StackRadar

CVE-2026-54411

High

Advisory

Published 14 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,470
of 17,828 indexed, latest versions
Container images
2,505
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: pam security update

Carried by container images the latest versions of 2,470 of 17,828 indexed charts deploy, on 2,505 images.

Affected packageAffected versionsFixed inImages
pamdeb1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.12,325
pamrpm1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+29 more0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more180
OSV records
DEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
Also known as
RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1

Charts affected

2,470 by stars
ChartLatestAffected imagesRadar Score
my-nginxna-helm-chartsVerified publisher1.0.01 of 1See more

my-nginx na-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
dependency-tracknaj980.0.91 of 3See more

dependency-track naj98 0.0.9

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dependencytrack/apiserver:latest9008fc010a21
pam@1.7.0-5
no fix listed

Open the chart page →

1,565
smallandnaj980.0.51 of 1See more

smalland naj98 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/98jan/smalland-server/smalland-server:deveb7be822d5b2
pam@1.1.8-3.6ubuntu2.18.04.6
no fix listed

Open the chart page →

3,067
pagesnarain1.0.02 of 3See more

pages narain 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,350
pagesnarasimha-pages1.0.02 of 3See more

pages narasimha-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,350
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
pam@1.5.2-6
no fix listed

Open the chart page →

12,919
pagesnavin-brixton1.0.02 of 3See more

pages navin-brixton 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,350
incorencsaVerified publisher1.38.02 of 29See more

incore ncsa 1.38.0

2 of the 29 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
pam@1.5.2-6+deb12u1
no fix listed
bitnamilegacy/postgresql:16.4.03ba6e6f11388
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

15,562
smilencsaVerified publisher1.1.07 of 23See more

smile ncsa 1.1.0

7 of the 23 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
socialmediamacroscope/autophrase:0.1.570fb11d4f531
pam@1.3.1-5ubuntu4.6
no fix listed
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
pam@1.1.8-3.6ubuntu2.18.04.4
no fix listed
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
pam@1.5.2-6
no fix listed
socialmediamacroscope/image_crawler:0.1.2f508216be63c
pam@1.1.8-3.6ubuntu2.18.04.4
no fix listed
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
pam@1.5.2-6
no fix listed
socialmediamacroscope/preprocessing:0.1.3ca863306314b
pam@1.5.2-6
no fix listed
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
pam@1.5.2-6
no fix listed

Open the chart page →

270,271
uptime-kumancsaVerified publisher1.7.31 of 1See more

uptime-kuma ncsa 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.5c74379ac4509
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

30,720
neosyncneosyncVerified publisher0.5.412 of 3See more

neosync neosync 0.5.41

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
pam@1.5.2-6+deb12u1
no fix listed
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

7,329
apineosync-apiVerified publisher0.5.411 of 1See more

api neosync-api 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

2,888
workerneosync-workerVerified publisher0.5.411 of 1See more

worker neosync-worker 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

2,866
core-keeper-dedicatednerkho-helm-charts0.1.11 of 1See more

core-keeper-dedicated nerkho-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
escaping/core-keeper-dedicated:latest87fa79255962
pam@1.7.0-5
no fix listed

Open the chart page →

3,970
netbirdnetbird1.9.01 of 4See more

netbird netbird 1.9.0

1 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
netbirdio/management:0.46.0b0adc4ad4ec6
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6

Open the chart page →

6,500
web-applicationnetology-yc-helmVerified publisher4.0.01 of 1See more

web-application netology-yc-helm 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
egorz/netology-diploma-web-app:4.05627a54bd1ad
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

6,406
netris-dpu-agentnetrisai0.1.01 of 1See more

netris-dpu-agent netrisai 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
netrisai/bare-metal-dpu-agent:4.7.0.003c271efe749d0
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

1,621
neuralbank-stackneuralbank-stack0.1.02 of 4See more

neuralbank-stack neuralbank-stack 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:latest4210a3296e7c
pam@1.7.0-5
no fix listed
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
pam@1.5.1-26.el9_6
0:1.5.1-27.el9_8.1

Open the chart page →

5,432
neurofaceneurofaceVerified publisher1.4.23 of 3See more

neuroface neuroface 1.4.2

3 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
openvino/model_server:2025.2.11e7cd1d70cc1
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.6
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
pam@1.5.1-28.el9
0:1.5.1-28.el9_8.1
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
pam@1.5.1-26.el9_6
0:1.5.1-27.el9_8.1

Open the chart page →

7,686
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
pam@1.7.0-5
no fix listed

Open the chart page →

3,922
agent-control-bootstrapnewrelic1.8.161 of 1See more

agent-control-bootstrap newrelic 1.8.16

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:1.24.047520b65d6b2
pam@1.7.0-5
no fix listed

Open the chart page →

996
nfl-walletnfl-walletVerified publisher0.1.31 of 4See more

nfl-wallet nfl-wallet 0.1.3

1 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
pam@1.3.1-39.el8_10
0:1.3.1-40.el8_10

Open the chart page →

13,518
nginx-appnginx-app0.1.21 of 1See more

nginx-app nginx-app 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
pam@1.7.0-5
no fix listed

Open the chart page →

1,965
nginx-samplenginx-sample0.5.01 of 1See more

nginx-sample nginx-sample 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

5,405
nginx-sample-dependentnginx-sample-dependent0.2.01 of 1See more

nginx-sample-dependent nginx-sample-dependent 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

5,405
nginx-examplengrok-ingress-helm0.3.01 of 2See more

nginx-example ngrok-ingress-helm 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

2,722
audacitynicholaswildeVerified publisher0.1.41 of 1See more

audacity nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/audacity:version-3.0.2cdf203db1e50
pam@1.3.1-5ubuntu4.2
no fix listed

Open the chart page →

23,286
booksonicnicholaswildeVerified publisher1.0.11 of 1See more

booksonic nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic:version-1.2677efca1065d
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed

Open the chart page →

17,091
digikamnicholaswildeVerified publisher1.0.01 of 1See more

digikam nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed

Open the chart page →

24,394
doublecommandernicholaswildeVerified publisher1.0.21 of 1See more

doublecommander nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed

Open the chart page →

25,571
remminanicholaswildeVerified publisher0.1.41 of 1See more

remmina nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed

Open the chart page →

22,447
sqlitebrowsernicholaswildeVerified publisher1.0.11 of 1See more

sqlitebrowser nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
pam@1.1.8-3.6ubuntu2.18.04.3
no fix listed

Open the chart page →

23,673
ciliumnicklasfrahm-ciliumVerified publisher0.7.42 of 6See more

cilium nicklasfrahm-cilium 0.7.4

2 of the 6 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.18.2858f807ea4e2
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.6
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.6

Open the chart page →

7,312
terraform-backendnimbolus0.3.21 of 2See more

terraform-backend nimbolus 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/redis:8.2.24521b581dbdd
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

2,516
minio-directpvnineinfra-charts4.0.81 of 5See more

minio-directpv nineinfra-charts 4.0.8

1 of the 5 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/minio/directpv:v4.0.84560083eb77d
pam@1.3.1-27.el8
0:1.3.1-40.el8_10

Open the chart page →

7,073
redisnineinfra-charts0.7.51 of 1See more

redis nineinfra-charts 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,975
basenn-coVerified publisher0.1.01 of 1See more

base nn-co 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

10,451
node-debug-dashboardnode-debug-dashboardVerified publisher0.3.21 of 1See more

node-debug-dashboard node-debug-dashboard 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

7,052
firehose-corenodeifyVerified publisher1.2.62 of 2See more

firehose-core nodeify 1.2.6

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
sigp/lighthouse:latest-amd6450f66cfebb6d
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

6,684
firehose-ethereumnodeifyVerified publisher1.7.12 of 2See more

firehose-ethereum nodeify 1.7.1

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
sigp/lighthouse:v8.1.344aa773dcf27
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

5,797
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

4,819
app1node-web-app10.1.31 of 1See more

app1 node-web-app1 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
pam@1.7.0-5
no fix listed

Open the chart page →

1,965
app2node-web-app10.1.31 of 1See more

app2 node-web-app1 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:stable0aa2d81d65bc
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
nginx-chartnomadshk-nginx0.1.01 of 1See more

nginx-chart nomadshk-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

1,589
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

22,898
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
pam@1.7.0-5
no fix listed

Open the chart page →

5,951
keycloak-helm-chartnotesprojectchart0.1.01 of 2See more

keycloak-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
pam@1.7.0-5
no fix listed

Open the chart page →

1,696
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
pam@1.7.0-5
no fix listed

Open the chart page →

6,917
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
pam@1.5.2-6
no fix listed

Open the chart page →

15,365

Container images carrying it

2,505 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
pam@1.5.2-6+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
pam@1.5.2-6+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
pam@1.5.2-6+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
pam@1.5.2-6+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
pam@1.5.2-6+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.