StackRadar

CVE-2026-54370

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,432
of 17,813 indexed, latest versions
Container images
2,427
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-54370 affecting package acl for versions less than 2.4.0-1

Carried by container images the latest versions of 2,432 of 17,813 indexed charts deploy, on 2,427 images.

Affected packageAffected versionsFixed inImages
acldeb2.2.52-1, 2.2.52-3, 2.2.52-3build1, 2.2.53-6+8 more2.4.0-12,424
aclrpm2.3.1-2.azl32.4.0-13
OSV records
DEBIAN-CVE-2026-54370UBUNTU-CVE-2026-54370AZL-91394ECHO-ae30-49be-9cc5

Charts affected

2,432 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,427 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
acl@2.3.1-3
no fix listed
1
ghcr.io/enderdash-com/enderdash-agent:latest8525a1a67958
acl@2.3.2-1build1.1
no fix listed
1
ghcr.io/ente/web:5ab0c5b4c7a89c4e470ef6f793600da33cebf35d3f4864eb7f11
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/erlkoenig91/prompt-db-backend:1.0.7ab120359810d
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/eslupmi/impulse:v3.7.03ded1b7ebca0
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/esphome/esphome:latest000c5ee5ee96
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
acl@2.3.1-3
no fix listed
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
acl@2.3.1-3
no fix listed
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
acl@2.2.53-6
no fix listed
1
ghcr.io/firecrawl/firecrawl:2.11.35987ebe1dc85b0
acl@2.3.1-3
no fix listed
1
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
acl@2.3.1-3
no fix listed
1
ghcr.io/flanksource/facet:0.1.7237237038be15
acl@2.3.1-3
no fix listed
1
ghcr.io/flanksource/mission-control-ai-assistant:1.0.1229a635cbeeb5
acl@2.3.1-3
no fix listed
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
acl@2.3.1-3
no fix listed
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
acl@2.3.1-3
no fix listed
1
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
acl@2.3.1-3
no fix listed
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
acl@2.3.1-1
no fix listed
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
acl@2.3.1-1
no fix listed
1
ghcr.io/gamosoft/notediscovery:0.31.5c06aa0fa9a85
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
acl@2.3.1-3
no fix listed
1
ghcr.io/getsentry/snuba:26.7.210f8d164109b
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/getsentry/taskbroker:26.7.264d0da74a578
acl@2.3.1-3
no fix listed
1
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/glassflow/glassflow-notifier:v1.0.3d1b0ce10b513
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/goauthentik/server:2026.8.3ab9b4e8cc4ab
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
acl@2.3.1-3
no fix listed
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
acl@2.3.2-1build1.1
no fix listed
1
ghcr.io/grycap/im:latest06a16d4f279f
acl@2.3.2-1build1.1
no fix listed
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
acl@2.2.53-6
no fix listed
1
ghcr.io/hemslo/chat-search:latest39d48995a5bd
acl@2.3.1-3
no fix listed
1
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
acl@2.3.2-1build1.1
no fix listed
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.666db77d7856c
acl@2.3.1-3
no fix listed
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.9.3ad950d30878e
acl@2.3.1-3
no fix listed
1
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
acl@2.3.1-3
no fix listed
1
ghcr.io/hypolia/kanri:0.1.2-rc4fa7d5cc7fb7d
acl@2.3.1-3
no fix listed
1
ghcr.io/icegatetech/icegate-ingest:0.1.1bae3c441894a
acl@2.3.1-3
no fix listed
1
ghcr.io/icegatetech/icegate-maintain:0.1.193e85b2b76ee
acl@2.3.1-3
no fix listed
1
ghcr.io/icegatetech/icegate-query:0.1.17542b4e7fff2
acl@2.3.1-3
no fix listed
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
acl@2.3.1-3
no fix listed
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
acl@2.3.1-3
no fix listed
1
ghcr.io/iisas/domino-rest:latest3009350bfc11
acl@2.3.2-2+b1
no fix listed
1
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
acl@2.3.2-1build1.1
no fix listed
1
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
acl@2.3.1-3
no fix listed
1
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
acl@2.3.1-3
no fix listed
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.