StackRadar

CVE-2026-54411

High

Advisory

Published 14 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,459
of 17,821 indexed, latest versions
Container images
2,489
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: pam security update

Carried by container images the latest versions of 2,459 of 17,821 indexed charts deploy, on 2,489 images.

Affected packageAffected versionsFixed inImages
pamdeb1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.12,311
pamrpm1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+29 more0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more178
OSV records
DEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
Also known as
RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1

Charts affected

2,459 by stars
ChartLatestAffected imagesRadar Score
nightingalexxl-job-adminVerified publisher0.2.113 of 6See more

nightingale xxl-job-admin 0.2.11

3 of the 6 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6
flashcatcloud/nightingale:8.0.0-beta.11ea1b0aaabe09
pam@1.5.2-6+deb12u1
no fix listed
library/redis:6.2d2ad7b21cafa
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

9,743
pgcatxxl-job-adminVerified publisher0.3.31 of 1See more

pgcat xxl-job-admin 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,197
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pam@1.7.0-5
no fix listed

Open the chart page →

1,887
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
pam@1.7.0-5
no fix listed

Open the chart page →

1,257
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
pam@1.7.0-5
no fix listed

Open the chart page →

1,887
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

2,638
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

2,710
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

1,593
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

9,297

Container images carrying it

2,489 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/trow-registry/trow:0.10.075b7d2dcdb91
pam@1.7.0-5
no fix listed
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
1
ghcr.io/twigex/cospace:lateste5ecfd607e42
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
pam@1.7.0-5
no fix listed
1
ghcr.io/utkuozdemir/nvidia_gpu_exporter:1.5.0d75967a4dd72
pam@1.7.0-5ubuntu3
1.7.0-5ubuntu3.1
1
ghcr.io/vinny1892/octantis:latest45459c0910fc
pam@1.7.0-5
no fix listed
1
ghcr.io/virtuos/librechat_exporter:2.0.050ea1cf0086f
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
pam@1.4.0-11ubuntu2.5
1.4.0-11ubuntu2.7
1
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
pam@1.5.2-6
no fix listed
1
ghcr.io/wearefrank/frank-gateway:1.0.05ccf797ccdf1
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6
1
ghcr.io/wekan/ferretdb:latestebed9a5eaae0
pam@1.7.0-5
no fix listed
1
ghcr.io/wekan/wekan:v11.90078ca230c0df
pam@1.7.0-5
no fix listed
1
ghcr.io/wgbh-mla/chowda:main86ab9effd1a5
pam@1.7.0-5
no fix listed
1
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/wiremind/bitnami/redis:8.4.0-debian-12-r31f0f7ddc4370
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/wittdennis/homeassistant-otbr:4.2.5282f840612d9
pam@1.7.0-5
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7
1
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/wrenix/autopush-rs/autoconnect:1.84.285f93ced88b2
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/wrenix/autopush-rs/autoendpoint:1.84.2d95e9a124eed
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
pam@1.7.0-5
no fix listed
1
ghcr.io/yourls/yourls:1.10.67550ff86b15f
pam@1.7.0-5
no fix listed
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
pam@1.5.2-6+deb12u2
no fix listed
1
ghcr.io/zammad/zammad:7.1.3-0014ce435c77651e
pam@1.7.0-5
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
pam@1.5.2-6+deb12u1
no fix listed
1
ghcr.io/zystem-io/zymtrace-pub-gateway:26.9.2ae9ae0925ff8
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7
1
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
pam@1.3.1-5ubuntu4.3
no fix listed
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
pam@1.1.8-3.6ubuntu2.18.04.6
no fix listed
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
pam@1.3.1-5ubuntu4.3
no fix listed
1
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
pam@1.1.8-3.6ubuntu2.18.04.6
no fix listed
1
mcr.microsoft.com/playwright/mcp:v0.0.43e101b832b34d
pam@1.5.2-6+deb12u1
no fix listed
1
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest5a5d32281374
pam@1.5.2-6+deb12u2
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6
1
public.ecr.aws/aktosecurity/redis47200b041382
pam@1.5.2-6+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.