StackRadar

CVE-2026-54370

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,501
of 17,805 indexed, latest versions
Container images
2,471
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-54370 affecting package acl for versions less than 2.4.0-1

Carried by container images the latest versions of 2,501 of 17,805 indexed charts deploy, on 2,471 images.

Affected packageAffected versionsFixed inImages
acldeb2.2.52-1, 2.2.52-3, 2.2.52-3build1, 2.2.53-6+8 more2.4.0-12,468
aclrpm2.3.1-2.azl32.4.0-13
OSV records
DEBIAN-CVE-2026-54370UBUNTU-CVE-2026-54370AZL-91394ECHO-ae30-49be-9cc5

Charts affected

2,501 by stars
ChartLatestAffected imagesRadar Score
helmmirasys-chart0.1.03 of 4See more

helm mirasys-chart 0.1.0

3 of the 4 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
acl@2.3.2-1build1.1
no fix listed
library/redis:latest298e5b3bc566
acl@2.3.2-2+b1
no fix listed
sepehrmdn/mirasys-assignment:1.0.12567228e33c8
acl@2.3.1-3
no fix listed

Open the chart page →

4,462
simplewebappmlohrVerified publisher1.1.01 of 1See more

simplewebapp mlohr 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,885
mariadbmmontesVerified publisher0.3.01 of 1See more

mariadb mmontes 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/mariadb:10.7.307e06f2e7ae9
acl@2.2.53-6
no fix listed

Open the chart page →

10,135
mongodbmmontesVerified publisher0.5.01 of 1See more

mongodb mmontes 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/mongo:4.4.1305678ae4e5e1
acl@2.2.53-6
no fix listed

Open the chart page →

7,172
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
acl@2.2.53-6
no fix listed

Open the chart page →

11,848
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
acl@2.2.53-6
no fix listed

Open the chart page →

11,848
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
acl@2.2.53-6
no fix listed

Open the chart page →

12,262
backendmojaloop0.1.01 of 6See more

backend mojaloop 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:8.4.5-debian-12-r07089d796fc9b
acl@2.3.1-3
no fix listed

Open the chart page →

16,337
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
acl@2.2.53-6
no fix listed

Open the chart page →

11,633
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
acl@2.2.53-6
no fix listed

Open the chart page →

19,405
reporting-nifi-processor-svcmojaloop0.0.21 of 3See more

reporting-nifi-processor-svc mojaloop 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/mongo:6.0.271a63fc2438e
acl@2.2.53-6
no fix listed

Open the chart page →

6,245
mollysocketmollysocketVerified publisher0.2.81 of 1See more

mollysocket mollysocket 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
acl@2.3.1-3
no fix listed

Open the chart page →

3,069
mollysocketmollysocket-wrenixVerified publisher0.1.141 of 2See more

mollysocket mollysocket-wrenix 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/mollyim/mollysocket:1.7.1c675622546a4
acl@2.3.1-3
no fix listed

Open the chart page →

2,550
mongo-compassmongo-compass-webVerified publisher1.1.41 of 1See more

mongo-compass mongo-compass-web 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.1f4f8fe4e21f1
acl@2.3.1-3
no fix listed

Open the chart page →

1,808
mongo-compassmongo-compass-web-helm1.1.01 of 1See more

mongo-compass mongo-compass-web-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.054f2112602ee
acl@2.3.1-3
no fix listed

Open the chart page →

2,446
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
acl@2.2.53-6
no fix listed

Open the chart page →

5,244
moodlemoodle1.0.31 of 2See more

moodle moodle 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
cloudtooling/moodle:5.2.3f4f04e0fc401
acl@2.3.1-3
no fix listed

Open the chart page →

4,018
camera-viewermoreillonVerified publisher0.2.12 of 4See more

camera-viewer moreillon 0.2.1

2 of the 4 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
acl@2.3.1-1
no fix listed
moreillon/camera-viewer:lateste418cc694bd5
acl@2.3.1-3
no fix listed

Open the chart page →

11,718
group-managermoreillonVerified publisher0.4.42 of 3See more

group-manager moreillon 0.4.4

2 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
acl@2.3.1-1
no fix listed
moreillon/group-manager-front:v3.3.1c9f85db3baa5
acl@2.3.1-3
no fix listed

Open the chart page →

9,909
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
acl@2.3.1-1
no fix listed

Open the chart page →

11,037
user-manager-mongodbmoreillonVerified publisher0.6.23 of 4See more

user-manager-mongodb moreillon 0.6.2

3 of the 4 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
acl@2.3.1-1
no fix listed
moreillon/user-manager-front:v5.0.3b067dbbbb6af
acl@2.3.1-3
no fix listed
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
acl@2.3.1-3
no fix listed

Open the chart page →

25,919
user-manager-neo4jmoreillonVerified publisher0.9.74 of 6See more

user-manager-neo4j moreillon 0.9.7

4 of the 6 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
acl@2.3.1-1
no fix listed
moreillon/group-manager-front:v3.3.1c9f85db3baa5
acl@2.3.1-3
no fix listed
moreillon/user-manager:v5.0.2e1c9bfab5c16
acl@2.3.1-3
no fix listed
moreillon/user-manager-front:v5.1.06597e6b98d21
acl@2.3.1-3
no fix listed

Open the chart page →

30,586
genericmorremeyer8.0.01 of 1See more

generic morremeyer 8.0.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/nginx:1.25.167f9a4f10d14
acl@2.3.1-3
no fix listed

Open the chart page →

6,858
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
acl@2.2.53-6
no fix listed

Open the chart page →

101,289
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
acl@2.2.53-6
no fix listed

Open the chart page →

15,975
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2ebf761c7d437
acl@2.3.2-1build1.1
no fix listed

Open the chart page →

5,738
codimdmt1905027.2.21 of 3See more

codimd mt190502 7.2.2

1 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,688
commafeedmt1905028.2.02 of 3See more

commafeed mt190502 8.2.0

2 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
athou/commafeed:6.2.0-postgresql5e388351df1a
acl@2.3.2-2+b1
no fix listed
library/postgres:184ef4dbc939d6
acl@2.3.2-2+b1
no fix listed

Open the chart page →

3,802
filestashmt1905024.0.01 of 1See more

filestash mt190502 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
machines/filestash:latest0b8fc005e52e
acl@2.3.2-2+b1
no fix listed

Open the chart page →

3,606
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
acl@2.3.1-3
no fix listed

Open the chart page →

5,037
keycloakmt1905021.4.61 of 3See more

keycloak mt190502 1.4.6

1 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
acl@2.3.2-2+b1
no fix listed

Open the chart page →

2,993
memosmt1905027.3.21 of 3See more

memos mt190502 7.3.2

1 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
acl@2.3.2-2+b1
no fix listed

Open the chart page →

2,657
minifluxmt1905021.1.61 of 3See more

miniflux mt190502 1.1.6

1 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
acl@2.3.2-2+b1
no fix listed

Open the chart page →

2,733
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
acl@2.2.53-6
no fix listed

Open the chart page →

6,673
open-webuimt1905022.3.101 of 3See more

open-webui mt190502 2.3.10

1 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,688
paperless-ngxmt1905027.6.143 of 4See more

paperless-ngx mt190502 7.6.14

3 of the 4 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
acl@2.3.2-2+b1
no fix listed
library/redis:771da9275c5f3
acl@2.3.1-3
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
acl@2.3.2-2+b1
no fix listed

Open the chart page →

12,222
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
acl@2.3.2-2+b1
no fix listed

Open the chart page →

4,076
vaultwardenmt1905027.3.42 of 3See more

vaultwarden mt190502 7.3.4

2 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
acl@2.3.2-2+b1
no fix listed
vaultwarden/server:1.35.443498a94b22f
acl@2.3.2-2+b1
no fix listed

Open the chart page →

4,819
vikunjamt1905027.1.21 of 3See more

vikunja mt190502 7.1.2

1 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
acl@2.3.2-2+b1
no fix listed

Open the chart page →

3,031
backendmulti-chart-app0.1.01 of 1See more

backend multi-chart-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,885
frontendmulti-chart-app0.1.01 of 1See more

frontend multi-chart-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
acl@2.3.2-2+b1
no fix listed

Open the chart page →

1,885
mongodbmulti-chart-app0.1.01 of 1See more

mongodb multi-chart-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/mongo:7b096b4cb9269
acl@2.3.1-1
no fix listed

Open the chart page →

2,007
my-multi-chart-appmulti-chart-app0.1.02 of 2See more

my-multi-chart-app multi-chart-app 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/mongo:7b096b4cb9269
acl@2.3.1-1
no fix listed
library/nginx:latest05b8cb60c354
acl@2.3.2-2+b1
no fix listed

Open the chart page →

3,892
mum-discord-botmum-discord-botVerified publisher0.3.71 of 1See more

mum-discord-bot mum-discord-bot 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
acl@2.3.1-3
no fix listed

Open the chart page →

13,826
devops-demomungari-development-charts1.0.42 of 4See more

devops-demo mungari-development-charts 1.0.4

2 of the 4 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
acl@2.3.2-2+b1
no fix listed
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
acl@2.2.52-3build1
no fix listed

Open the chart page →

9,030
pagesmuthu-pages1.0.02 of 3See more

pages muthu-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
acl@2.2.53-6
no fix listed
flyway/flyway:6.4.422d97ceb0c47
acl@2.2.52-3build1
no fix listed

Open the chart page →

20,279
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
acl@2.3.1-1
no fix listed

Open the chart page →

101,985
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
acl@2.3.1-1
no fix listed

Open the chart page →

101,985
clickhousemyaVerified publisher0.2403.11 of 1See more

clickhouse mya 0.2403.1

1 of the 1 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.2ed9640bfff07
acl@2.2.53-6
no fix listed

Open the chart page →

3,620
cognativemyaVerified publisher0.2403.31 of 3See more

cognative mya 0.2403.3

1 of the 3 container images this version deploys carry CVE-2026-54370.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.2ed9640bfff07
acl@2.2.53-6
no fix listed

Open the chart page →

7,406

Container images carrying it

2,471 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
acl@2.3.2-1build1.1
no fix listed
1
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
acl@2.3.2-2
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
acl@2.3.1-3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
acl@2.3.2-2+b1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
acl@2.2.53-6
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
acl@2.3.1-3
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
acl@2.3.1-3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
acl@2.3.2-2+b1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
acl@2.3.1-3
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
acl@2.3.1-3
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
acl@2.3.1-3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
acl@2.3.1-3
no fix listed
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.