StackRadar

CVE-2026-54411

High

Advisory

Published 14 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,470
of 17,828 indexed, latest versions
Container images
2,505
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: pam security update

Carried by container images the latest versions of 2,470 of 17,828 indexed charts deploy, on 2,505 images.

Affected packageAffected versionsFixed inImages
pamdeb1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.12,325
pamrpm1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+29 more0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more180
OSV records
DEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
Also known as
RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1

Charts affected

2,470 by stars
ChartLatestAffected imagesRadar Score
puppeteergeek-cookbookVerified publisher1.2.21 of 1See more

puppeteer geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

15,855
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

12,081
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
pam@1.4.0-11ubuntu2
1.4.0-11ubuntu2.7

Open the chart page →

10,632
readarrgeek-cookbookVerified publisher6.4.21 of 1See more

readarr geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
pam@1.3.1-5ubuntu4.1
no fix listed

Open the chart page →

7,852
resilio-syncgeek-cookbookVerified publisher5.4.21 of 1See more

resilio-sync geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/resilio-sync:version-2.7.2.1375605b6d544028
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed

Open the chart page →

5,946
satisfactorygeek-cookbookVerified publisher1.2.21 of 1See more

satisfactory geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:lateste103700ae6ae
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7

Open the chart page →

3,512
sdtdgeek-cookbookVerified publisher0.3.21 of 1See more

sdtd geek-cookbook 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/reitermarkus/7d2d:main39953b387b61
pam@1.7.0-5
no fix listed

Open the chart page →

2,557
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
pam@1.3.1-5ubuntu4.1
no fix listed

Open the chart page →

98,535
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pam@1.7.0-5
no fix listed

Open the chart page →

9,091
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
pam@1.1.8-3.2ubuntu4
no fix listed

Open the chart page →

27,112
transmissiongeek-cookbookVerified publisher8.4.31 of 1See more

transmission geek-cookbook 8.4.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

12,135
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

18,210
chproxygeneral-helm-chartsVerified publisher0.0.21 of 1See more

chproxy general-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
contentsquareplatform/chproxy:v1.26.524555f22d4be
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,756
mongogengxiankun-charts0.1.01 of 1See more

mongo gengxiankun-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
pam@1.3.1-5ubuntu4.7
no fix listed

Open the chart page →

4,049
redisgengxiankun-charts0.2.01 of 1See more

redis gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
pam@1.7.0-5
no fix listed

Open the chart page →

1,008
rocketmqgengxiankun-charts0.3.01 of 1See more

rocketmq gengxiankun-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
apache/rocketmq:5.3.0434d8398f996
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6

Open the chart page →

5,016
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

4,297
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.84 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

4 of the 5 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
pam@1.1.8-3.6ubuntu2.18.04.6
no fix listed
jingking/geonetwork-hnap:4.2.843e74ab234e1
pam@1.3.1-5ubuntu4.7
no fix listed
library/elasticsearch:7.17.1588c2ec10c7f2
pam@1.3.1-5ubuntu4.6
no fix listed
library/kibana:7.17.150172f1c538e7
pam@1.3.1-5ubuntu4.6
no fix listed

Open the chart page →

35,118
istiogetindataVerified publisher1.11.12 of 2See more

istio getindata 1.11.1

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:1.11.1c552478f8f11
pam@1.3.1-5ubuntu4.2
no fix listed
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
pam@1.3.1-5ubuntu4.2
no fix listed

Open the chart page →

16,922
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

8,919
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,030
redis-uigin0.0.11 of 1See more

redis-ui gin 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
patrikx3/p3x-redis-ui:latestf19eb45b0694
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

1,099
knativegitlabVerified publisher0.10.03 of 10See more

knative gitlab 0.10.0

3 of the 10 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
istio/node-agent-k8s:1.2.9268ab879ea51
pam@1.1.8-3.2ubuntu2.1
no fix listed
istio/pilot:1.2.9c09319753454
pam@1.1.8-3.2ubuntu2.1
no fix listed
istio/proxyv2:1.2.90c78be035e98
pam@1.1.8-3.2ubuntu2.1
no fix listed

Open the chart page →

197,341
glassflow-etlglassflowVerified publisher0.5.211 of 16See more

glassflow-etl glassflow 0.5.21

1 of the 16 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/glassflow/glassflow-notifier:v1.0.3d1b0ce10b513
pam@1.7.0-5
no fix listed

Open the chart page →

12,107
pgbouncerglassflowVerified publisher0.1.01 of 1See more

pgbouncer glassflow 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/pgbouncer:1.23.192356da09704
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,330
glauthglauthVerified publisher0.3.171 of 2See more

glauth glauth 0.3.17

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
nouchka/sqlite3:latestce0d90cbe832
pam@1.7.0-5
no fix listed

Open the chart page →

2,652
glpiglpi-chart0.1.12 of 3See more

glpi glpi-chart 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
pam@1.7.0-5
no fix listed
vdiogov/glpi-conteiner:latest6945f84f0058
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

12,550
goofy-chartgoofy-chart0.1.01 of 1See more

goofy-chart goofy-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
platformgoofy-chart0.1.01 of 1See more

platform goofy-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
devopsgoofy/k8s-platform:latestad865312099f
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

2,839
googly-logingoogly-login0.1.01 of 2See more

googly-login googly-login 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
pam@1.7.0-5
no fix listed

Open the chart page →

1,268
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
pam@1.7.0-5
no fix listed

Open the chart page →

22,760
jaegergpg-dev3.3.32 of 5See more

jaeger gpg-dev 3.3.3

2 of the 5 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
pam@1.4.0-11ubuntu2.3
1.4.0-11ubuntu2.7
library/cassandra:3.11.65aa8400b4b3b
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

19,460
kubernetes-dashboardgpg-dev7.5.01 of 5See more

kubernetes-dashboard gpg-dev 7.5.0

1 of the 5 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
pam@1.4.0-11ubuntu2.5
1.4.0-11ubuntu2.7

Open the chart page →

6,139
openclawgpg-dev1.5.361 of 2See more

openclaw gpg-dev 1.5.36

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
chromedp/headless-shell:148.0.7778.97313ed7255ae1
pam@1.7.0-5
no fix listed

Open the chart page →

1,698
opentelemetry-demogpg-dev0.33.89 of 27See more

opentelemetry-demo gpg-dev 0.33.8

9 of the 27 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
pam@1.5.2-6+deb12u1
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-accountingservice6d051840bb29
pam@1.5.2-6+deb12u1
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
pam@1.5.2-6+deb12u1
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
pam@1.5.2-6+deb12u1
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-frontendproxy9fdec1be03e4
pam@1.4.0-11ubuntu2.4
1.4.0-11ubuntu2.7
ghcr.io/open-telemetry/demo:1.12.0-emailservicea1f5cebb5240
pam@1.5.2-6+deb12u1
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-shippingservicea3ca4c02a5df
pam@1.5.2-6+deb12u1
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
ghcr.io/open-telemetry/demo:1.12.0-recommendationserviceb294a4278407
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

50,116
video-analytics-demogpu-operator0.1.92 of 3See more

video-analytics-demo gpu-operator 0.1.9

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
pam@1.3.1-5ubuntu4.6
no fix listed
library/nginx:latest05b8cb60c354
pam@1.7.0-5
no fix listed

Open the chart page →

15,981
video-analytics-demo-l4tgpu-operator0.1.31 of 3See more

video-analytics-demo-l4t gpu-operator 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pam@1.7.0-5
no fix listed

Open the chart page →

1,965
grafana-samplinggrafana1.1.71 of 2See more

grafana-sampling grafana 1.1.7

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
grafana/alloy:v1.11.38c7256f412fe
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

3,435
mimir-openshift-experimentalgrafana2.1.01 of 4See more

mimir-openshift-experimental grafana 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
pam@1.3.1-11.el8
0:1.3.1-40.el8_10

Open the chart page →

17,824
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6

Open the chart page →

82,839
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7

Open the chart page →

4,742
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
graylog/graylog:6.1.1019de1aff48c2
pam@1.4.0-11ubuntu2.5
1.4.0-11ubuntu2.7

Open the chart page →

5,083
gridgain9gridgainVerified publisher1.1.101 of 2See more

gridgain9 gridgain 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/debian:12.12-slimd5d3f9c23164
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,275
routergroundcover1.12.3782 of 7See more

router groundcover 1.12.378

2 of the 7 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
pam@1.4.0-11ubuntu2.5
1.4.0-11ubuntu2.7
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
pam@1.7.0-5+e4
1.7.0-5+e5

Open the chart page →

6,256
librechat-exporterhajowielandVerified publisher1.0.01 of 1See more

librechat-exporter hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/virtuos/librechat_exporter:2.0.050ea1cf0086f
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

2,326
rag-apihajowielandVerified publisher1.0.01 of 1See more

rag-api hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latestf9f34c8ed688
pam@1.7.0-5
no fix listed

Open the chart page →

1,764
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latest7e2ef5261764
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

6,089
hatchet-apihatchetOfficialVerified publisher0.19.01 of 4See more

hatchet-api hatchet 0.19.0

1 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
pam@1.7.0-5
no fix listed

Open the chart page →

1,736
hatchet-hahatchetOfficialVerified publisher0.19.03 of 8See more

hatchet-ha hatchet 0.19.0

3 of the 8 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
pam@1.5.2-6+deb12u1
no fix listed
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
pam@1.5.2-6+deb12u1
no fix listed
library/postgres:latest4ef4dbc939d6
pam@1.7.0-5
no fix listed

Open the chart page →

7,672
hatchet-stackhatchetOfficialVerified publisher0.19.03 of 8See more

hatchet-stack hatchet 0.19.0

3 of the 8 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
pam@1.5.2-6+deb12u1
no fix listed
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
pam@1.5.2-6+deb12u1
no fix listed
library/postgres:latest4ef4dbc939d6
pam@1.7.0-5
no fix listed

Open the chart page →

7,672

Container images carrying it

2,505 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
pam@1.5.2-6+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
pam@1.5.2-6+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
pam@1.5.2-6+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
pam@1.5.2-6+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
pam@1.5.2-6+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.