StackRadar

CVE-2026-41850

High

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
380
of 17,781 indexed, latest versions
Container images
337
deployed by those charts
Fix available
1 of 1
affected package

Spring Framework Algorithmic Denial of Service via SpEL Expressions

Carried by container images the latest versions of 380 of 17,781 indexed charts deploy, on 337 images.

Affected packageAffected versionsFixed inImages
spring-expressionmaven3.2.18.RELEASE, 4.1.1.RELEASE, 4.2.1.RELEASE, 4.3.1.RELEASE+98 more6.2.19, 7.0.8337
OSV records
GHSA-r5w3-xv2f-j59q

Charts affected

380 by stars
ChartLatestAffected imagesRadar Score
gridgaingridgainOfficialVerified publisher1.0.61 of 1See more

gridgain gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
gridgain/community:8.9.11d32d182a0e6a
spring-expression@5.3.39
no fix listed

Open the chart page →

4,679
hawkhawk1.1.51 of 4See more

hawk hawk 1.1.5

1 of the 4 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
spring-expression@6.1.1
no fix listed

Open the chart page →

13,610
seata-serverheidaodageshiwoVerified publisher1.0.01 of 1See more

seata-server heidaodageshiwo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
seataio/seata-server:1.5.1ee1ed55f4144
spring-expression@5.3.13
no fix listed

Open the chart page →

5,624
ipfix-generatorjfwenischVerified publisher0.3.16-feature-helm-package.01 of 1See more

ipfix-generator jfwenisch 0.3.16-feature-helm-package.0

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/ipfix-generator:latesta1b05567dbf6
spring-expression@6.2.18
6.2.19

Open the chart page →

697
jenkinsjkimVerified publisher5.5.141 of 2See more

jenkins jkim 5.5.14

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
spring-expression@5.3.39
no fix listed

Open the chart page →

7,387
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
spring-expression@5.3.22
no fix listed

Open the chart page →

13,479
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
torrespro/mca-worker:2.0.06d3bd305a1ba
spring-expression@5.2.1.RELEASE
no fix listed

Open the chart page →

19,187
data-prepperopensearch-project-helm-chartsVerified publisher0.3.11 of 1See more

data-prepper opensearch-project-helm-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
opensearchproject/data-prepper:2.8.057c25fa01d3c
spring-expression@5.3.28
no fix listed

Open the chart page →

1,692
todo-apipavanelthepu0.1.01 of 2See more

todo-api pavanelthepu 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
pavanelthepu/todo-api:1.0.2f47658e3b24c
spring-expression@5.3.8
no fix listed

Open the chart page →

2,544
spring-boot-api-apppiominVerified publisher0.3.111 of 1See more

spring-boot-api-app piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
spring-expression@5.3.23
no fix listed

Open the chart page →

7,576
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
treskon/portrait:DEV-latest88e813f22347
spring-expression@6.1.15
no fix listed

Open the chart page →

31,844
nifi-registryprofyu1.14.0-r0011 of 1See more

nifi-registry profyu 1.14.0-r001

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
apache/nifi-registry:1.14.0090b7f87ec7f
spring-expression@5.3.5
no fix listed

Open the chart page →

4,621
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
spring-expression@5.3.18
no fix listed

Open the chart page →

3,958
reportportalreportportal-ioOfficialVerified publisher26.8.121 of 15See more

reportportal reportportal-io 26.8.12

1 of the 15 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
reportportal/service-jobs:5.15.299d27d58d6b4
spring-expression@6.2.18
6.2.19

Open the chart page →

11,869
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
zbalogh/reservation-api-server:1.0.97c247e399a1f
spring-expression@5.3.23
no fix listed

Open the chart page →

6,639
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
rm3l/dev-feed-api:latest9a7f732245a3
spring-expression@5.3.23
no fix listed

Open the chart page →

9,837
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
spring-expression@5.3.13
no fix listed

Open the chart page →

10,120
seldon-coreseldon0.2.72 of 3See more

seldon-core seldon 0.2.7

2 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
seldonio/apife:0.2.7ba81b17f00eb
spring-expression@4.3.20.RELEASE
no fix listed
seldonio/cluster-manager:0.2.729e362bb1ba2
spring-expression@4.3.20.RELEASE
no fix listed

Open the chart page →

13,798
sentinel-dashboardsentinel-dashboardVerified publisher0.1.01 of 1See more

sentinel-dashboard sentinel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
royalwang/sentinel-dashboard:1.8.4df99e2499f91
spring-expression@5.3.18
no fix listed

Open the chart page →

4,287
querysiakhooiVerified publisher1.0.01 of 1See more

query siakhooi 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
siakhooi/query:1.0.0f1f4b5b1b870
spring-expression@7.0.6
7.0.8

Open the chart page →

1,792
ocean-metric-exporterspot1.1.11 of 1See more

ocean-metric-exporter spot 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
spring-expression@6.2.10
6.2.19

Open the chart page →

1,482
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
spring-expression@5.3.24
no fix listed

Open the chart page →

13,486
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
spring-expression@6.2.18
6.2.19

Open the chart page →

2,826
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
spring-expression@5.3.29
no fix listed

Open the chart page →

9,102
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
spring-expression@5.3.29
no fix listed

Open the chart page →

9,102
migrationadeptia-automate-migration5.2.91 of 1See more

migration adeptia-automate-migration 5.2.9

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
spring-expression@6.2.15
6.2.19

Open the chart page →

395
airsonic-advancedairsonic-advancedVerified publisher0.3.11 of 1See more

airsonic-advanced airsonic-advanced 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
spring-expression@6.1.12
no fix listed

Open the chart page →

1,748
akto-testing-db-layerakto1.42.161 of 2See more

akto-testing-db-layer akto 1.42.16

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
spring-expression@5.3.16
no fix listed

Open the chart page →

5,489
pagesalstom-pages-app1.0.01 of 3See more

pages alstom-pages-app 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190
amorphieamorphie0.1.23 of 18See more

amorphie amorphie 0.1.2

3 of the 18 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
camunda/zeebe:8.4.5ab5abc09e407
spring-expression@6.1.4
no fix listed
hazelcast/management-center:5.3.2f9d34300d330
spring-expression@5.3.29
no fix listed
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
spring-expression@6.1.2
no fix listed

Open the chart page →

28,131
pagesandrei-pages1.0.01 of 3See more

pages andrei-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
spring-expression@5.1.6.RELEASE
no fix listed

Open the chart page →

11,553
apache-iotdbapache-iotdb-single-nodeVerified publisher0.1.01 of 1See more

apache-iotdb apache-iotdb-single-node 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
apache/iotdb:0.11.28647309f95d1
spring-expression@4.3.18.RELEASE
no fix listed

Open the chart page →

5,277
apimap-apiapimapOfficialVerified publisher1.8.111 of 1See more

apimap-api apimap 1.8.11

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
apimap/api:v1.8.11ae2b3ab00177
spring-expression@5.3.23
no fix listed

Open the chart page →

2,231
apispringbootHelmapispringboot0.1.01 of 1See more

apispringbootHelm apispringboot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
rabeh/apibootspring:1.0941007b6946e
spring-expression@6.1.1
no fix listed

Open the chart page →

6,187
d.vazquezm.2021_helmapphelmVerified publisher1.0.01 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
davidvmar/urjc-davidvmar-worker:1.0.10d221e834a21
spring-expression@5.2.1.RELEASE
no fix listed

Open the chart page →

19,745
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
spring-expression@5.2.20.RELEASE
no fix listed

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
spring-expression@5.2.20.RELEASE
no fix listed

Open the chart page →

16,975
kafka-uiappscodeVerified publisher2026.3.301 of 1See more

kafka-ui appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
spring-expression@6.2.17
6.2.19

Open the chart page →

729
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
spring-expression@5.2.9.RELEASE
no fix listed

Open the chart page →

8,866
dashboard-pui9assist-iot-tactile-dashboard0.2.01 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
spring-expression@5.3.20
no fix listed

Open the chart page →

4,145
url-shortenerbeastob1.0.21 of 3See more

url-shortener beastob 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
beastob/url-shortener:1.0.299a49885ab33
spring-expression@5.3.10
no fix listed

Open the chart page →

3,607
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
spring-expression@5.2.5.RELEASE
no fix listed

Open the chart page →

5,806
pagesberrutig-pages1.0.01 of 3See more

pages berrutig-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190
blackduck-alertblackduck8.4.01 of 4See more

blackduck-alert blackduck 8.4.0

1 of the 4 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
spring-expression@6.1.21
no fix listed

Open the chart page →

4,292
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
spring-expression@5.3.18
no fix listed

Open the chart page →

13,459
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
spring-expression@6.2.6
6.2.19

Open the chart page →

1,816
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-agg:logbc25b152d88e
spring-expression@6.2.1
6.2.19

Open the chart page →

26,996
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
spring-expression@5.3.33
no fix listed

Open the chart page →

8,323
pagesbrian-pages1.0.01 of 3See more

pages brian-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190

Container images carrying it

337 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
spring-expression@7.0.6
7.0.8
1
ghcr.io/gla-rad/enav-aton-admin-service:latestcf85570b1324
spring-expression@7.0.7
7.0.8
1
ghcr.io/gla-rad/enav-aton-service:latest3be878690629
spring-expression@7.0.7
7.0.8
1
ghcr.io/gla-rad/enav-aton-service-client:latestf1629ac5f9ec
spring-expression@7.0.7
7.0.8
1
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
spring-expression@7.0.6
7.0.8
1
ghcr.io/gla-rad/enav-eureka:latest05002092c621
spring-expression@7.0.6
7.0.8
1
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
spring-expression@7.0.6
7.0.8
1
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
spring-expression@7.0.6
7.0.8
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
spring-expression@6.2.14
6.2.19
1
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
spring-expression@6.2.6
6.2.19
1
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
spring-expression@6.2.10
6.2.19
1
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
spring-expression@6.2.1
6.2.19
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
spring-expression@5.3.23
no fix listed
1
ghcr.io/jfwenisch/ipfix-generator:latesta1b05567dbf6
spring-expression@6.2.18
6.2.19
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
spring-expression@6.2.0
6.2.19
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
spring-expression@6.2.0
6.2.19
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
spring-expression@5.2.7.RELEASE
no fix listed
1
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-expression@6.2.3
6.2.19
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
spring-expression@5.2.6.RELEASE
no fix listed
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
spring-expression@5.3.23
no fix listed
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
spring-expression@6.1.1
no fix listed
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
spring-expression@5.3.31
no fix listed
1
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
spring-expression@5.1.8.RELEASE
no fix listed
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
spring-expression@5.3.24
no fix listed
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
spring-expression@7.0.7
7.0.8
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
spring-expression@6.2.18
6.2.19
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
spring-expression@5.3.16
no fix listed
1
public.ecr.aws/aws-containers/retail-store-sample-cart:1.3.05d767569c976
spring-expression@6.2.10
6.2.19
1
public.ecr.aws/aws-containers/retail-store-sample-orders:1.3.0e85f034bcf48
spring-expression@6.2.10
6.2.19
1
public.ecr.aws/aws-containers/retail-store-sample-ui:1.3.0ce3f2e935eb3
spring-expression@6.2.10
6.2.19
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
spring-expression@5.3.24
no fix listed
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
spring-expression@6.1.1
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
spring-expression@6.1.3
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
spring-expression@6.1.3
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
spring-expression@6.1.3
no fix listed
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
spring-expression@5.3.31
no fix listed
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
spring-expression@5.3.7
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.