StackRadar

CVE-2026-5795

High

Advisory

Published 14 Apr 2026In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
4 of 4
affected packages

Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables

Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
jetty-jaspimaven9.4.22.v20191022, 9.4.27.v20200227, 9.4.32.v20200930, 9.4.36.v20210114+5 more9.4.6113
jetty-ee10-jaspimaven12.1.612.1.81
jetty-ee11-jaspimaven12.1.612.1.81
jetty-ee9-jaspimaven12.1.612.1.81
OSV records
GHSA-r7p8-xq5m-436c

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
plantumlstevehipwellVerified publisher3.49.01 of 1See more

plantuml stevehipwell 3.49.0

1 of the 1 container images this version deploys carry CVE-2026-5795.

Container imageDigestPackageFixed in
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
jetty-ee10-jaspi@12.1.6
jetty-ee11-jaspi@12.1.6
jetty-ee9-jaspi@12.1.6
12.1.8
12.1.8
12.1.8

Open the chart page →

1,869
activemq-artemisactivemq-artemis-helm0.3.61 of 1See more

activemq-artemis activemq-artemis-helm 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-5795.

Container imageDigestPackageFixed in
vromero/activemq-artemis:2.16.0408d6a46b153
jetty-jaspi@9.4.27.v20200227
9.4.61

Open the chart page →

4,419
akto-testing-db-layerakto1.42.161 of 2See more

akto-testing-db-layer akto 1.42.16

1 of the 2 container images this version deploys carry CVE-2026-5795.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
jetty-jaspi@9.4.58.v20250814
9.4.61

Open the chart page →

5,489
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-5795.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
jetty-jaspi@9.4.58.v20250814
9.4.61

Open the chart page →

3,442
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-5795.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
jetty-jaspi@9.4.43.v20210629
9.4.61

Open the chart page →

7,936
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-5795.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
jetty-jaspi@9.4.53.v20231009
9.4.61

Open the chart page →

9,412
openhabgeek-cookbookVerified publisher1.5.21 of 1See more

openhab geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-5795.

Container imageDigestPackageFixed in
openhab/openhab:3.2.0d0aa4af452c1
jetty-jaspi@9.4.43.v20210629
9.4.61

Open the chart page →

2,887
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2026-5795.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
jetty-jaspi@9.4.36.v20210114
9.4.61

Open the chart page →

26,944
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-5795.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
jetty-jaspi@9.4.53.v20231009
9.4.61

Open the chart page →

34,754
dynamo-dbk8s-home-lab-repo0.0.31 of 1See more

dynamo-db k8s-home-lab-repo 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-5795.

Container imageDigestPackageFixed in
amazon/dynamodb-local:1.20.01ed00881c937
jetty-jaspi@9.4.48.v20220622
9.4.61

Open the chart page →

444
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2026-5795.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
jetty-jaspi@9.4.32.v20200930
9.4.61

Open the chart page →

55,726
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-5795.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
jetty-jaspi@9.4.22.v20191022
9.4.61

Open the chart page →

12,927
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2026-5795.

Container imageDigestPackageFixed in
voltha/voltha-onos:5.1.8e038acb950d3
jetty-jaspi@9.4.43.v20210629
9.4.61

Open the chart page →

41,044
bastillion-upstreamrock8sVerified publisher0.1.01 of 1See more

bastillion-upstream rock8s 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-5795.

Container imageDigestPackageFixed in
iamdorsah/bastillion:v0.1db83a0254d81
jetty-jaspi@9.4.45.v20220203
9.4.61

Open the chart page →

3,051

Container images carrying it

14 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
aktosecurity/data-ingestion-service213aded7adc5
jetty-jaspi@9.4.58.v20250814
9.4.61
1
amazon/dynamodb-local:1.20.01ed00881c937
jetty-jaspi@9.4.48.v20220622
9.4.61
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
jetty-jaspi@9.4.43.v20210629
9.4.61
1
craigwillis/c2metadata-bd:latestae317d7e4724
jetty-jaspi@9.4.32.v20200930
9.4.61
1
iamdorsah/bastillion:v0.1db83a0254d81
jetty-jaspi@9.4.45.v20220203
9.4.61
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
jetty-jaspi@9.4.53.v20231009
9.4.61
1
localstack/localstack:3.19d278167f2b7
jetty-jaspi@9.4.53.v20231009
9.4.61
1
onosproject/onos:2.2.144914a8d4b3f
jetty-jaspi@9.4.22.v20191022
9.4.61
1
openhab/openhab:3.2.0d0aa4af452c1
jetty-jaspi@9.4.43.v20210629
9.4.61
1
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
jetty-ee10-jaspi@12.1.6
jetty-ee11-jaspi@12.1.6
jetty-ee9-jaspi@12.1.6
12.1.8
12.1.8
12.1.8
1
sismics/docs:v1.10f4b0ef019cf1
jetty-jaspi@9.4.36.v20210114
9.4.61
1
voltha/voltha-onos:5.1.8e038acb950d3
jetty-jaspi@9.4.43.v20210629
9.4.61
1
vromero/activemq-artemis:2.16.0408d6a46b153
jetty-jaspi@9.4.27.v20200227
9.4.61
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
jetty-jaspi@9.4.58.v20250814
9.4.61
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.