StackRadar

CVE-2026-47890

Critical

Advisory

Published 27 Aug 2026In the index since 8 Oct 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
85
of 18,053 indexed, latest versions
Container images
102
deployed by those charts
Fix available
2 of 2
affected packages

Spring Framework Server Sent Event stream corruption while rendering fragments

Carried by container images the latest versions of 85 of 18,053 indexed charts deploy, on 102 images.

Affected packageAffected versionsFixed inImages
spring-webmvcmaven6.2.0, 6.2.1, 6.2.2, 6.2.5+15 more7.0.993
spring-webfluxmaven6.2.0, 6.2.2, 6.2.3, 6.2.6+9 more7.0.934
OSV records
GHSA-j9f9-w8pj-32f8

Charts affected

85 by stars
ChartLatestAffected imagesRadar Score
mod-inn-reachfolio-org0.1.71 of 1See more

mod-inn-reach folio-org 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
folioci/mod-inn-reach:latestcc8584e43382
spring-webmvc@7.0.8
7.0.9

Open the chart page →

513
mod-password-validatorfolio-org0.1.341 of 1See more

mod-password-validator folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
folioci/mod-password-validator:latestb31d75f2bf7b
spring-webmvc@7.0.8
7.0.9

Open the chart page →

395
mod-remote-storagefolio-org0.1.321 of 1See more

mod-remote-storage folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
folioci/mod-remote-storage:latest4f12177123dc
spring-webmvc@7.0.8
7.0.9

Open the chart page →

572
mod-tagsfolio-org0.1.341 of 1See more

mod-tags folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
folioci/mod-tags:latest6e8beeb70272
spring-webmvc@7.0.8
7.0.9

Open the chart page →

343
cc-spring-appgridgainVerified publisher1.0.61 of 1See more

cc-spring-app gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
gridgain/cloud-connector:2025.5.15ab838d7d3cb
spring-webflux@6.2.15
spring-webmvc@6.2.15
no fix listed
no fix listed

Open the chart page →

1,984
hello-world-apihello-world-api0.0.51 of 1See more

hello-world-api hello-world-api 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
fabioformosa/hello-world-api:latest063873af085c
spring-webmvc@6.2.5
no fix listed

Open the chart page →

1,555
alfiohelmforgeVerified publisher1.2.121 of 3See more

alfio helmforge 1.2.12

1 of the 3 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
alfio/alf.io:2.0-M5-26060c836a081446
spring-webmvc@6.2.18
no fix listed

Open the chart page →

2,310
booklorehelmforgeVerified publisher2.0.21 of 3See more

booklore helmforge 2.0.2

1 of the 3 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
ghcr.io/booklore-app/booklore:v2.3.1d3d3af34bc2c
spring-webmvc@7.0.8
7.0.9

Open the chart page →

2,416
komgahelmforgeVerified publisher1.4.161 of 1See more

komga helmforge 1.4.16

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
gotson/komga:1.27.19cf102f5fb78
spring-webflux@6.2.19
spring-webmvc@6.2.19
no fix listed
no fix listed

Open the chart page →

36,012
openaevhelm-openbasVerified publisher2.0.111 of 7See more

openaev helm-openbas 2.0.11

1 of the 7 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
openaev/platform:3.261005.0eaf26c4106a1
spring-webflux@6.2.19
spring-webmvc@6.2.19
no fix listed
no fix listed

Open the chart page →

21,120
appswitcher-serverit-at-mOfficialVerified publisher2.0.21 of 1See more

appswitcher-server it-at-m 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
spring-webmvc@6.2.6
no fix listed

Open the chart page →

4,528
daveit-at-mOfficialVerified publisher0.2.187 of 9See more

dave it-at-m 0.2.18

7 of the 9 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
spring-webflux@6.2.19
no fix listed
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
spring-webflux@6.2.19
spring-webmvc@6.2.19
no fix listed
no fix listed
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
spring-webflux@6.2.19
spring-webmvc@6.2.19
no fix listed
no fix listed
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
spring-webmvc@6.2.19
no fix listed
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
spring-webflux@6.2.19
no fix listed
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
spring-webflux@6.2.19
spring-webmvc@6.2.19
no fix listed
no fix listed
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal:10.0.0d352df1b94b6
spring-webflux@6.2.19
no fix listed

Open the chart page →

15,089
kf-app-eaiit-at-mOfficialVerified publisher0.1.71 of 1See more

kf-app-eai it-at-m 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
spring-webmvc@6.2.10
no fix listed

Open the chart page →

2,254
zammad-ldap-syncit-at-mVerified publisher0.6.51 of 1See more

zammad-ldap-sync it-at-m 0.6.5

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
spring-webmvc@6.2.1
no fix listed

Open the chart page →

1,585
proxerajfwenisch0.12.201 of 1See more

proxera jfwenisch 0.12.20

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
ghcr.io/wenisch-tech/proxera:0.12.205ac0e9f6b42f
spring-webmvc@7.0.8
7.0.9

Open the chart page →

343
k8sforjavak8sforjava0.1.01 of 1See more

k8sforjava k8sforjava 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
vincentgwzhang/k8sforjava:latesta9139f2cd98f
spring-webmvc@6.2.1
no fix listed

Open the chart page →

1,635
aapm-servicekron-pam-aapm-helmcharts1.2.91 of 1See more

aapm-service kron-pam-aapm-helmcharts 1.2.9

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
krontechnology/aapm-service:1.2.3b964408930a5
spring-webmvc@6.2.18
no fix listed

Open the chart page →

3,025
kron-aapm-agentkron-pam-aapm-helmcharts1.2.61 of 1See more

kron-aapm-agent kron-pam-aapm-helmcharts 1.2.6

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.8.508e04ea66dfd
spring-webmvc@6.2.18
no fix listed

Open the chart page →

3,129
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
spring-webflux@6.2.0
spring-webmvc@6.2.0
no fix listed
no fix listed

Open the chart page →

4,095
nacosnacos-yunyeVerified publisher1.0.31 of 1See more

nacos nacos-yunye 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.130a39cb0c54d
spring-webmvc@6.2.5
no fix listed

Open the chart page →

2,242
onyxiaonyxia11.8.21 of 2See more

onyxia onyxia 11.8.2

1 of the 2 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
inseefrlab/onyxia-api:v4.12.0b377aec3ead1
spring-webflux@6.2.18
spring-webmvc@6.2.18
no fix listed
no fix listed

Open the chart page →

4,944
cp-cmfopenshift2.4.31 of 1See more

cp-cmf openshift 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
confluentinc/cp-cmf:2.4.3c7617bf49a1b
spring-webmvc@6.2.19
no fix listed

Open the chart page →

98
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
spring-webmvc@6.2.5
no fix listed

Open the chart page →

8,669
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
spring-webmvc@6.2.5
no fix listed

Open the chart page →

2,410
unifiqaoruVerified publisher1.1.61 of 2See more

unifi qaoru 1.1.6

1 of the 2 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
linuxserver/unifi-network-application:10.6.106-ls1485d288401f8bc
spring-webmvc@6.2.18
no fix listed

Open the chart page →

3,812
komgarubxkubeVerified publisher0.1.51 of 1See more

komga rubxkube 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
gotson/komga:1.28.1d8f772dce7b3
spring-webflux@6.2.19
spring-webmvc@6.2.19
no fix listed
no fix listed

Open the chart page →

24,589
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
spring-webmvc@7.0.7
7.0.9

Open the chart page →

7,228
retail-store-sample-cart-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-cart-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-cart:1.3.05d767569c976
spring-webmvc@6.2.10
no fix listed

Open the chart page →

1,254
retail-store-sample-orders-chartstacksimplifyVerified publisher2.0.01 of 1See more

retail-store-sample-orders-chart stacksimplify 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-orders:1.3.0e85f034bcf48
spring-webmvc@6.2.10
no fix listed

Open the chart page →

1,466
retail-store-sample-ui-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-ui-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-ui:1.3.0ce3f2e935eb3
spring-webflux@6.2.10
no fix listed

Open the chart page →

1,030
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
spring-webmvc@6.2.10
no fix listed

Open the chart page →

2,148
tekton-ci-environment-injectortekton-ci-environment-injectorVerified publisher0.2.41 of 1See more

tekton-ci-environment-injector tekton-ci-environment-injector 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
spring-webflux@7.0.8
7.0.9

Open the chart page →

694
tekton-stash-and-cachetekton-stash-and-cacheVerified publisher0.2.21 of 1See more

tekton-stash-and-cache tekton-stash-and-cache 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
spring-webflux@7.0.8
7.0.9

Open the chart page →

1,590
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
spring-webmvc@6.2.11
no fix listed

Open the chart page →

1,760
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-47890.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
spring-webmvc@6.2.9
no fix listed

Open the chart page →

1,921

Container images carrying it

102 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apache/fineract:1.12.1a83cf1980609
spring-webmvc@6.2.5
no fix listed
2
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
spring-webmvc@6.2.6
no fix listed
2
nacos/nacos-server:latest1c191c30c8cd
spring-webmvc@6.2.18
no fix listed
2
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
spring-webflux@6.2.17
no fix listed
2
2martens/timetable:latestbd1ba6ab84c9
spring-webmvc@6.2.11
no fix listed
1
2martens/wahlrecht:latestba2c3040dab0
spring-webmvc@6.2.9
no fix listed
1
acryldata/datahub-upgrade:v1.7.0.1c3db54d8fb94
spring-webmvc@7.0.8
7.0.9
1
adeptiainc/adeptia-connect-migration:5.2.98607f4f29732
spring-webmvc@6.2.15
no fix listed
1
adeptiainc/adeptia-connect-migration:4.8.1f1087da3da0b
spring-webmvc@6.2.17
no fix listed
1
alfio/alf.io:2.0-M5-26060c836a081446
spring-webmvc@6.2.18
no fix listed
1
apache/hertzbeat:1.8.075d48a62748f
spring-webflux@6.2.2
spring-webmvc@6.2.2
no fix listed
no fix listed
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
spring-webmvc@6.2.2
no fix listed
1
atlassian/bamboo:12.1.12eb98d6fbeee7
spring-webmvc@6.2.19
no fix listed
1
atlassian/bitbucket:10.2.85aed3d8cb4bc
spring-webmvc@6.2.19
no fix listed
1
atlassian/crowd:7.2.4c7c8e2423952
spring-webmvc@6.2.19
no fix listed
1
atlassian/jira-software:11.3.120850cf22b851
spring-webmvc@6.2.19
no fix listed
1
bluerange/bluerange:26.2.0503577ef9143
spring-webflux@6.2.6
spring-webmvc@6.2.6
no fix listed
no fix listed
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
spring-webmvc@6.2.11
no fix listed
1
confluentinc/cp-cmf:2.4.3c7617bf49a1b
spring-webmvc@6.2.19
no fix listed
1
epam/ai-dial-admin-backend:0.21.08b91130e3731
spring-webmvc@6.2.19
no fix listed
1
erudikaltd/scoold:1.66.0949c56b57e8f
spring-webmvc@7.0.3
7.0.9
1
fabioformosa/hello-world-api:latest063873af085c
spring-webmvc@6.2.5
no fix listed
1
folioci/edge-caiasoft:latestc3cfa89eee2f
spring-webmvc@7.0.8
7.0.9
1
folioci/edge-dematic:latest48c9b1d180d4
spring-webmvc@7.0.8
7.0.9
1
folioci/edge-inn-reach:latestc64e4d9dd3fc
spring-webmvc@7.0.8
7.0.9
1
folioci/edge-rtac:latest15ef73b1abd0
spring-webmvc@7.0.5
7.0.9
1
folioci/mod-calendar:latest22f65982efd7
spring-webmvc@7.0.8
7.0.9
1
folioci/mod-data-export:latest0cc86bf09755
spring-webmvc@7.0.3
7.0.9
1
folioci/mod-data-export-spring:latestf1d7caf4544b
spring-webmvc@7.0.3
7.0.9
1
folioci/mod-data-export-worker:latest1ad1811c9b37
spring-webmvc@7.0.3
7.0.9
1
folioci/mod-ebsconet:latest3ae8cb99daa3
spring-webmvc@7.0.3
7.0.9
1
folioci/mod-inn-reach:latestcc8584e43382
spring-webmvc@7.0.8
7.0.9
1
folioci/mod-password-validator:latestb31d75f2bf7b
spring-webmvc@7.0.8
7.0.9
1
folioci/mod-remote-storage:latest4f12177123dc
spring-webmvc@7.0.8
7.0.9
1
folioci/mod-tags:latest6e8beeb70272
spring-webmvc@7.0.8
7.0.9
1
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
spring-webmvc@7.0.8
7.0.9
1
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
spring-webflux@7.0.8
spring-webmvc@7.0.8
7.0.9
7.0.9
1
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
spring-webflux@7.0.8
spring-webmvc@7.0.8
7.0.9
7.0.9
1
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
spring-webflux@7.0.8
spring-webmvc@7.0.8
7.0.9
7.0.9
1
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
spring-webflux@7.0.8
spring-webmvc@7.0.8
7.0.9
7.0.9
1
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
spring-webflux@7.0.8
spring-webmvc@7.0.8
7.0.9
7.0.9
1
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
spring-webflux@7.0.8
spring-webmvc@7.0.8
7.0.9
7.0.9
1
glarad/mc-service-registry:latest7b02b9e7f1ef
spring-webflux@7.0.8
spring-webmvc@7.0.8
7.0.9
7.0.9
1
gotson/komga:1.27.19cf102f5fb78
spring-webflux@6.2.19
spring-webmvc@6.2.19
no fix listed
no fix listed
1
gotson/komga:1.22.0ba892ab3e082
spring-webflux@6.2.0
spring-webmvc@6.2.0
no fix listed
no fix listed
1
gotson/komga:1.28.1d8f772dce7b3
spring-webflux@6.2.19
spring-webmvc@6.2.19
no fix listed
no fix listed
1
graviteeio/am-management-api:4.12.849d0188a58ae
spring-webmvc@6.2.19
no fix listed
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
spring-webflux@6.2.15
spring-webmvc@6.2.15
no fix listed
no fix listed
1
inseefrlab/onyxia-api:v4.12.0b377aec3ead1
spring-webflux@6.2.18
spring-webmvc@6.2.18
no fix listed
no fix listed
1
kdhrubo/db2rest:lateste20610ff81b0
spring-webmvc@6.2.10
no fix listed
1

syft 1.42.1 · advisories as of 8 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.