StackRadar

CVE-2026-50645

High

Advisory

Published 12 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
39
of 17,781 indexed, latest versions
Container images
36
deployed by those charts
Fix available
1 of 1
affected package

Apache cxf-core: No restriction on attachment headers per message

Carried by container images the latest versions of 39 of 17,781 indexed charts deploy, on 36 images.

Affected packageAffected versionsFixed inImages
cxf-coremaven3.0.3, 3.0.12, 3.1.11, 3.2.2+21 more3.6.12, 4.1.736
OSV records
GHSA-ghvc-7hp8-2g2v

Charts affected

39 by stars
ChartLatestAffected imagesRadar Score
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
cxf-core@3.4.5
3.6.12

Open the chart page →

7,713
openhabhelmforgeVerified publisher1.2.01 of 1See more

openhab helmforge 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
openhab/openhab:5.2.1bfd4a60e90da
cxf-core@3.6.10
3.6.12

Open the chart page →

3,641
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.10.0c8f3ebd2a934
cxf-core@4.0.2
4.1.7

Open the chart page →

10,530
oesopsmxVerified publisher4.0.322 of 25See more

oes opsmx 4.0.32

2 of the 25 container images this version deploys carry CVE-2026-50645.

Open the chart page →

107,811
paperless-ngxadnoctemVerified publisher0.4.21 of 5See more

paperless-ngx adnoctem 0.4.2

1 of the 5 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
apache/tika:2.9.0.092d055a84e9e
cxf-core@3.5.6
3.6.12

Open the chart page →

19,691
tikaapache-tika3.2.21 of 1See more

tika apache-tika 3.2.2

1 of the 1 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
apache/tika:3.2.2.0-fullffab324253ed
cxf-core@4.0.8
4.1.7

Open the chart page →

437
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
cxf-core@3.4.0
3.6.12

Open the chart page →

10,730
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
cxf-core@3.5.5
3.6.12

Open the chart page →

13,479
signserver-cesignserverOfficialVerified publisher2.3.51 of 1See more

signserver-ce signserver 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.3.2798fbbe00283
cxf-core@4.0.6
4.1.7

Open the chart page →

2,406
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
cxf-core@3.4.5
3.6.12

Open the chart page →

7,713
airsonic-advancedairsonic-advancedVerified publisher0.3.11 of 1See more

airsonic-advanced airsonic-advanced 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
cxf-core@4.0.5
4.1.7

Open the chart page →

1,748
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
cxf-core@3.4.5
3.6.12

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
cxf-core@3.4.5
3.6.12

Open the chart page →

16,975
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
cxf-core@3.4.0
3.6.12

Open the chart page →

8,866
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
cxf-core@3.4.5
3.6.12

Open the chart page →

13,352
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
cxf-core@3.4.0
3.6.12

Open the chart page →

5,806
opensearch-singlenodecaptnbpVerified publisher1.0.91 of 2See more

opensearch-singlenode captnbp 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.15.01963b3ece46d
cxf-core@4.0.4
4.1.7

Open the chart page →

1,073
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
cxf-core@4.1.1
4.1.7

Open the chart page →

4,578
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
cxf-core@3.4.3
3.6.12

Open the chart page →

18,230
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
cxf-core@3.3.6
3.6.12

Open the chart page →

19,215
openhabgeek-cookbookVerified publisher1.5.21 of 1See more

openhab geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
openhab/openhab:3.2.0d0aa4af452c1
cxf-core@3.4.5
3.6.12

Open the chart page →

2,887
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
cxf-core@3.2.6
3.6.12

Open the chart page →

27,949
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
cxf-core@3.0.12
3.6.12

Open the chart page →

34,754
paperlesshpVerified publisher0.1.11 of 5See more

paperless hp 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
apache/tika:3.3.1.090b7fa1dc018
cxf-core@4.0.11
4.1.7

Open the chart page →

26,612
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
cxf-core@3.2.2
3.6.12

Open the chart page →

39,349
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
cxf-core@3.1.11
3.6.12
ibmcom/microclimate-theia:lateste17bdccc5030
cxf-core@3.1.11
3.6.12

Open the chart page →

57,669
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
cxf-core@3.5.8
3.6.12

Open the chart page →

45,239
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
cxf-core@3.2.2
3.6.12

Open the chart page →

7,929
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
cxf-core@3.4.4
3.6.12

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
cxf-core@3.4.4
3.6.12

Open the chart page →

10,603
sentinelopennms-helm-chartsVerified publisher0.4.01 of 2See more

sentinel opennms-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.288869082a14f
cxf-core@3.6.11
3.6.12

Open the chart page →

2,024
dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
cxf-core@4.0.3
4.1.7

Open the chart page →

1,190
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
cxf-core@4.0.4
4.1.7

Open the chart page →

1,753
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
cxf-core@3.0.3
3.6.12

Open the chart page →

6,907
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
cxf-core@4.0.11
4.1.7

Open the chart page →

1,825
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
cxf-core@3.5.8
3.6.12

Open the chart page →

45,239
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
cxf-core@3.3.10
3.6.12

Open the chart page →

28,605
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
cxf-core@3.4.0
3.6.12

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2026-50645.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
cxf-core@3.3.7
3.6.12

Open the chart page →

6,213

Container images carrying it

36 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
cxf-core@3.4.0
3.6.12
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
cxf-core@3.5.8
3.6.12
2
opensearchproject/opensearch:2.1.04254021a8c71
cxf-core@3.4.5
3.6.12
2
opensearchproject/opensearch:1.1.0967d7f57f72f
cxf-core@3.4.4
3.6.12
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
cxf-core@3.4.5
3.6.12
2
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
cxf-core@3.4.3
3.6.12
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
cxf-core@3.2.2
3.6.12
1
apache/tika:3.3.1.090b7fa1dc018
cxf-core@4.0.11
4.1.7
1
apache/tika:2.9.0.092d055a84e9e
cxf-core@3.5.6
3.6.12
1
apache/tika:3.2.2.0-fullffab324253ed
cxf-core@4.0.8
4.1.7
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
cxf-core@3.4.0
3.6.12
1
assistiot/identity-manager_kc:latest0df4b4fa899a
cxf-core@3.4.5
3.6.12
1
castlemock/castlemock:latestb7f3f1527ba9
cxf-core@4.1.1
4.1.7
1
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
cxf-core@3.4.0
3.6.12
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
cxf-core@3.2.2
3.6.12
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
cxf-core@3.1.11
3.6.12
1
ibmcom/microclimate-theia:lateste17bdccc5030
cxf-core@3.1.11
3.6.12
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
cxf-core@3.0.12
3.6.12
1
keyfactor/signserver-ce:7.3.2798fbbe00283
cxf-core@4.0.6
4.1.7
1
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
cxf-core@4.0.5
4.1.7
1
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
cxf-core@3.5.5
3.6.12
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
cxf-core@3.3.7
3.6.12
1
openhab/openhab:5.2.1bfd4a60e90da
cxf-core@3.6.10
3.6.12
1
openhab/openhab:3.2.0d0aa4af452c1
cxf-core@3.4.5
3.6.12
1
openkm/openkm-ce:6.3.113bc465a7461b
cxf-core@3.2.6
3.6.12
1
opennms/sentinel:36.0.288869082a14f
cxf-core@3.6.11
3.6.12
1
opensearchproject/opensearch:2.15.01963b3ece46d
cxf-core@4.0.4
4.1.7
1
opensearchproject/opensearch:2.14.0466a49f379bb
cxf-core@4.0.4
4.1.7
1
opensearchproject/opensearch:2.12.0645d3d9390ad
cxf-core@4.0.3
4.1.7
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
cxf-core@4.0.2
4.1.7
1
xetusoss/archiva:v2.2.588f25242b9ee
cxf-core@3.0.3
3.6.12
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
cxf-core@4.0.11
4.1.7
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
cxf-core@3.3.6
3.6.12
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
cxf-core@3.3.10
3.6.12
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
cxf-core@4.0.3
4.1.7
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
cxf-core@4.0.3
4.1.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.