StackRadar

CVE-2026-54369

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,446
of 17,790 indexed, latest versions
Container images
2,421
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: acl security update

Carried by container images the latest versions of 2,446 of 17,790 indexed charts deploy, on 2,421 images.

Affected packageAffected versionsFixed inImages
acldeb2.2.52-1, 2.2.52-3, 2.2.52-3build1, 2.2.53-6+8 more2.4.0-12,402
aclrpm2.3.1-2.azl3, 2.3.1-3.el9, 2.3.1-4.el90:2.4.0-0.el9_2.1, 0:2.4.0-0.el9_4.1, 2.4.0-119
OSV records
DEBIAN-CVE-2026-54369RHSA-2026:67142RHSA-2026:67144UBUNTU-CVE-2026-54369AZL-91397ECHO-b5ce-94bd-9b5b

Charts affected

2,446 by stars
ChartLatestAffected imagesRadar Score
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
acl@2.3.1-3
no fix listed

Open the chart page →

4,079
flinkflink0.5.11 of 1See more

flink flink 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/flink:1.14.6-scala_2.122461f02672b3
acl@2.3.1-1
no fix listed

Open the chart page →

5,690
floriapp-mongodbfloriapp1.0.01 of 1See more

floriapp-mongodb floriapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
acl@2.2.52-3build1
no fix listed

Open the chart page →

8,046
fluentd-aggregatorfluentd-aggregatorOfficialVerified publisher1.0.01 of 2See more

fluentd-aggregator fluentd-aggregator 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,712
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
acl@2.3.1-3
no fix listed

Open the chart page →

3,384
dump1090fnzv0.2.81 of 1See more

dump1090 fnzv 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
fnzv/dump1090:latestb3079b95c336
acl@2.3.1-1
no fix listed

Open the chart page →

4,123
fr24feederfnzv0.1.21 of 1See more

fr24feeder fnzv 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest917e53402d51
acl@2.3.2-2+b1
no fix listed

Open the chart page →

2,246
mod-z3950folio-org0.1.31 of 1See more

mod-z3950 folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
folioci/mod-z3950:latest2493041ce880
acl@2.3.2-2+b1
no fix listed

Open the chart page →

2,432
ledgerformance1.2.01 of 1See more

ledger formance 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
acl@2.3.1-1
no fix listed

Open the chart page →

4,641
ff-testfrankframework0.7.61 of 2See more

ff-test frankframework 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/postgres:17-bookworm051f7b7b3abd
acl@2.3.1-3
no fix listed

Open the chart page →

1,657
frank2examplefrankframework0.7.41 of 2See more

frank2example frankframework 0.7.4

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/postgres:17-bookworm051f7b7b3abd
acl@2.3.1-3
no fix listed

Open the chart page →

1,657
plexfydrah-charts2.2.01 of 1See more

plex fydrah-charts 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
acl@2.2.52-3
no fix listed

Open the chart page →

8,971
passboltg0dscookie0.5.21 of 2See more

passbolt g0dscookie 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/mariadb:10.79a48ac9f196f
acl@2.2.53-6
no fix listed

Open the chart page →

7,983
changedetection-iogabe565Verified publisher0.12.01 of 2See more

changedetection-io gabe565 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:latestecacd9fd0c66
acl@2.3.1-3
no fix listed

Open the chart page →

2,602
esphomegabe565Verified publisher0.15.01 of 1See more

esphome gabe565 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:latest000c5ee5ee96
acl@2.3.2-2+b1
no fix listed

Open the chart page →

3,143
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
acl@2.3.1-3
no fix listed

Open the chart page →

13,247
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
acl@2.3.2-2+b1
no fix listed

Open the chart page →

6,425
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
acl@2.2.53-6
no fix listed

Open the chart page →

5,980
accumulogaffer2.2.12 of 4See more

accumulo gaffer 2.2.1

2 of the 4 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
acl@2.3.2-1build1
no fix listed
gchq/hdfs:3.3.35ec58edbb2db
acl@2.3.2-1build1
no fix listed

Open the chart page →

16,969
gaffer-road-trafficgaffer2.2.11 of 8See more

gaffer-road-traffic gaffer 2.2.1

1 of the 8 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
acl@2.3.2-1build1
no fix listed

Open the chart page →

9,381
garge-apigargeVerified publisher0.1.551 of 1See more

garge-api garge 0.1.55

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
sondresjo/garge-api:v2.12.6f41e452800ff
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

1,084
garge-appgargeVerified publisher0.1.471 of 1See more

garge-app garge 0.1.47

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
sondresjo/garge-app:v1.20.70382ebf9dfc8
acl@2.3.1-3
no fix listed

Open the chart page →

1,755
garge-operatorgargeVerified publisher0.1.341 of 1See more

garge-operator garge 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
sondresjo/garge-operator:v1.9.416cb6643dae6
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

684
pagesgary-pages1.0.02 of 3See more

pages gary-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
acl@2.2.53-6
no fix listed
flyway/flyway:6.4.422d97ceb0c47
acl@2.2.52-3build1
no fix listed

Open the chart page →

20,233
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
acl@2.2.53-6
no fix listed

Open the chart page →

18,217
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
acl@2.2.53-6
no fix listed

Open the chart page →

14,698
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
acl@2.2.52-3build1
no fix listed

Open the chart page →

19,234
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
acl@2.2.53-6
no fix listed

Open the chart page →

16,178
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
acl@2.2.52-3build1
no fix listed

Open the chart page →

13,572
dizquetvgeek-cookbookVerified publisher4.4.21 of 1See more

dizquetv geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
vexorian/dizquetv:1.4.37e2b99844a5c
acl@2.2.52-3build1
no fix listed

Open the chart page →

4,885
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
acl@2.2.53-6
no fix listed

Open the chart page →

12,270
duplicatigeek-cookbookVerified publisher5.4.21 of 1See more

duplicati geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/duplicati:latesta792931146b4
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

1,764
embygeek-cookbookVerified publisher3.4.21 of 1See more

emby geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
acl@2.2.53-6
no fix listed

Open the chart page →

8,584
factoriogeek-cookbookVerified publisher1.2.21 of 2See more

factorio geek-cookbook 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
factoriotools/factorio:stablec6092b912bd1
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,449
gapsgeek-cookbookVerified publisher5.4.21 of 1See more

gaps geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
housewrecker/gaps:latestf417dd0a7547
acl@2.2.53-6
no fix listed

Open the chart page →

8,982
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
acl@2.2.53-6
no fix listed

Open the chart page →

11,042
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
acl@2.3.1-3
no fix listed

Open the chart page →

9,103
jackettgeek-cookbookVerified publisher11.7.21 of 1See more

jackett geek-cookbook 11.7.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
acl@2.2.53-6
no fix listed

Open the chart page →

9,736
komgageek-cookbookVerified publisher2.4.21 of 1See more

komga geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
gotson/komga:0.99.49b15ea6bfc30
acl@2.2.52-3build1
no fix listed

Open the chart page →

12,586
lancachegeek-cookbookVerified publisher0.6.21 of 1See more

lancache geek-cookbook 0.6.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
lancachenet/monolithic:latest37f28b362c93
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

1,270
lidarrgeek-cookbookVerified publisher14.2.21 of 1See more

lidarr geek-cookbook 14.2.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
acl@2.2.53-6
no fix listed

Open the chart page →

14,328
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
acl@2.3.1-3
no fix listed

Open the chart page →

12,993
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
acl@2.3.1-1
no fix listed

Open the chart page →

12,124
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
acl@2.2.53-6
no fix listed

Open the chart page →

17,758
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
acl@2.2.53-6
no fix listed

Open the chart page →

28,039
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
acl@2.3.1-1
no fix listed

Open the chart page →

19,560
puppeteergeek-cookbookVerified publisher1.2.21 of 1See more

puppeteer geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
acl@2.2.53-6
no fix listed

Open the chart page →

15,792
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
acl@2.2.53-6
no fix listed

Open the chart page →

11,855
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
acl@2.3.1-1
no fix listed

Open the chart page →

10,418
readarrgeek-cookbookVerified publisher6.4.21 of 1See more

readarr geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
acl@2.2.53-6
no fix listed

Open the chart page →

7,806

Container images carrying it

2,421 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
langgenius/dify-api:0.6.11fca918260dd6
acl@2.3.1-3
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
acl@2.3.2-1build1.1
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
acl@2.3.2-1build1.1
no fix listed
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
acl@2.3.2-1build1.1
no fix listed
1
langgenius/dify-sandbox:0.2.15750e1111426e
acl@2.3.2-2+b1
no fix listed
1
lib42/jackett:latesta55596cda383
acl@2.3.1-3
no fix listed
1
library/buildpack-deps:scmac978b783657
acl@2.3.2-2+b1
no fix listed
1
library/cassandra:4.0093ee8ee5eb2
acl@2.3.1-3
no fix listed
1
library/cassandra:3.11.10b095ff3248c6
acl@2.2.53-6
no fix listed
1
library/convertigo:8.4.3ae605bfcda05
acl@2.3.2-1build1.1
no fix listed
1
library/couchdb:3.4.22817ad50b5c5
acl@2.3.1-3
no fix listed
1
library/debian:12.5-slim67f3931ad8cb
acl@2.3.1-3
no fix listed
1
library/debian:bookworm6ebd97fa83de
acl@2.3.1-3
no fix listed
1
library/debian:12.12-slimd5d3f9c23164
acl@2.3.1-3
no fix listed
1
library/debian:latestf324c7ff5432
acl@2.3.2-2+b1
no fix listed
1
library/drupal:11.4.6-php8.5-apache-bookworm28f7931ecbcb
acl@2.3.1-3
no fix listed
1
library/eclipse-temurin:211f79c73404fb
acl@2.3.2-2
no fix listed
1
library/eclipse-temurin:2185f00967bcc6
acl@2.3.2-2
no fix listed
1
library/elasticsearch:8.17.32cc40b15dff8
acl@2.2.53-6
no fix listed
1
library/elasticsearch:8.15.0310b9fc03b06
acl@2.2.53-6
no fix listed
1
library/elasticsearch:7.17.0332c6d416808
acl@2.2.53-6
no fix listed
1
library/elasticsearch:7.17.1588c2ec10c7f2
acl@2.2.53-6
no fix listed
1
library/elasticsearch:7.17.8fdc73b3249c1
acl@2.2.53-6
no fix listed
1
library/flink:1.14.6-scala_2.122461f02672b3
acl@2.3.1-1
no fix listed
1
library/ghost:6.37.01ef2e532ca4d
acl@2.3.1-3
no fix listed
1
library/ghost:6.25.12654b1e90413
acl@2.3.1-3
no fix listed
1
library/ghost:6.41.129773d6be407
acl@2.3.1-3
no fix listed
1
library/ghost:5.79.083f7bf209844
acl@2.3.1-3
no fix listed
1
library/golang:latest512690a56605
acl@2.3.2-2+b1
no fix listed
1
library/haproxy:3.4.10f597665a2a6
acl@2.3.2-2+b1
no fix listed
1
library/haproxy:3.1-bookworm49a0a0d6f0b8
acl@2.3.1-3
no fix listed
1
library/haproxy:2.8.288baa7d29a27a
acl@2.3.2-2+b1
no fix listed
1
library/haproxy:2.9.6fc5748ff7c72
acl@2.3.1-3
no fix listed
1
library/httpd:2.4.631ae8051591a5
acl@2.3.1-3
no fix listed
1
library/influxdb:2.8571eb4514977
acl@2.3.1-3
no fix listed
1
library/influxdb:3.10.5-core695a8063ff10
acl@2.3.2-1build1.1
no fix listed
1
library/influxdb:3.11.2-enterprise6ce2bf22499b
acl@2.3.2-1build1.1
no fix listed
1
library/influxdb:1.12.3-meta8812029260b5
acl@2.3.1-3
no fix listed
1
library/influxdb:1.12.3-datab0f9fc41ed79
acl@2.3.1-3
no fix listed
1
library/influxdb:latestf75e48af0598
acl@2.3.1-3
no fix listed
1
library/kibana:7.17.150172f1c538e7
acl@2.2.53-6
no fix listed
1
library/kibana:8.18.004c0fc150f3a
acl@2.2.53-6
no fix listed
1
library/kibana:7.17.8c5781ba340ef
acl@2.2.53-6
no fix listed
1
library/kibana:7.17.3e2e2031c15be
acl@2.2.53-6
no fix listed
1
library/kong:3.8.0712e407b20ea
acl@2.3.1-1
no fix listed
1
library/logstash:7.17.817a4f64e9cf5
acl@2.2.53-6
no fix listed
1
library/mariadb:10.7.307e06f2e7ae9
acl@2.2.53-6
no fix listed
1
library/mariadb:10.11.21c33370a599c
acl@2.3.1-1
no fix listed
1
library/mariadb:10.422edfe1c7834
acl@2.2.53-6
no fix listed
1
library/mariadb:112439dcd7d140
acl@2.3.2-1build1.1
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.