-serverheidaodageshiwoVerified publisher1.0.01 of 1See more

seata-server heidaodageshiwo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
seataio/seata-server:1.5.1ee1ed55f4144
spring-security-web@5.4.9
no fix listed

Open the chart page →

5,627
jenkinsjkimVerified publisher5.5.141 of 2See more

jenkins jkim 5.5.14

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
spring-security-web@5.8.14
no fix listed

Open the chart page →

7,404
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
treskon/portrait:DEV-latest88e813f22347
spring-security-web@6.3.5
no fix listed

Open the chart page →

32,033
nifi-registryprofyu1.14.0-r0011 of 1See more

nifi-registry profyu 1.14.0-r001

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
apache/nifi-registry:1.14.0090b7f87ec7f
spring-security-web@5.5.0
no fix listed

Open the chart page →

4,623
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
spring-security-web@5.5.5
no fix listed

Open the chart page →

3,959
reportportalreportportal-ioOfficialVerified publisher26.8.122 of 15See more

reportportal reportportal-io 26.8.12

2 of the 15 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
reportportal/service-api:5.15.4bf193091525a
spring-security-web@6.5.10
6.5.11
reportportal/service-authorization:5.15.16a954407b417
spring-security-web@6.5.10
6.5.11

Open the chart page →

11,993
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
zbalogh/reservation-api-server:1.0.97c247e399a1f
spring-security-web@5.7.3
no fix listed

Open the chart page →

6,640
seldon-coreseldon0.2.71 of 3See more

seldon-core seldon 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
seldonio/apife:0.2.7ba81b17f00eb
spring-security-web@4.2.9.RELEASE
no fix listed

Open the chart page →

13,804
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
spring-security-web@5.7.6
no fix listed

Open the chart page →

13,536
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
spring-security-web@6.5.10
6.5.11

Open the chart page →

2,881
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
spring-security-web@5.8.7
no fix listed

Open the chart page →

9,119
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
spring-security-web@5.8.7
no fix listed

Open the chart page →

9,119
airsonic-advancedairsonic-advancedVerified publisher0.3.11 of 1See more

airsonic-advanced airsonic-advanced 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
spring-security-web@6.3.3
no fix listed

Open the chart page →

1,750
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
spring-security-web@5.6.2
no fix listed

Open the chart page →

4,866
amorphieamorphie0.1.21 of 18See more

amorphie amorphie 0.1.2

1 of the 18 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
hazelcast/management-center:5.3.2f9d34300d330
spring-security-web@5.7.10
no fix listed

Open the chart page →

28,289
apimap-apiapimapOfficialVerified publisher1.8.111 of 1See more

apimap-api apimap 1.8.11

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
apimap/api:v1.8.11ae2b3ab00177
spring-security-web@5.7.4
no fix listed

Open the chart page →

2,233
kafka-uiappscodeVerified publisher2026.3.301 of 1See more

kafka-ui appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
spring-security-web@6.5.9
6.5.11

Open the chart page →

729
dashboard-pui9assist-iot-tactile-dashboard0.2.01 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
spring-security-web@5.7.1
no fix listed

Open the chart page →

4,146
blackduck-alertblackduck8.4.01 of 4See more

blackduck-alert blackduck 8.4.0

1 of the 4 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
spring-security-web@6.3.10
no fix listed

Open the chart page →

4,297
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
spring-security-web@5.8.11
no fix listed

Open the chart page →

8,339
geoservercamptocamp20.0.35 of 12See more

geoserver camptocamp2 0.0.3

5 of the 12 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
spring-security-web@5.3.4.RELEASE
no fix listed

Open the chart page →

88,618
event-store-servicechoerodon0.8.01 of 2See more

event-store-service choerodon 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
choerodon/event-store-service:0.8.03c94c97f6f69
spring-security-web@4.2.2.RELEASE
no fix listed

Open the chart page →

9,810
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
spring-security-web@5.5.3
no fix listed

Open the chart page →

6,514
gocdcloudnativeapp1.9.21 of 2See more

gocd cloudnativeapp 1.9.2

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
gocd/gocd-server:v19.3.02da45cb09d57
spring-security-web@4.2.11.RELEASE
no fix listed

Open the chart page →

9,146
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
spring-security-web@4.2.7.RELEASE
no fix listed

Open the chart page →

23,697
clusterfactoryclusterfactory0.2.01 of 5See more

clusterfactory clusterfactory 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
spring-security-web@6.5.7
6.5.11

Open the chart page →

7,193
gitea-jenkinsclusterfactory0.1.11 of 5See more

gitea-jenkins clusterfactory 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
spring-security-web@6.5.7
6.5.11

Open the chart page →

6,982

Container images carrying it

142 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
spring-security-web@5.5.0
no fix listed
1
emeraldpay/dshackle:0.14.0126f0ae0b388
spring-security-web@5.5.3
no fix listed
1
emeraldpay/dshackle:0.12ac2a4bc66ab6
spring-security-web@5.5.3
no fix listed
1
epam/ai-dial-admin-backend:0.20.00ac5be78d7c2
spring-security-web@6.5.10
6.5.11
1
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
spring-security-web@5.7.5
no fix listed
1
flowable/flowable-rest:7.1.0b7ae287502cd
spring-security-web@6.3.3
no fix listed
1
folioci/mod-agreements:latest29c3f233a498
spring-security-web@5.8.16
no fix listed
1
folioci/mod-licenses:latestcfd6109bf477
spring-security-web@5.8.16
no fix listed
1
folioci/mod-oa:latestae3b069d4ba5
spring-security-web@5.8.16
no fix listed
1
folioci/mod-serials-management:latest571fa1ffe8c9
spring-security-web@5.8.16
no fix listed
1
folioci/mod-service-interaction:latestf53c327a48e8
spring-security-web@5.8.16
no fix listed
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
spring-security-web@5.3.6.RELEASE
no fix listed
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
spring-security-web@5.8.16
no fix listed
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
spring-security-web@5.3.4.RELEASE
no fix listed
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
spring-security-web@5.3.4.RELEASE
no fix listed
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
spring-security-web@5.3.4.RELEASE
no fix listed
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
spring-security-web@5.3.4.RELEASE
no fix listed
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
spring-security-web@5.3.4.RELEASE
no fix listed
1
gocd/gocd-server:v19.3.02da45cb09d57
spring-security-web@4.2.11.RELEASE
no fix listed
1
gocd/gocd-server:v26.1.0720d1012b93f
spring-security-web@4.2.20.RELEASE
no fix listed
1
gotson/komga:0.99.49b15ea6bfc30
spring-security-web@5.4.6
no fix listed
1
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
spring-security-web@5.7.4
no fix listed
1
gresearchdev/siembol-storm-topology-manager:latest8dad36a05ebf
spring-security-web@5.7.4
no fix listed
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
spring-security-web@6.5.7
6.5.11
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
spring-security-web@5.6.2
no fix listed
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
spring-security-web@5.6.2
no fix listed
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
spring-security-web@5.6.2
no fix listed
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
spring-security-web@5.6.2
no fix listed
1
hazelcast/management-center:5.3.2f9d34300d330
spring-security-web@5.7.10
no fix listed
1
housewrecker/gaps:latestf417dd0a7547
spring-security-web@5.6.2
no fix listed
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
spring-security-web@5.8.14
no fix listed
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
spring-security-web@5.8.11
no fix listed
1
jhipster/jhipster-registry:latest7184525acd4d
spring-security-web@5.7.3
no fix listed
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
spring-security-web@5.7.11
no fix listed
1
just1not2/streama:1.10.48a2305192dec
spring-security-web@4.1.4.RELEASE
no fix listed
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
spring-security-web@5.4.1
no fix listed
1
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
spring-security-web@5.3.4.RELEASE
no fix listed
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
spring-security-web@5.3.4.RELEASE
no fix listed
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
spring-security-web@5.4.5
no fix listed
1
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
spring-security-web@6.3.3
no fix listed
1
nacos/nacos-server:1.4.1fe6e5688cdf3
spring-security-web@5.1.12.RELEASE
no fix listed
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
spring-security-web@5.8.14
no fix listed
1
openbas/platform:2.0.5d986d80b0a75
spring-security-web@6.3.6
no fix listed
1
openkm/openkm-ce:6.3.113bc465a7461b
spring-security-web@3.2.10.RELEASE
no fix listed
1
platform9community/api-gateway:latest40a4970de568
spring-security-web@5.3.3.RELEASE
no fix listed
1
platform9community/customers-service:latest2089811e5cc6
spring-security-web@5.3.3.RELEASE
no fix listed
1
platform9community/vets-service:latestd1165c94dfb3
spring-security-web@5.3.3.RELEASE
no fix listed
1
platform9community/visits-service:latest8d11b50368c6
spring-security-web@5.3.3.RELEASE
no fix listed
1
remche/shinyproxy:2.6.18bcda8a04d3b
spring-security-web@5.5.5
no fix listed
1
reportportal/service-api:5.7.29df41f8fb320
spring-security-web@5.2.4.RELEASE
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.