StackRadar

CVE-2026-54399

High

Advisory

Published 1 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
152
of 17,781 indexed, latest versions
Container images
168
deployed by those charts
Fix available
1 of 1
affected package

Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service

Carried by container images the latest versions of 152 of 17,781 indexed charts deploy, on 168 images.

Affected packageAffected versionsFixed inImages
httpcore5maven5.0.1, 5.0.2, 5.1.1, 5.1.3+14 more5.4.3168
OSV records
GHSA-hf6x-8p5f-cgmf

Charts affected

152 by stars
ChartLatestAffected imagesRadar Score
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-54399.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
httpcore5@5.2.2
5.4.3

Open the chart page →

3,480
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-54399.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
httpcore5@5.0.2
5.4.3

Open the chart page →

6,016

Container images carrying it

168 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jacobalberty/unifi:v10.0.162896c0ab82d33
httpcore5@5.2.5
5.4.3
3
airbyte/workload-launcher:2.2.0119be7bfb719
httpcore5@5.3.4
5.4.3
2
apache/druid:37.0.00116fb802786
httpcore5@5.3.6
5.4.3
2
apache/fineract:1.12.1a83cf1980609
httpcore5@5.3.3
5.4.3
2
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
httpcore5@5.4.2
5.4.3
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
httpcore5@5.1.3
5.4.3
2
metabase/metabase:v0.61.1.x9491ed11c901
httpcore5@5.3.5
5.4.3
2
nacos/nacos-server:latest1c191c30c8cd
httpcore5@5.3.6
5.4.3
2
opensearchproject/opensearch:2.18.07f6fa1efee8f
httpcore5@5.2.2
5.4.3
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
httpcore5@5.3.4
5.4.3
2
ghcr.io/janssenproject/jans/casa:0.0.0-nightly3f2d14563495
httpcore5@5.3.4
5.4.3
2
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2:latestb53a854bd7c1
httpcore5@5.2.4
5.4.3
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
httpcore5@5.0.2
5.4.3
2
2martens/configserver:latestbf1cdb80239d
httpcore5@5.2.5
5.4.3
1
2martens/timetable:latestbd1ba6ab84c9
httpcore5@5.3.5
5.4.3
1
2martens/wahlrecht:latestba2c3040dab0
httpcore5@5.3.4
5.4.3
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
httpcore5@5.3.4
5.4.3
1
airbyte/bootloader:2.2.0f71cf4e185d5
httpcore5@5.3.4
5.4.3
1
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
httpcore5@5.3.4
5.4.3
1
airbyte/cron:0.40.17caf4f551c546
httpcore5@5.0.2
5.4.3
1
airbyte/cron:2.2.0d97b67a1346d
httpcore5@5.3.4
5.4.3
1
airbyte/server:2.2.070e125498a1c
httpcore5@5.3.4
5.4.3
1
airbyte/worker:2.2.08060b88b29c8
httpcore5@5.3.4
5.4.3
1
airbyte/workload-api-server:2.2.042093cff86e9
httpcore5@5.3.4
5.4.3
1
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
httpcore5@5.2.4
5.4.3
1
aktosecurity/akto-threat-detection-backend:latest15ebb75b94dc
httpcore5@5.2.4
5.4.3
1
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
httpcore5@5.2.4
5.4.3
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
httpcore5@5.2.4
5.4.3
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
httpcore5@5.2.4
5.4.3
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
httpcore5@5.2.4
5.4.3
1
apache/drill:1.21.11f96558fd292
httpcore5@5.1.3
5.4.3
1
apache/druid:29.0.10cef139b6bf1
httpcore5@5.1.3
5.4.3
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
httpcore5@5.4
5.4.3
1
athou/commafeed:6.2.0-postgresql5e388351df1a
httpcore5@5.4
5.4.3
1
atlassian/bamboo:12.1.114af4bb6c8d46
httpcore5@5.3.4
5.4.3
1
atlassian/bitbucket:10.2.705933f2b1cfd
httpcore5@5.3.6
5.4.3
1
atlassian/crowd:7.2.3c81cc7d6bc9e
httpcore5@5.3.6
5.4.3
1
atlassian/jira-software:11.3.11e5548cd4eea8
httpcore5@5.3.4
5.4.3
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
httpcore5@5.0.2
5.4.3
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
httpcore5@5.0.2
5.4.3
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
httpcore5@5.0.2
5.4.3
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
httpcore5@5.2.2
5.4.3
1
bluerange/bluerange:26.1.307c8f73b55df
httpcore5@5.3.4
5.4.3
1
camunda/camunda-bpm-platform:latestbcc5bb0542df
httpcore5@5.3.4
5.4.3
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
httpcore5@5.2.1
5.4.3
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
httpcore5@5.2.3
5.4.3
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
httpcore5@5.2
5.4.3
1
conductoross/conductor:3.31.09fba127693e6
httpcore5@5.2.5
5.4.3
1
confluentinc/cp-cmf:2.4.1f466f8649aa8
httpcore5@5.3.6
5.4.3
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
httpcore5@5.0.2
5.4.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.