StackRadar

CVE-2026-54696

Low

Advisory

Published 30 Jun 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.004
32nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
32
of 17,781 indexed, latest versions
Container images
35
deployed by those charts
Fix available
1 of 5
affected packages

Ruby json: JSON generator heap buffer overflow when streaming to an IO

Carried by container images the latest versions of 32 of 17,781 indexed charts deploy, on 35 images.

Affected packageAffected versionsFixed inImages
jsongem2.9.1, 2.10.2, 2.12.2, 2.13.2+3 more2.19.924
ruby2.7deb2.7.0-5ubuntu1.4, 2.7.0-5ubuntu1.5, 2.7.0-5ubuntu1.8no fix listed6
ruby2.3deb2.3.1-2~16.04.5no fix listed2
ruby3.0deb3.0.2-7ubuntu2.4, 3.0.2-7ubuntu2.8no fix listed2
ruby2.5deb2.5.8-1bbox1~bionic1no fix listed1
OSV records
GHSA-x2f5-4prf-w687UBUNTU-CVE-2026-54696

Charts affected

32 by stars
ChartLatestAffected imagesRadar Score
fluentdfluent0.6.01 of 1See more

fluentd fluent 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.19.3-debian-elasticsearch7-1.1de9cf5f1127a
json@2.13.2
2.19.9

Open the chart page →

999
zammadzammadOfficialVerified publisher18.0.51 of 5See more

zammad zammad 18.0.5

1 of the 5 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
ghcr.io/zammad/zammad:7.1.3-0011e65123a43ecc
json@2.9.1
2.19.9

Open the chart page →

6,887
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.01 of 5See more

openproject openproject-helm-charts 13.11.0

1 of the 5 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
openproject/openproject:17.8.0-slim48952034215d
json@2.18.0
2.19.9

Open the chart page →

19,926
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
json@2.19.8
2.19.9

Open the chart page →

9,203
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
json@2.18.0
2.19.9

Open the chart page →

4,556
puppetserverpuppetserver9.5.21 of 5See more

puppetserver puppetserver 9.5.2

1 of the 5 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
ruby3.0@3.0.2-7ubuntu2.4
no fix listed

Open the chart page →

14,184
docusealzekker6Verified publisher1.130.01 of 1See more

docuseal zekker6 1.130.0

1 of the 1 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
docuseal/docuseal:3.2.4a8f063f916e3
json@2.18.0
2.19.9

Open the chart page →

112
manyfoldself-hosters-by-nightVerified publisher0.7.41 of 1See more

manyfold self-hosters-by-night 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
ghcr.io/manyfold3d/manyfold-solo:0.147.2ed5a792b0e8d
json@2.9.1
2.19.9

Open the chart page →

480
huginnutkuozdemirVerified publisher2.2.11 of 4See more

huginn utkuozdemir 2.2.1

1 of the 4 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
ruby2.5@2.5.8-1bbox1~bionic1
no fix listed

Open the chart page →

18,137
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
ruby2.7@2.7.0-5ubuntu1.5
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
ruby2.7@2.7.0-5ubuntu1.4
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
ruby2.7@2.7.0-5ubuntu1.5
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
ruby2.7@2.7.0-5ubuntu1.5
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
ruby2.7@2.7.0-5ubuntu1.5
no fix listed

Open the chart page →

113,791
redminemt1905027.3.41 of 3See more

redmine mt190502 7.3.4

1 of the 3 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
library/redmine:6.1.204ac44a2595b
json@2.9.1
2.19.9

Open the chart page →

7,527
opentelemetry-demoopentelemetry-helmVerified publisher0.41.11 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.1

1 of the 34 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:3.0.0-emaild674d4081ca4
json@2.18.0
2.19.9

Open the chart page →

22,420
redmineredmine-helm-chartVerified publisher0.2.61 of 1See more

redmine redmine-helm-chart 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
json@2.9.1
2.19.9

Open the chart page →

4,240
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
json@2.9.1
2.19.9

Open the chart page →

5,558
antigenic-docuseal-helm-chartantigenic-docuseal-helm-chartVerified publisher0.2.01 of 1See more

antigenic-docuseal-helm-chart antigenic-docuseal-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
docuseal/docuseal:2.4.17493fd7f6728
json@2.19.2
2.19.9

Open the chart page →

2,766
bdbablackduck2026.6.31 of 9See more

bdba blackduck 2026.6.3

1 of the 9 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
blackducksoftware/bdba-fluentd:2026.6.3c14bbbf45536
json@2.13.2
2.19.9

Open the chart page →

9,521
puppetservercamptocamp31.0.11 of 2See more

puppetserver camptocamp3 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
ruby3.0@3.0.2-7ubuntu2.8
no fix listed

Open the chart page →

5,886
monitoring-stackdata354-helmVerified publisher1.4.21 of 4See more

monitoring-stack data354-helm 1.4.2

1 of the 4 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
grafana/fluent-plugin-loki:latest8a3882e8c28b
json@2.9.1
2.19.9

Open the chart page →

3,176
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
json@2.12.2
2.19.9

Open the chart page →

2,942
fluentd-aggregatorfluentd-aggregatorOfficialVerified publisher1.0.01 of 2See more

fluentd-aggregator fluentd-aggregator 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
json@2.9.1
2.19.9

Open the chart page →

1,742
octoboxhalkeye0.1.11 of 1See more

octobox halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
octoboxio/octobox:latestd909041c46eb
json@2.18.0
2.19.9

Open the chart page →

3,255
manyfoldjeffrescVerified publisher1.0.31 of 1See more

manyfold jeffresc 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
json@2.9.1
2.19.9

Open the chart page →

1,960
deltabadgerk8s-chartsVerified publisher2.0.01 of 1See more

deltabadger k8s-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
json@2.9.1
2.19.9

Open the chart page →

5,669
railsmatic-insurance2.4.41 of 1See more

rails matic-insurance 2.4.4

1 of the 1 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
bitnami/ruby:latest5df5a4639661
json@2.18.0
2.19.9

Open the chart page →

23
fluentd-kubernetes-daemonsetnovum-rgi-charts0.1.01 of 1See more

fluentd-kubernetes-daemonset novum-rgi-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1-debian-graylogfda93f768f98
json@2.9.1
2.19.9

Open the chart page →

999
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
ruby2.3@2.3.1-2~16.04.5
no fix listed

Open the chart page →

88,546
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
ruby2.3@2.3.1-2~16.04.5
no fix listed

Open the chart page →

38,865
redminerestic-pvc-backupVerified publisher0.2.61 of 1See more

redmine restic-pvc-backup 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
json@2.9.1
2.19.9

Open the chart page →

4,240
fluentdsinextraVerified publisher1.4.51 of 1See more

fluentd sinextra 1.4.5

1 of the 1 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/fluentd:1.19.33273d13f1e75
json@2.9.1
2.19.9

Open the chart page →

1,085
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
json@2.10.2
2.19.9

Open the chart page →

10,795
vulcanvulcan0.2.21 of 2See more

vulcan vulcan 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
mitre/vulcan:latest2bc4dfb8150f
json@2.9.1
2.19.9

Open the chart page →

1,516
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2026-54696.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
ruby2.7@2.7.0-5ubuntu1.8
no fix listed

Open the chart page →

11,405

Container images carrying it

35 by charts deploying them

A fixed version is listed for 1 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
library/redmine:6.1.3-trixief474a901faec
json@2.9.1
2.19.9
2
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
json@2.18.0
2.19.9
1
bitnami/ruby:latest5df5a4639661
json@2.18.0
2.19.9
1
blackducksoftware/bdba-fluentd:2026.6.3c14bbbf45536
json@2.13.2
2.19.9
1
chatwoot/chatwoot:v4.15.167ebc751c171
json@2.19.8
2.19.9
1
docuseal/docuseal:2.4.17493fd7f6728
json@2.19.2
2.19.9
1
docuseal/docuseal:3.2.4a8f063f916e3
json@2.18.0
2.19.9
1
fluent/fluentd-kubernetes-daemonset:v1.19.3-debian-elasticsearch7-1.1de9cf5f1127a
json@2.13.2
2.19.9
1
fluent/fluentd-kubernetes-daemonset:v1-debian-graylogfda93f768f98
json@2.9.1
2.19.9
1
grafana/fluent-plugin-loki:latest8a3882e8c28b
json@2.9.1
2.19.9
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
ruby2.5@2.5.8-1bbox1~bionic1
no fix listed
1
library/logstash:9.1.233eae14f0867
json@2.12.2
2.19.9
1
library/redmine:6.1.204ac44a2595b
json@2.9.1
2.19.9
1
mitre/vulcan:latest2bc4dfb8150f
json@2.9.1
2.19.9
1
muluder/prograncontrollermcord:0.1.843b597a93da7
ruby2.3@2.3.1-2~16.04.5
no fix listed
1
octoboxio/octobox:latestd909041c46eb
json@2.18.0
2.19.9
1
omecproject/onos-progran:1.0.05715e5648aa0
ruby2.3@2.3.1-2~16.04.5
no fix listed
1
openproject/openproject:17.8.0-slim48952034215d
json@2.18.0
2.19.9
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
ruby2.7@2.7.0-5ubuntu1.8
no fix listed
1
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
json@2.9.1
2.19.9
1
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
json@2.9.1
2.19.9
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
json@2.9.1
2.19.9
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
ruby2.7@2.7.0-5ubuntu1.5
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
ruby2.7@2.7.0-5ubuntu1.4
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
ruby2.7@2.7.0-5ubuntu1.5
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
ruby2.7@2.7.0-5ubuntu1.5
no fix listed
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
ruby2.7@2.7.0-5ubuntu1.5
no fix listed
1
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
json@2.9.1
2.19.9
1
ghcr.io/manyfold3d/manyfold-solo:0.147.2ed5a792b0e8d
json@2.9.1
2.19.9
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
json@2.10.2
2.19.9
1
ghcr.io/open-telemetry/demo:3.0.0-emaild674d4081ca4
json@2.18.0
2.19.9
1
ghcr.io/sergelogvinov/fluentd:1.19.33273d13f1e75
json@2.9.1
2.19.9
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
ruby3.0@3.0.2-7ubuntu2.4
no fix listed
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
ruby3.0@3.0.2-7ubuntu2.8
no fix listed
1
ghcr.io/zammad/zammad:7.1.3-0011e65123a43ecc
json@2.9.1
2.19.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.