StackRadar

CVE-2026-54371

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,749
of 17,813 indexed, latest versions
Container images
2,877
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: attr security update

Carried by container images the latest versions of 2,749 of 17,813 indexed charts deploy, on 2,877 images.

Affected packageAffected versionsFixed inImages
attrdeb1:2.4.47-1ubuntu1, 1:2.4.47-2, 1:2.4.47-2build1, 1:2.4.48-5+9 more1:2.4.47-1ubuntu1+esm1, 1:2.4.47-2ubuntu0.16.04.1~esm1, 1:2.4.47-2ubuntu0.18.04.1~esm1, 1:2.4.48-5ubuntu0.1~esm1+4 more2,427
attrrpm2.4.48-3.el8, 2.5.1-3.el9, 2.5.2-1.azl3, 2.5.2-5.el100:2.6.0-1.el8_10, 0:2.6.0-1.el9_8, 0:2.6.0-1.el10_2, 2.6.0-1450
aclrpm2.3.1-2.azl32.4.0-13
OSV records
DEBIAN-CVE-2026-54371UBUNTU-CVE-2026-54371RHSA-2026:56133RHSA-2026:59380RHSA-2026:60226RLSA-2026:56133RLSA-2026:59380RLSA-2026:60226AZL-91400AZL-91424ECHO-e81f-866f-9cb6
Also known as
USN-8691-1

Charts affected

2,749 by stars
ChartLatestAffected imagesRadar Score
amorphieamorphie0.1.23 of 18See more

amorphie amorphie 0.1.2

3 of the 18 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
camunda/zeebe:8.4.5ab5abc09e407
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
hazelcast/management-center:5.3.2f9d34300d330
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

28,437
anchore-admission-controlleranchore-charts0.9.01 of 2See more

anchore-admission-controller anchore-charts 0.9.0

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
attr@1:2.5.1-4
no fix listed

Open the chart page →

7,644
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
attr@1:2.5.1-4
no fix listed

Open the chart page →

5,919
stalwartandibraeuVerified publisher1.0.21 of 1See more

stalwart andibraeu 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
stalwartlabs/stalwart:v0.16.1425001929f36a
attr@1:2.5.2-3
no fix listed

Open the chart page →

1,635
pagesandrei-pages1.0.02 of 3See more

pages andrei-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
flyway/flyway:6.4.422d97ceb0c47
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1

Open the chart page →

20,285
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1

Open the chart page →

11,623
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
attr@1:2.5.1-4
no fix listed

Open the chart page →

7,465
speech-to-phraseandrenarchyVerified publisher1.3.01 of 1See more

speech-to-phrase andrenarchy 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
attr@1:2.5.1-4
no fix listed

Open the chart page →

4,094
games-on-whalesangelnu2.0.04 of 7See more

games-on-whales angelnu 2.0.0

4 of the 7 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

118,407
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
attr@1:2.5.2-3
no fix listed

Open the chart page →

5,684
ddosifyanteonVerified publisher1.7.52 of 13See more

ddosify anteon 1.7.5

2 of the 13 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
attr@1:2.5.1-4
no fix listed
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
attr@1:2.5.1-4
no fix listed

Open the chart page →

26,306
antigenic-stalwart-helm-chartantigenic-stalwart-helm-chartVerified publisher1.0.51 of 2See more

antigenic-stalwart-helm-chart antigenic-stalwart-helm-chart 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
stalwartlabs/stalwart:v0.15.5dcf575db2d53
attr@1:2.5.2-3
no fix listed

Open the chart page →

1,488
antmediaantmediaVerified publisher3.1.01 of 4See more

antmedia antmedia 3.1.0

1 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/mongo:8.002a0cc7939f5
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1

Open the chart page →

4,644
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

2,480
antrea-uiantreaVerified publisher0.8.01 of 2See more

antrea-ui antrea 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
attr@1:2.5.2-3
no fix listed

Open the chart page →

3,372
flow-aggregatorantreaVerified publisher2.7.01 of 1See more

flow-aggregator antrea 2.7.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
antrea/flow-aggregator:v2.7.0065193e7572f
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1

Open the chart page →

794
apishiftapishiftVerified publisher0.3.02 of 4See more

apishift apishift 0.3.0

2 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift:v0.3.08fbbcd23b902
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

2,996
apispringbootHelmapispringboot0.1.01 of 1See more

apispringbootHelm apispringboot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
rabeh/apibootspring:1.0941007b6946e
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

6,304
d.vazquezm.2021_helmapphelmVerified publisher1.0.01 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

19,830
app-mobilityappmo0.1.02 of 5See more

app-mobility appmo 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

12,562
accounts-uiappscodeVerified publisher2026.9.111 of 1See more

accounts-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
attr@1:2.5.1-4
no fix listed

Open the chart page →

2,716
aceappscodeVerified publisher2026.9.111 of 2See more

ace appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
attr@1:2.5.1-4
no fix listed

Open the chart page →

3,018
ace-installerappscodeVerified publisher2026.9.111 of 2See more

ace-installer appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
attr@1:2.5.1-4
no fix listed

Open the chart page →

3,374
ace-installer-certifiedappscodeVerified publisher2026.9.111 of 2See more

ace-installer-certified appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1178a9fb785ec5
attr@1:2.5.1-4
no fix listed

Open the chart page →

3,142
billingappscodeVerified publisher2026.9.111 of 1See more

billing appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
attr@1:2.5.1-4
no fix listed

Open the chart page →

2,716
cert-manager-csi-driver-cacertsappscodeVerified publisher2026.9.181 of 3See more

cert-manager-csi-driver-cacerts appscode 2026.9.18

1 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/appscode/csi-driver-cacerts:v0.6.0ab213b156017
attr@1:2.5.1-4
no fix listed

Open the chart page →

2,515
cluster-gatewayappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway:v1.12.158bed8d1e7fc
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

670
cluster-gateway-managerappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway-manager appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway-manager:v1.12.1f22cae0e6cf3
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

670
cluster-manager-hubappscodeVerified publisher2026.2.161 of 1See more

cluster-manager-hub appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/registration-operator:v1.2.00cbced8e6240
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

1,086
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

4,073
inbox-server-distributedappscodeVerified publisher2025.12.253 of 4See more

inbox-server-distributed appscode 2025.12.25

3 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
library/rabbitmq:3.12.1-managementf020c06da226
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
ghcr.io/appscode/inbox-server:latest536358d7b17e
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

15,894
james-komposeappscodeVerified publisher0.1.03 of 4See more

james-kompose appscode 0.1.0

3 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
library/rabbitmq:3.12.1-managementf020c06da226
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

17,276
managed-serviceaccountappscodeVerified publisher2024.2.251 of 1See more

managed-serviceaccount appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

2,405
managed-serviceaccount-managerappscodeVerified publisher2026.2.161 of 1See more

managed-serviceaccount-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:v0.10.0fc256885915b
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

928
marketplace-apiappscodeVerified publisher2026.9.111 of 1See more

marketplace-api appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
attr@1:2.5.1-4
no fix listed

Open the chart page →

2,716
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

4,192
multicluster-controlplaneappscodeVerified publisher2025.4.301 of 1See more

multicluster-controlplane appscode 2025.4.30

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

2,584
platform-apiappscodeVerified publisher2026.9.112 of 3See more

platform-api appscode 2026.9.11

2 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
attr@1:2.5.1-4
no fix listed
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
attr@1:2.5.2-3
no fix listed

Open the chart page →

38,114
s3proxyappscodeVerified publisher2026.9.111 of 1See more

s3proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

3,335
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
attr@1:2.5.1-4
no fix listed

Open the chart page →

5,720
maxscaleappuio2.0.11 of 1See more

maxscale appuio 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

2,903
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1

Open the chart page →

8,937
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
attr@1:2.5.2-3
no fix listed

Open the chart page →

7,722
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1

Open the chart page →

7,710
argonix-apiargonix0.3.61 of 4See more

argonix-api argonix 0.3.6

1 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0951622ae173b
attr@1:2.5.2-3
no fix listed

Open the chart page →

4,890
arlas-aiasarlas-stackVerified publisher28.9.09 of 22See more

arlas-aias arlas-stack 28.9.0

9 of the 22 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
attr@1:2.5.1-4
no fix listed
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
attr@1:2.5.1-4
no fix listed
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
attr@1:2.5.1-4
no fix listed
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
attr@1:2.5.1-4
no fix listed
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
attr@1:2.5.1-4
no fix listed
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
attr@1:2.5.1-4
no fix listed
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
attr@1:2.5.1-4
no fix listed
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
attr@1:2.5.1-4
no fix listed
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
attr@1:2.5.1-4
no fix listed

Open the chart page →

39,921
arma-reforgerarma-reforger0.5.31 of 8See more

arma-reforger arma-reforger 0.5.3

1 of the 8 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

23,478
bind9artem-shestakov1.0.11 of 1See more

bind9 artem-shestakov 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

3,745
keystonearzu0.2.293 of 4See more

keystone arzu 0.2.29

3 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/rabbitmq:3.7-managementb6dd45cc35b3
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

22,799
assemblylineassemblylineVerified publisher7.4.207 of 12See more

assemblyline assemblyline 7.4.20

7 of the 12 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
cccs/assemblyline-core:4.7.4.stable20098127270065
attr@1:2.5.1-4
no fix listed
cccs/assemblyline-rust:4.7.4.stable202be5e6a57427
attr@1:2.5.1-4
no fix listed
cccs/assemblyline-socketio:4.7.4.stable202b88493b62f7
attr@1:2.5.1-4
no fix listed
cccs/assemblyline-ui:4.7.4.stable20efa75509b854
attr@1:2.5.1-4
no fix listed
library/redis:latest298e5b3bc566
attr@1:2.5.2-3
no fix listed
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

12,896

Container images carrying it

2,877 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
attr@1:2.5.1-4
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/certificates:v19.4.01c38ad710b0c
attr@1:2.5.2-3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitaly:v19.4.0704cd68566af
attr@1:2.5.2-3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.0696d798a5c85
attr@1:2.5.2-3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabdc1a8972c640
attr@1:2.5.1-4
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.26645e014f75d
attr@1:2.5.2-3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
attr@1:2.5.2-3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3aca1bb3d5b7e
attr@1:2.5.2-3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.02256b49461fa
attr@1:2.5.2-3
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
attr@1:2.5.2-3
no fix listed
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
attr@1:2.5.1-4
no fix listed
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
attr@2.5.2-5.el10
0:2.6.0-1.el10_2
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
attr@2.5.1-3.el9
0:2.6.0-1.el9_8
1
registry.gitlab.com/xrow-public/velero-client/velero-client:1.4.203015f863a3e
attr@2.5.2-5.el10
0:2.6.0-1.el10_2
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
attr@1:2.5.1-4
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
attr@1:2.5.2-3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
attr@1:2.5.1-4
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
attr@1:2.5.1-4
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
attr@1:2.5.1-4
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
attr@1:2.5.1-4
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
attr@1:2.5.1-4
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
attr@1:2.5.1-4
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
attr@1:2.5.1-4
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.