StackRadar

CVE-2026-54399

High

Advisory

Published 1 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
152
of 17,781 indexed, latest versions
Container images
168
deployed by those charts
Fix available
1 of 1
affected package

Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service

Carried by container images the latest versions of 152 of 17,781 indexed charts deploy, on 168 images.

Affected packageAffected versionsFixed inImages
httpcore5maven5.0.1, 5.0.2, 5.1.1, 5.1.3+14 more5.4.3168
OSV records
GHSA-hf6x-8p5f-cgmf

Charts affected

152 by stars
ChartLatestAffected imagesRadar Score
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-54399.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
httpcore5@5.2.2
5.4.3

Open the chart page →

3,480
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-54399.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
httpcore5@5.0.2
5.4.3

Open the chart page →

6,016

Container images carrying it

168 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
httpcore5@5.0.1
5.4.3
1
confluentinc/cp-schema-registry:latestf0cfd047a839
httpcore5@5.3.4
5.4.3
1
dbeaver/cloudbeaver:26.1.287ab86d00f8c
httpcore5@5.3.6
5.4.3
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
httpcore5@5.4
5.4.3
1
dremio/dremio-oss:24.1.080ed2e3b7c43
httpcore5@5.1.3
5.4.3
1
easypi/openrefine:3.7.0d2950a36a576
httpcore5@5.2
5.4.3
1
eginnovations/agent:7.5.4e4dfe242fe9f
httpcore5@5.2.4
5.4.3
1
erudikaltd/para:latest_stable235e0bc53da2
httpcore5@5.4.2
5.4.3
1
erudikaltd/scoold:1.66.0949c56b57e8f
httpcore5@5.3.6
5.4.3
1
flowable/flowable-rest:7.1.0b7ae287502cd
httpcore5@5.2.5
5.4.3
1
folioci/edge-caiasoft:latestc3cfa89eee2f
httpcore5@5.4.2
5.4.3
1
folioci/edge-dematic:latest48c9b1d180d4
httpcore5@5.4.2
5.4.3
1
folioci/edge-inn-reach:latestc64e4d9dd3fc
httpcore5@5.4.2
5.4.3
1
folioci/edge-rtac:latest15ef73b1abd0
httpcore5@5.3.6
5.4.3
1
folioci/mod-calendar:latest22f65982efd7
httpcore5@5.0.2
5.4.3
1
folioci/mod-copycat:latest1513fad2b799
httpcore5@5.3.6
5.4.3
1
folioci/mod-email:latest79ea8e2e7ebf
httpcore5@5.0.2
5.4.3
1
folioci/mod-ncip:latest8ed83674352b
httpcore5@5.2
5.4.3
1
folioci/mod-password-validator:latestb31d75f2bf7b
httpcore5@5.3.6
5.4.3
1
folioci/mod-search:latest44d7ee9acdf6
httpcore5@5.4.2
5.4.3
1
glarad/mc-service-registry:latest7b02b9e7f1ef
httpcore5@5.3.6
5.4.3
1
graylog/graylog:7.1.9598bd41fefd5
httpcore5@5.3.4
5.4.3
1
graylog/graylog-enterprise:7.1.88a1f641cd7aa
httpcore5@5.3.4
5.4.3
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
httpcore5@5.3.6
5.4.3
1
gridgain/gridgain9:9.1.1895018390077b
httpcore5@5.4
5.4.3
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
httpcore5@5.2.4
5.4.3
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
httpcore5@5.1.3
5.4.3
1
keyfactor/signserver-ce:7.3.2798fbbe00283
httpcore5@5.2.4
5.4.3
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
httpcore5@5.3.6
5.4.3
1
kubebb/mesh-api:v5.7.0a3879931dfa1
httpcore5@5.2.2
5.4.3
1
labs64/auditflowc7b26d3ca11c
httpcore5@5.3.6
5.4.3
1
labs64/payment-gateway:0.0.10c66feefca17
httpcore5@5.3.6
5.4.3
1
library/xwiki:lts-postgres-tomcat56490ac14a31
httpcore5@5.3.6
5.4.3
1
linuxserver/unifi-network-application:10.6.101-ls144b6ce6968ee45
httpcore5@5.3.6
5.4.3
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
httpcore5@5.2.2
5.4.3
1
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
httpcore5@5.2.2
5.4.3
1
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
httpcore5@5.2.2
5.4.3
1
nacos/nacos-server:v3.0.20e951a1d07bb
httpcore5@5.3.3
5.4.3
1
nacos/nacos-server:v3.0.130a39cb0c54d
httpcore5@5.3.3
5.4.3
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
httpcore5@5.1.3
5.4.3
1
olvid/bot-daemon:2.0.1e0e6b165d879
httpcore5@5.2.4
5.4.3
1
openbas/platform:2.0.5d986d80b0a75
httpcore5@5.2.5
5.4.3
1
opennms/sentinel:36.0.288869082a14f
httpcore5@5.2
5.4.3
1
opensearchproject/data-prepper:2.8.057c25fa01d3c
httpcore5@5.2.4
5.4.3
1
opensearchproject/opensearch:2.15.01963b3ece46d
httpcore5@5.2.2
5.4.3
1
opensearchproject/opensearch:2.14.0466a49f379bb
httpcore5@5.2.2
5.4.3
1
opensearchproject/opensearch:3.1.0474ea3fdf25d
httpcore5@5.3.4
5.4.3
1
opensearchproject/opensearch:2.12.0645d3d9390ad
httpcore5@5.2.2
5.4.3
1
opensearchproject/opensearch:2.19.269588c664014
httpcore5@5.3.1
5.4.3
1
opensearchproject/opensearch:3.3.2798cf28e226a
httpcore5@5.3.4
5.4.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.