StackRadar

CVE-2026-54371

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,708
of 17,821 indexed, latest versions
Container images
2,836
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: attr security update

Carried by container images the latest versions of 2,708 of 17,821 indexed charts deploy, on 2,836 images.

Affected packageAffected versionsFixed inImages
attrdeb1:2.4.47-1ubuntu1, 1:2.4.47-2, 1:2.4.47-2build1, 1:2.4.48-5+9 more1:2.4.47-1ubuntu1+esm1, 1:2.4.47-2ubuntu0.16.04.1~esm1, 1:2.4.47-2ubuntu0.18.04.1~esm1, 1:2.4.48-5ubuntu0.1~esm1+4 more2,392
attrrpm2.4.48-3.el8, 2.5.1-3.el9, 2.5.2-1.azl3, 2.5.2-5.el100:2.6.0-1.el8_10, 0:2.6.0-1.el9_8, 0:2.6.0-1.el10_2, 2.6.0-1444
aclrpm2.3.1-2.azl32.4.0-13
OSV records
DEBIAN-CVE-2026-54371UBUNTU-CVE-2026-54371RHSA-2026:56133RHSA-2026:59380RHSA-2026:60226RLSA-2026:56133RLSA-2026:59380RLSA-2026:60226AZL-91400AZL-91424ECHO-e81f-866f-9cb6
Also known as
USN-8691-1

Charts affected

2,708 by stars
ChartLatestAffected imagesRadar Score
nacosgujunxiang0.1.51 of 1See more

nacos gujunxiang 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
attr@1:2.5.2-4
1:2.5.2-4ubuntu0.1

Open the chart page →

1,923
terrariahalkeye0.4.21 of 2See more

terraria halkeye 0.4.2

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ryshe/terraria:latestb1c89f7f359a
attr@1:2.5.1-4
no fix listed

Open the chart page →

4,270
netbirdhelmforgeVerified publisher1.0.102 of 4See more

netbird helmforge 1.0.10

2 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
attr@1:2.5.2-3
no fix listed
netbirdio/netbird-server:0.78.13086534361a1
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1

Open the chart page →

3,110
redishelmforgeVerified publisher3.0.01 of 1See more

redis helmforge 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
attr@1:2.5.2-3
no fix listed

Open the chart page →

1,010
simple-krr-dashboardhelm-simple-krr-dashboardVerified publisher1.6.21 of 3See more

simple-krr-dashboard helm-simple-krr-dashboard 1.6.2

1 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
robustadev/krr:v1.30.0b8d782e568c7
attr@1:2.6.0-1
no fix listed

Open the chart page →

2,279
typesensehmphuVerified publisher0.1.61 of 1See more

typesense hmphu 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
typesense/typesense:0.23.03accb727cbe2
attr@1:2.4.47-2
1:2.4.47-2ubuntu0.16.04.1~esm1

Open the chart page →

3,896
hpe-cosi-driverhpe-storageVerified publisher2.0.01 of 2See more

hpe-cosi-driver hpe-storage 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/hpestorage/cosi-driver:v2.0.0a4d2667f2b6e
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

1,696
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.19.24 of 5See more

infrahub-enterprise infrahub-enterprise 4.19.2

4 of the 5 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
attr@1:2.5.1-4
no fix listed
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
attr@1:2.5.1-4
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
attr@1:2.5.1-4
no fix listed
library/neo4j:2026.05.0-enterprise2caf944aa4a5
attr@1:2.5.2-3
no fix listed

Open the chart page →

10,778
coreinstill-aiOfficialVerified publisher0.1.753 of 15See more

core instill-ai 0.1.75

3 of the 15 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
instill/artifact-backend:b28766ac4a393e601ed
attr@1:2.5.2-3
no fix listed
instill/mgmt-backend:d0933d4ebe12f77a3f9
attr@1:2.5.2-3
no fix listed
instill/model-backend:611f0f2e980125e5ba5
attr@1:2.5.2-3
no fix listed

Open the chart page →

31,162
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
attr@1:2.5.2-1build1
1:2.5.2-1ubuntu0.1

Open the chart page →

4,552
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1

Open the chart page →

4,593
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

7,554
webdavk8s-webdavVerified publisher0.0.71 of 1See more

webdav k8s-webdav 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/httpd:2.4454942557d44
attr@1:2.5.2-3
no fix listed

Open the chart page →

1,239
kanister-operatorkanister0.118.01 of 1See more

kanister-operator kanister 0.118.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/kanisterio/controller:0.118.0d22616a5998b
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

1,188
klancesklances0.1.41 of 1See more

klances klances 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
attr@1:2.5.2-3
no fix listed

Open the chart page →

1,765
kraken-cikraken-ciVerified publisher1.7.361 of 10See more

kraken-ci kraken-ci 1.7.36

1 of the 10 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/redis:6e7b96daa9a18
attr@1:2.5.1-4
no fix listed

Open the chart page →

2,313
kuadrant-operatorkuadrantOfficialVerified publisher1.5.31 of 4See more

kuadrant-operator kuadrant 1.5.3

1 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/kuadrant/authorino-operator:v0.25.395a0670bffe6
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

303
radondb-mysqlkubesphere-testVerified publisher1.0.11 of 3See more

radondb-mysql kubesphere-test 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

7,406
kubevpnkubevpn-charts2.11.91 of 1See more

kubevpn kubevpn-charts 2.11.9

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/kubenetworks/kubevpn:v2.11.93feb9da85270
attr@1:2.5.1-4
no fix listed

Open the chart page →

1,689
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

59,088
lightsteplightstepsatellite1.2.41 of 1See more

lightstep lightstepsatellite 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
attr@1:2.4.47-2
1:2.4.47-2ubuntu0.16.04.1~esm1

Open the chart page →

15,533
kafdroplsst-sqre0.1.31 of 1See more

kafdrop lsst-sqre 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

7,966
kubecostmesosphere-stable0.37.52 of 9See more

kubecost mesosphere-stable 0.37.5

2 of the 9 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
attr@1:2.5.1-4
no fix listed
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

17,907
mogenius-operatormogeniusOfficialVerified publisher2.30.01 of 2See more

mogenius-operator mogenius 2.30.0

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
valkey/valkey:9.1.2c123e3715db6
attr@1:2.5.2-3
no fix listed

Open the chart page →

960
mortalgpumortalgpuOfficialVerified publisher1.3.71 of 1See more

mortalgpu mortalgpu 1.3.7

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/maxiv/mortalgpu:1.3.7e1c5c194bbf0
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

379
move2kubemove2kube0.3.151 of 1See more

move2kube move2kube 0.3.15

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

3,829
nebraskanebraska3.0.01 of 2See more

nebraska nebraska 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.042a8200d3597
attr@1:2.5.1-4
no fix listed

Open the chart page →

4,276
keycloak-operatornewsaktuell0.1.71 of 1See more

keycloak-operator newsaktuell 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

5,068
mariadbnicholaswildeVerified publisher1.0.61 of 1See more

mariadb nicholaswilde 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/mariadb:version-110.4.21mariabionic7a94d7e89f52
attr@1:2.4.47-2build1
1:2.4.47-2ubuntu0.18.04.1~esm1

Open the chart page →

9,669
observalobservalVerified publisher1.13.13 of 8See more

observal observal 1.13.1

3 of the 8 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.3810861a2e2d0
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
library/postgres:16f1c3376c26f2
attr@1:2.5.2-3
no fix listed
ghcr.io/observal/observal-api:1.13.1153b8b893232
attr@1:2.5.2-3
no fix listed

Open the chart page →

6,224
oesopsmxVerified publisher4.0.329 of 25See more

oes opsmx 4.0.32

9 of the 25 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
attr@1:2.4.47-2
1:2.4.47-2ubuntu0.16.04.1~esm1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
attr@1:2.5.2-3
no fix listed
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
attr@2.4.48-3.el8
0:2.6.0-1.el8_10
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

101,186
part-dbpart-dbVerified publisher0.1.21 of 1See more

part-db part-db 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
jbtronics/part-db1:latestfd68338829ed
attr@1:2.5.1-4
no fix listed

Open the chart page →

3,379
redispascaliskeVerified publisher2.1.01 of 1See more

redis pascaliske 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/redis:8.0.3be0a135f1955
attr@1:2.5.1-4
no fix listed

Open the chart page →

1,902
psmdb-operatorpercona1.23.11 of 1See more

psmdb-operator percona 1.23.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
percona/percona-server-mongodb-operator:1.23.0feaff989e253
attr@2.5.2-5.el10
0:2.6.0-1.el10_2

Open the chart page →

281
phpmyadminphpmyadminVerified publisher1.0.31 of 1See more

phpmyadmin phpmyadmin 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
attr@1:2.5.2-3
no fix listed

Open the chart page →

2,718
ipmi-exporterpnnl-miscscripts0.1.151 of 1See more

ipmi-exporter pnnl-miscscripts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
attr@2.4.48-3.el8
0:2.6.0-1.el8_10

Open the chart page →

2,995
prometheus-prefect-exporterprefectVerified publisher2026.9.162012261 of 1See more

prometheus-prefect-exporter prefect 2026.9.16201226

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
prefecthq/prometheus-prefect-exporter:4.1.06e0e79cabdc2
attr@1:2.5.2-3
no fix listed

Open the chart page →

861
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/nginx:1.27.409369da6b103
attr@1:2.5.1-4
no fix listed

Open the chart page →

5,524
repoflowrepoflow-helm-public0.9.13 of 8See more

repoflow repoflow-helm-public 0.9.1

3 of the 8 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.48.10f6c1c4b957d2
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1
library/elasticsearch:8.15.0310b9fc03b06
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1
library/postgres:16.24aea012537ed
attr@1:2.5.1-4
no fix listed

Open the chart page →

12,704
nominatimrobjuz6.4.22 of 4See more

nominatim robjuz 6.4.2

2 of the 4 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
attr@1:2.5.1-4
no fix listed
mediagis/nominatim:5.3.27923a8e67197
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1

Open the chart page →

50,868
rocketmq-clusterrocketmq12.6.02 of 2See more

rocketmq-cluster rocketmq 12.6.0

2 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
attr@1:2.5.2-1build1.1
1:2.5.2-1ubuntu0.1
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

6,435
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
attr@1:2.4.48-5
1:2.4.48-5ubuntu0.1~esm1

Open the chart page →

100,687
satisfactory-serversatisfactoryVerified publisher0.1.61 of 1See more

satisfactory-server satisfactory 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.10e103700ae6ae
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

3,490
seldon-core-operatorseldon1.19.01 of 1See more

seldon-core-operator seldon 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

875
lldapself-hosters-by-nightVerified publisher0.5.21 of 2See more

lldap self-hosters-by-night 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
attr@1:2.5.2-3
no fix listed

Open the chart page →

3,474
skypilotskypilotOfficialVerified publisher0.13.01 of 3See more

skypilot skypilot 0.13.0

1 of the 3 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
attr@1:2.5.2-3
no fix listed

Open the chart page →

6,017
kafka-chartsoldevelo-kafka-chart32.4.41 of 1See more

kafka-chart soldevelo-kafka-chart 32.4.4

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
attr@1:2.5.1-4
no fix listed

Open the chart page →

2,408
miniosolidchartsVerified publisher0.5.01 of 1See more

minio solidcharts 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
ghcr.io/coollabsio/minio:RELEASE.2025-10-15T17-29-55Z69b55a1c1c5d
attr@2.5.1-3.el9
0:2.6.0-1.el9_8

Open the chart page →

1,187
spartanspartan0.9.11 of 1See more

spartan spartan 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
attr@1:2.5.2-3
no fix listed

Open the chart page →

1,580
freeradiusstartechnicaVerified publisher1.2.01 of 1See more

freeradius startechnica 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-54371.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.2.8af6fd34a5b78
attr@1:2.5.1-1build1
1:2.5.1-1ubuntu0.1

Open the chart page →

5,945

Container images carrying it

2,836 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

No deployed image carries CVE-2026-54371.

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.