StackRadar

CVE-2026-54905

Medium

Advisory

Published 19 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
52
of 17,781 indexed, latest versions
Container images
54
deployed by those charts
Fix available
1 of 1
affected package

Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity

Carried by container images the latest versions of 52 of 17,781 indexed charts deploy, on 54 images.

Affected packageAffected versionsFixed inImages
concurrent-rubygem1.0.5, 1.1.3, 1.1.4, 1.1.5+10 more1.3.754
OSV records
GHSA-wv3x-4vxv-whpp

Charts affected

52 by stars
ChartLatestAffected imagesRadar Score
velero-notificationsvelero-notifications1.1.01 of 1See more

velero-notifications velero-notifications 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-54905.

Container imageDigestPackageFixed in
ghcr.io/simoncaron/velero-notifications:1.0.0d058963d4de7
concurrent-ruby@1.1.10
1.3.7

Open the chart page →

1,285
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-54905.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
concurrent-ruby@1.3.5
1.3.7

Open the chart page →

10,795

Container images carrying it

54 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
concurrent-ruby@1.2.2
1.3.7
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
concurrent-ruby@1.2.3
1.3.7
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
concurrent-ruby@1.2.3
1.3.7
1
quay.io/fluentd_elasticsearch/fluentd:v4.2.399079df58561
concurrent-ruby@1.1.10
1.3.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.