StackRadar

CVE-2026-41706

Medium

Advisory

Published 10 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
119
of 17,792 indexed, latest versions
Container images
142
deployed by those charts
Fix available
1 of 1
affected package

Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache

Carried by container images the latest versions of 119 of 17,792 indexed charts deploy, on 142 images.

Affected packageAffected versionsFixed inImages
spring-security-webmaven3.2.10.RELEASE, 4.1.3.RELEASE, 4.1.4.RELEASE, 4.2.2.RELEASE+57 more6.5.11, 7.0.6142
OSV records
GHSA-x2r2-rvhq-2mqv

Charts affected

119 by stars
ChartLatestAffected imagesRadar Score
smartquerysearchhub0.1.01 of 1See more

smartquery searchhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
commerceexperts/smartquery-service:2.2.09e33ad89baf6
spring-security-web@5.7.10
no fix listed

Open the chart page →

1,529
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
spring-security-web@5.7.11
no fix listed

Open the chart page →

4,248
seldon-core-oauth-gatewayseldon0.3.11 of 2See more

seldon-core-oauth-gateway seldon 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
seldonio/apife:0.3.1eea0d3f578ca
spring-security-web@4.2.9.RELEASE
no fix listed

Open the chart page →

8,101
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
spring-security-web@5.6.5
no fix listed

Open the chart page →

8,806
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-web@5.2.1.RELEASE
no fix listed

Open the chart page →

12,516
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
spring-security-web@5.7.3
no fix listed

Open the chart page →

5,897
umsappstacksimplifyVerified publisher1.0.01 of 3See more

umsapp stacksimplify 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
spring-security-web@5.1.5.RELEASE
no fix listed

Open the chart page →

6,104
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
spring-security-web@5.7.5
no fix listed

Open the chart page →

13,696
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
spring-security-web@4.1.4.RELEASE
no fix listed

Open the chart page →

8,556
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
spring-security-web@6.3.8
no fix listed

Open the chart page →

1,830
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
spring-security-web@5.8.3
no fix listed

Open the chart page →

18,846
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-web@5.2.1.RELEASE
no fix listed

Open the chart page →

12,516
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
thingsboard/tb-node:3.4.1645f43b688f7
spring-security-web@5.7.1
no fix listed

Open the chart page →

25,423
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
spring-security-web@6.5.5
6.5.11

Open the chart page →

1,530
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
spring-security-web@6.5.2
6.5.11

Open the chart page →

1,693
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-web@5.6.1
no fix listed

Open the chart page →

14,414
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-web@5.6.1
no fix listed

Open the chart page →

28,697
hazelcastwenerme5.10.31 of 2See more

hazelcast wenerme 5.10.3

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.20095e0320623
spring-security-web@6.3.3
no fix listed

Open the chart page →

2,624
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-41706.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-security-web@5.7.6
no fix listed

Open the chart page →

5,852

Container images carrying it

142 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-web@5.2.1.RELEASE
no fix listed
3
apache/nifi-registry:1.26.07cdfd8deec92
spring-security-web@5.8.11
no fix listed
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
spring-security-web@5.3.4.RELEASE
no fix listed
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
spring-security-web@5.3.4.RELEASE
no fix listed
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
spring-security-web@5.3.4.RELEASE
no fix listed
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
spring-security-web@5.3.4.RELEASE
no fix listed
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
spring-security-web@5.3.4.RELEASE
no fix listed
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
spring-security-web@6.5.10
6.5.11
2
hazelcast/management-center:5.5.20095e0320623
spring-security-web@6.3.3
no fix listed
2
hookiesolutions/webhookie:latest0629694246ba
spring-security-web@5.6.1
no fix listed
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
spring-security-web@5.8.7
no fix listed
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
spring-security-web@6.5.7
6.5.11
2
nacos/nacos-server:latest1c191c30c8cd
spring-security-web@6.5.10
6.5.11
2
nacos/nacos-server:v2.1.0dcf04549c6d7
spring-security-web@5.1.12.RELEASE
no fix listed
2
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
spring-security-web@5.6.0
no fix listed
2
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
spring-security-web@5.6.0
no fix listed
2
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
spring-security-web@5.6.0
no fix listed
2
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
spring-security-web@5.6.0
no fix listed
2
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
spring-security-web@5.6.0
no fix listed
2
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
spring-security-web@5.6.0
no fix listed
2
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
spring-security-web@5.6.0
no fix listed
2
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
spring-security-web@5.6.0
no fix listed
2
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
spring-security-web@5.6.0
no fix listed
2
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
spring-security-web@6.5.9
6.5.11
2
2martens/timetable:latestbd1ba6ab84c9
spring-security-web@6.5.5
6.5.11
1
2martens/wahlrecht:latestba2c3040dab0
spring-security-web@6.5.2
6.5.11
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
spring-security-web@5.5.0
no fix listed
1
alfio/alf.io:2.0-M5-26060c836a081446
spring-security-web@6.5.10
6.5.11
1
andrianrf/backoffice-be:latest6036614803d4
spring-security-web@5.7.8
no fix listed
1
andrianrf/bpjstk-service:latest46abe878d9d8
spring-security-web@5.3.4.RELEASE
no fix listed
1
andrianrf/iso-client:latestba560086ce15
spring-security-web@5.3.4.RELEASE
no fix listed
1
apache/nifi-registry:1.14.0090b7f87ec7f
spring-security-web@5.5.0
no fix listed
1
apache/nifi-registry:1.27.063b8e3e40742
spring-security-web@5.8.13
no fix listed
1
apache/nifi-registry:0.8.0974efa2f21da
spring-security-web@5.2.2.RELEASE
no fix listed
1
apache/ranger:2.7.076c176e8a0e4
spring-security-web@5.7.12
no fix listed
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
spring-security-web@5.6.5
no fix listed
1
apimap/api:v1.8.11ae2b3ab00177
spring-security-web@5.7.4
no fix listed
1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
spring-security-web@5.7.1
no fix listed
1
atlassian/crowd:5.2.2ebf761c7d437
spring-security-web@5.5.8
no fix listed
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
spring-security-web@5.3.3.RELEASE
no fix listed
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
spring-security-web@6.3.10
no fix listed
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
spring-security-web@6.5.5
6.5.11
1
choerodon/event-store-service:0.8.03c94c97f6f69
spring-security-web@4.2.2.RELEASE
no fix listed
1
commerceexperts/smartquery-service:2.2.09e33ad89baf6
spring-security-web@5.7.10
no fix listed
1
craigwillis/c2metadata-bd:latestae317d7e4724
spring-security-web@4.1.3.RELEASE
no fix listed
1
dannielkil/book-backend:lateste3b479a55a69
spring-security-web@5.7.3
no fix listed
1
drpcorg/dshackle:0.54.08858fae1859d
spring-security-web@5.5.3
no fix listed
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
spring-security-web@4.2.17.RELEASE
no fix listed
1
elastictranscoder/media:627e21dc963ab3858c6b
spring-security-web@5.5.0
no fix listed
1
elastictranscoder/media-storage:f6d861a026208b8c2359
spring-security-web@5.5.0
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.