StackRadar

CVE-2026-54371

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,685
of 17,792 indexed, latest versions
Container images
2,785
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: attr security update

Carried by container images the latest versions of 2,685 of 17,792 indexed charts deploy, on 2,785 images.

Affected packageAffected versionsFixed inImages
attrdeb1:2.4.47-1ubuntu1, 1:2.4.47-2, 1:2.4.47-2build1, 1:2.4.48-5+9 more1:2.4.47-1ubuntu1+esm1, 1:2.4.47-2ubuntu0.16.04.1~esm1, 1:2.4.47-2ubuntu0.18.04.1~esm1, 1:2.4.48-5ubuntu0.1~esm1+4 more2,331
attrrpm2.4.48-3.el8, 2.5.1-3.el9, 2.5.2-1.azl3, 2.5.2-5.el100:2.6.0-1.el8_10, 0:2.6.0-1.el9_8, 0:2.6.0-1.el10_2, 2.6.0-1454
aclrpm2.3.1-2.azl32.4.0-13
OSV records
DEBIAN-CVE-2026-54371UBUNTU-CVE-2026-54371RHSA-2026:56133RHSA-2026:59380RHSA-2026:60226RLSA-2026:56133RLSA-2026:59380RLSA-2026:60226AZL-91400AZL-91424ECHO-e81f-866f-9cb6
Also known as
USN-8691-1

Charts affected

2,685 by stars
ChartLatestAffected imagesRadar Score
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
attr@1:2.5.1-4
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1
quay.io/devtron/postgres:14.91b594392f7cb
attr@1:2.5.1-4
no fix listed

Open the chart page →

33,180
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1

Open the chart page →

3,675
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1

Open the chart page →

5,403
nextcloudgroundhog2k0.22.61 of 3See more

nextcloud groundhog2k 0.22.6

1 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/nextcloud:34.0.4:34.0.4-apache8418c398d767
attr@1:2.5.2-3
no fix listed

Open the chart page →

3,837
ilumilumOfficialVerified publisher6.7.35 of 19See more

ilum ilum 6.7.3

5 of the 19 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
attr@1:2.5.1-4
no fix listed
bitnamilegacy/postgresql:16233f361c5819
attr@1:2.5.1-4
no fix listed
ilum/api:6.7.3624fd09528c8
attr@1:2.5.2-3
no fix listed
ilum/marquez:0.54.06e1d709d41f8
attr@1:2.5.1-4
no fix listed
minio/mc:RELEASE.2025-04-16T18-13-26Zaead63c77f9d
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

23,362
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1

Open the chart page →

3,440
lakekeeperlakekeeperVerified publisher0.12.01 of 2See more

lakekeeper lakekeeper 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
attr@1:2.5.2-3
no fix listed

Open the chart page →

1,956
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
attr@1:2.5.1-4
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
attr@1:2.5.1-4
no fix listed

Open the chart page →

7,063
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
attr@1:2.5.2-3
no fix listed

Open the chart page →

5,702
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
attr@1:2.5.2-3
no fix listed

Open the chart page →

4,354
netris-controllernetrisai2.8.24 of 14See more

netris-controller netrisai 2.8.2

4 of the 14 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
netrisai/controller-grpc:4.6.0.00753178bf173c2
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
netrisai/controller-telescope:4.6.0.00414d82948a8b2
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
netrisai/controller-web-session-generator:0.2.0a030a31289f4
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

30,504
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
attr@1:2.5.2-3
no fix listed

Open the chart page →

2,267
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
attr@1:2.5.1-4
no fix listed

Open the chart page →

17,370
paperless-ngxpaperless-ngxVerified publisher0.3.223 of 3See more

paperless-ngx paperless-ngx 0.3.22

3 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
attr@1:2.5.1-4
no fix listed
valkey/valkey:9.1.2c123e3715db6
attr@1:2.5.2-3
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
attr@1:2.5.2-3
no fix listed

Open the chart page →

8,553
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1
platform9community/api-gateway:latest40a4970de568
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1
platform9community/customers-service:latest2089811e5cc6
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1
platform9community/vets-service:latestd1165c94dfb3
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1
platform9community/visits-service:latest8d11b50368c6
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1

Open the chart page →

41,926
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

14,281
selenium3selenium31.2.41 of 1See more

selenium3 selenium3 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

11,827
tbmq-clustertbmq-helm-chartOfficialVerified publisher2.1.02 of 3See more

tbmq-cluster tbmq-helm-chart 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
attr@1:2.5.2-3
no fix listed
thingsboard/tbmq-node:2.4.070661025dba5
attr@1:2.5.2-3
no fix listed

Open the chart page →

3,575
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

7,360
plexutkuozdemirVerified publisher2.1.11 of 1See more

plex utkuozdemir 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
linuxserver/plex:1.25.24a13ced2326c
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

6,390
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1

Open the chart page →

2,327
istio-operatorwiremindVerified publisher1.18.21 of 1See more

istio-operator wiremind 1.18.2

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
istio/operator:1.18.270f9d1fe5fff
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

5,679
zabbix-serveraekondratievVerified publisher1.0.63 of 4See more

zabbix-server aekondratiev 1.0.6

3 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

30,813
phpmyadminalekcVerified publisher0.3.11 of 1See more

phpmyadmin alekc 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
attr@1:2.5.2-3
no fix listed

Open the chart page →

2,650
wazuh-agentavistoVerified publisher4.12.21 of 1See more

wazuh-agent avisto 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
attr@1:2.5.1-4
no fix listed

Open the chart page →

6,531
awx-operatorawx-operator-helm3.2.11 of 2See more

awx-operator awx-operator-helm 3.2.1

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

9,882
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

12,166
memcachedcloudpirates-memcachedVerified publisher0.14.91 of 1See more

memcached cloudpirates-memcached 0.14.9

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/memcached:1.6.4575c93cc91e76
attr@1:2.5.2-3
no fix listed

Open the chart page →

1,074
cluster-secretclutersecretVerified publisher0.7.01 of 1See more

cluster-secret clutersecret 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
attr@1:2.5.1-4
no fix listed

Open the chart page →

3,050
codercoderOfficialVerified publisher1.44.62 of 2See more

coder coder 1.44.6

2 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
coderenvs/coder-service:1.44.61deffc4670e6
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
coderenvs/timescale:1.44.676fd37fe6830
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

7,183
convoyconvoyVerified publisher3.7.132 of 3See more

convoy convoy 3.7.13

2 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
attr@1:2.5.1-4
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
attr@1:2.5.1-4
no fix listed

Open the chart page →

5,943
cortexcortex3.3.82 of 4See more

cortex cortex 3.3.8

2 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/memcached:1.6.4575c93cc91e76
attr@1:2.5.2-3
no fix listed
library/nginx:1.3105b8cb60c354
attr@1:2.5.2-3
no fix listed

Open the chart page →

3,948
grayloggraylog2OfficialVerified publisher2.0.01 of 2See more

graylog graylog2 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
graylog/graylog-enterprise:7.1.88a1f641cd7aa
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1

Open the chart page →

1,544
valkeygroundhog2k2.3.41 of 1See more

valkey groundhog2k 2.3.4

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
valkey/valkey:9.1.2475ee65cc75c
attr@1:2.5.2-3
no fix listed

Open the chart page →

829
hasurahasura-extraVerified publisher3.0.11 of 1See more

hasura hasura-extra 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.34.0-ce0111b0204136
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

4,954
docmosthelmforgeVerified publisher1.2.123 of 4See more

docmost helmforge 1.2.12

3 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
docmost/docmost:0.96.0b56947fcfd08
attr@1:2.5.2-3
no fix listed
library/postgres:18.6-trixie4ef4dbc939d6
attr@1:2.5.2-3
no fix listed
library/redis:8.10.1298e5b3bc566
attr@1:2.5.2-3
no fix listed

Open the chart page →

4,113
wordpresshelmforgeVerified publisher3.0.61 of 3See more

wordpress helmforge 3.0.6

1 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
attr@1:2.5.2-3
no fix listed

Open the chart page →

4,215
coturnjaconiVerified publisher1.0.51 of 1See more

coturn jaconi 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
coturn/coturn:4.10.0-r1f4c2af06c3c5
attr@1:2.5.2-3
no fix listed

Open the chart page →

2,924
mongooseimmongoose0.4.111 of 1See more

mongooseim mongoose 0.4.11

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
erlangsolutions/mongooseim:6.6.0cc5bf032931f
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1

Open the chart page →

1,307
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1

Open the chart page →

8,692
nessienessie0.108.41 of 1See more

nessie nessie 0.108.4

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/projectnessie/nessie:0.108.4c0f42874c810
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

222
nginx-ingressnginx-ingress-chartVerified publisher0.0.0-edge1 of 1See more

nginx-ingress nginx-ingress-chart 0.0.0-edge

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
nginx/nginx-ingress:edge520d439f9a9a
attr@1:2.5.2-3
no fix listed

Open the chart page →

1,266
technitium-dnsserverobeoneVerified publisher1.13.01 of 1See more

technitium-dnsserver obeone 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
technitium/dns-server:15.4.0df7d90ef0f7b
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1

Open the chart page →

1,231
passboltpassbolt2.1.16 of 6See more

passbolt passbolt 2.1.1

6 of the 6 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
attr@1:2.5.1-4
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
attr@1:2.5.1-4
no fix listed
bitnamilegacy/redis-sentinel:8.2.1-debian-12-r00ca3ea1d2f82
attr@1:2.5.1-4
no fix listed
library/haproxy:3.4.10f597665a2a6
attr@1:2.5.2-3
no fix listed
library/mariadb:latestdd9b303aed4f
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
attr@1:2.5.2-3
no fix listed

Open the chart page →

13,523
redis-enterprise-operatorredis-enterprise-operator-officialOfficialVerified publisher8.0.18-111 of 1See more

redis-enterprise-operator redis-enterprise-operator-official 8.0.18-11

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
redislabs/operator:8.0.18-119078e713bb6a
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

921
reposilitereposilite1.4.21 of 1See more

reposilite reposilite 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
dzikoysk/reposilite:3.6.390de4c8e6c0e
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1

Open the chart page →

1,033
mssqlserver-2022simcube1.2.31 of 1See more

mssqlserver-2022 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

2,955
swo-k8s-collectorsolarwindsOfficialVerified publisher5.3.01 of 3See more

swo-k8s-collector solarwinds 5.3.0

1 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
solarwinds/solarwinds-otel-collector:0.152.3-k8s3c1110e8bdfb
attr@1:2.5.1-4
no fix listed

Open the chart page →

2,377
thehivestrangebee-helmOfficialVerified publisher1.0.76 of 7See more

thehive strangebee-helm 1.0.7

6 of the 7 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
attr@1:2.5.1-4
no fix listed
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
attr@1:2.5.1-4
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
attr@1:2.5.1-4
no fix listed
minio/mc:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
strangebee/thehive:5.8.0-1a7f7b05fba24
attr@1:2.5.1-4
no fix listed

Open the chart page →

16,220
truenas-csptruenas-cspVerified publisher1.2.45 of 11See more

truenas-csp truenas-csp 1.2.4

5 of the 11 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/hpestorage/csi-driver:v3.2.0ef7f4e1544fa
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
quay.io/hpestorage/csi-extensions:v1.2.1189146672a7ac
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
quay.io/hpestorage/volume-group-provisioner:v1.0.107bf9d8f16a5d
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
quay.io/hpestorage/volume-group-snapshotter:v1.0.10caeaaffe7e2b
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
quay.io/hpestorage/volume-mutator:v1.3.109e98b2e697bd
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

5,918

Container images carrying it

2,785 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
1
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
1
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
1
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
attr@1:2.5.2-3
no fix listed
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
attr@1:2.5.1-4
no fix listed
1
ghcr.io/enderdash-com/enderdash-agent:latest8525a1a67958
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/ente/web:5ab0c5b4c7a89c4e470ef6f793600da33cebf35d3f4864eb7f11
attr@1:2.5.2-3
no fix listed
1
ghcr.io/erlkoenig91/prompt-db-backend:1.0.7ab120359810d
attr@1:2.5.2-3
no fix listed
1
ghcr.io/eslupmi/impulse:v3.7.03ded1b7ebca0
attr@1:2.5.2-3
no fix listed
1
ghcr.io/esphome/esphome:latest000c5ee5ee96
attr@1:2.5.2-3
no fix listed
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
attr@1:2.5.1-4
no fix listed
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
attr@1:2.5.1-4
no fix listed
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
ghcr.io/feresberbeche/alertigate:1.2.1628d49e0e01b
attr@1:2.5.2-3
no fix listed
1
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
attr@1:2.5.2-3
no fix listed
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
attr@1:2.5.1-4
no fix listed
1
ghcr.io/flanksource/mission-control-ai-assistant:1.0.1229a635cbeeb5
attr@1:2.5.1-4
no fix listed
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
attr@1:2.5.1-4
no fix listed
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
attr@1:2.5.1-4
no fix listed
1
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
attr@1:2.5.2-3
no fix listed
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
attr@1:2.5.1-4
no fix listed
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
1
ghcr.io/gamosoft/notediscovery:0.31.5c06aa0fa9a85
attr@1:2.5.2-3
no fix listed
1
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
attr@1:2.5.1-4
no fix listed
1
ghcr.io/getsentry/snuba:26.7.210f8d164109b
attr@1:2.5.2-3
no fix listed
1
ghcr.io/getsentry/taskbroker:26.7.264d0da74a578
attr@1:2.5.1-4
no fix listed
1
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
attr@1:2.5.2-3
no fix listed
1
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
attr@1:2.5.2-3
no fix listed
1
ghcr.io/glassflow/glassflow-notifier:v1.0.3d1b0ce10b513
attr@1:2.5.2-3
no fix listed
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
attr@1:2.5.2-3
no fix listed
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
attr@1:2.5.2-3
no fix listed
1
ghcr.io/goauthentik/server:2026.8.2ff8489a5af4f
attr@1:2.5.2-3
no fix listed
1
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
1
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
1
ghcr.io/grafana/alloy-operator:1.12.14ee4b71cf16a
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
1
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
attr@1:2.5.1-4
no fix listed
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/grycap/im:latest06a16d4f279f
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
ghcr.io/hemslo/chat-search:latest39d48995a5bd
attr@1:2.5.1-4
no fix listed
1
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
attr@1:2.5.2-3
no fix listed
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.666db77d7856c
attr@1:2.5.1-4
no fix listed
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.9.3ad950d30878e
attr@1:2.5.1-4
no fix listed
1
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
attr@1:2.5.1-4
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.