StackRadar

CVE-2026-54411

High

Advisory

Published 14 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,453
of 17,837 indexed, latest versions
Container images
2,457
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: pam security update

Carried by container images the latest versions of 2,453 of 17,837 indexed charts deploy, on 2,457 images.

Affected packageAffected versionsFixed inImages
pamdeb1.1.8-1ubuntu2, 1.1.8-1ubuntu2.2, 1.1.8-3.2ubuntu2, 1.1.8-3.2ubuntu2.1+33 more1.4.0-11ubuntu2.7, 1.5.3-5ubuntu5.6, 1.7.0-5+e5, 1.7.0-5ubuntu3.12,278
pamrpm1.1.8-22.el7, 1.1.8-23.el7, 1.3.0-150000.6.86.1, 1.3.0-lp151.7.38+29 more0:1.1.8-23.el7_9.3, 0:1.3.1-40.el8_10, 0:1.5.1-27.el9_8.1, 0:1.5.1-28.el9_8.1+4 more179
OSV records
DEBIAN-CVE-2026-54411RHSA-2026:56131RHSA-2026:59379RHSA-2026:60224RHSA-2026:61227RHSA-2026:64815RLSA-2026:56131RLSA-2026:59379RLSA-2026:64815UBUNTU-CVE-2026-54411ECHO-a8ba-b20f-6ddaopenSUSE-SU-2026:11201-1SUSE-SU-2026:22639-1SUSE-SU-2026:3163-1
Also known as
RHSA-2026:61223, RHSA-2026:61224, RHSA-2026:61225, RHSA-2026:61226, RHSA-2026:61228, RHSA-2026:61230, USN-8601-1

Charts affected

2,453 by stars
ChartLatestAffected imagesRadar Score
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/redis:8.2.2f0957bcaa75f
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

4,844
revwallet-apirevwallet0.7.121 of 1See more

revwallet-api revwallet 0.7.12

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
arthurjguerra18/revwallet:v0.7.12f540af20b307
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

6,024
bookinforgnu1.0.03 of 7See more

bookinfo rgnu 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.14.0ee156b8aefd6
pam@1.1.8-3.2ubuntu2.1
no fix listed
istio/examples-bookinfo-reviews-v2:1.14.0eab80bcd2132
pam@1.1.8-3.2ubuntu2.1
no fix listed
istio/examples-bookinfo-reviews-v3:1.14.01e37fca43550
pam@1.1.8-3.2ubuntu2.1
no fix listed

Open the chart page →

20,980
httpbinrgnu1.0.01 of 1See more

httpbin rgnu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
citizenstig/httpbin:latestb81c818ccb86
pam@1.1.8-3.2ubuntu2
no fix listed

Open the chart page →

11,504
istio-bookinforgnu1.0.23 of 7See more

istio-bookinfo rgnu 1.0.2

3 of the 7 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.14.0ee156b8aefd6
pam@1.1.8-3.2ubuntu2.1
no fix listed
istio/examples-bookinfo-reviews-v2:1.14.0eab80bcd2132
pam@1.1.8-3.2ubuntu2.1
no fix listed
istio/examples-bookinfo-reviews-v3:1.14.01e37fca43550
pam@1.1.8-3.2ubuntu2.1
no fix listed

Open the chart page →

20,980
istio-helloworldrgnu1.0.12 of 2See more

istio-helloworld rgnu 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
istio/examples-helloworld-v1:latest328b237e4fb1
pam@1.5.2-6+deb12u1
no fix listed
istio/examples-helloworld-v2:latest0a7f02b2c7c9
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

9,588
rhbk-neurofacerhbk-neurofaceVerified publisher1.0.02 of 4See more

rhbk-neuroface rhbk-neuroface 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
pam@1.5.1-28.el9
0:1.5.1-28.el9_8.1
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
pam@1.5.1-26.el9_6
0:1.5.1-27.el9_8.1

Open the chart page →

4,065
rke2-canal-1.19-1.20rke2-charts3.13.3-build20211022022 of 2See more

rke2-canal-1.19-1.20 rke2-charts 3.13.3-build2021102202

2 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
pam@1.1.8-23.el7
0:1.1.8-23.el7_9.3
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
pam@1.1.8-23.el7
0:1.1.8-23.el7_9.3

Open the chart page →

5,960
rke2-kube-proxyrke2-charts1.20.21 of 1See more

rke2-kube-proxy rke2-charts 1.20.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
rancher/hardened-kube-proxy:v1.20.2d0600143c23c
pam@1.1.8-23.el7
0:1.1.8-23.el7_9.3

Open the chart page →

1,552
kube-web-viewrlex0.5.01 of 1See more

kube-web-view rlex 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:23.8.0431f1bf013d0
pam@1.5.2-6
no fix listed

Open the chart page →

4,995
kresusrm3lVerified publisher0.2.12 of 3See more

kresus rm3l 0.2.1

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
pam@1.5.2-6+deb12u1
no fix listed
bnjbvr/kresus:0.22.137e216b182c8
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

15,978
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latest7e2ef5261764
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

6,576
pagesroccohiggins-pages1.0.02 of 3See more

pages roccohiggins-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,372
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

9,359
reviewboardrock8sVerified publisher0.0.11 of 3See more

reviewboard rock8s 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
pam@1.7.0-5
no fix listed

Open the chart page →

5,879
rocketchat-voiprocketchat-server0.1.01 of 1See more

rocketchat-voip rocketchat-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
rocketchat/freeswitch:stablecfba5c20a5cc
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

5,840
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

9,825
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
pam@1.4.0-11ubuntu2
1.4.0-11ubuntu2.7

Open the chart page →

13,259
calertromholdings0.0.11 of 1See more

calert romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
pam@1.3.1-5ubuntu4.3
no fix listed

Open the chart page →

4,743
calicoromholdings0.1.11 of 4See more

calico romholdings 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
pam@1.3.1-4.el8
0:1.3.1-40.el8_10

Open the chart page →

10,100
devtron-enterpriseromholdings48.0.08 of 28See more

devtron-enterprise romholdings 48.0.0

8 of the 28 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
pam@1.5.2-6+deb12u1
no fix listed
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
pam@1.1.8-3.2ubuntu2.3
no fix listed
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
pam@1.5.2-6+deb12u1
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

70,037
devtron-logs-dumpromholdings0.1.01 of 1See more

devtron-logs-dump romholdings 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
pam@1.4.0-11ubuntu2.3
1.4.0-11ubuntu2.7

Open the chart page →

5,023
devtron-operatorromholdings0.23.35 of 11See more

devtron-operator romholdings 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
pam@1.5.2-6+deb12u1
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.6
quay.io/devtron/postgres:14.91b594392f7cb
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

33,562
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
pam@1.3.1-5ubuntu4.1
no fix listed

Open the chart page →

12,045
migration-incluster-cdromholdings0.10.01 of 1See more

migration-incluster-cd romholdings 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,982
pagesronan-pages1.0.02 of 3See more

pages ronan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
pam@1.3.1-5ubuntu4.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
pam@1.1.8-3.6ubuntu2.18.04.1
no fix listed

Open the chart page →

20,372
rosette-serverrosette-serverOfficialVerified publisher3.6.01 of 3See more

rosette-server rosette-server 3.6.0

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
rosette/root-rli:7.23.21.c82.0a4467d3bb211
pam@1.3.1-39.el8_10
0:1.3.1-40.el8_10

Open the chart page →

198
genoarotationalVerified publisher1.4.01 of 1See more

genoa rotational 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
rotationalio/genoa:1.2.03ab583519215
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

1,041
honurotationalVerified publisher0.5.31 of 1See more

honu rotational 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
rotationalio/honu:0.5.069fd30c2e31c
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

2,234
imgtagrotationalVerified publisher0.2.01 of 1See more

imgtag rotational 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,400
routehub-serverroutehub-helm1.0.12 of 3See more

routehub-server routehub-helm 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
pam@1.3.1-5ubuntu4.6
no fix listed
library/postgres:latest86c951e05bf5
pam@1.7.0-5
no fix listed

Open the chart page →

7,073
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

3,618
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

4,825
prepull-daemonsetrstudioVerified publisher0.0.51 of 2See more

prepull-daemonset rstudio 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/ubuntu:bionic152dc042452c
pam@1.1.8-3.6ubuntu2.18.04.6
no fix listed

Open the chart page →

1,770
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
pam@1.4.0-11ubuntu2.6
1.4.0-11ubuntu2.7

Open the chart page →

7,916
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
pam@1.7.0-5
no fix listed

Open the chart page →

10,897
flaresolverrrubxkubeVerified publisher0.1.11 of 1See more

flaresolverr rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

28,413
jellyfinrubxkubeVerified publisher1.3.11 of 1See more

jellyfin rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
pam@1.7.0-5
no fix listed

Open the chart page →

2,727
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

7,540
linkdingrubxkubeVerified publisher1.2.41 of 1See more

linkding rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.47.0e35cb50e0581
pam@1.7.0-5
no fix listed

Open the chart page →

2,120
simple-coffeerubxkubeVerified publisher0.1.01 of 1See more

simple-coffee rubxkube 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
qjoly/kubernetes-coffee-image:simple9f0c5ce8b5d7
pam@1.7.0-5
no fix listed

Open the chart page →

2,033
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
pam@1.5.3-5ubuntu5.5
1.5.3-5ubuntu5.6

Open the chart page →

6,452
trmnl-serverrubxkubeVerified publisher0.1.01 of 2See more

trmnl-server rubxkube 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
library/python:3.14-slimcaaf356f4066
pam@1.7.0-5
no fix listed

Open the chart page →

2,701
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
pam@1.5.2-6+deb12u2
no fix listed

Open the chart page →

31,398
vaultwardenrubxkubeVerified publisher1.2.41 of 1See more

vaultwarden rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
pam@1.7.0-5
no fix listed

Open the chart page →

1,812
your-spotifyrubxkubeVerified publisher1.0.11 of 3See more

your-spotify rubxkube 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:latestb0652af9c8d0
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

5,497
rybbitrybbit-helm1.3.21 of 7See more

rybbit rybbit-helm 1.3.2

1 of the 7 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
valkey/valkey:9.1.164e361b630ec
pam@1.7.0-5
no fix listed

Open the chart page →

6,248
nadekobotryuunosukeds30.1.21 of 2See more

nadekobot ryuunosukeds3 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
pam@1.4.0-11ubuntu2.5
1.4.0-11ubuntu2.7

Open the chart page →

8,929
orbitalryuunosukeds30.2.01 of 1See more

orbital ryuunosukeds3 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54411.

Container imageDigestPackageFixed in
ryuunosukeds3/orbital:latest0879f7261b10
pam@1.5.2-6+deb12u1
no fix listed

Open the chart page →

2,726
transmissionryuunosukeds31.7.01See more

transmission ryuunosukeds3 1.7.0

1 container image this version deploys carries CVE-2026-54411.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
pam@1.7.0-5
no fix listed

Open the chart page →

Container images carrying it

2,457 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

No deployed image carries CVE-2026-54411.

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.