StackRadar

CVE-2026-54371

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,668
of 17,813 indexed, latest versions
Container images
2,801
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: attr security update

Carried by container images the latest versions of 2,668 of 17,813 indexed charts deploy, on 2,801 images.

Affected packageAffected versionsFixed inImages
attrdeb1:2.4.47-1ubuntu1, 1:2.4.47-2, 1:2.4.47-2build1, 1:2.4.48-5+9 more1:2.4.47-1ubuntu1+esm1, 1:2.4.47-2ubuntu0.16.04.1~esm1, 1:2.4.47-2ubuntu0.18.04.1~esm1, 1:2.4.48-5ubuntu0.1~esm1+4 more2,356
attrrpm2.4.48-3.el8, 2.5.1-3.el9, 2.5.2-1.azl3, 2.5.2-5.el100:2.6.0-1.el8_10, 0:2.6.0-1.el9_8, 0:2.6.0-1.el10_2, 2.6.0-1445
aclrpm2.3.1-2.azl32.4.0-13
OSV records
DEBIAN-CVE-2026-54371UBUNTU-CVE-2026-54371RHSA-2026:56133RHSA-2026:59380RHSA-2026:60226RLSA-2026:56133RLSA-2026:59380RLSA-2026:60226AZL-91400AZL-91424ECHO-e81f-866f-9cb6
Also known as
USN-8691-1

Charts affected

2,668 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.62 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

2 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
attr@1:2.5.1-4
no fix listed
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

11,647
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
attr@1:2.5.1-4
no fix listed

Open the chart page →

7,679
xkopsxkops0.1.04 of 5See more

xkops xkops 0.1.0

4 of the 5 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
attr@1:2.5.1-4
no fix listed
hamzaarshad10/querypodpy:1.7154f38e8668e
attr@1:2.5.1-4
no fix listed
library/mongo:latest5211c51171f5
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
murtazashah46/helmfile:latest4d11726cf803
attr@1:2.5.1-4
no fix listed

Open the chart page →

13,895
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1

Open the chart page →

2,166
cloudeye-exporterxxl-job-adminVerified publisher0.1.21 of 1See more

cloudeye-exporter xxl-job-admin 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
dellnoantechnp/cloudeye-exporter:v2.0.316873356c882d
attr@1:2.5.1-4
no fix listed

Open the chart page →

2,693
dingtalk-botxxl-job-adminVerified publisher0.1.21 of 2See more

dingtalk-bot xxl-job-admin 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
attr@1:2.5.2-3
no fix listed

Open the chart page →

3,180
nightingalexxl-job-adminVerified publisher0.2.113 of 6See more

nightingale xxl-job-admin 0.2.11

3 of the 6 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
flashcatcloud/nightingale:8.0.0-beta.11ea1b0aaabe09
attr@1:2.5.1-4
no fix listed
library/redis:6.2d2ad7b21cafa
attr@1:2.5.1-4
no fix listed

Open the chart page →

9,730
pgcatxxl-job-adminVerified publisher0.3.31 of 1See more

pgcat xxl-job-admin 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
attr@1:2.5.1-4
no fix listed

Open the chart page →

3,192
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
attr@1:2.5.2-3
no fix listed

Open the chart page →

1,885
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
attr@1:2.5.2-3
no fix listed

Open the chart page →

1,334
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
attr@1:2.5.2-3
no fix listed

Open the chart page →

1,885
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
attr@1:2.5.1-4
no fix listed

Open the chart page →

2,714
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

6,023
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

3,700
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
attr@1:2.5.1-4
no fix listed

Open the chart page →

2,687
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
attr@1:2.5.2-3
no fix listed

Open the chart page →

1,885
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1
yandex/clickhouse-server:21.3.204eccfffb01d7
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

9,296
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

7,964

Container images carrying it

2,801 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/projectnessie/nessie:0.108.4c0f42874c810
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
1
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
attr@1:2.5.2-3
no fix listed
1
ghcr.io/qovery/iam-eks-user-mapper:mainc41e3efc6097
attr@1:2.5.2-3
no fix listed
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
attr@1:2.5.2-3
no fix listed
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
attr@1:2.5.2-4
1:2.5.2-4ubuntu0.1
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
attr@1:2.5.1-4
no fix listed
1
ghcr.io/reitermarkus/7d2d:main39953b387b61
attr@1:2.5.2-3
no fix listed
1
ghcr.io/retyc/retyc-k8s-csi:v0.2.01521d4baeb85
attr@1:2.5.2-3
no fix listed
1
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
attr@1:2.5.1-4
no fix listed
1
ghcr.io/rss-bridge/rss-bridge:latest606896116558
attr@1:2.5.1-4
no fix listed
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
attr@1:2.5.2-3
no fix listed
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
attr@1:2.5.1-4
no fix listed
1
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest917e53402d51
attr@1:2.5.2-3
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
attr@1:2.5.1-4
no fix listed
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
attr@1:2.5.2-3
no fix listed
1
ghcr.io/securo-finance/securo-backend:0.16.0f452147e07f1
attr@1:2.5.2-3
no fix listed
1
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
attr@1:2.5.1-4
no fix listed
1
ghcr.io/sergelogvinov/fluentd:1.19.33273d13f1e75
attr@1:2.5.2-3
no fix listed
1
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
attr@1:2.5.1-4
no fix listed
1
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
1
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/sergelogvinov/pgbouncer:16.1518f1121ba0a4
attr@1:2.5.1-4
no fix listed
1
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
attr@1:2.5.1-4
no fix listed
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
attr@1:2.5.2-3
no fix listed
1
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
attr@1:2.5.1-4
no fix listed
1
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
attr@1:2.5.1-4
no fix listed
1
ghcr.io/sikalabs/hello-world-server:latestcf8538bf6489
attr@1:2.5.2-3
no fix listed
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
attr@1:2.5.2-3
no fix listed
1
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/spidernet-io/spiderpool/spiderpool-agent:v1.2.08bb9411e47e0
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
attr@1:2.5.1-4
no fix listed
1
ghcr.io/stac-utils/stac-fastapi-pgstac:7.0.08b026c47cc1b
attr@1:2.5.2-3
no fix listed
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
ghcr.io/steadybit/agent:2.4.6d246bfa55f63
attr@1:2.5.2-3
no fix listed
1
ghcr.io/steadybit/extension-container:v1.8.1ae79f958b479
attr@1:2.5.2-3
no fix listed
1
ghcr.io/steadybit/extension-host:v1.8.103a5ef26aac5
attr@1:2.5.2-3
no fix listed
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.