StackRadar

CVE-2026-54411

High

Advisory

Published 14 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,470
of 17,828 indexed, latest versions
Container images
2,505
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: pam security update

Carried by container images the latest versions of 2,470 of 17,828 indexed charts deploy, on 2,505 images.

Affected packageAffected versionsFixed inImages
pamdeb1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.12,325
pamrpm1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+29 more0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more180
OSV records
DEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
Also known as
RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1

Charts affected

2,470 by stars
ChartLatestAffected imagesRadar Score
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/redis:8.10.18a1efc5f4795
pam@1.7.0-5
no fix listed

Open the chart page →

1,932
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
pam@1.7.0-5
no fix listed

Open the chart page →

7,481
postgresql-ha-chartsoldevelo-postgresql-ha-chart16.3.42 of 2See more

postgresql-ha-chart soldevelo-postgresql-ha-chart 16.3.4

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
soldevelo/pgpool:4.6.3-debian-12-r0044d16a65129
pam@1.5.2-6+deb12u2
no fix listed
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

4,704
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

5,752
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

10,549
squidsquid-helmVerified publisher0.1.01 of 1See more

squid squid-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ubuntu/squid:5.2-22.04_beta723891b5bc74
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7

Open the chart page →

2,713
splunk-operatorstakaterVerified publisher0.0.61 of 2See more

splunk-operator stakater 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
splunk/splunk-operator:2.0.0c4e0d3146226
pam@1.3.1-16.el8
0:1.3.1-40.el8_10

Open the chart page →

11,457
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
graphprotocol/graph-node:v0.37.0f4452cdedd68
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

4,731
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

13,652
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
pam@1.3.1-5ubuntu4.2
no fix listed

Open the chart page →

100,276
stornxstornxVerified publisher1.1.13 of 9See more

stornx stornx 1.1.1

3 of the 9 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6
alazidis/stornx:1.1.1602d4f7f090c
pam@1.5.2-6+deb12u2
no fix listed
istio/pilot:1.29.1f8b0e412ac4a
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

11,890
consolestratosVerified publisher4.4.04 of 4See more

console stratos 4.4.0

4 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
splatform/stratos-config-init:4.4.0-bc65c315c9f4edaca0af7
pam@1.3.0-lp152.10.25
1.7.2+git12-2.1
splatform/stratos-console:4.4.0-bc65c315c406b95a98b4a
pam@1.3.0-lp152.10.25
1.7.2+git12-2.1
splatform/stratos-jetstream:4.4.0-bc65c315c886311c331b9
pam@1.3.0-lp152.10.25
1.7.2+git12-2.1
splatform/stratos-mariadb:4.4.0-bc65c315c28560b598108
pam@1.3.0-lp152.10.25
1.7.2+git12-2.1

Open the chart page →

22,766
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

2,976
supabasesupabse0.8.06 of 11See more

supabase supabse 0.8.0

6 of the 11 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.30.13b709e4a0e5e
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6
kong/kong:3.9.16addf50e6bd8
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
supabase/edge-runtime:v1.74.02781daf92394
pam@1.5.2-6+deb12u2
no fix listed
supabase/postgres-meta:v0.96.6a84cc713585e
pam@1.5.2-6+deb12u2
no fix listed
supabase/realtime:v2.102.3aa1c92c0cf32
pam@1.5.2-6+deb12u1
no fix listed
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

18,347
supersonicsupersonicVerified publisher0.3.11 of 2See more

supersonic supersonic 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.92956bd9de830
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7

Open the chart page →

2,185
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
pam@1.7.0-5
no fix listed

Open the chart page →

3,375
mumblesyntaxerror404Verified publisher1.0.51 of 1See more

mumble syntaxerror404 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

2,233
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
teamcity-serverteamcity-server3.3.51 of 2See more

teamcity-server teamcity-server 3.3.5

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/haproxy:3.2ad870ce41292
pam@1.7.0-5
no fix listed

Open the chart page →

579
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
pam@1.7.0-5+dhi1
no fix listed

Open the chart page →

2,488
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

9,155
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

9,155
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
pam@1.7.0-5
no fix listed

Open the chart page →

13,742
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6

Open the chart page →

4,127
typemilltypemill-helm-chart2.2.02 of 2See more

typemill typemill-helm-chart 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
kixote/typemilldigest-pinned4e9dff179519
pam@1.7.0-5
no fix listed
kixote/typemilldigest-pinned628f79a08cc7
pam@1.7.0-5
no fix listed

Open the chart page →

5,606
typesensetypesenseVerified publisher1.1.41 of 1See more

typesense typesense 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
typesense/typesense:30.191604dc128e2
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7

Open the chart page →

1,953
ueransim-gnbueransim-gnbVerified publisher0.2.61 of 1See more

ueransim-gnb ueransim-gnb 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7

Open the chart page →

4,004
ueransim-uesueransim-uesVerified publisher0.1.21 of 1See more

ueransim-ues ueransim-ues 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7

Open the chart page →

4,004
u-storeunifieVerified publisher1.2.01 of 1See more

u-store unifie 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

15,337
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

12,815
taigaunxwaresVerified publisher2026.3.82 of 6See more

taiga unxwares 2026.3.8

2 of the 6 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
pam@1.7.0-5
no fix listed
taigaio/taiga-protected:latestfd4568a97a59
pam@1.7.0-5
no fix listed

Open the chart page →

9,260
varnish-cachevarnishVerified publisher1.1.11 of 1See more

varnish-cache varnish 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/varnish:7.5.04d0bb287d87b
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

4,462
varnish-ingress-controllervarnish-ingress-controllerVerified publisher0.5.01 of 1See more

varnish-ingress-controller varnish-ingress-controller 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
mariusm/vingress:0.5.0b3db186c3d72
pam@1.7.0-5
no fix listed

Open the chart page →

2,377
vaultwarden-kubernetes-secretsvaultwarden-kubernetes-secrets0.0.0-main1 of 2See more

vaultwarden-kubernetes-secrets vaultwarden-kubernetes-secrets 0.0.0-main

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

4,139
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

5,283
phpipamvquieVerified publisher1.0.31 of 3See more

phpipam vquie 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/mariadb:10.11.21c33370a599c
pam@1.4.0-11ubuntu2.3
1.4.0-11ubuntu2.7

Open the chart page →

7,129
waldurwaldur-chartsVerified publisher8.1.22 of 3See more

waldur waldur-charts 8.1.2

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
pam@1.7.0-5
no fix listed
opennode/waldur-mastermind:8.1.24c82b15d9042
pam@1.7.0-5
no fix listed

Open the chart page →

4,681
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

16,078
kafka-devwikimedia0.2.01 of 1See more

kafka-dev wikimedia 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
pam@1.1.8-1ubuntu2
no fix listed

Open the chart page →

41,568
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
pam@1.3.1-5ubuntu4.7
no fix listed

Open the chart page →

53,859
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
pam@1.7.0-5
no fix listed

Open the chart page →

7,805
wordpress-helmwordpress-helm0.2.91 of 4See more

wordpress-helm wordpress-helm 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
pam@1.7.0-5
no fix listed

Open the chart page →

8,519
workflows-sinkworkflows-sinkVerified publisher0.16.31 of 1See more

workflows-sink workflows-sink 0.16.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

1,443
wraftwraft0.1.122 of 9See more

wraft wraft 0.1.12

2 of the 9 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
typesense/typesense:28.0.rc35dea1b62b7b6e
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
pam@1.3.1-25.el8
0:1.3.1-40.el8_10

Open the chart page →

9,325
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
pam@1.4.0-11ubuntu2.3
1.4.0-11ubuntu2.7

Open the chart page →

9,925
yugawareyugabyteVerified publisher2026.1.11 of 3See more

yugaware yugabyte 2026.1.1

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:14.22eba8ddbdd837
pam@1.7.0-5
no fix listed

Open the chart page →

2,698
zcash-stackzcashVerified publisher0.4.51 of 2See more

zcash-stack zcash 0.4.5

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
electriccoinco/lightwalletd:v0.5.42ae3a551e111
pam@1.7.0-5
no fix listed

Open the chart page →

2,974
crowdsec-web-uizekker6Verified publisher0.51.01 of 1See more

crowdsec-web-ui zekker6 0.51.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
pam@1.7.0-5
no fix listed

Open the chart page →

1,466
mikochizer0tonin1.11.01 of 1See more

mikochi zer0tonin 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
zer0tonin/mikochi:1.11.009872bae1554
pam@1.7.0-5ubuntu3
1.7.0-5ubuntu3.1

Open the chart page →

1,048

Container images carrying it

2,505 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
pam@1.5.2-6+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
pam@1.5.2-6+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
pam@1.5.2-6+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
pam@1.5.2-6+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
pam@1.5.2-6+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.