StackRadar

CVE-2026-54369

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,557
of 17,813 indexed, latest versions
Container images
2,558
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: acl security update

Carried by container images the latest versions of 2,557 of 17,813 indexed charts deploy, on 2,558 images.

Affected packageAffected versionsFixed inImages
acldeb2.2.52-1, 2.2.52-3, 2.2.52-3build1, 2.2.53-6+8 more2.4.0-12,515
aclrpm2.3.1-2.azl3, 2.3.1-3.el9, 2.3.1-4.el90:2.4.0-0.el9_2.1, 0:2.4.0-0.el9_4.1, 0:2.4.0-0.el9_6.1, 2.4.0-143
OSV records
DEBIAN-CVE-2026-54369RHSA-2026:67140RHSA-2026:67142RHSA-2026:67144UBUNTU-CVE-2026-54369AZL-91397ECHO-b5ce-94bd-9b5b

Charts affected

2,557 by stars
ChartLatestAffected imagesRadar Score
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,338
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,956
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
acl@2.3.1-3
no fix listed

Open the chart page →

2,718
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
acl@2.3.1-3
no fix listed

Open the chart page →

2,697
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,956
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
acl@2.2.52-3build1
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
acl@2.2.53-6
no fix listed

Open the chart page →

9,296
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
acl@2.3.1-1
no fix listed

Open the chart page →

7,966

Container images carrying it

2,558 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
istio/operator:1.18.270f9d1fe5fff
acl@2.3.1-1
no fix listed
1
istio/pilot:1.10.0294ca55bd1cc
acl@2.2.52-3build1
no fix listed
1
istio/pilot:1.29.0325156535773
acl@2.3.2-1build1.1
no fix listed
1
istio/pilot:1.23.69c3d6a218181
acl@2.3.2-1build1.1
no fix listed
1
istio/pilot:1.16.0ac0284d75ec9
acl@2.3.1-1
no fix listed
1
istio/pilot:1.2.9c09319753454
acl@2.2.52-3
no fix listed
1
istio/pilot:1.17.1ce9d87606701
acl@2.3.1-1
no fix listed
1
istio/pilot:1.15.2db08d6963975
acl@2.3.1-1
no fix listed
1
istio/pilot:1.10.3e7e110a421c2
acl@2.2.52-3build1
no fix listed
1
istio/pilot:1.29.1f8b0e412ac4a
acl@2.3.2-1build1.1
no fix listed
1
istio/proxyv2:1.2.90c78be035e98
acl@2.2.52-3
no fix listed
1
istio/proxyv2:1.9.687a9db561d2e
acl@2.2.52-3build1
no fix listed
1
istio/proxyv2:1.10.088c6c693e67a
acl@2.2.52-3build1
no fix listed
1
istio/proxyv2:1.14.1df69c1a7af7c
acl@2.2.53-6
no fix listed
1
istio/ztunnel:1.25.005f3972d80a9
acl@2.3.2-1build1.1
no fix listed
1
itzg/bungeecord:latestde76286c0e73
acl@2.3.2-2
no fix listed
1
itzg/minecraft-server:latest8672e335dbef
acl@2.3.2-1build1.1
no fix listed
1
itzg/minecraft-server:2026.9.1e8640538dac5
acl@2.3.2-1build1.1
no fix listed
1
ixsystems/truecommand:3.2.019c218455cd2
acl@2.3.2-2+b1
no fix listed
1
jacobalberty/unifi:v7.1.664a3616625dda
acl@2.2.52-3build1
no fix listed
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
acl@2.2.52-3build1
no fix listed
1
jacobalberty/unifi:5.10.19c409924e2463
acl@2.2.52-3
no fix listed
1
jaedb/iris:latest048cfbf58d57
acl@2.3.1-3
no fix listed
1
jakowenko/double-take:1.6.0b858bac9e32a
acl@2.2.53-6
no fix listed
1
janzo83/serviceexample:latestfb3c4ac36f3e
acl@2.3.1-3
no fix listed
1
jbtronics/part-db1:latestfd68338829ed
acl@2.3.1-3
no fix listed
1
jedi132000/nextapp:latestdc2a81e92f23
acl@2.2.53-6
no fix listed
1
jellyfin/jellyfin:10.11.81694ff069f0c
acl@2.3.2-2+b1
no fix listed
1
jellyfin/jellyfin:10.11.717285f9cce63
acl@2.3.2-2+b1
no fix listed
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
acl@2.3.1-3
no fix listed
1
jellyfin/jellyfin:10.11.6333b64771663
acl@2.3.2-2+b1
no fix listed
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
acl@2.3.1-3
no fix listed
1
jellyfin/jellyfin:10.10.77ae36aab93ef
acl@2.3.1-3
no fix listed
1
jellyfin/jellyfin:10.10.696b09723b22f
acl@2.3.1-3
no fix listed
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
acl@2.3.1-3
no fix listed
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
acl@2.3.1-3
no fix listed
1
jertel/elastalert2:2.31.03cbf63f9b7dc
acl@2.3.2-2+b1
no fix listed
1
jhipster/jhipster-registry:latest7184525acd4d
acl@2.2.53-6
no fix listed
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
acl@2.3.1-3
no fix listed
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
acl@2.2.53-6
no fix listed
1
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
acl@2.3.1-3
no fix listed
1
jmferrer/azure-devops-agent:latest030f68ec6998
acl@2.2.52-3
no fix listed
1
jodogne/orthanc-plugins:latest6ff510aa29c2
acl@2.3.2-2+b1
no fix listed
1
johly/airtrail:v3.11.19f702b91e0e7
acl@2.3.1-3
no fix listed
1
joplin/server:latest3f7b852959aa
acl@2.3.1-3
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
acl@2.3.1-3
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
acl@2.3.1-1
no fix listed
1
journeyapps/powersync-service:latest413a0c813e96
acl@2.3.2-2+b1
no fix listed
1
jpgouin/openldap:2.6.9-fixbfdd0088c776
acl@2.3.1-3
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
acl@2.3.2-1build1.1
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.