CVE-2026-54411
HighAdvisory
Published 14 Jun 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.2
- base score, highest
- EPSS
- 0.003
- 25th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,459
- of 17,821 indexed, latest versions
- Container images
- 2,489
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Red Hat Security Advisory: pam security update
Carried by container images the latest versions of 2,459 of 17,821 indexed charts deploy, on 2,489 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pamdeb | 1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more | 1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.1 | 2,311 |
| pamrpm | 1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+29 more | 0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more | 178 |
- OSV records
- DEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
- Also known as
- RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1
Charts affected
2,459 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| nightingalexxl-job-adminVerified publisher | 0.2.11 | 3 of 6See more | 9,743 |
| pgcatxxl-job-adminVerified publisher | 0.3.3 | 1 of 1See more | 3,197 |
| nginx-chartxxoznge-nginx | 0.1.0 | 1 of 1See more | 1,887 |
| helm-demoyahoon-helm-demoVerified publisher | 1.0.0 | 1 of 1See more | 1,257 |
| my-nginx-appyasser-nginx-app | 0.1.0 | 1 of 1See more | 1,887 |
| api-snapyoukadevVerified publisher | 0.1.1 | 1 of 1See more | 2,638 |
| changedetection-iozekker6Verified publisher | 1.102.0 | 1 of 1See more | 2,710 |
| NEW_APPzekker6Verified publisher | 0.0.0 | 1 of 1See more | 1,593 |
| clickhousezloi-space | 1.2.0 | 2 of 3See more | 9,297 |
Container images carrying it
2,489 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| frankescobar/ | 0815040339a9 | pam | no fix listed | 1 |
| frankescobar/ | 4154286c0209 | pam | 1.5.3-5ubuntu5.6 | 1 |
| frankescobar/ | 8a4d7e9308de | pam | no fix listed | 1 |
| frankescobar/ | cafa03b94dac | pam | no fix listed | 1 |
| frankescobar/ | dc171ec796d5 | pam | 1.5.3-5ubuntu5.6 | 1 |
| free5gmano/ | 36f806935519 | pam | no fix listed | 1 |
| freedom98/ | d7ce1533f297 | pam | no fix listed | 1 |
| freeradius/ | af6fd34a5b78 | pam | 1.4.0-11ubuntu2.7 | 1 |
| galaxy/ | e5c265fe9fcd | pam | no fix listed | 1 |
| galaxy/ | 0267bad550e6 | pam | no fix listed | 1 |
| galaxy/ | 8e577a626dfd | pam | no fix listed | 1 |
| galaxy/ | e50a890e24c9 | pam | no fix listed | 1 |
| galexrt/ | 5373078a3a08 | pam | no fix listed | 1 |
| gchq/ | c460bb587d6d | pam | 1.5.3-5ubuntu5.6 | 1 |
| geonetwork/ | 20c9bb761f67 | pam | no fix listed | 1 |
| geonode/ | 81b1d431b7e9 | pam | 1.4.0-11ubuntu2.7 | 1 |
| geopython/ | 84662ea6b78b | pam | no fix listed | 1 |
| geoscienceaustralia/ | f4039b45572a | pam | no fix listed | 1 |
| geoservercloud/ | ca58b74529cd | pam | no fix listed | 1 |
| geoservercloud/ | 5dc0c93a1710 | pam | no fix listed | 1 |
| geoservercloud/ | 47ae1bdb4bcc | pam | no fix listed | 1 |
| geoservercloud/ | 28c3e5a8c5a3 | pam | no fix listed | 1 |
| geoservercloud/ | 8c70ee06d5ab | pam | no fix listed | 1 |
| geoservercloud/ | 42775ba6a4da | pam | no fix listed | 1 |
| gethue/ | 11b649636e68 | pam | no fix listed | 1 |
| gethue/ | 5702b2c37ff9 | pam | no fix listed | 1 |
| gethue/ | 7d5c1b9f8a79 | pam | 1.4.0-11ubuntu2.7 | 1 |
| getsentry/ | ba7bf9163219 | pam | no fix listed | 1 |
| ghostfolio/ | e3c6ab53e49b | pam | no fix listed | 1 |
| ghusta/ | 879d0919fdcc | pam | no fix listed | 1 |
| gitlab/ | 860d4a3fec7a | pam | no fix listed | 1 |
| glasskube/ | be5133100d63 | pam | 1.4.0-11ubuntu2.7 | 1 |
| glpi/ | 7b50172cdb7d | pam | no fix listed | 1 |
| gobitfly/ | 1d08a7986348 | pam | 1.4.0-11ubuntu2.7 | 1 |
| golenski/ | c863dcb0c513 | pam | no fix listed | 1 |
| golenski/ | 3a2b36df247b | pam | no fix listed | 1 |
| golenski/ | 954caf4aaf6a | pam | no fix listed | 1 |
| gopaddle/ | 435359250b63 | pam | 1.4.0-11ubuntu2.7 | 1 |
| gopinatht/ | 632cb2e9c399 | pam | no fix listed | 1 |
| gotenberg/ | 0d28ae9a9644 | pam | no fix listed | 1 |
| gotenberg/ | 206a6c708fc6 | pam | no fix listed | 1 |
| gotenberg/ | 67097317623a | pam | no fix listed | 1 |
| gotenberg/ | cf0b9a7ca3cf | pam | no fix listed | 1 |
| gotson/ | 9b15ea6bfc30 | pam | no fix listed | 1 |
| gradiant/ | 332031245fce | pam | 1.5.3-5ubuntu5.6 | 1 |
| grafana/ | 3364714a2f64 | pam | 1.5.3-5ubuntu5.6 | 1 |
| grafana/ | 01a63f4e032c | pam | 1.5.3-5ubuntu5.6 | 1 |
| grafana/ | 06bdcbb51fc2 | pam | 1.5.3-5ubuntu5.6 | 1 |
| grafana/ | 491b0578c049 | pam | 1.5.3-5ubuntu5.6 | 1 |
| grafana/ | 84b76d56c594 | pam | 1.5.3-5ubuntu5.6 | 1 |