CVE-2026-54411
HighAdvisory
Published 14 Jun 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.2
- base score, highest
- EPSS
- 0.003
- 25th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,459
- of 17,821 indexed, latest versions
- Container images
- 2,489
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Red Hat Security Advisory: pam security update
Carried by container images the latest versions of 2,459 of 17,821 indexed charts deploy, on 2,489 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pamdeb | 1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more | 1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.1 | 2,311 |
| pamrpm | 1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+29 more | 0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more | 178 |
- OSV records
- DEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
- Also known as
- RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1
Charts affected
2,459 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| nightingalexxl-job-adminVerified publisher | 0.2.11 | 3 of 6See more | 9,743 |
| pgcatxxl-job-adminVerified publisher | 0.3.3 | 1 of 1See more | 3,197 |
| nginx-chartxxoznge-nginx | 0.1.0 | 1 of 1See more | 1,887 |
| helm-demoyahoon-helm-demoVerified publisher | 1.0.0 | 1 of 1See more | 1,257 |
| my-nginx-appyasser-nginx-app | 0.1.0 | 1 of 1See more | 1,887 |
| api-snapyoukadevVerified publisher | 0.1.1 | 1 of 1See more | 2,638 |
| changedetection-iozekker6Verified publisher | 1.102.0 | 1 of 1See more | 2,710 |
| NEW_APPzekker6Verified publisher | 0.0.0 | 1 of 1See more | 1,593 |
| clickhousezloi-space | 1.2.0 | 2 of 3See more | 9,297 |
Container images carrying it
2,489 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| jaedb/ | 048cfbf58d57 | pam | no fix listed | 1 |
| jakowenko/ | b858bac9e32a | pam | no fix listed | 1 |
| janzo83/ | fb3c4ac36f3e | pam | no fix listed | 1 |
| jbtronics/ | fd68338829ed | pam | no fix listed | 1 |
| jedi132000/ | dc2a81e92f23 | pam | no fix listed | 1 |
| jellyfin/ | 1694ff069f0c | pam | no fix listed | 1 |
| jellyfin/ | 17285f9cce63 | pam | no fix listed | 1 |
| jellyfin/ | 17c3a8d9dddb | pam | no fix listed | 1 |
| jellyfin/ | 333b64771663 | pam | no fix listed | 1 |
| jellyfin/ | 78d3ea1207d1 | pam | no fix listed | 1 |
| jellyfin/ | 79fb3d73a3e9 | pam | no fix listed | 1 |
| jellyfin/ | 7ae36aab93ef | pam | no fix listed | 1 |
| jellyfin/ | 96b09723b22f | pam | no fix listed | 1 |
| jenkins/ | 95313257a8cd | pam | no fix listed | 1 |
| jenkins/ | de4fea113221 | pam | no fix listed | 1 |
| jertel/ | 3cbf63f9b7dc | pam | no fix listed | 1 |
| jhipster/ | 7184525acd4d | pam | no fix listed | 1 |
| jhoncytech/ | 18c3ca1f411e | pam | no fix listed | 1 |
| jingking/ | 43e74ab234e1 | pam | no fix listed | 1 |
| jjorozco20/ | b5e44e3ba09c | pam | no fix listed | 1 |
| jmferrer/ | 030f68ec6998 | pam | no fix listed | 1 |
| jodogne/ | 6ff510aa29c2 | pam | no fix listed | 1 |
| johly/ | 9f702b91e0e7 | pam | no fix listed | 1 |
| joplin/ | 3f7b852959aa | pam | no fix listed | 1 |
| jordan/ | f75025fe8ea8 | pam | no fix listed | 1 |
| josh5/ | 4d49c4816260 | pam | 1.4.0-11ubuntu2.7 | 1 |
| journeyapps/ | 413a0c813e96 | pam | no fix listed | 1 |
| jpgouin/ | bfdd0088c776 | pam | no fix listed | 1 |
| jupyterhub/ | 3974ba945e65 | pam | 1.5.3-5ubuntu5.6 | 1 |
| jupyterhub/ | b6b4a1a34bf0 | pam | no fix listed | 1 |
| jupyterhub/ | e4770285aaf7 | pam | no fix listed | 1 |
| jupyterhub/ | ec78bdae0fed | pam | no fix listed | 1 |
| jupyterhub/ | e3e6f3051df8 | pam | no fix listed | 1 |
| kafkace/ | 7adc206bf5a4 | pam | 1.5.3-5ubuntu5.6 | 1 |
| kafkakraft/ | 062d697db7e5 | pam | 1.4.0-11ubuntu2.7 | 1 |
| kafkakraft/ | f261ad288fce | pam | 1.4.0-11ubuntu2.7 | 1 |
| kafkakraft/ | 2e4b593b878b | pam | 1.4.0-11ubuntu2.7 | 1 |
| kayrosuno/ | f3bd44b29b0d | pam | 1.5.3-5ubuntu5.6 | 1 |
| kennethreitz/ | 599fe5e50731 | pam | no fix listed | 1 |
| kfirfer/ | 2efb4a5d74a3 | pam | no fix listed | 1 |
| kimai/ | 3084f1e5ecdc | pam | no fix listed | 1 |
| kinseii/ | 7160eb143728 | pam | no fix listed | 1 |
| kitware/ | d7767d9b9da4 | pam | no fix listed | 1 |
| kixote/ | 4e9dff179519 | pam | no fix listed | 1 |
| kixote/ | 628f79a08cc7 | pam | no fix listed | 1 |
| knspar/ | 09499d2dc91a | pam | 1.5.3-5ubuntu5.6 | 1 |
| knspar/ | 0c4f0543ee58 | pam | no fix listed | 1 |
| kong/ | a6ac46531193 | pam | 1.4.0-11ubuntu2.7 | 1 |
| kong/ | 6addf50e6bd8 | pam | 1.5.3-5ubuntu5.6 | 1 |
| krontechnology/ | 1cc7d5be6529 | pam | 1.4.0-11ubuntu2.7 | 1 |