StackRadar

CVE-2026-54411

High

Advisory

Published 14 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,423
of 17,828 indexed, latest versions
Container images
2,448
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: pam security update

Carried by container images the latest versions of 2,423 of 17,828 indexed charts deploy, on 2,448 images.

Affected packageAffected versionsFixed inImages
pamdeb1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.12,272
pamrpm1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+29 more0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more176
OSV records
DEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
Also known as
RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1

Charts affected

2,423 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,448 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/mongo:8.0.20098862b1339f
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6
2
library/mongo:5.041108d183e97
pam@1.3.1-5ubuntu4.7
no fix listed
2
library/mongo:4.2.358b25d51baa1
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed
2
library/nginx:latest6e23479198b9
pam@1.7.0-5
no fix listed
2
library/nginx:1.27.098f8ec75657d
pam@1.5.2-6+deb12u1
no fix listed
2
library/nginx:1.29.49dd288848f44
pam@1.7.0-5
no fix listed
2
library/phpmyadmin:5.2.3-apache:latest3a8a8d6b5289
pam@1.7.0-5
no fix listed
2
library/phpmyadmin:5.2.16e75aa8f767c
pam@1.5.2-6+deb12u1
no fix listed
2
library/postgres:17-bookworm051f7b7b3abd
pam@1.5.2-6+deb12u2
no fix listed
2
library/postgres:16.109f23e02d766
pam@1.5.2-6+deb12u1
no fix listed
2
library/postgres:18.11090bc3a8ccf
pam@1.7.0-5
no fix listed
2
library/postgres:14156f0b253fd6
pam@1.7.0-5
no fix listed
2
library/postgres:16.24aea012537ed
pam@1.5.2-6+deb12u1
no fix listed
2
library/postgres:18.06f3e42ad37de
pam@1.7.0-5
no fix listed
2
library/postgres:16.4e62fbf9d3e2b
pam@1.5.2-6+deb12u1
no fix listed
2
library/python:3.12-slim2f17fc044b57
pam@1.7.0-5
no fix listed
2
library/python:3.7eedf63967cdb
pam@1.5.2-6
no fix listed
2
library/rabbitmq:4.1.0-management935b3f84c1e4
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
2
library/rabbitmq:3.12.1-managementf020c06da226
pam@1.4.0-11ubuntu2.3
1.4.0-11ubuntu2.7
2
library/redis:8.10.1602d361c4da9
pam@1.7.0-5
no fix listed
2
library/redis:7.2.3a7cee7c8178f
pam@1.5.2-6+deb12u1
no fix listed
2
library/redis:8.2.2f0957bcaa75f
pam@1.5.2-6+deb12u1
no fix listed
2
library/redmine:6.1.3-trixief474a901faec
pam@1.7.0-5
no fix listed
2
library/ubuntu:16.04:xenial1f1a2d56de1d
pam@1.1.8-3.2ubuntu2.3
no fix listed
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
pam@1.7.0-5
no fix listed
2
library/wordpress:7.1.0-apache:latest5a93c470ae82
pam@1.7.0-5
no fix listed
2
library/wordpress:latesta85a30d9e752
pam@1.7.0-5
no fix listed
2
library/wordpress:7.1.0-apacheedeeae67330a
pam@1.7.0-5
no fix listed
2
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
pam@1.1.8-3.2ubuntu2.1
no fix listed
2
linuxserver/cloud9:latest:version-1.29.245c5fe102ff3
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed
2
locustio/locust:2.32.2a0d4b88e42c1
pam@1.5.2-6+deb12u1
no fix listed
2
longhornio/longhorn-manager:v1.2.3dca34321452c
pam@1.3.1-5ubuntu4.3
no fix listed
2
louislam/uptime-kuma:2.5.4917318f9d7be
pam@1.5.2-6+deb12u2
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
pam@1.5.2-6+deb12u2
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
pam@1.5.2-6+deb12u2
no fix listed
2
mbentley/omada-controller:4.3f4e682274bed
pam@1.1.8-3.6ubuntu2.18.04.6
no fix listed
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
pam@1.3.1-5ubuntu4.1
no fix listed
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
pam@1.5.2-6+deb12u1
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
pam@1.5.2-6+deb12u1
no fix listed
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
pam@1.5.2-6+deb12u1
no fix listed
2
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
pam@1.1.8-3.6ubuntu2
no fix listed
2
obolnetwork/charon:v1.10.0278c7e2897b6
pam@1.7.0-5
no fix listed
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
pam@1.3.1-5ubuntu4.3
no fix listed
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
pam@1.1.8-3.2ubuntu2.1
no fix listed
2
opea/embedding-tei:1.05c9639de61c1
pam@1.5.2-6+deb12u1
no fix listed
2
opea/reranking-tei:1.0e48613afb191
pam@1.5.2-6+deb12u1
no fix listed
2
opea/retriever-redis:1.0eb746b263705
pam@1.5.2-6+deb12u1
no fix listed
2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
pam@1.5.2-6+deb12u1
no fix listed
2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
pam@1.5.2-6+deb12u1
no fix listed
2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
pam@1.5.2-6+deb12u1
no fix listed
2

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.