StackRadar

CVE-2026-54411

High

Advisory

Published 14 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,426
of 17,821 indexed, latest versions
Container images
2,442
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: pam security update

Carried by container images the latest versions of 2,426 of 17,821 indexed charts deploy, on 2,442 images.

Affected packageAffected versionsFixed inImages
pamdeb1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.12,266
pamrpm1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+29 more0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more176
OSV records
DEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
Also known as
RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1

Charts affected

2,426 by stars
ChartLatestAffected imagesRadar Score
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
pam@1.7.0-5
no fix listed

Open the chart page →

3,921
vaultwardenpascaliskeVerified publisher2.0.01 of 1See more

vaultwarden pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
pam@1.7.0-5
no fix listed

Open the chart page →

3,459
examplepauls-helm-charts0.1.21 of 1See more

example pauls-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
pam@1.7.0-5
no fix listed

Open the chart page →

1,956
kubeconpauls-helm-charts0.1.01 of 1See more

kubecon pauls-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
pam@1.7.0-5
no fix listed

Open the chart page →

1,956
pagespawan-pages1.0.02 of 3See more

pages pawan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,285
matomopetbattle11.0.12 of 2See more

matomo petbattle 11.0.1

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
pam@1.5.2-6+deb12u1
no fix listed
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

11,303
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
pam@1.3.1-14.el8
0:1.3.1-40.el8_10

Open the chart page →

15,479
pet-battle-nsffpetbattle0.0.21 of 4See more

pet-battle-nsff petbattle 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
tensorflow/serving:latest8a208c232297
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7

Open the chart page →

3,887
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
pam@1.3.1-14.el8
0:1.3.1-40.el8_10

Open the chart page →

15,479
clickhousepetersandor14.3.21 of 1See more

clickhouse petersandor 14.3.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.3.2.398745843b17f9
pam@1.4.0-11ubuntu2.5
1.4.0-11ubuntu2.7

Open the chart page →

2,243
mariadbpetersandor15.2.51 of 1See more

mariadb petersandor 15.2.5

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnami/mariadb:11.7.216a7dae804fb
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

2,958
memcachedpetersandor14.1.61 of 1See more

memcached petersandor 14.1.6

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnami/memcached:1.6.38dd8f2cba9a5b
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

2,437
mongodbpetersandor14.1.81 of 1See more

mongodb petersandor 14.1.8

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnami/mongodb:8.0.8b3bd5b6be9a0
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

4,519
redispetersandor15.2.21 of 1See more

redis petersandor 15.2.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnami/redis:7.4.24e65bf641805
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

2,790
pgcatpgcatVerified publisher0.2.51 of 1See more

pgcat pgcat 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,832
redis-stack-awsphamxuanduong0.1.01 of 1See more

redis-stack-aws phamxuanduong 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.4.0-v0887cf87cc744
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7

Open the chart page →

3,315
dummy-servicephanVerified publisher0.3.41 of 1See more

dummy-service phan 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
phan2410/dummy-service:0.0.89c6ed6de26ca
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

5,917
falcon-asgi-serverphanVerified publisher0.1.01 of 1See more

falcon-asgi-server phan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
phan2410/falcon-asgi-server:0.1.04a86d138832d
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

8,401
azure-votephppgadmin-helmVerified publisher0.1.11See more

azure-vote phppgadmin-helm 0.1.1

1 container image this version deploys carries CVE-2026-54411.

Container imageDigestPackageFixed in
library/redis:latest8a1efc5f4795
pam@1.7.0-5
no fix listed

Open the chart page →

phronetisphronetis0.1.272 of 2See more

phronetis phronetis 0.1.27

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
knspar/phronetis:0.1.4609499d2dc91a
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
knspar/phronetis-operator:0.1.60c4f0543ee58
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

16,538
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
pam@1.3.1-5ubuntu4.1
no fix listed

Open the chart page →

92,617
pieeatpieeatOfficialVerified publisher0.9.31 of 1See more

pieeat pieeat 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/maxiv/pieeat:0.9.3099715479210
pam@1.7.0-5
no fix listed

Open the chart page →

1,472
pagespighosh-pages1.0.02 of 3See more

pages pighosh-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,285
firehose-corepinaxVerified publisher0.1.11 of 2See more

firehose-core pinax 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
sigp/lighthouse:latest-amd6450f66cfebb6d
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7

Open the chart page →

3,562
firehose-ethereumpinaxVerified publisher0.3.22 of 2See more

firehose-ethereum pinax 0.3.2

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
sigp/lighthouse:latest-amd6450f66cfebb6d
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.6

Open the chart page →

7,237
subgraph-oraclepinaxVerified publisher0.0.11 of 1See more

subgraph-oracle pinax 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

11,569
substreams-sink-kvpinaxVerified publisher0.0.41 of 1See more

substreams-sink-kv pinax 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
pam@1.3.1-5ubuntu4.7
no fix listed

Open the chart page →

58,425
substreams-sink-nooppinaxVerified publisher0.0.31 of 1See more

substreams-sink-noop pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
pam@1.3.1-5ubuntu4.7
no fix listed

Open the chart page →

58,366
substreams-tier-2pinaxVerified publisher0.0.81 of 1See more

substreams-tier-2 pinax 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.6

Open the chart page →

5,001
pingdom-operatorpingdom-operator0.0.201 of 1See more

pingdom-operator pingdom-operator 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

12,156
spring-boot-openshiftpiominVerified publisher0.3.111 of 1See more

spring-boot-openshift piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
pam@1.4.0-11ubuntu2
1.4.0-11ubuntu2.7

Open the chart page →

7,632
web-chartpjw-ktcloudlab0.1.01 of 1See more

web-chart pjw-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pam@1.7.0-5
no fix listed

Open the chart page →

1,956
planectlplanectlVerified publisher0.7.04 of 10See more

planectl planectl 0.7.0

4 of the 10 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
pam@1.5.2-6+deb12u1
no fix listed
bitnamilegacy/valkey:8.1.3-debian-12-r34f0191fba7d3
pam@1.5.2-6+deb12u1
no fix listed
library/node:208f693eaa7e0a
pam@1.5.2-6+deb12u2
no fix listed
quay.io/argoproj/argocd:v2.14.115fc69e31c755
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6

Open the chart page →

26,565
playlist-mirrorplaylist-mirrorVerified publisher1.0.31 of 1See more

playlist-mirror playlist-mirror 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/itobey/playlist-mirror:1.0.0601082677a46
pam@1.7.0-5
no fix listed

Open the chart page →

1,090
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
pam@1.3.1-4.el8
0:1.3.1-40.el8_10

Open the chart page →

11,165
k8s-oidc-discovery-providerpnnl-miscscripts0.1.21 of 2See more

k8s-oidc-discovery-provider pnnl-miscscripts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:1.29.49dd288848f44
pam@1.7.0-5
no fix listed

Open the chart page →

4,396
nginx-apppnnl-miscscripts0.1.21 of 1See more

nginx-app pnnl-miscscripts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pam@1.7.0-5
no fix listed

Open the chart page →

1,956
pixiecore-simpleconfigpnnl-miscscripts0.1.51 of 1See more

pixiecore-simpleconfig pnnl-miscscripts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
pam@1.7.0-5
no fix listed

Open the chart page →

1,956
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
pam@1.3.1-25.el8
0:1.3.1-40.el8_10

Open the chart page →

13,114
pod-birdspod-birds0.1.01 of 1See more

pod-birds pod-birds 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
teknas09/bird-pod:latest12a1fa85c4aa
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

13,144
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

79,983
libretimepodzone-chartsVerified publisher0.4.12 of 9See more

libretime podzone-charts 0.4.1

2 of the 9 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed
library/postgres:16.24aea012537ed
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

11,435
static-sitepodzone-chartsVerified publisher0.1.11 of 2See more

static-site podzone-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

6,614
agentpolyaxon2.17.03 of 4See more

agent polyaxon 2.17.0

3 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
polyaxon/polyaxon-agent:2.17.0da877a2647fc
pam@1.7.0-5
no fix listed
polyaxon/polyaxon-cli:2.17.0297ed47ed63a
pam@1.7.0-5
no fix listed
polyaxon/polyaxon-streams:2.17.0a5fec70e757b
pam@1.7.0-5
no fix listed

Open the chart page →

9,046
polyaxonpolyaxon2.17.04 of 5See more

polyaxon polyaxon 2.17.0

4 of the 5 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1102e2f47a405e
pam@1.5.2-6+deb12u1
no fix listed
polyaxon/polyaxon-agent:2.17.0da877a2647fc
pam@1.7.0-5
no fix listed
polyaxon/polyaxon-api:2.17.0163707082036
pam@1.7.0-5
no fix listed
polyaxon/polyaxon-cli:2.17.0297ed47ed63a
pam@1.7.0-5
no fix listed

Open the chart page →

12,838
beylaportefaix-hub0.1.01 of 1See more

beyla portefaix-hub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
grafana/beyla:1.3.336d07f8d276e
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

2,736
quickwitportefaix-hub0.1.11 of 1See more

quickwit portefaix-hub 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.1d29332bdadcc
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,683
postgrespostgresVerified publisher0.1.11 of 1See more

postgres postgres 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:13.12ced3ba927f4c
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

4,986
svc-postgrespostgres-fiap-lanches0.1.01 of 1See more

svc-postgres postgres-fiap-lanches 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
pam@1.7.0-5
no fix listed

Open the chart page →

1,699
keydbpozetron0.5.31 of 1See more

keydb pozetron 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
pozetroninc/keydb:v6.0.1653ae64f29da8
pam@1.1.8-3.6ubuntu2.18.04.2
no fix listed

Open the chart page →

7,035

Container images carrying it

2,442 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

No deployed image carries CVE-2026-54411.

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.