StackRadar

CVE-2026-42778

Critical

Advisory

Published 1 May 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.007
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
1 of 1
affected package

Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41409 Incomplete Fix)

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
mina-coremaven2.1.3, 2.2.2, 2.2.3, 2.2.42.1.12, 2.2.78
OSV records
GHSA-995c-6rp3-4m4x

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-42778.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
mina-core@2.2.4
2.2.7

Open the chart page →

3,606
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-42778.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
mina-core@2.2.4
2.2.7

Open the chart page →

3,606
guacamolehalkeye0.2.11 of 3See more

guacamole halkeye 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-42778.

Container imageDigestPackageFixed in
guacamole/guacamole:1.1.0333a7f40c145
mina-core@2.1.3
2.1.12

Open the chart page →

4,839
guacamolehelmforgeVerified publisher1.5.21 of 5See more

guacamole helmforge 1.5.2

1 of the 5 container images this version deploys carry CVE-2026-42778.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
mina-core@2.2.4
2.2.7

Open the chart page →

8,716
clusterfactoryclusterfactory0.2.01 of 5See more

clusterfactory clusterfactory 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-42778.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
mina-core@2.2.4
2.2.7

Open the chart page →

7,168
gitea-jenkinsclusterfactory0.1.11 of 5See more

gitea-jenkins clusterfactory 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-42778.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
mina-core@2.2.4
2.2.7

Open the chart page →

5,238
gerrit-operatorepmdedpVerified publisher2.25.01 of 2See more

gerrit-operator epmdedp 2.25.0

1 of the 2 container images this version deploys carry CVE-2026-42778.

Container imageDigestPackageFixed in
epamedp/edp-gerrit:3.14.249e8fe9c4855
mina-core@2.2.4
2.2.7

Open the chart page →

1,159
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-42778.

Container imageDigestPackageFixed in
guacamole/guacamole:1.3.0739cb6820ae8
mina-core@2.1.3
2.1.12

Open the chart page →

6,412
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2026-42778.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
mina-core@2.1.3
2.1.12

Open the chart page →

26,944
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-42778.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
mina-core@2.2.2
2.2.7

Open the chart page →

5,269
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42778.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
mina-core@2.2.3
2.2.7

Open the chart page →

5,456

Container images carrying it

8 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
guacamole/guacamole:1.6.0f344085e618b
mina-core@2.2.4
2.2.7
3
jenkins/jenkins:2.541.3-jdk21c4098086090c
mina-core@2.2.4
2.2.7
2
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
mina-core@2.2.2
2.2.7
1
epamedp/edp-gerrit:3.14.249e8fe9c4855
mina-core@2.2.4
2.2.7
1
guacamole/guacamole:1.5.50f62f6d17ab3
mina-core@2.2.3
2.2.7
1
guacamole/guacamole:1.1.0333a7f40c145
mina-core@2.1.3
2.1.12
1
guacamole/guacamole:1.3.0739cb6820ae8
mina-core@2.1.3
2.1.12
1
sismics/docs:v1.10f4b0ef019cf1
mina-core@2.1.3
2.1.12
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.