StackRadar

CVE-2026-54371

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,701
of 17,797 indexed, latest versions
Container images
2,809
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: attr security update

Carried by container images the latest versions of 2,701 of 17,797 indexed charts deploy, on 2,809 images.

Affected packageAffected versionsFixed inImages
attrdeb1:2.4.47-1ubuntu1, 1:2.4.47-2, 1:2.4.47-2build1, 1:2.4.48-5+9 more1:2.4.47-1ubuntu1+esm1, 1:2.4.47-2ubuntu0.16.04.1~esm1, 1:2.4.47-2ubuntu0.18.04.1~esm1, 1:2.4.48-5ubuntu0.1~esm1+4 more2,355
attrrpm2.4.48-3.el8, 2.5.1-3.el9, 2.5.2-1.azl3, 2.5.2-5.el100:2.6.0-1.el8_10, 0:2.6.0-1.el9_8, 0:2.6.0-1.el10_2, 2.6.0-1454
aclrpm2.3.1-2.azl32.4.0-13
OSV records
DEBIAN-CVE-2026-54371UBUNTU-CVE-2026-54371RHSA-2026:56133RHSA-2026:59380RHSA-2026:60226RLSA-2026:56133RLSA-2026:59380RLSA-2026:60226AZL-91400AZL-91424ECHO-e81f-866f-9cb6
Also known as
USN-8691-1

Charts affected

2,701 by stars
ChartLatestAffected imagesRadar Score
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

7,936

Container images carrying it

2,809 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
clickhouse/clickhouse-server:26.8.2:latestfa394da808cc
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
1
cloudtooling/moodle:5.2.3f4f04e0fc401
attr@1:2.5.1-4
no fix listed
1
cloudve/janis-terminal:latestaf56e77ca587
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1
1
cloudve/ttyd:latestd79c1c5881c0
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
attr@1:2.5.1-4
no fix listed
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
attr@1:2.5.1-4
no fix listed
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
attr@1:2.5.1-4
no fix listed
1
cm2network/squad:latest8cba47f53df5
attr@1:2.5.2-3
no fix listed
1
cockroachdb/cockroach:v22.2.91116820f4134
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
cockroachdb/cockroachdb-operator-v2:v1.0.04335d8bcbd3d
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
1
cockroachdb/cockroach-operator:v2.1.0983312754620
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
codedesignplus/ms-emails-grpc:lateste336012bc781
attr@1:2.5.1-4
no fix listed
1
codedesignplus/ms-emails-rest:latestac84661c605e
attr@1:2.5.1-4
no fix listed
1
codedesignplus/ms-licenses-grpc:latest360144457f4d
attr@1:2.5.1-4
no fix listed
1
codedesignplus/ms-modules-grpc:latest3f6aaa32d526
attr@1:2.5.1-4
no fix listed
1
coderenvs/coder-service:1.44.61deffc4670e6
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
coderenvs/timescale:1.44.676fd37fe6830
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
codetogether/codetogether:latest4348c8a38752
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
1
collabora/code:24.04.13.2.101dc4ab83977
attr@1:2.5.1-4
no fix listed
1
collabora/code:23.05.10.1.105299b452f7f
attr@1:2.5.1-4
no fix listed
1
conductoross/conductor:3.31.09fba127693e6
attr@1:2.5.2-3
no fix listed
1
confluentinc/cp-cmf:2.4.1f466f8649aa8
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
confluentinc/cp-kafka:latest0ad069035863
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
confluentinc/cp-kafka:7.5.1dc9b972db002
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
confluentinc/cp-schema-registry:latestf0cfd047a839
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
consensys/teku:latest3a4f5761ae1c
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
consensys/teku:25.4.1bf6ecd2ea716
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
consensys/web3signer:latestf146a51a1ba3
attr@1:2.5.2-4
1:2.5.2-4ubuntu0.1
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
attr@1:2.5.1-4
no fix listed
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
attr@1:2.5.1-4
no fix listed
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
1
cortezaproject/corteza:2024.9.08eb7a26605c9
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
attr@1:2.5.1-4
no fix listed
1
coturn/coturn:4.10.0-r1f4c2af06c3c5
attr@1:2.5.2-3
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.