StackRadar

CVE-2026-54371

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,685
of 17,792 indexed, latest versions
Container images
2,785
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: attr security update

Carried by container images the latest versions of 2,685 of 17,792 indexed charts deploy, on 2,785 images.

Affected packageAffected versionsFixed inImages
attrdeb1:2.4.47-1ubuntu1, 1:2.4.47-2, 1:2.4.47-2build1, 1:2.4.48-5+9 more1:2.4.47-1ubuntu1+esm1, 1:2.4.47-2ubuntu0.16.04.1~esm1, 1:2.4.47-2ubuntu0.18.04.1~esm1, 1:2.4.48-5ubuntu0.1~esm1+4 more2,331
attrrpm2.4.48-3.el8, 2.5.1-3.el9, 2.5.2-1.azl3, 2.5.2-5.el100:2.6.0-1.el8_10, 0:2.6.0-1.el9_8, 0:2.6.0-1.el10_2, 2.6.0-1454
aclrpm2.3.1-2.azl32.4.0-13
OSV records
DEBIAN-CVE-2026-54371UBUNTU-CVE-2026-54371RHSA-2026:56133RHSA-2026:59380RHSA-2026:60226RLSA-2026:56133RLSA-2026:59380RLSA-2026:60226AZL-91400AZL-91424ECHO-e81f-866f-9cb6
Also known as
USN-8691-1

Charts affected

2,685 by stars
ChartLatestAffected imagesRadar Score
deploy-elibrarydeploy-elibrary-helm0.1.01 of 1See more

deploy-elibrary deploy-elibrary-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
psorab/elibrary:latest53b68896c4ce
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

7,254
deploy-elibrarydeploy-elibrary-oo0.1.01 of 1See more

deploy-elibrary deploy-elibrary-oo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
jedi132000/nextapp:latestdc2a81e92f23
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

8,149
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

14,920
apachedevops0.1.02 of 4See more

apache devops 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/mariadb:10.8.30abf60f81588
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
ghcr.io/codingducksrl/laravel:8.15be52524664c
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

30,156
laraveldevops0.10.32 of 4See more

laravel devops 0.10.3

2 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/mariadb:10.9.4fbb8456ebdb1
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
ghcr.io/codingducksrl/laravel:8.15be52524664c
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

29,157
wordpressdevops0.12.01 of 4See more

wordpress devops 0.12.0

1 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/mariadb:10.8.30abf60f81588
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

13,039
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
attr@1:2.5.1-4
no fix listed

Open the chart page →

9,685
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

13,011
calertdevtron0.0.11 of 1See more

calert devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

4,690
devtron-enterprisedevtron48.0.08 of 28See more

devtron-enterprise devtron 48.0.0

8 of the 28 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
attr@1:2.5.1-4
no fix listed
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
attr@1:2.4.47-2
1:2.4.47-2ubuntu0.16.04.1~esm1
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
attr@1:2.5.1-4
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
attr@1:2.5.1-4
no fix listed

Open the chart page →

68,695
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

4,972
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

11,959
migration-incluster-cddevtron0.10.01 of 1See more

migration-incluster-cd devtron 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
attr@1:2.5.1-4
no fix listed

Open the chart page →

3,908
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
attr@1:2.5.1-4
no fix listed

Open the chart page →

9,685
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

13,011
calertdevtron-labs0.0.11 of 1See more

calert devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

4,690
calicodevtron-labs0.1.11 of 4See more

calico devtron-labs 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

10,094
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.08 of 28See more

devtron-enterprise devtron-labs 48.0.0

8 of the 28 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
attr@1:2.5.1-4
no fix listed
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
attr@1:2.4.47-2
1:2.4.47-2ubuntu0.16.04.1~esm1
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
attr@1:2.5.1-4
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
attr@1:2.5.1-4
no fix listed

Open the chart page →

68,695
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

4,972
devtron-operatordevtron-labs0.23.35 of 11See more

devtron-operator devtron-labs 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
attr@1:2.5.1-4
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1
quay.io/devtron/postgres:14.91b594392f7cb
attr@1:2.5.1-4
no fix listed

Open the chart page →

33,180
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

11,959
migration-incluster-cddevtron-labs0.10.01 of 1See more

migration-incluster-cd devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
attr@1:2.5.1-4
no fix listed

Open the chart page →

3,908
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.03 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1
library/rabbitmq:3-managemente582c0bc7766
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
oscarsotosanchez/weatherservice:v1.0911ec961d10b
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1

Open the chart page →

27,620
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
attr@1:2.5.1-4
no fix listed

Open the chart page →

4,064
difydify1.0.03 of 4See more

dify dify 1.0.0

3 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
attr@1:2.5.1-4
no fix listed
langgenius/dify-plugin-daemon:main-localda995c129e2f
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
langgenius/dify-sandbox:0.2.009b7e8705673
attr@1:2.5.1-4
no fix listed

Open the chart page →

19,399
pagesdipak1.0.02 of 3See more

pages dipak 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
flyway/flyway:6.4.422d97ceb0c47
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1

Open the chart page →

20,242
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
attr@1:2.5.2-3
no fix listed

Open the chart page →

7,501
alertifydjjudas21Verified publisher0.1.01 of 1See more

alertify djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
djjudas21/alertify:0.1.0ba22be670c37
attr@1:2.5.1-4
no fix listed

Open the chart page →

2,395
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
attr@1:2.5.1-4
no fix listed

Open the chart page →

7,203
ownclouddjjudas21Verified publisher0.3.233 of 3See more

owncloud djjudas21 0.3.23

3 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
attr@1:2.5.1-4
no fix listed
owncloud/server:10.16.3b3f9efdcd7f7
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
valkey/valkey:8.1.481db6d39e1bb
attr@1:2.5.2-3
no fix listed

Open the chart page →

10,144
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1

Open the chart page →

17,053
spoolmandjjudas21Verified publisher0.1.81 of 1See more

spoolman djjudas21 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.24.042135965c42d
attr@1:2.5.1-4
no fix listed

Open the chart page →

1,850
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
attr@1:2.5.2-3
no fix listed

Open the chart page →

5,197
webtreesdjjudas21Verified publisher3.0.01 of 1See more

webtrees djjudas21 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
attr@1:2.5.2-3
no fix listed

Open the chart page →

5,998
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
attr@1:2.5.1-4
no fix listed

Open the chart page →

14,700
dnation-kubernetes-jsonnet-translatordnationcloud2.0.11 of 1See more

dnation-kubernetes-jsonnet-translator dnationcloud 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
attr@1:2.5.1-4
no fix listed

Open the chart page →

3,839
dnation-kubernetes-monitoringdnationcloud3.0.21 of 1See more

dnation-kubernetes-monitoring dnationcloud 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
attr@1:2.5.1-4
no fix listed

Open the chart page →

3,839
dnation-kubernetes-monitoring-stackdnationcloud4.0.23 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

3 of the 17 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
attr@1:2.5.1-4
no fix listed
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

21,744
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1

Open the chart page →

8,995
dnsmasq-k8sdnsmasq-k8s1.4.11 of 1See more

dnsmasq-k8s dnsmasq-k8s 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
attr@1:2.5.2-3
no fix listed

Open the chart page →

3,066
dominodomino-iisasVerified publisher0.3.13 of 3See more

domino domino-iisas 0.3.1

3 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
attr@1:2.5.2-3
no fix listed
ghcr.io/iisas/domino-frontend:k8s8e53861be292
attr@1:2.5.1-4
no fix listed
ghcr.io/iisas/domino-rest:latest3009350bfc11
attr@1:2.5.2-3
no fix listed

Open the chart page →

10,340
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

3,185
exim4dossif0.2.01 of 1See more

exim4 dossif 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
tianon/exim4:latestb489049cdbca
attr@1:2.5.2-3
no fix listed

Open the chart page →

1,384
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

24,962
healthchecksdoubanVerified publisher1.0.101 of 2See more

healthchecks douban 1.0.10

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
healthchecks/healthchecks:latestaa08a61b0dcf
attr@1:2.5.2-3
no fix listed

Open the chart page →

1,731
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

11,827
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.03 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1
library/rabbitmq:3-managemente582c0bc7766
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
oscarsotosanchez/weatherservice:v1.0911ec961d10b
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1

Open the chart page →

24,726
drogue-cloud-coredrogue-iotVerified publisher0.7.1120 of 22See more

drogue-cloud-core drogue-iot 0.7.11

20 of the 22 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
quay.io/keycloak/keycloak:20.0054ef67eb7da
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

55,990
drogue-cloud-examplesdrogue-iotVerified publisher0.7.114 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

4 of the 6 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
ghcr.io/ctron/kubectl:1.25e37d61b5277c
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

30,753

Container images carrying it

2,785 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
splunk/splunk-operator:2.0.0c4e0d3146226
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
spy86/rabbitmq-stomp:latestea649101b9fb
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
sslhep/servicex_app:v1.8.51d12f943cec5
attr@1:2.5.2-3
no fix listed
1
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
attr@1:2.5.2-3
no fix listed
1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
attr@1:2.5.2-3
no fix listed
1
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
attr@1:2.5.2-3
no fix listed
1
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
attr@1:2.5.2-3
no fix listed
1
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
attr@1:2.5.2-3
no fix listed
1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
attr@1:2.5.2-3
no fix listed
1
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
attr@1:2.5.2-3
no fix listed
1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
attr@1:2.5.2-3
no fix listed
1
stackstorm/st2actionrunner:3.888235ba70cad
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
stackstorm/st2api:3.86f56d239d280
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
stackstorm/st2auth:3.833ecfda16608
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
stackstorm/st2notifier:3.8f190a6212195
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
stackstorm/st2rulesengine:3.8259503496ff9
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
stackstorm/st2scheduler:3.8b1de2055c362
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
stackstorm/st2stream:3.81c8904a3bf67
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
stackstorm/st2timersengine:3.81bf35bfaf00c
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
stackstorm/st2web:3.809989a26c8b7
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
stackstorm/st2workflowengine:3.819fdfffdbba8
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
stakater/workshop-operator:v0.0.3897bf456cc97c
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
stalwartlabs/stalwart:v0.16.1425001929f36a
attr@1:2.5.2-3
no fix listed
1
stalwartlabs/stalwart:v0.16.22388dcb75a707
attr@1:2.5.2-3
no fix listed
1
stalwartlabs/stalwart:v0.16.2074ca4f7f6885
attr@1:2.5.2-3
no fix listed
1
stalwartlabs/stalwart:v0.15.5dcf575db2d53
attr@1:2.5.2-3
no fix listed
1
stashapp/stash:latest24dbd7607174
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
stashapp/stash-box:latesta534c8afdf39
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
statcan/ckan:2.93921305425b8
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
statusim/nimbus-eth2:multiarch-latest6ccd9d382885
attr@1:2.5.1-4
no fix listed
1
steamcmd/steamcmd:latest5028a25268e7
attr@1:2.5.2-4
1:2.5.2-4ubuntu0.1
1
strangebee/thehive:5.8.0-1a7f7b05fba24
attr@1:2.5.1-4
no fix listed
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
structurizr/onpremises:2025.11.094b5ffb5119c8
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
substratusai/verba:v0.4.0-baseURL261695be635eb
attr@1:2.5.1-4
no fix listed
1
supabase/edge-runtime:v1.74.02781daf92394
attr@1:2.5.1-4
no fix listed
1
supabase/edge-runtime:v1.59.0eff9c554d649
attr@1:2.5.1-4
no fix listed
1
supabase/logflare:latest49bfe526f1b4
attr@1:2.5.2-3
no fix listed
1
supabase/postgres-meta:v0.96.6a84cc713585e
attr@1:2.5.1-4
no fix listed
1
supabase/postgres-meta:v0.84.2d0a96973e9f1
attr@1:2.5.1-4
no fix listed
1
supabase/realtime:v2.102.3aa1c92c0cf32
attr@1:2.5.1-4
no fix listed
1
supabase/realtime:v2.33.8d207e6e23ad3
attr@1:2.5.1-4
no fix listed
1
supabase/realtime:latestd3aa0c86c7b3
attr@1:2.5.2-3
no fix listed
1
supabase/studio:20241021-9f9b08326d8070c55e9
attr@1:2.5.1-4
no fix listed
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
attr@1:2.5.1-4
no fix listed
1
supabase/studio:latest94a2a9d2906e
attr@1:2.5.1-4
no fix listed
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.