StackRadar

CVE-2026-42198

High

Advisory

Published 1 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.033
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
266
of 17,781 indexed, latest versions
Container images
209
deployed by those charts
Fix available
3 of 3
affected packages

pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS

Carried by container images the latest versions of 266 of 17,781 indexed charts deploy, on 209 images.

Affected packageAffected versionsFixed inImages
postgresqlmaven42.2.1, 42.2.2, 42.2.2.jre7, 42.2.5+43 more42.7.11209
postgresql-jdbc-driverbitnami42.7.7, 42.7.842.7.112
PostgreSQL JDBC Driverbitnami42.6.0, 42.7.342.7.112
OSV records
BIT-postgresql-jdbc-driver-2026-42198GHSA-98qh-xjc8-98pq

Charts affected

266 by stars
ChartLatestAffected imagesRadar Score
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
postgresql@42.2.8
42.7.11

Open the chart page →

12,513
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
thingsboard/tb-node:3.4.1645f43b688f7
postgresql@42.2.20
42.7.11

Open the chart page →

25,394
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.7.11

Open the chart page →

20,190
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.7.11

Open the chart page →

20,190
togglr-backendtogglrVerified publisher1.0.01 of 1See more

togglr-backend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
postgresql@42.7.3
42.7.11

Open the chart page →

3,221
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
postgresql@42.7.7
42.7.11

Open the chart page →

1,527
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.1.4044a457e0498
postgresql@42.7.4
42.7.11

Open the chart page →

45,239
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.7.11

Open the chart page →

20,190
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.7.11

Open the chart page →

20,190
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
postgresql@42.2.8
42.7.11

Open the chart page →

5,460
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
postgresql@42.2.5
42.7.11

Open the chart page →

28,605
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
postgresql@42.7.8
postgresql-jdbc-driver@42.7.8
42.7.11
42.7.11

Open the chart page →

7,624
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
postgresql@42.2.16
42.7.11

Open the chart page →

3,424
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
postgresql@42.6.0
42.7.11

Open the chart page →

11,577
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
postgresql@42.4.3
42.7.11
zahoriaut/zahori-server:0.1.17b2de13916f3e
postgresql@42.3.8
42.7.11

Open the chart page →

5,846
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-42198.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
postgresql@42.5.1
42.7.11

Open the chart page →

6,016

Container images carrying it

209 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/keycloak/keycloak:26.49409c59bdfb6
postgresql@42.7.7
42.7.11
1
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
postgresql@42.7.4
42.7.11
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
postgresql@42.5.1
42.7.11
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
postgresql@42.7.8
42.7.11
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
postgresql@42.6.0
42.7.11
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
postgresql@42.7.2
42.7.11
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
postgresql@42.7.2
42.7.11
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
postgresql@42.7.2
42.7.11
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
postgresql@42.7.4
42.7.11
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.