StackRadar

CVE-2026-41854

Medium

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.2
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
60
of 17,781 indexed, latest versions
Container images
62
deployed by those charts
Fix available
1 of 1
affected package

Spring Framework Server-Side Request Forgery via UriComponentsBuilder

Carried by container images the latest versions of 60 of 17,781 indexed charts deploy, on 62 images.

Affected packageAffected versionsFixed inImages
spring-webmaven6.2.0, 6.2.1, 6.2.2, 6.2.3+14 more6.2.19, 7.0.862
OSV records
GHSA-7m2p-62gw-p8qq

Charts affected

60 by stars
ChartLatestAffected imagesRadar Score
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-41854.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
spring-web@6.2.5
6.2.19

Open the chart page →

7,792
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-41854.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
spring-web@6.2.5
6.2.19

Open the chart page →

2,003
unifiqaoruVerified publisher1.1.21 of 2See more

unifi qaoru 1.1.2

1 of the 2 container images this version deploys carry CVE-2026-41854.

Container imageDigestPackageFixed in
linuxserver/unifi-network-application:10.6.101-ls144b6ce6968ee45
spring-web@6.2.18
6.2.19

Open the chart page →

3,642
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41854.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
spring-web@7.0.7
7.0.8

Open the chart page →

6,207
retail-store-sample-cart-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-cart-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41854.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-cart:1.3.05d767569c976
spring-web@6.2.10
6.2.19

Open the chart page →

1,068
retail-store-sample-orders-chartstacksimplifyVerified publisher2.0.01 of 1See more

retail-store-sample-orders-chart stacksimplify 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-41854.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-orders:1.3.0e85f034bcf48
spring-web@6.2.10
6.2.19

Open the chart page →

1,223
retail-store-sample-ui-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-ui-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41854.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-ui:1.3.0ce3f2e935eb3
spring-web@6.2.10
6.2.19

Open the chart page →

836
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-41854.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
spring-web@6.2.11
6.2.19

Open the chart page →

1,827
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41854.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
spring-web@6.2.11
6.2.19

Open the chart page →

1,527
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-41854.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
spring-web@6.2.9
6.2.19

Open the chart page →

1,689

Container images carrying it

62 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
spring-web@6.2.6
6.2.19
1
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
spring-web@6.2.10
6.2.19
1
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
spring-web@6.2.1
6.2.19
1
ghcr.io/jfwenisch/ipfix-generator:latesta1b05567dbf6
spring-web@6.2.18
6.2.19
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
spring-web@6.2.0
6.2.19
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
spring-web@6.2.0
6.2.19
1
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-web@6.2.3
6.2.19
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
spring-web@7.0.7
7.0.8
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
spring-web@6.2.18
6.2.19
1
public.ecr.aws/aws-containers/retail-store-sample-cart:1.3.05d767569c976
spring-web@6.2.10
6.2.19
1
public.ecr.aws/aws-containers/retail-store-sample-orders:1.3.0e85f034bcf48
spring-web@6.2.10
6.2.19
1
public.ecr.aws/aws-containers/retail-store-sample-ui:1.3.0ce3f2e935eb3
spring-web@6.2.10
6.2.19
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.