StackRadar

CVE-2026-54411

High

Advisory

Published 14 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,398
of 17,792 indexed, latest versions
Container images
2,404
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: pam security update

Carried by container images the latest versions of 2,398 of 17,792 indexed charts deploy, on 2,404 images.

Affected packageAffected versionsFixed inImages
pamdeb1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.12,227
pamrpm1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+28 more0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more177
OSV records
DEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
Also known as
RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1

Charts affected

2,398 by stars
ChartLatestAffected imagesRadar Score
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
pam@1.3.1-5ubuntu4.6
no fix listed
stackstorm/st2api:3.86f56d239d280
pam@1.3.1-5ubuntu4.6
no fix listed
stackstorm/st2auth:3.833ecfda16608
pam@1.3.1-5ubuntu4.6
no fix listed
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
pam@1.3.1-5ubuntu4.6
no fix listed
stackstorm/st2notifier:3.8f190a6212195
pam@1.3.1-5ubuntu4.6
no fix listed
stackstorm/st2rulesengine:3.8259503496ff9
pam@1.3.1-5ubuntu4.6
no fix listed
stackstorm/st2scheduler:3.8b1de2055c362
pam@1.3.1-5ubuntu4.6
no fix listed
stackstorm/st2sensorcontainer:3.8b1a338f64773
pam@1.3.1-5ubuntu4.6
no fix listed
stackstorm/st2stream:3.81c8904a3bf67
pam@1.3.1-5ubuntu4.6
no fix listed
stackstorm/st2timersengine:3.81bf35bfaf00c
pam@1.3.1-5ubuntu4.6
no fix listed
stackstorm/st2web:3.809989a26c8b7
pam@1.3.1-5ubuntu4.6
no fix listed
stackstorm/st2workflowengine:3.819fdfffdbba8
pam@1.3.1-5ubuntu4.6
no fix listed

Open the chart page →

97,160
supabasetokens-studioVerified publisher1.0.05 of 14See more

supabase tokens-studio 1.0.0

5 of the 14 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
supabase/edge-runtime:v1.59.0eff9c554d649
pam@1.5.2-6+deb12u1
no fix listed
supabase/postgres-meta:v0.84.2d0a96973e9f1
pam@1.5.2-6+deb12u1
no fix listed
supabase/realtime:v2.33.8d207e6e23ad3
pam@1.5.2-6+deb12u1
no fix listed
supabase/studio:20241021-9f9b08326d8070c55e9
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

23,400
wekanwekanVerified publisher11.83.02 of 3See more

wekan wekan 11.83.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/wekan/ferretdb:latest6cb94aa01999
pam@1.7.0-5
no fix listed
ghcr.io/wekan/wekan:v11.83137951e3fb40
pam@1.7.0-5
no fix listed

Open the chart page →

1,635
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
pam@1.5.2-6+deb12u1
no fix listed
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

8,586
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

1,824
budibasebudibase0.0.0-master3 of 7See more

budibase budibase 0.0.0-master

3 of the 7 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
pam@1.5.2-6+deb12u2
no fix listed
budibase/proxy:3.41.38d780b6ee602
pam@1.7.0-5
no fix listed
library/redis:latest298e5b3bc566
pam@1.7.0-5
no fix listed

Open the chart page →

10,981
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
pam@1.4.0-11ubuntu2
1.4.0-11ubuntu2.7

Open the chart page →

3,504
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,055
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
pam@1.4.0-11ubuntu2.3
1.4.0-11ubuntu2.7

Open the chart page →

7,968
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

1,295
quickwitquickwit0.8.171 of 1See more

quickwit quickwit 0.8.17

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,507
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
pam@1.3.1-5ubuntu4.2
no fix listed

Open the chart page →

11,470
zillazillaOfficialVerified publisher2.4.31 of 1See more

zilla zilla 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/aklivity/zilla:2.4.3e33d59dbb606
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7

Open the chart page →

1,746
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
pam@1.7.0-5
no fix listed

Open the chart page →

2,981
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
pam@1.4.0-11ubuntu2.3
1.4.0-11ubuntu2.7

Open the chart page →

4,294
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,049
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
pam@1.5.2-6+deb12u1
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
quay.io/devtron/postgres:14.91b594392f7cb
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

33,219
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6

Open the chart page →

3,722
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
pam@1.5.3-5ubuntu5
1.5.3-5ubuntu5.6

Open the chart page →

5,415
nextcloudgroundhog2k0.22.61 of 3See more

nextcloud groundhog2k 0.22.6

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nextcloud:34.0.4:34.0.4-apache8418c398d767
pam@1.7.0-5
no fix listed

Open the chart page →

3,845
ilumilumOfficialVerified publisher6.7.34 of 19See more

ilum ilum 6.7.3

4 of the 19 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
pam@1.5.2-6+deb12u1
no fix listed
bitnamilegacy/postgresql:16233f361c5819
pam@1.5.2-6+deb12u1
no fix listed
ilum/api:6.7.3624fd09528c8
pam@1.7.0-5
no fix listed
ilum/marquez:0.54.06e1d709d41f8
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

23,406
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6

Open the chart page →

3,450
lakekeeperlakekeeperVerified publisher0.12.01 of 2See more

lakekeeper lakekeeper 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
pam@1.7.0-5
no fix listed

Open the chart page →

1,982
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
pam@1.5.2-6+deb12u1
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

7,071
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
pam@1.7.0-5
no fix listed

Open the chart page →

5,730
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
pam@1.7.0-5
no fix listed

Open the chart page →

4,454
netris-controllernetrisai2.8.24 of 14See more

netris-controller netrisai 2.8.2

4 of the 14 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
netrisai/controller-grpc:4.6.0.00753178bf173c2
pam@1.3.1-5ubuntu4.7
no fix listed
netrisai/controller-telescope:4.6.0.00414d82948a8b2
pam@1.3.1-5ubuntu4.7
no fix listed
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
pam@1.3.1-5ubuntu4.7
no fix listed
netrisai/controller-web-session-generator:0.2.0a030a31289f4
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

30,532
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
pam@1.7.0-5
no fix listed

Open the chart page →

2,361
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

17,394
paperless-ngxpaperless-ngxVerified publisher0.3.223 of 3See more

paperless-ngx paperless-ngx 0.3.22

3 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
pam@1.5.2-6+deb12u1
no fix listed
valkey/valkey:9.1.2c123e3715db6
pam@1.7.0-5
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
pam@1.7.0-5
no fix listed

Open the chart page →

8,591
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed
platform9community/api-gateway:latest40a4970de568
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed
platform9community/customers-service:latest2089811e5cc6
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed
platform9community/vets-service:latestd1165c94dfb3
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed
platform9community/visits-service:latest8d11b50368c6
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed

Open the chart page →

41,967
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7

Open the chart page →

14,283
selenium3selenium31.2.41 of 1See more

selenium3 selenium3 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
pam@1.3.1-5ubuntu4.1
no fix listed

Open the chart page →

11,848
tbmq-clustertbmq-helm-chartOfficialVerified publisher2.1.02 of 3See more

tbmq-cluster tbmq-helm-chart 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
pam@1.7.0-5
no fix listed
thingsboard/tbmq-node:2.4.070661025dba5
pam@1.7.0-5
no fix listed

Open the chart page →

3,577
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
pam@1.3.1-5ubuntu4.7
no fix listed

Open the chart page →

7,407
plexutkuozdemirVerified publisher2.1.11 of 1See more

plex utkuozdemir 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
linuxserver/plex:1.25.24a13ced2326c
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

6,397
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

2,334
istio-operatorwiremindVerified publisher1.18.21 of 1See more

istio-operator wiremind 1.18.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
istio/operator:1.18.270f9d1fe5fff
pam@1.4.0-11ubuntu2.3
1.4.0-11ubuntu2.7

Open the chart page →

5,686
zabbix-serveraekondratievVerified publisher1.0.63 of 4See more

zabbix-server aekondratiev 1.0.6

3 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
pam@1.3.1-5ubuntu4.3
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
pam@1.3.1-5ubuntu4.3
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

30,852
phpmyadminalekcVerified publisher0.3.11 of 1See more

phpmyadmin alekc 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
pam@1.7.0-5
no fix listed

Open the chart page →

2,676
wazuh-agentavistoVerified publisher4.12.21 of 1See more

wazuh-agent avisto 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

6,533
awx-operatorawx-operator-helm3.2.11 of 2See more

awx-operator awx-operator-helm 3.2.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
pam@1.3.1-27.el8
0:1.3.1-40.el8_10

Open the chart page →

9,882
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
pam@1.3.1-5ubuntu4.6
no fix listed

Open the chart page →

12,176
memcachedcloudpirates-memcachedVerified publisher0.14.91 of 1See more

memcached cloudpirates-memcached 0.14.9

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/memcached:1.6.4575c93cc91e76
pam@1.7.0-5
no fix listed

Open the chart page →

1,081
cluster-secretclutersecretVerified publisher0.7.01 of 1See more

cluster-secret clutersecret 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,057
codercoderOfficialVerified publisher1.44.62 of 2See more

coder coder 1.44.6

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
coderenvs/coder-service:1.44.61deffc4670e6
pam@1.3.1-27.el8
0:1.3.1-40.el8_10
coderenvs/timescale:1.44.676fd37fe6830
pam@1.3.1-27.el8
0:1.3.1-40.el8_10

Open the chart page →

7,183
convoyconvoyVerified publisher3.7.132 of 3See more

convoy convoy 3.7.13

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
pam@1.5.2-6+deb12u1
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

5,969
cortexcortex3.3.82 of 4See more

cortex cortex 3.3.8

2 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/memcached:1.6.4575c93cc91e76
pam@1.7.0-5
no fix listed
library/nginx:1.3105b8cb60c354
pam@1.7.0-5
no fix listed

Open the chart page →

3,967
valkeygroundhog2k2.3.41 of 1See more

valkey groundhog2k 2.3.4

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
valkey/valkey:9.1.2475ee65cc75c
pam@1.7.0-5
no fix listed

Open the chart page →

836
hasurahasura-extraVerified publisher3.0.11 of 1See more

hasura hasura-extra 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.34.0-ce0111b0204136
pam@1.4.0-11ubuntu2.3
1.4.0-11ubuntu2.7

Open the chart page →

4,973

Container images carrying it

2,404 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/steadybit/extension-container:v1.8.0dd31d4713ef6
pam@1.7.0-5
no fix listed
1
ghcr.io/steadybit/extension-host:v1.8.0a198ac7bc8c1
pam@1.7.0-5
no fix listed
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6
1
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.6
1
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.6
1
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
pam@1.3.1-5ubuntu4.7
no fix listed
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
pam@1.3.1-5ubuntu4.7
no fix listed
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6
1
ghcr.io/strrl/wonder-mesh-net:v2026.629.0625b140372fd
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
1
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/sudo-kraken/3d-printing-cost-calculators:v1.1.1220c5e4e1a3d
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/sudo-kraken/authentik-webfinger-proxy:v1.1.1e1351a977607
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/sudo-kraken/fantasy-dice-chamber:v1.3.299fd4cb0f4fe
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/sudo-kraken/finances-tracker:v1.1.1c73527cde81c
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/sudo-kraken/jf-pushover-webhook:v1.1.0ee9cf22a39ab
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
pam@1.7.0-5
no fix listed
1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
pam@1.7.0-5
no fix listed
1
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7
1
ghcr.io/trow-registry/trow:0.10.075b7d2dcdb91
pam@1.7.0-5
no fix listed
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
1
ghcr.io/twigex/cospace:lateste5ecfd607e42
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
pam@1.7.0-5
no fix listed
1
ghcr.io/utkuozdemir/nvidia_gpu_exporter:1.5.0d75967a4dd72
pam@1.7.0-5ubuntu3
1.7.0-5ubuntu3.1
1
ghcr.io/vinny1892/octantis:latest45459c0910fc
pam@1.7.0-5
no fix listed
1
ghcr.io/virtuos/librechat_exporter:2.0.050ea1cf0086f
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
pam@1.4.0-11ubuntu2.5
1.4.0-11ubuntu2.7
1
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
pam@1.5.2-6
no fix listed
1
ghcr.io/wearefrank/frank-gateway:1.0.05ccf797ccdf1
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6
1
ghcr.io/wekan/ferretdb:latest6cb94aa01999
pam@1.7.0-5
no fix listed
1
ghcr.io/wekan/wekan:v11.83137951e3fb40
pam@1.7.0-5
no fix listed
1
ghcr.io/wgbh-mla/chowda:main86ab9effd1a5
pam@1.7.0-5
no fix listed
1
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/wiremind/bitnami/redis:8.4.0-debian-12-r31f0f7ddc4370
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/wittdennis/homeassistant-otbr:4.2.5282f840612d9
pam@1.7.0-5
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.