StackRadar

CVE-2026-53572

Medium

Advisory

Published 7 Jul 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
15
deployed by those charts
Fix available
1 of 1
affected package

KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
github.com/kedacore/keda/v2golangv2.16.0, v2.17.0, v2.17.2, v2.17.3+1 more2.20.015
OSV records
GHSA-6w3m-4hhp-775q
Also known as
GO-2026-5940

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
inference-manager-engineinference-manager-engine1.46.01 of 1See more

inference-manager-engine inference-manager-engine 1.46.0

1 of the 1 container images this version deploys carry CVE-2026-53572.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/inference-manager-engine:1.46.0c46f109c3d0b
github.com/kedacore/keda/v2@v2.17.3
2.20.0

Open the chart page →

259
seldon-core-operatorseldon1.19.01 of 1See more

seldon-core-operator seldon 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-53572.

Container imageDigestPackageFixed in
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
github.com/kedacore/keda/v2@v2.17.3
2.20.0

Open the chart page →

841
kedaarieotechVerified publisher0.1.02 of 3See more

keda arieotech 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-53572.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.16.002348a19aeae
github.com/kedacore/keda/v2@v2.16.0
2.20.0
ghcr.io/kedacore/keda-metrics-apiserver:2.16.073a2ebae4413
github.com/kedacore/keda/v2@v2.16.0
2.20.0

Open the chart page →

2,276
keda-add-ons-httpkedacore0.15.03 of 3See more

keda-add-ons-http kedacore 0.15.0

3 of the 3 container images this version deploys carry CVE-2026-53572.

Container imageDigestPackageFixed in
ghcr.io/kedacore/http-add-on-interceptor:0.15.04e88e7808652
github.com/kedacore/keda/v2@v2.18.3
2.20.0
ghcr.io/kedacore/http-add-on-operator:0.15.0d579b952ff0a
github.com/kedacore/keda/v2@v2.18.3
2.20.0
ghcr.io/kedacore/http-add-on-scaler:0.15.0f748178bc4af
github.com/kedacore/keda/v2@v2.18.3
2.20.0

Open the chart page →

410
go-kube-downscalerpy-kube-downscalerVerified publisher1.3.41 of 1See more

go-kube-downscaler py-kube-downscaler 1.3.4

1 of the 1 container images this version deploys carry CVE-2026-53572.

Container imageDigestPackageFixed in
ghcr.io/caas-team/gokubedownscaler:1.3.4cea3dd2f1312
github.com/kedacore/keda/v2@v2.18.3
2.20.0

Open the chart page →

220
llmarinerllmariner1.53.11 of 21See more

llmariner llmariner 1.53.1

1 of the 21 container images this version deploys carry CVE-2026-53572.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/inference-manager-engine:1.46.0c46f109c3d0b
github.com/kedacore/keda/v2@v2.17.3
2.20.0

Open the chart page →

12,036
onyx-stackonyx0.3.13 of 12See more

onyx-stack onyx 0.3.1

3 of the 12 container images this version deploys carry CVE-2026-53572.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.17.272dc058e478d
github.com/kedacore/keda/v2@v2.17.2
2.20.0
ghcr.io/kedacore/keda-admission-webhooks:2.17.2c8227c6edb4d
github.com/kedacore/keda/v2@v2.17.2
2.20.0
ghcr.io/kedacore/keda-metrics-apiserver:2.17.2f312f50ddc57
github.com/kedacore/keda/v2@v2.17.2
2.20.0

Open the chart page →

6,338
otel-add-onotel-add-onVerified publisher0.1.41 of 1See more

otel-add-on otel-add-on 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-53572.

Container imageDigestPackageFixed in
ghcr.io/kedify/otel-add-on:v0.1.4a6f2155bd822
github.com/kedacore/keda/v2@v2.17.3
2.20.0

Open the chart page →

725
kedasoftonic2.17.03 of 3See more

keda softonic 2.17.0

3 of the 3 container images this version deploys carry CVE-2026-53572.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.17.0112fc427d933
github.com/kedacore/keda/v2@v2.17.0
2.20.0
ghcr.io/kedacore/keda-admission-webhooks:2.17.0a87c42275757
github.com/kedacore/keda/v2@v2.17.0
2.20.0
ghcr.io/kedacore/keda-metrics-apiserver:2.17.0167fd532bd43
github.com/kedacore/keda/v2@v2.17.0
2.20.0

Open the chart page →

2,583

Container images carrying it

15 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/cloudnatix/llmariner/inference-manager-engine:1.46.0c46f109c3d0b
github.com/kedacore/keda/v2@v2.17.3
2.20.0
2
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
github.com/kedacore/keda/v2@v2.17.3
2.20.0
1
ghcr.io/caas-team/gokubedownscaler:1.3.4cea3dd2f1312
github.com/kedacore/keda/v2@v2.18.3
2.20.0
1
ghcr.io/kedacore/http-add-on-interceptor:0.15.04e88e7808652
github.com/kedacore/keda/v2@v2.18.3
2.20.0
1
ghcr.io/kedacore/http-add-on-operator:0.15.0d579b952ff0a
github.com/kedacore/keda/v2@v2.18.3
2.20.0
1
ghcr.io/kedacore/http-add-on-scaler:0.15.0f748178bc4af
github.com/kedacore/keda/v2@v2.18.3
2.20.0
1
ghcr.io/kedacore/keda:2.16.002348a19aeae
github.com/kedacore/keda/v2@v2.16.0
2.20.0
1
ghcr.io/kedacore/keda:2.17.0112fc427d933
github.com/kedacore/keda/v2@v2.17.0
2.20.0
1
ghcr.io/kedacore/keda:2.17.272dc058e478d
github.com/kedacore/keda/v2@v2.17.2
2.20.0
1
ghcr.io/kedacore/keda-admission-webhooks:2.17.0a87c42275757
github.com/kedacore/keda/v2@v2.17.0
2.20.0
1
ghcr.io/kedacore/keda-admission-webhooks:2.17.2c8227c6edb4d
github.com/kedacore/keda/v2@v2.17.2
2.20.0
1
ghcr.io/kedacore/keda-metrics-apiserver:2.17.0167fd532bd43
github.com/kedacore/keda/v2@v2.17.0
2.20.0
1
ghcr.io/kedacore/keda-metrics-apiserver:2.16.073a2ebae4413
github.com/kedacore/keda/v2@v2.16.0
2.20.0
1
ghcr.io/kedacore/keda-metrics-apiserver:2.17.2f312f50ddc57
github.com/kedacore/keda/v2@v2.17.2
2.20.0
1
ghcr.io/kedify/otel-add-on:v0.1.4a6f2155bd822
github.com/kedacore/keda/v2@v2.17.3
2.20.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.