StackRadar

CVE-2026-54370

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,524
of 17,837 indexed, latest versions
Container images
2,490
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-54370 affecting package acl for versions less than 2.4.0-1

Carried by container images the latest versions of 2,524 of 17,837 indexed charts deploy, on 2,490 images.

Affected packageAffected versionsFixed inImages
acldeb2.2.52-1, 2.2.52-3, 2.2.52-3build1, 2.2.53-6+8 more2.4.0-12,487
aclrpm2.3.1-2.azl32.4.0-13
OSV records
DEBIAN-CVE-2026-54370UBUNTU-CVE-2026-54370AZL-91394ECHO-ae30-49be-9cc5

Charts affected

2,524 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,490 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/redis83edc2b8e9ff
acl@2.3.1-3
no fix listed
1
library/redis:8.4a17e6c4fec82
acl@2.3.2-2+b1
no fix listed
1
library/redis:8.0.2b43d2dcbbdb1
acl@2.3.1-3
no fix listed
1
library/redis:7.4.1bb142a9c18ac
acl@2.3.1-3
no fix listed
1
library/redis:8.0.3be0a135f1955
acl@2.3.1-3
no fix listed
1
library/redis:6.2d2ad7b21cafa
acl@2.3.1-3
no fix listed
1
library/redis:8.2.3d31852005202
acl@2.3.1-3
no fix listed
1
library/redmine:6.1.204ac44a2595b
acl@2.3.2-2+b1
no fix listed
1
library/sonarqube:10.7.0-community0842dcd4c8f8
acl@2.3.1-1
no fix listed
1
library/sonarqube:10.0.0-communityef9723cf4fe4
acl@2.3.1-1
no fix listed
1
library/telegraf:1.27507a3eecf809
acl@2.3.1-3
no fix listed
1
library/tomcat:11.0.25-jdk17-temurin-nobledbde329dcbfa
acl@2.3.2-1build1.1
no fix listed
1
library/ubuntu:bionic152dc042452c
acl@2.2.52-3build1
no fix listed
1
library/ubuntu:22.04b8b6ee6aa931
acl@2.3.1-1
no fix listed
1
library/varnish:7.5.04d0bb287d87b
acl@2.3.1-3
no fix listed
1
library/wordpress:7.1.1-apache51464c8fdb10
acl@2.3.2-2+b1
no fix listed
1
library/wordpress:6.4.3-apache8ae66efb09a2
acl@2.3.1-3
no fix listed
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
acl@2.3.2-2+b1
no fix listed
1
library/wordpress:7.1.0-apacheedeeae67330a
acl@2.3.2-2+b1
no fix listed
1
library/wordpress:php8.1-apachef73396626d2f
acl@2.3.2-2+b1
no fix listed
1
library/xwiki:lts-postgres-tomcat9b8142bce157
acl@2.3.2-1build1.1
no fix listed
1
library/zookeeper:3.8-temurin55d1e5b2e601
acl@2.3.1-1
no fix listed
1
library/zookeeper:3.9.4dfa9ba46d14b
acl@2.3.1-1
no fix listed
1
libretranslate/libretranslate:v1.9.61de2d7056bb8
acl@2.3.1-3
no fix listed
1
lightbend/curl:7.47.0b0c9894ac8dd
acl@2.2.52-3
no fix listed
1
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
acl@2.2.52-3build1
no fix listed
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
acl@2.2.52-3build1
no fix listed
1
linuxserver/calibre-web:0.6.24241009026e6f
acl@2.3.2-1build1.1
no fix listed
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
acl@2.2.53-6
no fix listed
1
linuxserver/code-server:4.10.1a5e43a05ae79
acl@2.3.1-1
no fix listed
1
linuxserver/codimd:latestb801bbcf6386
acl@2.2.52-3build1
no fix listed
1
linuxserver/deluge:18.04.10ac871624394
acl@2.2.52-3build1
no fix listed
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
acl@2.2.52-3build1
no fix listed
1
linuxserver/foldingathome:7.6.219a997426d71e
acl@2.3.2-1build1
no fix listed
1
linuxserver/foldingathome:8.5.6ebb32940e4bb
acl@2.3.2-1build1.1
no fix listed
1
linuxserver/jellyfin:10.7.72427dde159a2
acl@2.2.53-6
no fix listed
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
acl@2.2.52-3build1
no fix listed
1
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
acl@2.2.52-3build1
no fix listed
1
linuxserver/plex:1.43.22785a6ad64d3
acl@2.3.2-1build1.1
no fix listed
1
linuxserver/plex:1.25.24a13ced2326c
acl@2.2.53-6
no fix listed
1
linuxserver/unifi-controller:8.0.240ae315a3a456
acl@2.2.53-6
no fix listed
1
linuxserver/unifi-controller:7.3.83ab105cc50322
acl@2.2.53-6
no fix listed
1
linuxserver/unifi-network-application:10.6.106-ls1467f15f34937ce
acl@2.3.2-2
no fix listed
1
lis314/project-zomboid-docker:latestaa2089c37920
acl@2.3.1-3
no fix listed
1
litmuschaos/mongo:4.2.899961210d467
acl@2.2.52-3build1
no fix listed
1
livekit/ingress:v1.2.21ab01641b366
acl@2.3.1-1
no fix listed
1
lmacka/snappass:2.1.293f5c048b7d4
acl@2.3.2-2+b1
no fix listed
1
localstack/localstack:3.19d278167f2b7
acl@2.3.1-3
no fix listed
1
locustio/locust:2.24.151d866285170
acl@2.3.1-3
no fix listed
1
logiqai/flash:v3.10.265b996bc7bdc
acl@2.3.1-3
no fix listed
1

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.