StackRadar

CVE-2026-54370

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,489
of 17,821 indexed, latest versions
Container images
2,480
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-54370 affecting package acl for versions less than 2.4.0-1

Carried by container images the latest versions of 2,489 of 17,821 indexed charts deploy, on 2,480 images.

Affected packageAffected versionsFixed inImages
acldeb2.2.52-1, 2.2.52-3, 2.2.52-3build1, 2.2.53-6+8 more2.4.0-12,477
aclrpm2.3.1-2.azl32.4.0-13
OSV records
DEBIAN-CVE-2026-54370UBUNTU-CVE-2026-54370AZL-91394ECHO-ae30-49be-9cc5

Charts affected

2,489 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,480 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
jedi132000/nextapp:latestdc2a81e92f23
acl@2.2.53-6
no fix listed
1
jellyfin/jellyfin:10.11.81694ff069f0c
acl@2.3.2-2+b1
no fix listed
1
jellyfin/jellyfin:10.11.717285f9cce63
acl@2.3.2-2+b1
no fix listed
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
acl@2.3.1-3
no fix listed
1
jellyfin/jellyfin:10.11.6333b64771663
acl@2.3.2-2+b1
no fix listed
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
acl@2.3.1-3
no fix listed
1
jellyfin/jellyfin:10.10.77ae36aab93ef
acl@2.3.1-3
no fix listed
1
jellyfin/jellyfin:10.10.696b09723b22f
acl@2.3.1-3
no fix listed
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
acl@2.3.1-3
no fix listed
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
acl@2.3.1-3
no fix listed
1
jertel/elastalert2:2.31.03cbf63f9b7dc
acl@2.3.2-2+b1
no fix listed
1
jhipster/jhipster-registry:latest7184525acd4d
acl@2.2.53-6
no fix listed
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
acl@2.3.1-3
no fix listed
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
acl@2.2.53-6
no fix listed
1
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
acl@2.3.1-3
no fix listed
1
jmferrer/azure-devops-agent:latest030f68ec6998
acl@2.2.52-3
no fix listed
1
jodogne/orthanc-plugins:latest6ff510aa29c2
acl@2.3.2-2+b1
no fix listed
1
johly/airtrail:v3.11.19f702b91e0e7
acl@2.3.1-3
no fix listed
1
joplin/server:latest3f7b852959aa
acl@2.3.1-3
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
acl@2.3.1-3
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
acl@2.3.1-1
no fix listed
1
journeyapps/powersync-service:latest413a0c813e96
acl@2.3.2-2+b1
no fix listed
1
jpgouin/openldap:2.6.9-fixbfdd0088c776
acl@2.3.1-3
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
acl@2.3.2-1build1.1
no fix listed
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
acl@2.2.53-6
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
acl@2.2.53-6
no fix listed
1
jupyterhub/k8s-hub:0.9.1ec78bdae0fed
acl@2.2.52-3build1
no fix listed
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
acl@2.2.53-6
no fix listed
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
acl@2.3.2-1build1
no fix listed
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
acl@2.3.1-1
no fix listed
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
acl@2.3.1-1
no fix listed
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
acl@2.3.1-1
no fix listed
1
kayrosuno/kping:latestf3bd44b29b0d
acl@2.3.2-1build1.1
no fix listed
1
kennethreitz/httpbin:latest599fe5e50731
acl@2.2.52-3build1
no fix listed
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
acl@2.2.53-6
no fix listed
1
kimai/kimai2:2.67.03084f1e5ecdc
acl@2.3.1-3
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
acl@2.3.1-3
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
acl@2.3.2-2+b1
no fix listed
1
kixote/typemill4e9dff179519
acl@2.3.2-2+b1
no fix listed
1
kixote/typemill628f79a08cc7
acl@2.3.2-2+b1
no fix listed
1
knspar/phronetis:0.1.4609499d2dc91a
acl@2.3.2-1build1.1
no fix listed
1
knspar/phronetis-operator:0.1.60c4f0543ee58
acl@2.3.1-3
no fix listed
1
kong/httpbin:latesta6ac46531193
acl@2.3.1-1
no fix listed
1
kong/kong:3.9.16addf50e6bd8
acl@2.3.2-1build1.1
no fix listed
1
kong/kong-ai-gateway:2.0.3367ed5985b76
acl@2.3.2-1build1.1
no fix listed
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
acl@2.3.1-1
no fix listed
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
acl@2.2.53-6
no fix listed
1
krontechnology/aapm-service:1.1.39dd602db8baa
acl@2.3.1-1
no fix listed
1
kserve/models-web-app:v0.13.073486345a602
acl@2.3.1-3
no fix listed
1
kubeflownotebookswg/jupyter-web-app:v1.9.2afb52057c997
acl@2.3.1-3
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.