StackRadar

CVE-2026-54369

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,570
of 17,821 indexed, latest versions
Container images
2,580
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: acl security update

Carried by container images the latest versions of 2,570 of 17,821 indexed charts deploy, on 2,580 images.

Affected packageAffected versionsFixed inImages
acldeb2.2.52-1, 2.2.52-3, 2.2.52-3build1, 2.2.53-6+8 more2.4.0-12,537
aclrpm2.3.1-2.azl3, 2.3.1-3.el9, 2.3.1-4.el90:2.4.0-0.el9_2.1, 0:2.4.0-0.el9_4.1, 0:2.4.0-0.el9_6.1, 2.4.0-143
OSV records
DEBIAN-CVE-2026-54369RHSA-2026:67140RHSA-2026:67142RHSA-2026:67144UBUNTU-CVE-2026-54369AZL-91397ECHO-b5ce-94bd-9b5b

Charts affected

2,570 by stars
ChartLatestAffected imagesRadar Score
basenn-coVerified publisher0.1.01 of 1See more

base nn-co 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,593
base-jobnn-coVerified publisher0.1.01 of 4See more

base-job nn-co 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/ubuntu:latestda6fc2be5478
acl@2.3.2-2
no fix listed

Open the chart page →

338
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
acl@2.3.1-3
no fix listed

Open the chart page →

10,456
node-debug-dashboardnode-debug-dashboardVerified publisher0.3.21 of 1See more

node-debug-dashboard node-debug-dashboard 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
acl@2.3.1-3
no fix listed

Open the chart page →

6,993
firehose-corenodeifyVerified publisher1.2.62 of 2See more

firehose-core nodeify 1.2.6

2 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
sigp/lighthouse:latest-amd6450f66cfebb6d
acl@2.3.1-1
no fix listed
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

6,628
firehose-ethereumnodeifyVerified publisher1.7.12 of 2See more

firehose-ethereum nodeify 1.7.1

2 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
sigp/lighthouse:v8.1.344aa773dcf27
acl@2.3.1-1
no fix listed
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

5,742
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

4,785
app1node-web-app10.1.31 of 1See more

app1 node-web-app1 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,887
app2node-web-app10.1.31 of 1See more

app2 node-web-app1 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,887
nginx-chartnomadshk-nginx0.1.01 of 1See more

nginx-chart nomadshk-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,887
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
acl@2.2.53-6
no fix listed

Open the chart page →

22,831
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
acl@2.3.2-2+b1
no fix listed

Open the chart page →

5,872
keycloak-helm-chartnotesprojectchart0.1.01 of 2See more

keycloak-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,618
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
acl@2.3.2-2+b1
no fix listed

Open the chart page →

6,839
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
acl@2.3.1-3
no fix listed

Open the chart page →

15,370
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
acl@2.3.1-3
no fix listed

Open the chart page →

15,443
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
acl@2.3.1-3
no fix listed

Open the chart page →

15,426
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
acl@2.3.2-2+b1
no fix listed

Open the chart page →

5,899
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
acl@2.3.2-2+b1
no fix listed

Open the chart page →

5,855
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
acl@2.2.52-1
no fix listed

Open the chart page →

41,495
notifynl-omcnotifynlOfficialVerified publisher0.4.351 of 1See more

notifynl-omc notifynl 0.4.35

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
worthnl/notifynl-omc:2.2.16f58fc28252d
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

401
fluentd-kubernetes-daemonsetnovum-rgi-charts0.1.01 of 1See more

fluentd-kubernetes-daemonset novum-rgi-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1-debian-graylogfda93f768f98
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,055
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
acl@2.2.52-3build1
no fix listed
linuxserver/codimd:latestb801bbcf6386
acl@2.2.52-3build1
no fix listed

Open the chart page →

27,585
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
acl@2.2.52-3build1
no fix listed

Open the chart page →

95,465
cloakbrowser-mcpobeoneVerified publisher0.3.11 of 1See more

cloakbrowser-mcp obeone 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
swimmwatch/cloakbrowser-mcp:1.13.0d48c705a58c8
acl@2.3.1-3
no fix listed

Open the chart page →

2,347
firecrawlobeoneVerified publisher3.0.83 of 5See more

firecrawl obeone 3.0.8

3 of the 5 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/firecrawl/firecrawl:2.11.371ea2d420cea57
acl@2.3.1-3
no fix listed
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
acl@2.3.2-2+b1
no fix listed
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
acl@2.3.1-3
no fix listed

Open the chart page →

9,807
libretranslateobeoneVerified publisher1.0.71 of 1See more

libretranslate obeone 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
libretranslate/libretranslate:v1.9.61de2d7056bb8
acl@2.3.1-3
no fix listed

Open the chart page →

1,978
ollamaobeoneVerified publisher0.3.11 of 2See more

ollama obeone 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/obeone/ollama-exporter:latestf43af285c6e0
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,112
olvid-botobeoneVerified publisher0.3.31 of 1See more

olvid-bot obeone 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
olvid/bot-daemon:2.0.1e0e6b165d879
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

2,116
parcelapp-mcpobeoneVerified publisher0.1.01 of 1See more

parcelapp-mcp obeone 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
acl@2.3.2-2+b1
no fix listed

Open the chart page →

898
ocellusaiocellusaiVerified publisher0.1.121 of 2See more

ocellusai ocellusai 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,203
lensoci-ai-incubations0.1.141 of 16See more

lens oci-ai-incubations 0.1.14

1 of the 16 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
acl@2.3.2-2+b1
no fix listed

Open the chart page →

17,198
kueue-addonocm-helm-chartsVerified publisher0.1.41 of 1See more

kueue-addon ocm-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
acl@2.3.1-4.el9
0:2.4.0-0.el9_6.1

Open the chart page →

1,619
octantisoctantis0.1.01 of 1See more

octantis octantis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/vinny1892/octantis:latest45459c0910fc
acl@2.3.2-2+b1
no fix listed

Open the chart page →

2,643
mockoidcoidcmockVerified publisher0.0.11 of 1See more

mockoidc oidcmock 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
marcoimme/oidcmock:latestb6035c0721a8
acl@2.3.2-2+b1
no fix listed

Open the chart page →

2,291
web-chartoje-ktcloudlab0.1.01 of 1See more

web-chart oje-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,887
ojp-serverojp0.1.51 of 1See more

ojp-server ojp 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
rrobetti/ojp:0.1.0-beta1141bd88232b
acl@2.3.2-1build1
no fix listed

Open the chart page →

2,665
automx2oleds-helm-chartsVerified publisher1.0.51 of 1See more

automx2 oleds-helm-charts 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
oled01/automx2:2025.1.105d3e398e675
acl@2.3.1-3
no fix listed

Open the chart page →

5,335
cmsmsoleds-helm-chartsVerified publisher0.1.61 of 1See more

cmsms oleds-helm-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.7-debian-12-r290dc6acb7b2e
acl@2.3.1-3
no fix listed

Open the chart page →

2,833
db-backupoleds-helm-chartsVerified publisher0.1.01 of 1See more

db-backup oleds-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
oled01/db-backup:0.1.06302fd2b5333
acl@2.3.1-1
no fix listed

Open the chart page →

8,156
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
acl@2.3.1-1
no fix listed

Open the chart page →

9,327
laravel-appoli-the-devVerified publisher2.0.171 of 1See more

laravel-app oli-the-dev 2.0.17

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
serversideup/php:8.5-fpm-nginx8f8c2f010ac5
acl@2.3.2-2+b1
no fix listed

Open the chart page →

2,852
node-appoli-the-devVerified publisher1.0.01 of 1See more

node-app oli-the-dev 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/node:22-bookworm-slim48e4b67d85f8
acl@2.3.1-3
no fix listed

Open the chart page →

1,151
paperless-ngxoli-the-devVerified publisher1.1.11 of 1See more

paperless-ngx oli-the-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
acl@2.3.2-2+b1
no fix listed

Open the chart page →

4,703
cron-jobonechart-slVerified publisher0.73.71 of 1See more

cron-job onechart-sl 0.73.7

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/debian:stable-slim5bc3287b2540
acl@2.3.2-2+b1
no fix listed

Open the chart page →

583
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

6,191
ontoserverontoserverVerified publisher0.5.21 of 2See more

ontoserver ontoserver 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,272
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
onyxdotapp/onyx-backend:latest473fdffe4e67
acl@2.3.2-2+b1
no fix listed

Open the chart page →

6,772
erigonop-chartsVerified publisher0.0.51 of 2See more

erigon op-charts 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
testinprod/op-erigon:latest0a125bd77a2d
acl@2.3.1-3
no fix listed

Open the chart page →

2,933
opds-shelfopds-shelfVerified publisher0.4.01 of 3See more

opds-shelf opds-shelf 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-54369.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:latest0767226fcf20
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

4,415

Container images carrying it

2,580 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
acl@2.3.2-1build1.1
no fix listed
1
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
acl@2.3.2-2
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/certificates:v19.4.01c38ad710b0c
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitaly:v19.4.0704cd68566af
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.0696d798a5c85
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabdc1a8972c640
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.26645e014f75d
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3aca1bb3d5b7e
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.02256b49461fa
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
acl@2.2.53-6
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
acl@2.3.1-4.el9
0:2.4.0-0.el9_6.1
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
acl@2.3.1-3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
acl@2.3.2-2+b1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
acl@2.3.1-3
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
acl@2.3.1-3
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
acl@2.3.1-3
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.