StackRadar

CVE-2026-54411

High

Advisory

Published 14 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,470
of 17,828 indexed, latest versions
Container images
2,505
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: pam security update

Carried by container images the latest versions of 2,470 of 17,828 indexed charts deploy, on 2,505 images.

Affected packageAffected versionsFixed inImages
pamdeb1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.12,325
pamrpm1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+29 more0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more180
OSV records
DEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
Also known as
RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1

Charts affected

2,470 by stars
ChartLatestAffected imagesRadar Score
plexbryanalves0.5.01 of 1See more

plex bryanalves 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

6,800
tautullibryanalves0.1.01 of 1See more

tautulli bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
tautulli/tautulli:latest670e68dd9efc
pam@1.7.0-5
no fix listed

Open the chart page →

1,952
node-appbryopsida0.5.12 of 2See more

node-app bryopsida 0.5.1

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/node:lts64af3819f927
pam@1.5.2-6+deb12u2
no fix listed
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6

Open the chart page →

72,281
nginx-chartbtrepoVerified publisher0.1.01 of 1See more

nginx-chart btrepo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/category:distributed02fc234353a9
pam@1.3.1-5ubuntu4.1
no fix listed

Open the chart page →

11,660
pages-microservicebusi-adsVerified publisher1.0.02 of 3See more

pages-microservice busi-ads 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,350
bpabusiness-partner-agentVerified publisher0.12.41 of 3See more

bpa business-partner-agent 0.12.4

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bcgovimages/aries-cloudagent:py36-1.16-1_0.7.4faa2e2d21916
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed

Open the chart page →

11,693
gotenbergbysamioVerified publisher0.2.01 of 1See more

gotenberg bysamio 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8-chromium0d28ae9a9644
pam@1.7.0-5
no fix listed

Open the chart page →

5,551
mariadbbysamioVerified publisher1.0.21 of 1See more

mariadb bysamio 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/mariadb:12.0.2607835cd628b
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

3,009
duoauthproxy-radius-simplecaerus0.1.01 of 1See more

duoauthproxy-radius-simple caerus 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ethanbergstrom/duoauthproxy:5.5.0345c2a46c103
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

3,055
rediscagriekinVerified publisher1.5.21 of 2See more

redis cagriekin 1.5.2

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/redis:8.8.1-trixie3eafabb4c93f
pam@1.7.0-5
no fix listed

Open the chart page →

1,425
ct-singlecalltelemetry0.8.41 of 7See more

ct-single calltelemetry 0.8.4

1 of the 7 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
calltelemetry/web:0.8.1-rc7205d13269e350
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

10,674
pagescamden-pages1.0.02 of 3See more

pages camden-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,350
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
pam@1.5.2-6
no fix listed

Open the chart page →

8,126
geoservercamptocamp20.0.37 of 12See more

geoserver camptocamp2 0.0.3

7 of the 12 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
pam@1.3.1-5ubuntu4.2
no fix listed
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
pam@1.3.1-5ubuntu4.2
no fix listed
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
pam@1.3.1-5ubuntu4.2
no fix listed
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
pam@1.3.1-5ubuntu4.2
no fix listed
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
pam@1.3.1-5ubuntu4.2
no fix listed
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
pam@1.3.1-5ubuntu4.2
no fix listed
library/postgres:122f2a8c2a7d10
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

88,995
httpd-ldapauth-proxycamptocamp31.0.21 of 1See more

httpd-ldapauth-proxy camptocamp3 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/httpd:2.4.631ae8051591a5
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,394
nginx-s3-gatewaycamptocamp31.0.01 of 1See more

nginx-s3-gateway camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss-202503313db8145349a3
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

5,115
pgbouncer-tlscamptocamp32.3.02 of 2See more

pgbouncer-tls camptocamp3 2.3.0

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/haproxy:3.2de601ccc9a79
pam@1.7.0-5
no fix listed
ghcr.io/camptocamp/pgbouncer:latest19dc5663cac4
pam@1.7.0-5
no fix listed

Open the chart page →

1,969
prometheus-puppetdb-sdcamptocamp38.0.21 of 2See more

prometheus-puppetdb-sd camptocamp3 8.0.2

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
puppet/puppet-agent:7.14.00b6fd9a6b7da
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed

Open the chart page →

6,224
puppetservercamptocamp31.0.11 of 2See more

puppetserver camptocamp3 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
pam@1.4.0-11ubuntu2.5
1.4.0-11ubuntu2.7

Open the chart page →

5,998
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

11,014
caninecanine0.1.101 of 7See more

canine canine 0.1.10

1 of the 7 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/caninehq/canine:latest68b19aee1c64
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

14,362
pagescarina-pages1.0.02 of 3See more

pages carina-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,350
pagescarmel-pages-dell1.0.02 of 3See more

pages carmel-pages-dell 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,350
cassandra-clustercassandra-clusterVerified publisher0.1.01 of 1See more

cassandra-cluster cassandra-cluster 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/cassandra:3.11.10b095ff3248c6
pam@1.3.1-5ubuntu4.2
no fix listed

Open the chart page →

9,594
castai-hibernatecastaiVerified publisher0.2.121 of 1See more

castai-hibernate castai 0.2.12

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
castai/hibernate:v0.14da62858c8381
pam@1.7.0-5
no fix listed

Open the chart page →

1,199
catalyst-agentscatalyst-agents0.1.331 of 18See more

catalyst-agents catalyst-agents 0.1.33

1 of the 18 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

17,696
getoutlinecfi20171.2.02 of 4See more

getoutline cfi2017 1.2.0

2 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:18.06f3e42ad37de
pam@1.7.0-5
no fix listed
library/redis:8.2.3d31852005202
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

4,531
opencvecfi20170.1.25 of 7See more

opencve cfi2017 0.1.2

5 of the 7 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:trixieabe47724e466
pam@1.7.0-5
no fix listed
library/postgres:18.06f3e42ad37de
pam@1.7.0-5
no fix listed
library/redis:7.2-bookworm0637954999d0
pam@1.5.2-6+deb12u2
no fix listed
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
pam@1.5.2-6+deb12u1
no fix listed
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
pam@1.7.0-5
no fix listed

Open the chart page →

15,360
nginx-chartchanhk10.1.01 of 1See more

nginx-chart chanhk1 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pam@1.7.0-5
no fix listed

Open the chart page →

1,965
clechaosnative0.2.71 of 6See more

cle chaosnative 0.2.7

1 of the 6 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
litmuschaos/mongo:4.2.899961210d467
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

16,460
charon-relaycharonOfficialVerified publisher0.8.01 of 2See more

charon-relay charon 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
obolnetwork/charon:v1.10.0278c7e2897b6
pam@1.7.0-5
no fix listed

Open the chart page →

4,508
dv-podcharonOfficialVerified publisher0.19.12 of 5See more

dv-pod charon 0.19.1

2 of the 5 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
obolnetwork/charon:v1.10.0278c7e2897b6
pam@1.7.0-5
no fix listed
sigp/lighthouse:v8.1.344aa773dcf27
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7

Open the chart page →

7,630
helioscharonVerified publisher0.1.51 of 1See more

helios charon 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
obolnetwork/helios:e10e753cb7e97d39d46
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6

Open the chart page →

2,177
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

5,928
kitchenowlchart-kitchenowl0.1.121 of 2See more

kitchenowl chart-kitchenowl 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
pam@1.7.0-5
no fix listed

Open the chart page →

4,914
calibre-webcharts-derwitt-devVerified publisher1.1.21 of 1See more

calibre-web charts-derwitt-dev 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

4,944
home-assistant-otbrcharts-derwitt-devVerified publisher2.1.41 of 1See more

home-assistant-otbr charts-derwitt-dev 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/homeassistant-otbr:4.2.5282f840612d9
pam@1.7.0-5
no fix listed

Open the chart page →

2,352
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
openthread/otbr:latest35c6e6520080
pam@1.1.8-3.6ubuntu2.18.04.6
no fix listed

Open the chart page →

64,076
paperless-ngxcharts-derwitt-devVerified publisher2.1.41 of 1See more

paperless-ngx charts-derwitt-dev 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
pam@1.7.0-5
no fix listed

Open the chart page →

4,703
chat-searchchat-searchVerified publisher0.1.71 of 1See more

chat-search chat-search 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/hemslo/chat-search:latest39d48995a5bd
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

4,132
opensipschetan-opensips0.1.01 of 1See more

opensips chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
chetangautamm/repo:Opensips_Buildb4b94155ff5a
pam@1.1.8-1ubuntu2.2
no fix listed

Open the chart page →

75,943
sippchetan-opensips0.1.01 of 1See more

sipp chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
chetangautamm/repo:sipp.v3e7f7049e1544
pam@1.3.1-5ubuntu4.1
no fix listed

Open the chart page →

88,824
mysqld-exporterchoerodon0.1.01 of 1See more

mysqld-exporter choerodon 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:stable0aa2d81d65bc
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
mcp-for-argocdchristianhuthVerified publisher2.0.01 of 1See more

mcp-for-argocd christianhuth 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

1,994
polrchristianhuthVerified publisher4.3.01 of 2See more

polr christianhuth 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

6,031
proxysqlchristianhuthVerified publisher3.1.11 of 1See more

proxysql christianhuth 3.1.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
proxysql/proxysql:3.0.110e95d1b7cc32
pam@1.7.0-5
no fix listed

Open the chart page →

1,332
timetaggerchristianhuthVerified publisher2.2.01 of 1See more

timetagger christianhuth 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

2,007
arbitrumchronicleVerified publisher0.3.41 of 1See more

arbitrum chronicle 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

7,200
basechronicleVerified publisher0.0.81 of 1See more

base chronicle 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7

Open the chart page →

4,935

Container images carrying it

2,505 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
pam@1.5.2-6+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
pam@1.5.2-6+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
pam@1.5.2-6+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
pam@1.5.2-6+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
pam@1.5.2-6+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.