StackRadar

CVE-2026-41839

Medium

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.2
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
55
of 17,781 indexed, latest versions
Container images
70
deployed by those charts
Fix available
1 of 1
affected package

Spring Framework Escalation via Session Fixation in WebFlux

Carried by container images the latest versions of 55 of 17,781 indexed charts deploy, on 70 images.

Affected packageAffected versionsFixed inImages
spring-webfluxmaven5.2.2.RELEASE, 5.2.7.RELEASE, 5.2.8.RELEASE, 5.3.1+28 more6.2.19, 7.0.870
OSV records
GHSA-4hfh-6x8g-gwpp

Charts affected

55 by stars
ChartLatestAffected imagesRadar Score
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-41839.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
spring-webflux@6.1.19
no fix listed

Open the chart page →

4,674
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-41839.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-webflux@5.2.2.RELEASE
no fix listed

Open the chart page →

12,513
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41839.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-webflux@5.3.15
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-41839.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-webflux@5.3.15
no fix listed

Open the chart page →

28,605
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-41839.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-webflux@5.3.25
no fix listed

Open the chart page →

5,846

Container images carrying it

70 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
streamnative/private-cloud-console:v2.3.27-all91e54375e154
spring-webflux@6.1.19
no fix listed
1
thingsboard/tb-postgres:latest2d17e4e36edc
spring-webflux@6.2.11
6.2.19
1
thmmniii/fbs-core:v1.27.15438517d9fc2
spring-webflux@5.3.27
no fix listed
1
treskon/portrait:DEV-latest88e813f22347
spring-webflux@6.1.15
no fix listed
1
vlebediantsev/logic-ms:latestdf8bf38c535b
spring-webflux@5.3.21
no fix listed
1
vrijbrp/haal-centraal-brp-bevragen:develop5c770c2ae48c
spring-webflux@5.3.27
no fix listed
1
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-webflux@5.3.25
no fix listed
1
zbalogh/reservation-api-server:1.0.97c247e399a1f
spring-webflux@5.3.23
no fix listed
1
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
spring-webflux@7.0.6
7.0.8
1
ghcr.io/gla-rad/enav-aton-admin-service:latestcf85570b1324
spring-webflux@7.0.7
7.0.8
1
ghcr.io/gla-rad/enav-aton-service:latest3be878690629
spring-webflux@7.0.7
7.0.8
1
ghcr.io/gla-rad/enav-aton-service-client:latestf1629ac5f9ec
spring-webflux@7.0.7
7.0.8
1
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
spring-webflux@7.0.6
7.0.8
1
ghcr.io/gla-rad/enav-eureka:latest05002092c621
spring-webflux@7.0.6
7.0.8
1
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
spring-webflux@7.0.6
7.0.8
1
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-webflux@6.2.3
6.2.19
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
spring-webflux@6.1.1
no fix listed
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
spring-webflux@5.3.24
no fix listed
1
public.ecr.aws/aws-containers/retail-store-sample-ui:1.3.0ce3f2e935eb3
spring-webflux@6.2.10
6.2.19
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
spring-webflux@5.3.24
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.