StackRadar

CVE-2026-54370

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,533
of 17,837 indexed, latest versions
Container images
2,512
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-54370 affecting package acl for versions less than 2.4.0-1

Carried by container images the latest versions of 2,533 of 17,837 indexed charts deploy, on 2,512 images.

Affected packageAffected versionsFixed inImages
acldeb2.2.52-1, 2.2.52-3, 2.2.52-3build1, 2.2.53-6+8 more2.4.0-12,509
aclrpm2.3.1-2.azl32.4.0-13
OSV records
DEBIAN-CVE-2026-54370UBUNTU-CVE-2026-54370AZL-91394ECHO-ae30-49be-9cc5

Charts affected

2,533 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,512 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
istio/pilot:1.16.0ac0284d75ec9
acl@2.3.1-1
no fix listed
1
istio/pilot:1.2.9c09319753454
acl@2.2.52-3
no fix listed
1
istio/pilot:1.17.1ce9d87606701
acl@2.3.1-1
no fix listed
1
istio/pilot:1.15.2db08d6963975
acl@2.3.1-1
no fix listed
1
istio/pilot:1.10.3e7e110a421c2
acl@2.2.52-3build1
no fix listed
1
istio/pilot:1.29.1f8b0e412ac4a
acl@2.3.2-1build1.1
no fix listed
1
istio/proxyv2:1.2.90c78be035e98
acl@2.2.52-3
no fix listed
1
istio/proxyv2:1.9.687a9db561d2e
acl@2.2.52-3build1
no fix listed
1
istio/proxyv2:1.10.088c6c693e67a
acl@2.2.52-3build1
no fix listed
1
istio/proxyv2:1.14.1df69c1a7af7c
acl@2.2.53-6
no fix listed
1
istio/ztunnel:1.25.005f3972d80a9
acl@2.3.2-1build1.1
no fix listed
1
itzg/bungeecord:latestde76286c0e73
acl@2.3.2-2
no fix listed
1
itzg/minecraft-server:latest77280d10744f
acl@2.3.2-1build1.1
no fix listed
1
itzg/minecraft-server:2026.9.1e8640538dac5
acl@2.3.2-1build1.1
no fix listed
1
ixsystems/truecommand:3.2.019c218455cd2
acl@2.3.2-2+b1
no fix listed
1
jacobalberty/unifi:v7.1.664a3616625dda
acl@2.2.52-3build1
no fix listed
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
acl@2.2.52-3build1
no fix listed
1
jacobalberty/unifi:5.10.19c409924e2463
acl@2.2.52-3
no fix listed
1
jaedb/iris:latest048cfbf58d57
acl@2.3.1-3
no fix listed
1
jakowenko/double-take:1.6.0b858bac9e32a
acl@2.2.53-6
no fix listed
1
janzo83/serviceexample:latestfb3c4ac36f3e
acl@2.3.1-3
no fix listed
1
jbtronics/part-db1:latestfd68338829ed
acl@2.3.1-3
no fix listed
1
jedi132000/nextapp:latestdc2a81e92f23
acl@2.2.53-6
no fix listed
1
jellyfin/jellyfin:10.11.81694ff069f0c
acl@2.3.2-2+b1
no fix listed
1
jellyfin/jellyfin:10.11.717285f9cce63
acl@2.3.2-2+b1
no fix listed
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
acl@2.3.1-3
no fix listed
1
jellyfin/jellyfin:10.11.6333b64771663
acl@2.3.2-2+b1
no fix listed
1
jellyfin/jellyfin:latest78d3ea1207d1
acl@2.3.2-2+b1
no fix listed
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
acl@2.3.1-3
no fix listed
1
jellyfin/jellyfin:10.10.77ae36aab93ef
acl@2.3.1-3
no fix listed
1
jellyfin/jellyfin:10.10.696b09723b22f
acl@2.3.1-3
no fix listed
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
acl@2.3.1-3
no fix listed
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
acl@2.3.1-3
no fix listed
1
jertel/elastalert2:2.31.03cbf63f9b7dc
acl@2.3.2-2+b1
no fix listed
1
jhipster/jhipster-registry:latest7184525acd4d
acl@2.2.53-6
no fix listed
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
acl@2.3.1-3
no fix listed
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
acl@2.2.53-6
no fix listed
1
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
acl@2.3.1-3
no fix listed
1
jmferrer/azure-devops-agent:latest030f68ec6998
acl@2.2.52-3
no fix listed
1
jodogne/orthanc-plugins:latest6ff510aa29c2
acl@2.3.2-2+b1
no fix listed
1
johly/airtrail:v3.11.19f702b91e0e7
acl@2.3.1-3
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
acl@2.3.1-3
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
acl@2.3.1-1
no fix listed
1
journeyapps/powersync-service:latest413a0c813e96
acl@2.3.2-2+b1
no fix listed
1
jpgouin/openldap:2.6.9-fixbfdd0088c776
acl@2.3.1-3
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
acl@2.3.2-1build1.1
no fix listed
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
acl@2.2.53-6
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
acl@2.2.53-6
no fix listed
1
jupyterhub/k8s-hub:0.9.1ec78bdae0fed
acl@2.2.52-3build1
no fix listed
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
acl@2.2.53-6
no fix listed
1

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.