StackRadar

CVE-2026-42403

High

Advisory

Published 1 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
1 of 1
affected package

Apache Neethi does not properly detect circular references in policy definitions.

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
neethimaven2.0.1, 3.0.3, 3.1.1, 3.2.0+1 more3.2.211
OSV records
GHSA-2hfh-9h53-qc24

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2026-42403.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
neethi@3.1.1
3.2.2

Open the chart page →

7,713
vrijbrpvrijbrpVerified publisher0.1.51 of 5See more

vrijbrp vrijbrp 0.1.5

1 of the 5 container images this version deploys carry CVE-2026-42403.

Container imageDigestPackageFixed in
vrijbrp/balie-ws:developc6603cb829ea
neethi@2.0.1
3.2.2

Open the chart page →

8,811
signserver-cesignserverOfficialVerified publisher2.3.51 of 1See more

signserver-ce signserver 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-42403.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.3.2798fbbe00283
neethi@3.2.1
3.2.2

Open the chart page →

2,406
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2026-42403.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
neethi@3.1.1
3.2.2

Open the chart page →

7,713
airsonic-advancedairsonic-advancedVerified publisher0.3.11 of 1See more

airsonic-advanced airsonic-advanced 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-42403.

Container imageDigestPackageFixed in
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
neethi@3.2.0
3.2.2

Open the chart page →

1,748
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42403.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
neethi@3.1.1
3.2.2

Open the chart page →

13,352
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-42403.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
neethi@3.2.1
3.2.2

Open the chart page →

4,578
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-42403.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
neethi@3.1.1
3.2.2

Open the chart page →

18,230
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-42403.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
neethi@3.1.1
3.2.2

Open the chart page →

19,215
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-42403.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
neethi@3.1.1
3.2.2

Open the chart page →

27,949
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-42403.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
neethi@3.0.3
3.2.2

Open the chart page →

34,754
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-42403.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
neethi@3.1.1
3.2.2

Open the chart page →

28,605

Container images carrying it

11 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
neethi@3.1.1
3.2.2
2
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
neethi@3.1.1
3.2.2
1
assistiot/identity-manager_kc:latest0df4b4fa899a
neethi@3.1.1
3.2.2
1
castlemock/castlemock:latestb7f3f1527ba9
neethi@3.2.1
3.2.2
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
neethi@3.0.3
3.2.2
1
keyfactor/signserver-ce:7.3.2798fbbe00283
neethi@3.2.1
3.2.2
1
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
neethi@3.2.0
3.2.2
1
openkm/openkm-ce:6.3.113bc465a7461b
neethi@3.1.1
3.2.2
1
vrijbrp/balie-ws:developc6603cb829ea
neethi@2.0.1
3.2.2
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
neethi@3.1.1
3.2.2
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
neethi@3.1.1
3.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.