StackRadar

CVE-2026-49268

High

Advisory

Published 17 Jun 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
35
of 17,781 indexed, latest versions
Container images
29
deployed by those charts
Fix available
1 of 1
affected package

Apache Shiro: LDAP DN Injection in DefaultLdapRealm

Carried by container images the latest versions of 35 of 17,781 indexed charts deploy, on 29 images.

Affected packageAffected versionsFixed inImages
shiro-coremaven1.2.3, 1.2.6, 1.4.0, 1.6.0+12 more2.2.129
OSV records
GHSA-x96m-rh44-vgv8

Charts affected

35 by stars
ChartLatestAffected imagesRadar Score
neo4jneo4j-helm4.3.2-11 of 1See more

neo4j neo4j-helm 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
shiro-core@1.7.1
2.2.1

Open the chart page →

2,640
grayloggroundhog2k0.13.101 of 1See more

graylog groundhog2k 0.13.10

1 of the 1 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
graylog/graylog:7.1.9598bd41fefd5
shiro-core@2.1.0
2.2.1

Open the chart page →

1,074
grayloggraylog2OfficialVerified publisher2.0.01 of 2See more

graylog graylog2 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
graylog/graylog-enterprise:7.1.88a1f641cd7aa
shiro-core@2.1.0
2.2.1

Open the chart page →

1,500
nexus-iq-serversonatypeVerified publisher207.1.01 of 1See more

nexus-iq-server sonatype 207.1.0

1 of the 1 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
sonatype/nexus-iq-server:1.207.1a70014ed10b1
shiro-core@2.2.0
2.2.1

Open the chart page →

38
thehivestrangebee-helmOfficialVerified publisher1.0.61 of 7See more

thehive strangebee-helm 1.0.6

1 of the 7 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
strangebee/thehive:5.7.6-1e77b713124dd
shiro-core@1.13.0
2.2.1

Open the chart page →

16,210
infrahubinfrahubVerified publisher4.33.21 of 5See more

infrahub infrahub 4.33.2

1 of the 5 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
library/neo4j:2026.05.06c162e2432f8
shiro-core@2.1.0
2.2.1

Open the chart page →

10,428
scm-managerscm-manager3.12.11 of 1See more

scm-manager scm-manager 3.12.1

1 of the 1 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
scmmanager/scm-manager:3.12.1bfb766050f34
shiro-core@1.13.0
2.2.1

Open the chart page →

649
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.19.21 of 5See more

infrahub-enterprise infrahub-enterprise 4.19.2

1 of the 5 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
library/neo4j:2026.05.0-enterprise2caf944aa4a5
shiro-core@2.1.0
2.2.1

Open the chart page →

10,530
neo4j-communityequinor-charts1.2.51 of 1See more

neo4j-community equinor-charts 1.2.5

1 of the 1 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
library/neo4j:4.2.4348e3f56faa2
shiro-core@1.7.1
2.2.1

Open the chart page →

2,751
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
shiro-core@1.4.0
2.2.1

Open the chart page →

11,553
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
library/neo4j:2026.02.25ab4ab0358cf
shiro-core@2.0.6
2.2.1

Open the chart page →

8,158
nexus-iq-server-hasonatypeVerified publisher207.1.01 of 2See more

nexus-iq-server-ha sonatype 207.1.0

1 of the 2 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
sonatype/nexus-iq-server:1.207.1a70014ed10b1
shiro-core@2.2.0
2.2.1

Open the chart page →

38
graylogt3n1.0.01 of 3See more

graylog t3n 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
graylog2/server:2.4.3-38ff28c66e6c1
shiro-core@1.4.0
2.2.1

Open the chart page →

8,063
zunivers-ninjaalexpressoVerified publisher1.31.21 of 2See more

zunivers-ninja alexpresso 1.31.2

1 of the 2 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
library/neo4j:5.18.18f01f7bb053e
shiro-core@1.13.0
2.2.1

Open the chart page →

1,165
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
shiro-core@1.4.0
2.2.1

Open the chart page →

11,553
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
shiro-core@1.9.1
2.2.1

Open the chart page →

9,722
cassandra-reapercloudnativeapp0.2.01 of 1See more

cassandra-reaper cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
thelastpickle/cassandra-reaper:1.3.09c53996c457d
shiro-core@1.2.3
2.2.1

Open the chart page →

5,078
neo4jcloudnativeapp1.0.01 of 1See more

neo4j cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
library/neo4j:3.4.5-enterprisea1ba477fa412
shiro-core@1.4.0
2.2.1

Open the chart page →

2,837
shenyuerdeng2.4.211 of 2See more

shenyu erdeng 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
shiro-core@1.7.0
2.2.1

Open the chart page →

12,513
my-chartfleet-web-app0.1.01 of 6See more

my-chart fleet-web-app 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
shiro-core@1.10.1
2.2.1

Open the chart page →

24,296
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
graylog/graylog:6.1.1019de1aff48c2
shiro-core@2.0.1
2.2.1

Open the chart page →

5,261
jenainseefrlab3.1.01 of 1See more

jena inseefrlab 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
stain/jena-fuseki:latestb1d0c96f19ad
shiro-core@2.0.1
2.2.1

Open the chart page →

1,262
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
shiro-core@1.6.0
2.2.1

Open the chart page →

12,856
shinsei-managerjtektVerified publisher0.2.01 of 8See more

shinsei-manager jtekt 0.2.0

1 of the 8 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
shiro-core@2.0.0
2.2.1

Open the chart page →

63,461
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
ladeit/ladeit:latest962b665ffe82
shiro-core@1.4.0
2.2.1

Open the chart page →

26,356
activemqmicroboxlabs3.8.01 of 1See more

activemq microboxlabs 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
shiro-core@1.13.0
2.2.1

Open the chart page →

1,494
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
shiro-core@1.2.6
2.2.1

Open the chart page →

43,341
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
shiro-core@2.0.0
2.2.1

Open the chart page →

30,363
neo4jneo4j-helm-old4.3.2-11 of 1See more

neo4j neo4j-helm-old 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
shiro-core@1.7.1
2.2.1

Open the chart page →

2,640
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
shiro-core@1.13.0
2.2.1

Open the chart page →

6,037
apache-knox-helmpfisterer-knox0.1.111 of 1See more

apache-knox-helm pfisterer-knox 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
farberg/apache-knox-docker:1.6.14b4a22487394
shiro-core@1.7.0
2.2.1

Open the chart page →

6,237
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.5.1e2be712fc4f4
shiro-core@1.8.0
2.2.1

Open the chart page →

8,804
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
shiro-core@1.7.0
2.2.1

Open the chart page →

12,513
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
shiro-core@1.10.0
2.2.1

Open the chart page →

4,946
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-49268.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
shiro-core@1.7.0
2.2.1

Open the chart page →

12,513

Container images carrying it

29 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/shenyu-admin:2.4.2e8b7c4ddd069
shiro-core@1.7.0
2.2.1
3
library/neo4j:5.20.052d3dec8d455
shiro-core@2.0.0
2.2.1
2
library/neo4j:4.3.2-enterprise56a9453c4064
shiro-core@1.7.1
2.2.1
2
mbentley/omada-controller:4.3f4e682274bed
shiro-core@1.4.0
2.2.1
2
sonatype/nexus-iq-server:1.207.1a70014ed10b1
shiro-core@2.2.0
2.2.1
2
1dev/server:11.9.0cd5b12fe5471
shiro-core@1.13.0
2.2.1
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
shiro-core@1.13.0
2.2.1
1
apache/shenyu-admin:2.5.1e2be712fc4f4
shiro-core@1.8.0
2.2.1
1
farberg/apache-knox-docker:1.6.14b4a22487394
shiro-core@1.7.0
2.2.1
1
graylog2/server:2.4.3-38ff28c66e6c1
shiro-core@1.4.0
2.2.1
1
graylog/graylog:6.1.1019de1aff48c2
shiro-core@2.0.1
2.2.1
1
graylog/graylog:7.1.9598bd41fefd5
shiro-core@2.1.0
2.2.1
1
graylog/graylog-enterprise:7.1.88a1f641cd7aa
shiro-core@2.1.0
2.2.1
1
ladeit/ladeit:latest962b665ffe82
shiro-core@1.4.0
2.2.1
1
library/neo4j:2026.05.0-enterprise2caf944aa4a5
shiro-core@2.1.0
2.2.1
1
library/neo4j:4.2.4348e3f56faa2
shiro-core@1.7.1
2.2.1
1
library/neo4j:2026.02.25ab4ab0358cf
shiro-core@2.0.6
2.2.1
1
library/neo4j:2026.05.06c162e2432f8
shiro-core@2.1.0
2.2.1
1
library/neo4j:5.18.18f01f7bb053e
shiro-core@1.13.0
2.2.1
1
library/neo4j:3.4.5-enterprisea1ba477fa412
shiro-core@1.4.0
2.2.1
1
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
shiro-core@1.2.6
2.2.1
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
shiro-core@1.9.1
2.2.1
1
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
shiro-core@1.10.1
2.2.1
1
scmmanager/scm-manager:3.12.1bfb766050f34
shiro-core@1.13.0
2.2.1
1
sonatype/nexus3:3.58.1586060431b64
shiro-core@1.10.0
2.2.1
1
stain/jena-fuseki:latestb1d0c96f19ad
shiro-core@2.0.1
2.2.1
1
strangebee/thehive:5.7.6-1e77b713124dd
shiro-core@1.13.0
2.2.1
1
thelastpickle/cassandra-reaper:1.3.09c53996c457d
shiro-core@1.2.3
2.2.1
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
shiro-core@1.6.0
2.2.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.