StackRadar

CVE-2026-41706

Medium

Advisory

Published 10 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
119
of 17,792 indexed, latest versions
Container images
142
deployed by those charts
Fix available
1 of 1
affected package

Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache

Carried by container images the latest versions of 119 of 17,792 indexed charts deploy, on 142 images.

Affected packageAffected versionsFixed inImages
spring-security-webmaven3.2.10.RELEASE, 4.1.3.RELEASE, 4.1.4.RELEASE, 4.2.2.RELEASE+57 more6.5.11, 7.0.6142
OSV records
GHSA-x2r2-rvhq-2mqv

Charts affected

119 by stars
ChartLatestAffected imagesRadar Score
smartquerysearchhub0.1.01 of 1See more

smartquery searchhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
commerceexperts/smartquery-service:2.2.09e33ad89baf6
spring-security-web@5.7.10
no fix listed

Open the chart page →

1,529
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
spring-security-web@5.7.11
no fix listed

Open the chart page →

4,248
seldon-core-oauth-gatewayseldon0.3.11 of 2See more

seldon-core-oauth-gateway seldon 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
seldonio/apife:0.3.1eea0d3f578ca
spring-security-web@4.2.9.RELEASE
no fix listed

Open the chart page →

8,101
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
spring-security-web@5.6.5
no fix listed

Open the chart page →

8,806
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-web@5.2.1.RELEASE
no fix listed

Open the chart page →

12,516
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
spring-security-web@5.7.3
no fix listed

Open the chart page →

5,897
umsappstacksimplifyVerified publisher1.0.01 of 3See more

umsapp stacksimplify 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
spring-security-web@5.1.5.RELEASE
no fix listed

Open the chart page →

6,104
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
spring-security-web@5.7.5
no fix listed

Open the chart page →

13,696
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
spring-security-web@4.1.4.RELEASE
no fix listed

Open the chart page →

8,556
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
spring-security-web@6.3.8
no fix listed

Open the chart page →

1,830
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
spring-security-web@5.8.3
no fix listed

Open the chart page →

18,846
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-web@5.2.1.RELEASE
no fix listed

Open the chart page →

12,516
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
thingsboard/tb-node:3.4.1645f43b688f7
spring-security-web@5.7.1
no fix listed

Open the chart page →

25,423
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
spring-security-web@6.5.5
6.5.11

Open the chart page →

1,530
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
spring-security-web@6.5.2
6.5.11

Open the chart page →

1,693
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-web@5.6.1
no fix listed

Open the chart page →

14,414
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-web@5.6.1
no fix listed

Open the chart page →

28,697
hazelcastwenerme5.10.31 of 2See more

hazelcast wenerme 5.10.3

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.20095e0320623
spring-security-web@6.3.3
no fix listed

Open the chart page →

2,624
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-security-web@5.7.6
no fix listed

Open the chart page →

5,852

Container images carrying it

142 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
spring-security-web@5.5.0
no fix listed
1
emeraldpay/dshackle:0.14.0126f0ae0b388
spring-security-web@5.5.3
no fix listed
1
emeraldpay/dshackle:0.12ac2a4bc66ab6
spring-security-web@5.5.3
no fix listed
1
epam/ai-dial-admin-backend:0.20.00ac5be78d7c2
spring-security-web@6.5.10
6.5.11
1
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
spring-security-web@5.7.5
no fix listed
1
flowable/flowable-rest:7.1.0b7ae287502cd
spring-security-web@6.3.3
no fix listed
1
folioci/mod-agreements:latest29c3f233a498
spring-security-web@5.8.16
no fix listed
1
folioci/mod-licenses:latestcfd6109bf477
spring-security-web@5.8.16
no fix listed
1
folioci/mod-oa:latestae3b069d4ba5
spring-security-web@5.8.16
no fix listed
1
folioci/mod-serials-management:latest571fa1ffe8c9
spring-security-web@5.8.16
no fix listed
1
folioci/mod-service-interaction:latestf53c327a48e8
spring-security-web@5.8.16
no fix listed
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
spring-security-web@5.3.6.RELEASE
no fix listed
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
spring-security-web@5.8.16
no fix listed
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
spring-security-web@5.3.4.RELEASE
no fix listed
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
spring-security-web@5.3.4.RELEASE
no fix listed
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
spring-security-web@5.3.4.RELEASE
no fix listed
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
spring-security-web@5.3.4.RELEASE
no fix listed
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
spring-security-web@5.3.4.RELEASE
no fix listed
1
gocd/gocd-server:v19.3.02da45cb09d57
spring-security-web@4.2.11.RELEASE
no fix listed
1
gocd/gocd-server:v26.1.0720d1012b93f
spring-security-web@4.2.20.RELEASE
no fix listed
1
gotson/komga:0.99.49b15ea6bfc30
spring-security-web@5.4.6
no fix listed
1
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
spring-security-web@5.7.4
no fix listed
1
gresearchdev/siembol-storm-topology-manager:latest8dad36a05ebf
spring-security-web@5.7.4
no fix listed
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
spring-security-web@6.5.7
6.5.11
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
spring-security-web@5.6.2
no fix listed
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
spring-security-web@5.6.2
no fix listed
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
spring-security-web@5.6.2
no fix listed
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
spring-security-web@5.6.2
no fix listed
1
hazelcast/management-center:5.3.2f9d34300d330
spring-security-web@5.7.10
no fix listed
1
housewrecker/gaps:latestf417dd0a7547
spring-security-web@5.6.2
no fix listed
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
spring-security-web@5.8.14
no fix listed
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
spring-security-web@5.8.11
no fix listed
1
jhipster/jhipster-registry:latest7184525acd4d
spring-security-web@5.7.3
no fix listed
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
spring-security-web@5.7.11
no fix listed
1
just1not2/streama:1.10.48a2305192dec
spring-security-web@4.1.4.RELEASE
no fix listed
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
spring-security-web@5.4.1
no fix listed
1
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
spring-security-web@5.3.4.RELEASE
no fix listed
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
spring-security-web@5.3.4.RELEASE
no fix listed
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
spring-security-web@5.4.5
no fix listed
1
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
spring-security-web@6.3.3
no fix listed
1
nacos/nacos-server:1.4.1fe6e5688cdf3
spring-security-web@5.1.12.RELEASE
no fix listed
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
spring-security-web@5.8.14
no fix listed
1
openbas/platform:2.0.5d986d80b0a75
spring-security-web@6.3.6
no fix listed
1
openkm/openkm-ce:6.3.113bc465a7461b
spring-security-web@3.2.10.RELEASE
no fix listed
1
platform9community/api-gateway:latest40a4970de568
spring-security-web@5.3.3.RELEASE
no fix listed
1
platform9community/customers-service:latest2089811e5cc6
spring-security-web@5.3.3.RELEASE
no fix listed
1
platform9community/vets-service:latestd1165c94dfb3
spring-security-web@5.3.3.RELEASE
no fix listed
1
platform9community/visits-service:latest8d11b50368c6
spring-security-web@5.3.3.RELEASE
no fix listed
1
remche/shinyproxy:2.6.18bcda8a04d3b
spring-security-web@5.5.5
no fix listed
1
reportportal/service-api:5.7.29df41f8fb320
spring-security-web@5.2.4.RELEASE
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.