StackRadar

CVE-2026-44241

High

Advisory

Published 6 May 2026In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
16
deployed by those charts
Fix available
1 of 1
affected package

Micronaut has unbounded `formattersCache` in `TimeConverterRegistrar` that Allows Memory Exhaustion via `Accept-Language` Header

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 16 images.

Affected packageAffected versionsFixed inImages
micronaut-contextmaven3.8.6, 3.10.3, 3.10.4, 4.5.3+5 more3.8.14, 3.10.6, 4.10.2216
OSV records
GHSA-8hjv-92q9-g4xj

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
airbyte-api-serverairbyteVerified publisher0.293.41 of 1See more

airbyte-api-server airbyte 0.293.4

1 of the 1 container images this version deploys carry CVE-2026-44241.

Container imageDigestPackageFixed in
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
micronaut-context@4.5.3
4.10.22

Open the chart page →

854
connector-rollout-workerairbyteVerified publisher1.9.21 of 1See more

connector-rollout-worker airbyte 1.9.2

1 of the 1 container images this version deploys carry CVE-2026-44241.

Container imageDigestPackageFixed in
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
micronaut-context@4.9.10
4.10.22

Open the chart page →

829
airbyteairbyte-v2Verified publisher2.2.06 of 10See more

airbyte airbyte-v2 2.2.0

6 of the 10 container images this version deploys carry CVE-2026-44241.

Container imageDigestPackageFixed in
airbyte/bootloader:2.2.0f71cf4e185d5
micronaut-context@4.10.18
4.10.22
airbyte/cron:2.2.0d97b67a1346d
micronaut-context@4.10.18
4.10.22
airbyte/server:2.2.070e125498a1c
micronaut-context@4.10.18
4.10.22
airbyte/worker:2.2.08060b88b29c8
micronaut-context@4.10.18
4.10.22
airbyte/workload-api-server:2.2.042093cff86e9
micronaut-context@4.10.18
4.10.22
airbyte/workload-launcher:2.2.0119be7bfb719
micronaut-context@4.10.18
4.10.22

Open the chart page →

12,473
airbyte-data-planeairbyte-v2Verified publisher2.2.01 of 1See more

airbyte-data-plane airbyte-v2 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-44241.

Container imageDigestPackageFixed in
airbyte/workload-launcher:2.2.0119be7bfb719
micronaut-context@4.10.18
4.10.22

Open the chart page →

790
consent-facadefiware0.1.11 of 1See more

consent-facade fiware 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-44241.

Container imageDigestPackageFixed in
quay.io/seamware/consent-facade:0.0.14be844c750c7e
micronaut-context@4.7.6
4.10.22

Open the chart page →

2,475
contract-managementfiware3.5.361 of 1See more

contract-management fiware 3.5.36

1 of the 1 container images this version deploys carry CVE-2026-44241.

Container imageDigestPackageFixed in
quay.io/fiware/contract-management:3.3.122bcfcf874451
micronaut-context@4.7.6
4.10.22

Open the chart page →

2,411
credentials-config-servicefiware2.6.41 of 1See more

credentials-config-service fiware 2.6.4

1 of the 1 container images this version deploys carry CVE-2026-44241.

Container imageDigestPackageFixed in
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
micronaut-context@4.10.12
4.10.22

Open the chart page →

2,293
dss-validation-servicefiware0.0.191 of 1See more

dss-validation-service fiware 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-44241.

Container imageDigestPackageFixed in
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
micronaut-context@4.7.6
4.10.22

Open the chart page →

4,536
trusted-issuers-listfiware0.18.71 of 1See more

trusted-issuers-list fiware 0.18.7

1 of the 1 container images this version deploys carry CVE-2026-44241.

Container imageDigestPackageFixed in
quay.io/fiware/trusted-issuers-list:0.9.13c886ce5c056
micronaut-context@4.10.11
4.10.22

Open the chart page →

1,701
trusted-issuers-registryfiware0.13.01 of 1See more

trusted-issuers-registry fiware 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-44241.

Container imageDigestPackageFixed in
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
micronaut-context@3.10.3
3.10.6

Open the chart page →

7,087
gridgain9gridgainVerified publisher1.1.101 of 2See more

gridgain9 gridgain 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-44241.

Container imageDigestPackageFixed in
gridgain/gridgain9:9.1.1895018390077b
micronaut-context@3.10.4
3.10.6

Open the chart page →

3,199
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-44241.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
micronaut-context@3.8.6
3.8.14

Open the chart page →

18,756

Container images carrying it

16 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
airbyte/workload-launcher:2.2.0119be7bfb719
micronaut-context@4.10.18
4.10.22
2
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
micronaut-context@4.5.3
4.10.22
1
airbyte/bootloader:2.2.0f71cf4e185d5
micronaut-context@4.10.18
4.10.22
1
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
micronaut-context@4.9.10
4.10.22
1
airbyte/cron:2.2.0d97b67a1346d
micronaut-context@4.10.18
4.10.22
1
airbyte/server:2.2.070e125498a1c
micronaut-context@4.10.18
4.10.22
1
airbyte/worker:2.2.08060b88b29c8
micronaut-context@4.10.18
4.10.22
1
airbyte/workload-api-server:2.2.042093cff86e9
micronaut-context@4.10.18
4.10.22
1
gridgain/gridgain9:9.1.1895018390077b
micronaut-context@3.10.4
3.10.6
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
micronaut-context@3.8.6
3.8.14
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
micronaut-context@4.7.6
4.10.22
1
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
micronaut-context@4.10.12
4.10.22
1
quay.io/fiware/trusted-issuers-list:0.9.13c886ce5c056
micronaut-context@4.10.11
4.10.22
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
micronaut-context@3.10.3
3.10.6
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
micronaut-context@4.7.6
4.10.22
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
micronaut-context@4.7.6
4.10.22
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.