StackRadar

CVE-2026-47892

Critical

Advisory

Published 27 Aug 2026In the index since 8 Oct 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
86
of 18,053 indexed, latest versions
Container images
97
deployed by those charts
Fix available
1 of 1
affected package

Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints

Carried by container images the latest versions of 86 of 18,053 indexed charts deploy, on 97 images.

Affected packageAffected versionsFixed inImages
spring-webfluxmaven5.2.7.RELEASE, 5.2.8.RELEASE, 5.3.1, 5.3.5+36 more7.0.997
OSV records
GHSA-9qf2-26p9-2q2q

Charts affected

86 by stars
ChartLatestAffected imagesRadar Score
eoloplanthttpd-eoloplant0.1.01 of 7See more

eoloplant httpd-eoloplant 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-webflux@6.0.2
no fix listed

Open the chart page →

36,869
prometheushuangchengwu-helm-chart0.1.01 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
apache/skywalking-ui:9.2.0295f1dc87d98
spring-webflux@5.3.19
no fix listed

Open the chart page →

18,266
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
apache/skywalking-ui:8.9.180530f0308a5
spring-webflux@5.3.7
no fix listed

Open the chart page →

22,355
eoloserverihuertas2021-vmartinp2021-helm0.1.01 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-webflux@6.0.2
no fix listed

Open the chart page →

32,409
daveit-at-mOfficialVerified publisher0.2.186 of 9See more

dave it-at-m 0.2.18

6 of the 9 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
spring-webflux@6.2.19
no fix listed
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
spring-webflux@6.2.19
no fix listed
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
spring-webflux@6.2.19
no fix listed
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
spring-webflux@6.2.19
no fix listed
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
spring-webflux@6.2.19
no fix listed
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal:10.0.0d352df1b94b6
spring-webflux@6.2.19
no fix listed

Open the chart page →

15,089
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
spring-webflux@6.2.0
no fix listed

Open the chart page →

4,095
elastictranscoderluiscajl0.46.01 of 4See more

elastictranscoder luiscajl 0.46.0

1 of the 4 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
elastictranscoder/media-storage:f6d861a026208b8c2359
spring-webflux@5.3.8
no fix listed

Open the chart page →

60,465
torznab-atomohdluiscajl0.0.31 of 1See more

torznab-atomohd luiscajl 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
lavandadelpatio/torznab-atomohd:latest214eaef5444c
spring-webflux@6.0.7
no fix listed

Open the chart page →

3,439
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
hugohg34/toposervice:0.0.2812a03b3f274
spring-webflux@5.3.13
no fix listed

Open the chart page →

34,223
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
spring-webflux@6.0.12
no fix listed

Open the chart page →

3,894
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
spring-webflux@6.0.12
no fix listed

Open the chart page →

5,286
streamsmicroslacVerified publisher0.1.01 of 6See more

streams microslac 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-webflux@6.0.11
no fix listed

Open the chart page →

21,678
mitre-siphonmitre-siphon0.2.91 of 4See more

mitre-siphon mitre-siphon 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
spring-webflux@6.0.9
no fix listed

Open the chart page →

3,241
Practica_4_helmmy-heml-appVerified publisher0.1.01 of 7See more

Practica_4_helm my-heml-app 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-webflux@6.0.2
no fix listed

Open the chart page →

32,409
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
spring-webflux@5.3.21
no fix listed

Open the chart page →

7,510
onyxiaonyxia11.8.21 of 2See more

onyxia onyxia 11.8.2

1 of the 2 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
inseefrlab/onyxia-api:v4.12.0b377aec3ead1
spring-webflux@6.2.18
no fix listed

Open the chart page →

4,944
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
spring-webflux@5.3.18
no fix listed

Open the chart page →

12,095
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
spring-webflux@6.0.2
no fix listed

Open the chart page →

30,634
Practica_4_helmpr04helm0.1.01 of 7See more

Practica_4_helm pr04helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-webflux@6.0.2
no fix listed

Open the chart page →

32,045
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
slagattollas/toposervice-practica:latestdc63973dae0d
spring-webflux@5.3.1
no fix listed

Open the chart page →

33,428
authentication-serviceredestroyder0.2.21 of 1See more

authentication-service redestroyder 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
redestroyder/authorization-service:0.0.1740364a619fd
spring-webflux@5.3.15
no fix listed

Open the chart page →

2,728
business-serviceredestroyder0.2.11 of 1See more

business-service redestroyder 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
redestroyder/business-service:0.0.1db03499a0726
spring-webflux@5.3.15
no fix listed

Open the chart page →

2,749
komgarubxkubeVerified publisher0.1.51 of 1See more

komga rubxkube 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
gotson/komga:1.28.1d8f772dce7b3
spring-webflux@6.2.19
no fix listed

Open the chart page →

24,589
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
spring-webflux@5.3.20
no fix listed

Open the chart page →

18,757
fmtok8s-frontendsalaboy0.1.31 of 1See more

fmtok8s-frontend salaboy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
spring-webflux@5.3.20
no fix listed

Open the chart page →

8,564
helm-chart-examplesalaboy0.1.01 of 1See more

helm-chart-example salaboy 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
salaboy/fmtok8s-monolith:v0.1.0f225568e6d03
spring-webflux@5.2.8.RELEASE
no fix listed

Open the chart page →

3,313
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-webflux@6.0.11
no fix listed

Open the chart page →

1,749
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
spring-webflux@5.3.20
no fix listed

Open the chart page →

9,126
retail-store-sample-ui-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-ui-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-ui:1.3.0ce3f2e935eb3
spring-webflux@6.2.10
no fix listed

Open the chart page →

1,030
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
spring-webflux@6.1.19
no fix listed

Open the chart page →

2,148
tekton-ci-environment-injectortekton-ci-environment-injectorVerified publisher0.2.41 of 1See more

tekton-ci-environment-injector tekton-ci-environment-injector 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
spring-webflux@7.0.8
7.0.9

Open the chart page →

694
tekton-stash-and-cachetekton-stash-and-cacheVerified publisher0.2.21 of 1See more

tekton-stash-and-cache tekton-stash-and-cache 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
spring-webflux@7.0.8
7.0.9

Open the chart page →

1,590
ten-percentten-percent0.1.01 of 1See more

ten-percent ten-percent 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
ephraimglick/ten-percent:latestba4cce835974
spring-webflux@5.3.5
no fix listed

Open the chart page →

3,664
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-webflux@5.3.15
no fix listed

Open the chart page →

15,236
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-webflux@5.3.15
no fix listed

Open the chart page →

30,326
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-47892.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-webflux@5.3.25
no fix listed

Open the chart page →

6,101

Container images carrying it

97 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
spring-webflux@6.0.2
no fix listed
13
oscarsotosanchez/toposervice:v1.0d4d020e9f272
spring-webflux@5.3.1
no fix listed
4
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-webflux@6.0.11
no fix listed
4
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
spring-webflux@5.2.8.RELEASE
no fix listed
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
spring-webflux@5.2.8.RELEASE
no fix listed
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
spring-webflux@5.2.8.RELEASE
no fix listed
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
spring-webflux@5.2.8.RELEASE
no fix listed
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
spring-webflux@5.2.8.RELEASE
no fix listed
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
spring-webflux@5.2.8.RELEASE
no fix listed
2
hookiesolutions/webhookie:latest0629694246ba
spring-webflux@5.3.15
no fix listed
2
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
spring-webflux@5.3.13
no fix listed
2
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
spring-webflux@5.3.13
no fix listed
2
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
spring-webflux@5.3.13
no fix listed
2
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
spring-webflux@5.3.13
no fix listed
2
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
spring-webflux@5.3.13
no fix listed
2
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
spring-webflux@5.3.13
no fix listed
2
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
spring-webflux@5.3.13
no fix listed
2
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
spring-webflux@5.3.13
no fix listed
2
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
spring-webflux@5.3.13
no fix listed
2
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
spring-webflux@6.2.17
no fix listed
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
spring-webflux@5.3.20
no fix listed
2
apache/hertzbeat:1.8.075d48a62748f
spring-webflux@6.2.2
no fix listed
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
spring-webflux@5.3.20
no fix listed
1
apache/skywalking-ui:9.2.0295f1dc87d98
spring-webflux@5.3.19
no fix listed
1
apache/skywalking-ui:8.9.180530f0308a5
spring-webflux@5.3.7
no fix listed
1
apimap/api:v1.8.11ae2b3ab00177
spring-webflux@5.3.23
no fix listed
1
bluerange/bluerange:26.2.0503577ef9143
spring-webflux@6.2.6
no fix listed
1
camunda/zeebe:8.4.5ab5abc09e407
spring-webflux@6.1.4
no fix listed
1
elastictranscoder/media-storage:f6d861a026208b8c2359
spring-webflux@5.3.8
no fix listed
1
ephraimglick/ten-percent:latestba4cce835974
spring-webflux@5.3.5
no fix listed
1
expediagroup/pitchfork:1.314f2cf61e7de9
spring-webflux@5.3.10
no fix listed
1
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
spring-webflux@5.2.8.RELEASE
no fix listed
1
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
spring-webflux@7.0.8
7.0.9
1
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
spring-webflux@7.0.8
7.0.9
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
spring-webflux@5.2.8.RELEASE
no fix listed
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
spring-webflux@5.2.8.RELEASE
no fix listed
1
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
spring-webflux@7.0.8
7.0.9
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
spring-webflux@5.2.8.RELEASE
no fix listed
1
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
spring-webflux@7.0.8
7.0.9
1
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
spring-webflux@7.0.8
7.0.9
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
spring-webflux@5.2.8.RELEASE
no fix listed
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
spring-webflux@5.2.8.RELEASE
no fix listed
1
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
spring-webflux@7.0.8
7.0.9
1
glarad/mc-service-registry:latest7b02b9e7f1ef
spring-webflux@7.0.8
7.0.9
1
gotson/komga:1.27.19cf102f5fb78
spring-webflux@6.2.19
no fix listed
1
gotson/komga:1.22.0ba892ab3e082
spring-webflux@6.2.0
no fix listed
1
gotson/komga:1.28.1d8f772dce7b3
spring-webflux@6.2.19
no fix listed
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
spring-webflux@6.2.15
no fix listed
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
spring-webflux@5.3.18
no fix listed
1
hugohg34/toposervice:0.0.2812a03b3f274
spring-webflux@5.3.13
no fix listed
1

syft 1.42.1 · advisories as of 8 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.