StackRadar

CVE-2026-54369

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,487
of 17,797 indexed, latest versions
Container images
2,463
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: acl security update

Carried by container images the latest versions of 2,487 of 17,797 indexed charts deploy, on 2,463 images.

Affected packageAffected versionsFixed inImages
acldeb2.2.52-1, 2.2.52-3, 2.2.52-3build1, 2.2.53-6+8 more2.4.0-12,419
aclrpm2.3.1-2.azl3, 2.3.1-3.el9, 2.3.1-4.el90:2.4.0-0.el9_2.1, 0:2.4.0-0.el9_4.1, 0:2.4.0-0.el9_6.1, 2.4.0-144
OSV records
DEBIAN-CVE-2026-54369RHSA-2026:67140RHSA-2026:67142RHSA-2026:67144UBUNTU-CVE-2026-54369AZL-91397ECHO-b5ce-94bd-9b5b

Charts affected

2,487 by stars
ChartLatestAffected imagesRadar Score
ms-licenses-grpccodedesignplus-chartsVerified publisher0.0.241 of 1See more

ms-licenses-grpc codedesignplus-charts 0.0.24

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
codedesignplus/ms-licenses-grpc:latest360144457f4d
acl@2.3.1-3
no fix listed

Open the chart page →

1,166
ms-modules-grpccodedesignplus-chartsVerified publisher0.0.241 of 1See more

ms-modules-grpc codedesignplus-charts 0.0.24

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
codedesignplus/ms-modules-grpc:latest3f6aaa32d526
acl@2.3.1-3
no fix listed

Open the chart page →

1,166
codehubcodehubVerified publisher6.2.183 of 5See more

codehub codehub 6.2.18

3 of the 5 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
acl@2.3.1-3
no fix listed
bitnamilegacy/postgresql:latest42a8200d3597
acl@2.3.1-3
no fix listed
jupyterhub/jupyterhub:5.4.63974ba945e65
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

13,359
cohdicohdi0.2.21 of 3See more

cohdi cohdi 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/cohdi/composable-dra-driver:v0.2.28c05f7366981
acl@2.3.2-2+b1
no fix listed

Open the chart page →

3,796
web3-prometheus-exportercoinpri-helm-chartsVerified publisher0.1.31 of 1See more

web3-prometheus-exporter coinpri-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
guillh/web3-prometheus-exporter:0.3.04fb99dbc32b2
acl@2.3.1-3
no fix listed

Open the chart page →

3,404
genericcolearendt0.2.71 of 1See more

generic colearendt 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,861
loki-stackcommon-chartsVerified publisher1.0.31 of 12See more

loki-stack common-charts 1.0.3

1 of the 12 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
grafana/alloy:v1.18.0491b0578c049
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

5,425
opencloudcommunity-opencloud3.0.01 of 11See more

opencloud community-opencloud 3.0.0

1 of the 11 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
apache/tika:latest-full80072bb73dd3
acl@2.3.2-2
no fix listed

Open the chart page →

3,823
sumo-besu-genesisconsensys0.1.751 of 1See more

sumo-besu-genesis consensys 0.1.75

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
acl@2.2.53-6
no fix listed

Open the chart page →

8,021
sumo-besu-nodeconsensys0.1.751 of 4See more

sumo-besu-node consensys 0.1.75

1 of the 4 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
acl@2.2.53-6
no fix listed

Open the chart page →

8,021
filesystem-exportercontainerooVerified publisher1.5.21 of 1See more

filesystem-exporter containeroo 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/containeroo/filesystem-exporter:v1.5.2a66121e16d4e
acl@2.3.1-3
no fix listed

Open the chart page →

1,268
ConvertServiceWeb-Helm-Buildconvertserviceweb-helm-build0.1.12 of 7See more

ConvertServiceWeb-Helm-Build convertserviceweb-helm-build 0.1.1

2 of the 7 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/rabbitmq:3.11.5-management1b0f675d2f24
acl@2.2.53-6
no fix listed
library/redis:latest298e5b3bc566
acl@2.3.2-2+b1
no fix listed

Open the chart page →

10,185
cortezacorteza1.1.02 of 3See more

corteza corteza 1.1.0

2 of the 3 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.4cb9f200de5d2
acl@2.3.1-1
no fix listed
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
acl@2.3.1-3
no fix listed

Open the chart page →

8,456
corteza-all-in-onecorteza0.1.01 of 2See more

corteza-all-in-one corteza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.08eb7a26605c9
acl@2.2.53-6
no fix listed

Open the chart page →

4,698
cosanetcosanet1.0.01 of 1See more

cosanet cosanet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/cosanet/cosanet:1.0.098cb5d9fa215
acl@2.3.2-2+b1
no fix listed

Open the chart page →

2,227
datumcosmicrocks1.0.51 of 2See more

datum cosmicrocks 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

2,993
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
acl@2.3.1-3
no fix listed

Open the chart page →

14,740
cospacecospace0.0.341 of 3See more

cospace cospace 0.0.34

1 of the 3 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/twigex/cospace:lateste5ecfd607e42
acl@2.3.1-3
no fix listed

Open the chart page →

2,289
grafana-mcpcowboysysopVerified publisher2.0.01 of 1See more

grafana-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
mcp/grafana:latest9362bcf6aa0e
acl@2.3.1-3
no fix listed

Open the chart page →

1,218
kubernetes-mcpcowboysysopVerified publisher2.0.01 of 1See more

kubernetes-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
acl@2.3.1-4.el9
0:2.4.0-0.el9_6.1

Open the chart page →

1,831
mariadbcowboysysopVerified publisher20.4.21 of 1See more

mariadb cowboysysop 20.4.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
acl@2.3.1-3
no fix listed

Open the chart page →

3,060
mongodbcowboysysopVerified publisher15.1.51 of 1See more

mongodb cowboysysop 15.1.5

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
acl@2.3.1-3
no fix listed

Open the chart page →

6,220
postgresqlcowboysysopVerified publisher15.5.71 of 1See more

postgresql cowboysysop 15.5.7

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r14cc55da2fa366
acl@2.3.1-3
no fix listed

Open the chart page →

4,815
qdrantcowboysysopVerified publisher3.0.01 of 1See more

qdrant cowboysysop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.4.166ee661d5241
acl@2.3.1-3
no fix listed

Open the chart page →

3,056
rediscowboysysopVerified publisher21.2.61 of 1See more

redis cowboysysop 21.2.6

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.0.2-debian-12-r4cdc2efa9c306
acl@2.3.1-3
no fix listed

Open the chart page →

2,651
logstream-leadercriblio4.20.01 of 1See more

logstream-leader criblio 4.20.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
cribl/cribl:4.20.0dddc9c0f2a52
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

870
logstream-mastercriblio2.9.91 of 1See more

logstream-master criblio 2.9.9

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
cribl/cribl:3.0.2762747cb6796
acl@2.2.52-3build1
no fix listed

Open the chart page →

9,306
logstream-workergroupcriblio4.20.01 of 1See more

logstream-workergroup criblio 4.20.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
cribl/cribl:4.20.0dddc9c0f2a52
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

870
iam-zencryptexlabsVerified publisher0.12.231 of 4See more

iam-zen cryptexlabs 0.12.23

1 of the 4 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
acl@2.3.1-3
no fix listed

Open the chart page →

3,900
pagescrypticcode-helmchart1.0.02 of 3See more

pages crypticcode-helmchart 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
acl@2.2.53-6
no fix listed
flyway/flyway:6.4.422d97ceb0c47
acl@2.2.52-3build1
no fix listed

Open the chart page →

20,262
csghubcsghubVerified publisher2.5.010 of 34See more

csghub csghub 2.5.0

10 of the 34 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/redis:7.4.1171da9275c5f3
acl@2.3.1-3
no fix listed
opencsghq/agenticflow:ee-v0.6.5-241cba9c366f1
acl@2.3.1-3
no fix listed
opencsghq/csgbot:v0.6.9-ee7d0271e26521
acl@2.3.2-2+b1
no fix listed
opencsghq/csghub-portal:v2.5.0-ee1cb36b49151e
acl@2.3.1-3
no fix listed
opencsghq/csghub-server:v2.5.0-ee587046575c2c
acl@2.3.1-3
no fix listed
opencsghq/csghub-xnet:v2.5.0-ee86ea22f495c7
acl@2.3.1-3
no fix listed
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
acl@2.3.1-3
no fix listed
opencsghq/gitlab-shell:v19.2.580a65ac370da
acl@2.3.1-3
no fix listed
opencsghq/label-studio:v2.5.047e22aa71870
acl@2.3.2-2+b1
no fix listed
opencsghq/postgres:15.19b98600564e07
acl@2.3.2-2+b1
no fix listed

Open the chart page →

49,244
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/redis:7.4.1171da9275c5f3
acl@2.3.1-3
no fix listed
opencsghq/postgres:15.19b98600564e07
acl@2.3.2-2+b1
no fix listed

Open the chart page →

11,573
dataflowcsghubVerified publisher2.5.02 of 7See more

dataflow csghub 2.5.0

2 of the 7 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
acl@2.3.2-2+b1
no fix listed
opencsghq/postgres:15.19b98600564e07
acl@2.3.2-2+b1
no fix listed

Open the chart page →

6,768
rtcsic-charts0.1.11 of 5See more

rt csic-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
firefart/requesttracker:5.0.40d6249906d8c
acl@2.3.1-3
no fix listed

Open the chart page →

15,397
wazuhcsic-charts0.1.02 of 4See more

wazuh csic-charts 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
acl@2.2.53-6
no fix listed
wazuh/wazuh-manager:4.4.121994f40e0da
acl@2.2.53-6
no fix listed

Open the chart page →

13,973
cspconsolecspconsole1.3.114 of 5See more

cspconsole cspconsole 1.3.11

4 of the 5 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
cspconsole/config-provider:1.0.365524a26a6c23
acl@2.3.1-3
no fix listed
cspconsole/csp-control-center:1.0.1046dda4a31bd6
acl@2.3.1-3
no fix listed
cspconsole/report-collector:1.0.15839750248193b
acl@2.3.1-3
no fix listed
cspconsole/report-processor:1.0.279a2d8840bfdf
acl@2.3.1-3
no fix listed

Open the chart page →

12,440
cypikcypik-app0.1.02 of 2See more

cypik cypik-app 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
acl@2.3.2-2+b1
no fix listed
library/nginx:1.25a484819eb602
acl@2.3.1-3
no fix listed

Open the chart page →

7,577
view-cadvisorcypik-helm-chart0.1.01 of 1See more

view-cadvisor cypik-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,861
irods-csi-drivercyverse0.12.01 of 4See more

irods-csi-driver cyverse 0.12.0

1 of the 4 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
cyverse/irods-csi-driver:v0.12.0aa69d105b292
acl@2.3.1-1
no fix listed

Open the chart page →

5,295
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
acl@2.3.1-3
no fix listed

Open the chart page →

16,732
miniod4nVerified publisher5.2.12 of 2See more

minio d4n 5.2.1

2 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-04-29T09-56-05Zc574fac67f60
acl@2.3.1-4.el9
0:2.4.0-0.el9_4.1
quay.io/minio/minio:RELEASE.2024-06-04T19-20-08Zc6b68f158628
acl@2.3.1-4.el9
0:2.4.0-0.el9_4.1

Open the chart page →

2,659
nifi-registryd4nVerified publisher1.0.01 of 2See more

nifi-registry d4n 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
acl@2.3.1-1
no fix listed

Open the chart page →

5,451
nginx-chartdaeho12Verified publisher0.1.01 of 1See more

nginx-chart daeho12 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,861
dakeradakera-helmVerified publisher0.11.1072 of 3See more

dakera dakera-helm 0.11.107

2 of the 3 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/dakera-ai/dakera:0.11.101af610992a416
acl@2.3.2-2+b1
no fix listed
ghcr.io/dakera-ai/dakera-mcp:0.10.11a3d48418b14a
acl@2.3.1-3
no fix listed

Open the chart page →

3,985
pagesdalston-pages1.0.02 of 3See more

pages dalston-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
acl@2.2.53-6
no fix listed
flyway/flyway:6.4.422d97ceb0c47
acl@2.2.52-3build1
no fix listed

Open the chart page →

20,262
pagesdaman-dell-kuber1.0.02 of 3See more

pages daman-dell-kuber 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
acl@2.2.53-6
no fix listed
flyway/flyway:6.4.422d97ceb0c47
acl@2.2.52-3build1
no fix listed

Open the chart page →

20,262
damap-chartdamapVerified publisher0.3.04 of 5See more

damap-chart damap 0.3.0

4 of the 5 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8f29984bd1e22
acl@2.3.2-2+b1
no fix listed
library/postgres:16f1c3376c26f2
acl@2.3.2-2+b1
no fix listed
ghcr.io/damap-org/damap-backend:5.0.0f3d0c7d35498
acl@2.3.2-1build1.1
no fix listed
ghcr.io/damap-org/damap-frontend:5.0.1609f48af4efc
acl@2.3.2-2+b1
no fix listed

Open the chart page →

14,458
nvidia-gpu-exporterdanchevVerified publisher1.0.31 of 1See more

nvidia-gpu-exporter danchev 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/utkuozdemir/nvidia_gpu_exporter:1.5.0d75967a4dd72
acl@2.3.2-2
no fix listed

Open the chart page →

1,238
dapr-agentsdapr-agents-devVerified publisher0.1.52 of 31See more

dapr-agents dapr-agents-dev 0.1.5

2 of the 31 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/redis:6.2143f7bfc2358
acl@2.3.1-3
no fix listed
mcp/grafana:latest9362bcf6aa0e
acl@2.3.1-3
no fix listed

Open the chart page →

22,370
dara-chartsdara-charts0.1.02 of 2See more

dara-charts dara-charts 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
acl@2.3.2-2+b1
no fix listed
razzy10/product-service:latest702e411956db
acl@2.3.1-4.el9
0:2.4.0-0.el9_6.1

Open the chart page →

3,616

Container images carrying it

2,463 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
acl@2.2.53-6
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
acl@2.3.1-4.el9
0:2.4.0-0.el9_6.1
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
acl@2.3.1-3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
acl@2.3.2-2+b1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
acl@2.3.1-3
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
acl@2.3.1-3
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
acl@2.3.1-3
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.