StackRadar

CVE-2026-47838

Medium

Advisory

Published 10 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
145
of 17,781 indexed, latest versions
Container images
157
deployed by those charts
Fix available
1 of 1
affected package

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

Carried by container images the latest versions of 145 of 17,781 indexed charts deploy, on 157 images.

Affected packageAffected versionsFixed inImages
spring-security-webmaven3.2.10.RELEASE, 4.1.3.RELEASE, 4.1.4.RELEASE, 4.2.2.RELEASE+68 more6.5.11157
OSV records
GHSA-293q-567p-wmwq

Charts affected

145 by stars
ChartLatestAffected imagesRadar Score
kafka-uiappscodeVerified publisher2026.3.301 of 1See more

kafka-ui appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
spring-security-web@6.5.9
6.5.11

Open the chart page →

729
automatedconfigurationassist-iot-automated-configuration1.0.01 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-security-web@6.1.3
no fix listed

Open the chart page →

14,728
dashboard-pui9assist-iot-tactile-dashboard0.2.01 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
spring-security-web@5.7.1
no fix listed

Open the chart page →

4,145
blackduck-alertblackduck8.4.01 of 4See more

blackduck-alert blackduck 8.4.0

1 of the 4 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
spring-security-web@6.3.10
no fix listed

Open the chart page →

4,292
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
spring-security-web@6.4.5
no fix listed

Open the chart page →

1,816
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
spring-security-web@5.8.11
no fix listed

Open the chart page →

8,323
geoservercamptocamp20.0.35 of 12See more

geoserver camptocamp2 0.0.3

5 of the 12 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
spring-security-web@5.3.4.RELEASE
no fix listed
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
spring-security-web@5.3.4.RELEASE
no fix listed

Open the chart page →

88,335
event-store-servicechoerodon0.8.01 of 2See more

event-store-service choerodon 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
choerodon/event-store-service:0.8.03c94c97f6f69
spring-security-web@4.2.2.RELEASE
no fix listed

Open the chart page →

9,808
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
spring-security-web@5.5.3
no fix listed

Open the chart page →

6,447
gocdcloudnativeapp1.9.21 of 2See more

gocd cloudnativeapp 1.9.2

1 of the 2 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
gocd/gocd-server:v19.3.02da45cb09d57
spring-security-web@4.2.11.RELEASE
no fix listed

Open the chart page →

9,144
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
spring-security-web@4.2.7.RELEASE
no fix listed

Open the chart page →

23,665
clusterfactoryclusterfactory0.2.01 of 5See more

clusterfactory clusterfactory 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
spring-security-web@6.5.7
6.5.11

Open the chart page →

7,168
gitea-jenkinsclusterfactory0.1.11 of 5See more

gitea-jenkins clusterfactory 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
spring-security-web@6.5.7
6.5.11

Open the chart page →

5,238
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
spring-security-web@6.4.4
no fix listed

Open the chart page →

4,578
nifi-registryd4nVerified publisher1.0.01 of 2See more

nifi-registry d4n 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
spring-security-web@5.8.11
no fix listed

Open the chart page →

5,398
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
spring-security-web@4.2.17.RELEASE
no fix listed

Open the chart page →

8,245
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
epam/ai-dial-admin-backend:0.20.00ac5be78d7c2
spring-security-web@6.5.10
6.5.11

Open the chart page →

4,046
kafka-uidoubanVerified publisher1.5.21 of 1See more

kafka-ui douban 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-security-web@6.4.3
no fix listed

Open the chart page →

1,269
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
spring-security-web@4.2.13.RELEASE
no fix listed

Open the chart page →

19,802
dshackledysnixVerified publisher0.1.11 of 2See more

dshackle dysnix 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.12ac2a4bc66ab6
spring-security-web@5.5.3
no fix listed

Open the chart page →

2,237
management-portaleclipse-aeriosVerified publisher1.1.01 of 2See more

management-portal eclipse-aerios 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
spring-security-web@6.2.2
no fix listed

Open the chart page →

3,888
shenyuerdeng2.4.211 of 2See more

shenyu erdeng 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-web@5.2.1.RELEASE
no fix listed

Open the chart page →

12,513
dshackleethereum-helm-chartsVerified publisher0.1.91 of 2See more

dshackle ethereum-helm-charts 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.14.0126f0ae0b388
spring-security-web@5.5.3
no fix listed

Open the chart page →

2,021
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
spring-security-web@6.4.4
no fix listed

Open the chart page →

7,792
scorpio-brokerfiware0.3.39 of 10See more

scorpio-broker fiware 0.3.3

9 of the 10 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
spring-security-web@5.6.0
no fix listed

Open the chart page →

55,600
scorpiobrokerfiware0.1.29 of 10See more

scorpiobroker fiware 0.1.2

9 of the 10 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
spring-security-web@5.6.0
no fix listed
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
spring-security-web@5.6.0
no fix listed

Open the chart page →

55,600
scorpio-broker-aaiofiware0.4.151 of 1See more

scorpio-broker-aaio fiware 0.4.15

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
spring-security-web@5.6.0
no fix listed

Open the chart page →

5,286
mod-agreementsfolio-org0.1.321 of 1See more

mod-agreements folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
folioci/mod-agreements:latest29c3f233a498
spring-security-web@5.8.16
no fix listed

Open the chart page →

1,874
mod-licensesfolio-org0.1.321 of 1See more

mod-licenses folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
folioci/mod-licenses:latestcfd6109bf477
spring-security-web@5.8.16
no fix listed

Open the chart page →

1,760
mod-oafolio-org0.1.21 of 1See more

mod-oa folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
folioci/mod-oa:latestae3b069d4ba5
spring-security-web@5.8.16
no fix listed

Open the chart page →

1,733
mod-serials-managementfolio-org0.1.11 of 1See more

mod-serials-management folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
folioci/mod-serials-management:latest571fa1ffe8c9
spring-security-web@5.8.16
no fix listed

Open the chart page →

1,733
mod-service-interactionfolio-org0.1.61 of 1See more

mod-service-interaction folio-org 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
folioci/mod-service-interaction:latestf53c327a48e8
spring-security-web@5.8.16
no fix listed

Open the chart page →

1,733
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
spring-security-web@5.5.0
no fix listed

Open the chart page →

18,230
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
spring-security-web@5.2.4.RELEASE
no fix listed

Open the chart page →

19,215
gapsgeek-cookbookVerified publisher5.4.21 of 1See more

gaps geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
housewrecker/gaps:latestf417dd0a7547
spring-security-web@5.6.2
no fix listed

Open the chart page →

8,943
komgageek-cookbookVerified publisher2.4.21 of 1See more

komga geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
gotson/komga:0.99.49b15ea6bfc30
spring-security-web@5.4.6
no fix listed

Open the chart page →

12,581
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
spring-security-web@5.3.3.RELEASE
no fix listed

Open the chart page →

17,702
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
spring-security-web@3.2.10.RELEASE
no fix listed

Open the chart page →

27,949
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.82 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

2 of the 5 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
spring-security-web@5.3.6.RELEASE
no fix listed
jingking/geonetwork-hnap:4.2.843e74ab234e1
spring-security-web@5.7.11
no fix listed

Open the chart page →

34,754
siembolgresearch0.1.62 of 4See more

siembol gresearch 0.1.6

2 of the 4 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
spring-security-web@5.7.4
no fix listed
gresearchdev/siembol-storm-topology-manager:latest8dad36a05ebf
spring-security-web@5.7.4
no fix listed

Open the chart page →

14,312
cc-spring-appgridgainVerified publisher1.0.61 of 1See more

cc-spring-app gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
gridgain/cloud-connector:2025.5.15ab838d7d3cb
spring-security-web@6.5.7
6.5.11

Open the chart page →

1,691
nacosheidaodageshiwoVerified publisher0.1.51 of 1See more

nacos heidaodageshiwo 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
spring-security-web@5.1.12.RELEASE
no fix listed

Open the chart page →

3,978
chart-bookhelm-deploy-book0.1.01 of 3See more

chart-book helm-deploy-book 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
dannielkil/book-backend:lateste3b479a55a69
spring-security-web@5.7.3
no fix listed

Open the chart page →

9,122
alfiohelmforgeVerified publisher1.2.121 of 3See more

alfio helmforge 1.2.12

1 of the 3 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
alfio/alf.io:2.0-M5-26060c836a081446
spring-security-web@6.5.10
6.5.11

Open the chart page →

2,091
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
openbas/platform:2.0.5d986d80b0a75
spring-security-web@6.3.6
no fix listed

Open the chart page →

25,017
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
spring-security-web@5.8.13
no fix listed

Open the chart page →

5,320
appswitcher-serverit-at-mOfficialVerified publisher2.0.21 of 1See more

appswitcher-server it-at-m 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
spring-security-web@6.4.5
no fix listed

Open the chart page →

3,774
kf-app-eaiit-at-mOfficialVerified publisher0.1.71 of 1See more

kf-app-eai it-at-m 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
spring-security-web@6.5.3
6.5.11

Open the chart page →

1,947
kron-aapm-agentkron-aapm-agent1.1.01 of 1See more

kron-aapm-agent kron-aapm-agent 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.1.07feef7d2ab42
spring-security-web@5.4.1
no fix listed

Open the chart page →

8,884
nacoskubesphere-testVerified publisher0.1.11 of 1See more

nacos kubesphere-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-47838.

Container imageDigestPackageFixed in
nacos/nacos-server:1.4.1fe6e5688cdf3
spring-security-web@5.1.12.RELEASE
no fix listed

Open the chart page →

4,153

Container images carrying it

157 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
spring-security-web@5.7.13
no fix listed
1
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
spring-security-web@5.1.5.RELEASE
no fix listed
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
spring-security-web@5.7.6
no fix listed
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
spring-security-web@6.5.10
6.5.11
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
spring-security-web@5.6.2
no fix listed
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
spring-security-web@6.2.0
no fix listed
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
spring-security-web@6.0.5
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.