StackRadar

CVE-2026-54370

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,501
of 17,805 indexed, latest versions
Container images
2,471
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-54370 affecting package acl for versions less than 2.4.0-1

Carried by container images the latest versions of 2,501 of 17,805 indexed charts deploy, on 2,471 images.

Affected packageAffected versionsFixed inImages
acldeb2.2.52-1, 2.2.52-3, 2.2.52-3build1, 2.2.53-6+8 more2.4.0-12,468
aclrpm2.3.1-2.azl32.4.0-13
OSV records
DEBIAN-CVE-2026-54370UBUNTU-CVE-2026-54370AZL-91394ECHO-ae30-49be-9cc5

Charts affected

2,501 by stars
ChartLatestAffected imagesRadar Score
fineractfineract-openshift0.1.12 of 4See more

fineract fineract-openshift 0.1.1

2 of the 4 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/mariadb:11.4611a2fcc5fa7
acl@2.3.2-1build1.1
no fix listed
library/nginx:latest05b8cb60c354
acl@2.3.2-2+b1
no fix listed

Open the chart page →

7,905
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
acl@2.3.2-2+b1
no fix listed

Open the chart page →

5,246
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
acl@2.3.2-2+b1
no fix listed
fireflyiii/data-importer:version-2.2.3ab52bf932546
acl@2.3.2-2+b1
no fix listed

Open the chart page →

10,674
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
acl@2.3.2-2+b1
no fix listed

Open the chart page →

5,036
flask-contactsfirst-idror-chart1.0.12 of 3See more

flask-contacts first-idror-chart 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
acl@2.3.2-2+b1
no fix listed
shashkist/flask-contacts-app:latest581de1fd6084
acl@2.3.1-3
no fix listed

Open the chart page →

5,884
business-api-ecosystemfiware1.1.02 of 4See more

business-api-ecosystem fiware 1.1.0

2 of the 4 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
acl@2.2.53-6
no fix listed
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
acl@2.3.1-3
no fix listed

Open the chart page →

112,968
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
acl@2.3.1-3
no fix listed

Open the chart page →

1,910
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
acl@2.3.1-3
no fix listed

Open the chart page →

1,551
apm-hubflanksourceVerified publisher0.0.472 of 2See more

apm-hub flanksource 0.0.47

2 of the 2 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
flanksource/apm-hub:v0.0.471dacc3195bf9
acl@2.3.1-1
no fix listed
library/postgres:14156f0b253fd6
acl@2.3.2-2+b1
no fix listed

Open the chart page →

6,210
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

5,544
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
acl@2.3.1-3
no fix listed

Open the chart page →

4,707
facetflanksourceVerified publisher0.1.721 of 1See more

facet flanksource 0.1.72

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/flanksource/facet:0.1.7237237038be15
acl@2.3.1-3
no fix listed

Open the chart page →

21,416
flanksource-uiflanksourceVerified publisher1.4.3191 of 1See more

flanksource-ui flanksource 1.4.319

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.319953948a194c9
acl@2.3.1-3
no fix listed

Open the chart page →

2,610
mission-controlflanksourceVerified publisher0.1.3382 of 8See more

mission-control flanksource 0.1.338

2 of the 8 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
acl@2.3.1-3
no fix listed
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
acl@2.3.1-3
no fix listed

Open the chart page →

9,013
mission-control-ai-assistantflanksourceVerified publisher1.0.121 of 1See more

mission-control-ai-assistant flanksource 1.0.12

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/flanksource/mission-control-ai-assistant:1.0.1229a635cbeeb5
acl@2.3.1-3
no fix listed

Open the chart page →

1,343
flask-contactsflask-contacts-generic1.0.12 of 3See more

flask-contacts flask-contacts-generic 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
acl@2.3.2-2+b1
no fix listed
shashkist/flask-contacts-app:latest581de1fd6084
acl@2.3.1-3
no fix listed

Open the chart page →

5,884
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
acl@2.3.1-3
no fix listed

Open the chart page →

4,119
flinkflink0.5.11 of 1See more

flink flink 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/flink:1.14.6-scala_2.122461f02672b3
acl@2.3.1-1
no fix listed

Open the chart page →

5,716
floriapp-mongodbfloriapp1.0.01 of 1See more

floriapp-mongodb floriapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
acl@2.2.52-3build1
no fix listed

Open the chart page →

8,069
fluentd-aggregatorfluentd-aggregatorOfficialVerified publisher1.0.01 of 2See more

fluentd-aggregator fluentd-aggregator 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,797
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
acl@2.3.1-3
no fix listed

Open the chart page →

3,588
dump1090fnzv0.2.81 of 1See more

dump1090 fnzv 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
fnzv/dump1090:latestb3079b95c336
acl@2.3.1-1
no fix listed

Open the chart page →

4,157
fr24feederfnzv0.1.21 of 1See more

fr24feeder fnzv 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest917e53402d51
acl@2.3.2-2+b1
no fix listed

Open the chart page →

2,482
mod-z3950folio-org0.1.31 of 1See more

mod-z3950 folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
folioci/mod-z3950:latest2493041ce880
acl@2.3.2-2+b1
no fix listed

Open the chart page →

2,594
ledgerformance1.2.01 of 1See more

ledger formance 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
acl@2.3.1-1
no fix listed

Open the chart page →

4,681
ff-testfrankframework0.7.61 of 2See more

ff-test frankframework 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/postgres:17-bookworm051f7b7b3abd
acl@2.3.1-3
no fix listed

Open the chart page →

1,798
frank2examplefrankframework0.7.41 of 2See more

frank2example frankframework 0.7.4

1 of the 2 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/postgres:17-bookworm051f7b7b3abd
acl@2.3.1-3
no fix listed

Open the chart page →

1,798
plexfydrah-charts2.2.01 of 1See more

plex fydrah-charts 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
acl@2.2.52-3
no fix listed

Open the chart page →

9,003
passboltg0dscookie0.5.21 of 2See more

passbolt g0dscookie 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/mariadb:10.79a48ac9f196f
acl@2.2.53-6
no fix listed

Open the chart page →

8,022
changedetection-iogabe565Verified publisher0.12.01 of 2See more

changedetection-io gabe565 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:latestecacd9fd0c66
acl@2.3.1-3
no fix listed

Open the chart page →

2,687
esphomegabe565Verified publisher0.15.01 of 1See more

esphome gabe565 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:latest000c5ee5ee96
acl@2.3.2-2+b1
no fix listed

Open the chart page →

3,220
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
acl@2.3.1-3
no fix listed

Open the chart page →

13,370
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
acl@2.3.2-2+b1
no fix listed

Open the chart page →

6,478
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
acl@2.2.53-6
no fix listed

Open the chart page →

6,016
accumulogaffer2.2.12 of 4See more

accumulo gaffer 2.2.1

2 of the 4 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
acl@2.3.2-1build1
no fix listed
gchq/hdfs:3.3.35ec58edbb2db
acl@2.3.2-1build1
no fix listed

Open the chart page →

17,123
gaffer-road-trafficgaffer2.2.11 of 8See more

gaffer-road-traffic gaffer 2.2.1

1 of the 8 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
acl@2.3.2-1build1
no fix listed

Open the chart page →

9,458
garge-apigargeVerified publisher0.1.551 of 1See more

garge-api garge 0.1.55

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
sondresjo/garge-api:v2.12.6f41e452800ff
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

1,104
garge-appgargeVerified publisher0.1.471 of 1See more

garge-app garge 0.1.47

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
sondresjo/garge-app:v1.20.70382ebf9dfc8
acl@2.3.1-3
no fix listed

Open the chart page →

1,885
garge-operatorgargeVerified publisher0.1.341 of 1See more

garge-operator garge 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
sondresjo/garge-operator:v1.9.416cb6643dae6
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

711
pagesgary-pages1.0.02 of 3See more

pages gary-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
acl@2.2.53-6
no fix listed
flyway/flyway:6.4.422d97ceb0c47
acl@2.2.52-3build1
no fix listed

Open the chart page →

20,279
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
acl@2.2.53-6
no fix listed

Open the chart page →

18,158
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
acl@2.2.53-6
no fix listed

Open the chart page →

14,888
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
acl@2.2.52-3build1
no fix listed

Open the chart page →

19,294
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
acl@2.2.53-6
no fix listed

Open the chart page →

16,253
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
acl@2.2.52-3build1
no fix listed

Open the chart page →

13,611
dizquetvgeek-cookbookVerified publisher4.4.21 of 1See more

dizquetv geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
vexorian/dizquetv:1.4.37e2b99844a5c
acl@2.2.52-3build1
no fix listed

Open the chart page →

4,909
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
acl@2.2.53-6
no fix listed

Open the chart page →

87,491
duplicatigeek-cookbookVerified publisher5.4.21 of 1See more

duplicati geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/duplicati:latesta792931146b4
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

1,812
embygeek-cookbookVerified publisher3.4.21 of 1See more

emby geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
acl@2.2.53-6
no fix listed

Open the chart page →

8,611
factoriogeek-cookbookVerified publisher1.2.21 of 2See more

factorio geek-cookbook 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
factoriotools/factorio:stablec6092b912bd1
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,480

Container images carrying it

2,471 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
acl@2.3.2-1build1.1
no fix listed
1
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
acl@2.3.2-2
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
acl@2.2.53-6
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
acl@2.3.1-3
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
acl@2.3.1-3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
acl@2.3.2-2+b1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
acl@2.3.1-3
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
acl@2.3.1-3
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
acl@2.3.1-3
no fix listed
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.