StackRadar

CVE-2026-47892

Critical

Advisory

Published 27 Aug 2026In the index since 8 Oct 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
86
of 18,053 indexed, latest versions
Container images
97
deployed by those charts
Fix available
1 of 1
affected package

Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints

Carried by container images the latest versions of 86 of 18,053 indexed charts deploy, on 97 images.

Affected packageAffected versionsFixed inImages
spring-webfluxmaven5.2.7.RELEASE, 5.2.8.RELEASE, 5.3.1, 5.3.5+36 more7.0.997
OSV records
GHSA-9qf2-26p9-2q2q

Charts affected

86 by stars
ChartLatestAffected imagesRadar Score
eoloplanthttpd-eoloplant0.1.01 of 7See more

eoloplant httpd-eoloplant 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-webflux@6.0.2
no fix listed

Open the chart page →

36,869
prometheushuangchengwu-helm-chart0.1.01 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
apache/skywalking-ui:9.2.0295f1dc87d98
spring-webflux@5.3.19
no fix listed

Open the chart page →

18,266
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
apache/skywalking-ui:8.9.180530f0308a5
spring-webflux@5.3.7
no fix listed

Open the chart page →

22,355
eoloserverihuertas2021-vmartinp2021-helm0.1.01 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-webflux@6.0.2
no fix listed

Open the chart page →

32,409
daveit-at-mOfficialVerified publisher0.2.186 of 9See more

dave it-at-m 0.2.18

6 of the 9 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
spring-webflux@6.2.19
no fix listed
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
spring-webflux@6.2.19
no fix listed
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
spring-webflux@6.2.19
no fix listed
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
spring-webflux@6.2.19
no fix listed
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
spring-webflux@6.2.19
no fix listed
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal:10.0.0d352df1b94b6
spring-webflux@6.2.19
no fix listed

Open the chart page →

15,089
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
spring-webflux@6.2.0
no fix listed

Open the chart page →

4,095
elastictranscoderluiscajl0.46.01 of 4See more

elastictranscoder luiscajl 0.46.0

1 of the 4 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
elastictranscoder/media-storage:f6d861a026208b8c2359
spring-webflux@5.3.8
no fix listed

Open the chart page →

60,465
torznab-atomohdluiscajl0.0.31 of 1See more

torznab-atomohd luiscajl 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
lavandadelpatio/torznab-atomohd:latest214eaef5444c
spring-webflux@6.0.7
no fix listed

Open the chart page →

3,439
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
hugohg34/toposervice:0.0.2812a03b3f274
spring-webflux@5.3.13
no fix listed

Open the chart page →

34,223
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
spring-webflux@6.0.12
no fix listed

Open the chart page →

3,894
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
spring-webflux@6.0.12
no fix listed

Open the chart page →

5,286
streamsmicroslacVerified publisher0.1.01 of 6See more

streams microslac 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-webflux@6.0.11
no fix listed

Open the chart page →

21,678
mitre-siphonmitre-siphon0.2.91 of 4See more

mitre-siphon mitre-siphon 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
spring-webflux@6.0.9
no fix listed

Open the chart page →

3,241
Practica_4_helmmy-heml-appVerified publisher0.1.01 of 7See more

Practica_4_helm my-heml-app 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-webflux@6.0.2
no fix listed

Open the chart page →

32,409
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
spring-webflux@5.3.21
no fix listed

Open the chart page →

7,510
onyxiaonyxia11.8.21 of 2See more

onyxia onyxia 11.8.2

1 of the 2 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
inseefrlab/onyxia-api:v4.12.0b377aec3ead1
spring-webflux@6.2.18
no fix listed

Open the chart page →

4,944
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
spring-webflux@5.3.18
no fix listed

Open the chart page →

12,095
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
spring-webflux@6.0.2
no fix listed

Open the chart page →

30,634
Practica_4_helmpr04helm0.1.01 of 7See more

Practica_4_helm pr04helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-webflux@6.0.2
no fix listed

Open the chart page →

32,045
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
slagattollas/toposervice-practica:latestdc63973dae0d
spring-webflux@5.3.1
no fix listed

Open the chart page →

33,428
authentication-serviceredestroyder0.2.21 of 1See more

authentication-service redestroyder 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
redestroyder/authorization-service:0.0.1740364a619fd
spring-webflux@5.3.15
no fix listed

Open the chart page →

2,728
business-serviceredestroyder0.2.11 of 1See more

business-service redestroyder 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
redestroyder/business-service:0.0.1db03499a0726
spring-webflux@5.3.15
no fix listed

Open the chart page →

2,749
komgarubxkubeVerified publisher0.1.51 of 1See more

komga rubxkube 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
gotson/komga:1.28.1d8f772dce7b3
spring-webflux@6.2.19
no fix listed

Open the chart page →

24,589
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
spring-webflux@5.3.20
no fix listed

Open the chart page →

18,757
fmtok8s-frontendsalaboy0.1.31 of 1See more

fmtok8s-frontend salaboy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
spring-webflux@5.3.20
no fix listed

Open the chart page →

8,564
helm-chart-examplesalaboy0.1.01 of 1See more

helm-chart-example salaboy 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
salaboy/fmtok8s-monolith:v0.1.0f225568e6d03
spring-webflux@5.2.8.RELEASE
no fix listed

Open the chart page →

3,313
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-webflux@6.0.11
no fix listed

Open the chart page →

1,749
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
spring-webflux@5.3.20
no fix listed

Open the chart page →

9,126
retail-store-sample-ui-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-ui-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-ui:1.3.0ce3f2e935eb3
spring-webflux@6.2.10
no fix listed

Open the chart page →

1,030
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
spring-webflux@6.1.19
no fix listed

Open the chart page →

2,148
tekton-ci-environment-injectortekton-ci-environment-injectorVerified publisher0.2.41 of 1See more

tekton-ci-environment-injector tekton-ci-environment-injector 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
spring-webflux@7.0.8
7.0.9

Open the chart page →

694
tekton-stash-and-cachetekton-stash-and-cacheVerified publisher0.2.21 of 1See more

tekton-stash-and-cache tekton-stash-and-cache 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
spring-webflux@7.0.8
7.0.9

Open the chart page →

1,590
ten-percentten-percent0.1.01 of 1See more

ten-percent ten-percent 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
ephraimglick/ten-percent:latestba4cce835974
spring-webflux@5.3.5
no fix listed

Open the chart page →

3,664
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-webflux@5.3.15
no fix listed

Open the chart page →

15,236
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-webflux@5.3.15
no fix listed

Open the chart page →

30,326
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-webflux@5.3.25
no fix listed

Open the chart page →

6,101

Container images carrying it

97 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
inseefrlab/onyxia-api:v4.12.0b377aec3ead1
spring-webflux@6.2.18
no fix listed
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
spring-webflux@6.0.7
no fix listed
1
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
spring-webflux@5.3.18
no fix listed
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
spring-webflux@6.0.12
no fix listed
1
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
spring-webflux@6.0.12
no fix listed
1
openaev/platform:3.261005.0eaf26c4106a1
spring-webflux@6.2.19
no fix listed
1
openbas/platform:2.0.5d986d80b0a75
spring-webflux@6.1.16
no fix listed
1
platform9community/admin-server:latestde3fa9b70df1
spring-webflux@5.2.7.RELEASE
no fix listed
1
platform9community/api-gateway:latest40a4970de568
spring-webflux@5.2.7.RELEASE
no fix listed
1
redestroyder/authorization-service:0.0.1740364a619fd
spring-webflux@5.3.15
no fix listed
1
redestroyder/business-service:0.0.1db03499a0726
spring-webflux@5.3.15
no fix listed
1
rm3l/dev-feed-api:latest896635ecc91f
spring-webflux@5.3.23
no fix listed
1
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
spring-webflux@5.3.13
no fix listed
1
salaboy/fmtok8s-monolith:v0.1.0f225568e6d03
spring-webflux@5.2.8.RELEASE
no fix listed
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
spring-webflux@5.3.13
no fix listed
1
slagattollas/toposervice-practica:latestdc63973dae0d
spring-webflux@5.3.1
no fix listed
1
streamnative/private-cloud-console:v2.3.27-all91e54375e154
spring-webflux@6.1.19
no fix listed
1
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
spring-webflux@6.2.19
no fix listed
1
thingsboard/tbmq-node:2.4.070661025dba5
spring-webflux@6.2.19
no fix listed
1
thingsboard/tb-postgres:latest2d17e4e36edc
spring-webflux@6.2.11
no fix listed
1
treskon/portrait:DEV-latest88e813f22347
spring-webflux@6.1.15
no fix listed
1
vitalii1992/api-gateway-service:latestaabe6ac39356
spring-webflux@6.0.9
no fix listed
1
vlebediantsev/logic-ms:latestdf8bf38c535b
spring-webflux@5.3.21
no fix listed
1
vrijbrp/haal-centraal-brp-bevragen:develop5c770c2ae48c
spring-webflux@5.3.27
no fix listed
1
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-webflux@5.3.25
no fix listed
1
zbalogh/reservation-api-server:1.0.97c247e399a1f
spring-webflux@5.3.23
no fix listed
1
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
spring-webflux@6.0.9
no fix listed
1
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
spring-webflux@7.0.6
7.0.9
1
ghcr.io/gla-rad/enav-aton-admin-service:latest8b963221a007
spring-webflux@7.0.7
7.0.9
1
ghcr.io/gla-rad/enav-aton-service:latest3ffe10cd9cef
spring-webflux@7.0.7
7.0.9
1
ghcr.io/gla-rad/enav-eureka:latest05002092c621
spring-webflux@7.0.6
7.0.9
1
ghcr.io/gla-rad/enav-msg-broker:latest5c0966fa0257
spring-webflux@7.0.6
7.0.9
1
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
spring-webflux@6.2.19
no fix listed
1
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
spring-webflux@6.2.19
no fix listed
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
spring-webflux@6.2.19
no fix listed
1
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
spring-webflux@6.2.19
no fix listed
1
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
spring-webflux@6.2.19
no fix listed
1
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal:10.0.0d352df1b94b6
spring-webflux@6.2.19
no fix listed
1
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-webflux@6.2.3
no fix listed
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
spring-webflux@6.1.1
no fix listed
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
spring-webflux@5.3.24
no fix listed
1
ghcr.io/thm-mni-ii/fbs-core:v2.0.734fd2032724c
spring-webflux@5.3.27
no fix listed
1
public.ecr.aws/aws-containers/retail-store-sample-ui:1.3.0ce3f2e935eb3
spring-webflux@6.2.10
no fix listed
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
spring-webflux@5.3.24
no fix listed
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
spring-webflux@6.0.11
no fix listed
1
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
spring-webflux@7.0.8
7.0.9
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
spring-webflux@7.0.8
7.0.9
1

syft 1.42.1 · advisories as of 8 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.