StackRadar

CVE-2026-55688

Medium

Advisory

Published 26 Aug 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.0
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
29
of 17,781 indexed, latest versions
Container images
36
deployed by those charts
Fix available
1 of 1
affected package

AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore

Carried by container images the latest versions of 29 of 17,781 indexed charts deploy, on 36 images.

Affected packageAffected versionsFixed inImages
async-http-clientmaven2.0.37, 2.5.3, 2.7.0, 2.10.1+7 more2.16.0, 3.0.1136
OSV records
GHSA-m452-q8c9-rg2f

Charts affected

29 by stars
ChartLatestAffected imagesRadar Score
milvusmilvus4.0.311 of 5See more

milvus milvus 4.0.31

1 of the 5 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
async-http-client@2.12.1
2.16.0

Open the chart page →

32,259
milvusmilvus-helm5.0.271 of 4See more

milvus milvus-helm 5.0.27

1 of the 4 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
async-http-client@2.12.1
2.16.0

Open the chart page →

10,670
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
async-http-client@3.0.2
3.0.11

Open the chart page →

3,812
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
async-http-client@2.5.3
2.16.0

Open the chart page →

7,930
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
async-http-client@2.0.37
2.16.0

Open the chart page →

7,166
hive-metastoreheva-helm-chartsVerified publisher0.2.01 of 2See more

hive-metastore heva-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
sslhep/hive-metastore:3.1.39e80af083079
async-http-client@2.0.37
2.16.0

Open the chart page →

7,335
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.261 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

1 of the 6 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
thingsboard/tb-node:3.6.0f40a542832c4
async-http-client@2.12.1
2.16.0

Open the chart page →

14,566
cp-schema-registrycp-schema-registryVerified publisher1.0.01 of 1See more

cp-schema-registry cp-schema-registry 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
async-http-client@2.12.4
2.16.0

Open the chart page →

1,864
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
treskon/portrait:DEV-latest88e813f22347
async-http-client@2.10.4
2.16.0

Open the chart page →

31,844
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
async-http-client@2.12.1
2.16.0

Open the chart page →

16,975
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
async-http-client@2.12.1
2.16.0

Open the chart page →

1,816
pulsarcnieg1.0.82 of 2See more

pulsar cnieg 1.0.8

2 of the 2 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
async-http-client@2.12.1
2.16.0
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
async-http-client@2.7.0
2.16.0

Open the chart page →

16,860
cp-helm-chartscp-helm-charts0.6.16 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

6 of the 8 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
async-http-client@2.10.1
2.16.0
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
async-http-client@2.10.1
2.16.0
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
async-http-client@2.10.1
2.16.0
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
async-http-client@2.10.1
2.16.0
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
async-http-client@2.10.1
2.16.0
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
async-http-client@2.10.1
2.16.0

Open the chart page →

58,857
kafka-connectdasmeta1.0.21 of 3See more

kafka-connect dasmeta 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
confluentinc/cp-schema-registry:latestf0cfd047a839
async-http-client@3.0.10
3.0.11

Open the chart page →

532
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
async-http-client@3.0.2
3.0.11

Open the chart page →

8,541
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
async-http-client@2.7.0
2.16.0

Open the chart page →

37,671
pinotinseefrlab0.2.01 of 2See more

pinot inseefrlab 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
apachepinot/pinot:latest-jdk110018bb04ced7
async-http-client@2.12.3
2.16.0

Open the chart page →

10,777
miot-modulithmicroboxlabs0.6.01 of 1See more

miot-modulith microboxlabs 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-srv:latest5796553b41ae
async-http-client@2.12.4
2.16.0

Open the chart page →

1,414
modulariotmicroboxlabs0.9.01 of 4See more

modulariot microboxlabs 0.9.0

1 of the 4 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-srv:latest4ec11d229028
async-http-client@2.12.4
2.16.0

Open the chart page →

2,256
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
async-http-client@2.7.0
2.16.0

Open the chart page →

15,855
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
async-http-client@2.12.1
2.16.0

Open the chart page →

25,933
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
async-http-client@2.12.1
2.16.0

Open the chart page →

15,675
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
async-http-client@2.12.1
2.16.0

Open the chart page →

9,005
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
async-http-client@2.12.3
2.16.0

Open the chart page →

5,269
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
async-http-client@2.12.3
2.16.0

Open the chart page →

15,520
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
async-http-client@2.12.1
2.16.0

Open the chart page →

8,804
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
async-http-client@2.12.4
2.16.0

Open the chart page →

1,827
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
async-http-client@2.10.5
2.16.0
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
async-http-client@2.10.5
2.16.0
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
async-http-client@2.10.5
2.16.0
thingsboard/tb-node:3.4.1645f43b688f7
async-http-client@2.10.5
2.16.0

Open the chart page →

25,394
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-55688.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
async-http-client@2.12.3
2.16.0

Open the chart page →

3,480

Container images carrying it

36 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/druid:37.0.00116fb802786
async-http-client@3.0.2
3.0.11
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
async-http-client@2.7.0
2.16.0
2
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
async-http-client@2.0.37
2.16.0
1
apache/druid:29.0.10cef139b6bf1
async-http-client@2.5.3
2.16.0
1
apachepinot/pinot:latest-jdk110018bb04ced7
async-http-client@2.12.3
2.16.0
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
async-http-client@2.12.1
2.16.0
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
async-http-client@2.12.1
2.16.0
1
apachepulsar/pulsar:2.6.14db6ff0b4045
async-http-client@2.12.1
2.16.0
1
apachepulsar/pulsar:3.0.79c9947de139d
async-http-client@2.12.1
2.16.0
1
apachepulsar/pulsar:2.9.0d056c89b7131
async-http-client@2.12.1
2.16.0
1
apachepulsar/pulsar:2.8.2d538416d5afe
async-http-client@2.12.1
2.16.0
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
async-http-client@2.12.1
2.16.0
1
bluerange/bluerange:26.1.307c8f73b55df
async-http-client@2.12.1
2.16.0
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
async-http-client@2.10.1
2.16.0
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
async-http-client@2.10.1
2.16.0
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
async-http-client@2.10.1
2.16.0
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
async-http-client@2.10.1
2.16.0
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
async-http-client@2.12.3
2.16.0
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
async-http-client@2.10.1
2.16.0
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
async-http-client@2.10.1
2.16.0
1
confluentinc/cp-schema-registry:latestf0cfd047a839
async-http-client@3.0.10
3.0.11
1
dremio/dremio-oss:24.1.080ed2e3b7c43
async-http-client@2.7.0
2.16.0
1
project2team4/react:latest3ff031a08887
async-http-client@2.12.3
2.16.0
1
sslhep/hive-metastore:3.1.39e80af083079
async-http-client@2.0.37
2.16.0
1
streamnative/private-cloud-console:v2.3.27-all91e54375e154
async-http-client@2.12.4
2.16.0
1
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
async-http-client@2.10.5
2.16.0
1
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
async-http-client@2.10.5
2.16.0
1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
async-http-client@2.10.5
2.16.0
1
thingsboard/tb-node:3.4.1645f43b688f7
async-http-client@2.10.5
2.16.0
1
thingsboard/tb-node:3.6.0f40a542832c4
async-http-client@2.12.1
2.16.0
1
treskon/portrait:DEV-latest88e813f22347
async-http-client@2.10.4
2.16.0
1
zahoriaut/zahori-process:0.1.13351f8a220ed7
async-http-client@2.12.3
2.16.0
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
async-http-client@2.12.1
2.16.0
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
async-http-client@2.12.4
2.16.0
1
ghcr.io/microboxlabs/miot-srv:latest4ec11d229028
async-http-client@2.12.4
2.16.0
1
ghcr.io/microboxlabs/miot-srv:latest5796553b41ae
async-http-client@2.12.4
2.16.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.