StackRadar

CVE-2026-41715

Medium

Advisory

Published 9 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
12
deployed by those charts
Fix available
1 of 1
affected package

Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 12 images.

Affected packageAffected versionsFixed inImages
reactor-nettymaven1.0.11, 1.0.15, 1.0.19, 1.1.0+5 more1.2.1812
OSV records
GHSA-pfc9-2cqg-9wq6

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-41715.

Container imageDigestPackageFixed in
thmmniii/fbs-core:v1.27.15438517d9fc2
reactor-netty@1.1.13
no fix listed

Open the chart page →

28,534
amgraviteeioVerified publisher4.12.62 of 3See more

am graviteeio 4.12.6

2 of the 3 container images this version deploys carry CVE-2026-41715.

Container imageDigestPackageFixed in
graviteeio/am-gateway:4.12.607b7f6dc267a
reactor-netty@1.1.0
no fix listed
graviteeio/am-management-api:4.12.6a8eb04ee0c70
reactor-netty@1.1.0
no fix listed

Open the chart page →

2,088
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-41715.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
reactor-netty@1.2.10
1.2.18

Open the chart page →

3,963
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2026-41715.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:latest536358d7b17e
reactor-netty@1.2.10
1.2.18

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-41715.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
reactor-netty@1.1.9
no fix listed

Open the chart page →

16,975
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-41715.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
reactor-netty@1.1.10
no fix listed

Open the chart page →

6,447
dshackledysnixVerified publisher0.1.11 of 2See more

dshackle dysnix 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-41715.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.12ac2a4bc66ab6
reactor-netty@1.0.11
no fix listed

Open the chart page →

2,237
dshackleethereum-helm-chartsVerified publisher0.1.91 of 2See more

dshackle ethereum-helm-charts 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-41715.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.14.0126f0ae0b388
reactor-netty@1.0.11
no fix listed

Open the chart page →

2,021
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-41715.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
reactor-netty@1.1.11
no fix listed

Open the chart page →

3,683
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-41715.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
reactor-netty@1.1.11
no fix listed

Open the chart page →

5,129
business-serviceredestroyder0.2.11 of 1See more

business-service redestroyder 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-41715.

Container imageDigestPackageFixed in
redestroyder/business-service:0.0.1db03499a0726
reactor-netty@1.0.15
no fix listed

Open the chart page →

2,600
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-41715.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
reactor-netty@1.0.19
no fix listed

Open the chart page →

8,804

Container images carrying it

12 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
reactor-netty@1.2.10
1.2.18
2
apache/shenyu-bootstrap:2.5.11bd5756f6273
reactor-netty@1.0.19
no fix listed
1
drpcorg/dshackle:0.54.08858fae1859d
reactor-netty@1.1.10
no fix listed
1
emeraldpay/dshackle:0.14.0126f0ae0b388
reactor-netty@1.0.11
no fix listed
1
emeraldpay/dshackle:0.12ac2a4bc66ab6
reactor-netty@1.0.11
no fix listed
1
graviteeio/am-gateway:4.12.607b7f6dc267a
reactor-netty@1.1.0
no fix listed
1
graviteeio/am-management-api:4.12.6a8eb04ee0c70
reactor-netty@1.1.0
no fix listed
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
reactor-netty@1.1.11
no fix listed
1
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
reactor-netty@1.1.11
no fix listed
1
redestroyder/business-service:0.0.1db03499a0726
reactor-netty@1.0.15
no fix listed
1
thmmniii/fbs-core:v1.27.15438517d9fc2
reactor-netty@1.1.13
no fix listed
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
reactor-netty@1.1.9
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.