StackRadar

CVE-2026-6860

Medium

Advisory

Published 9 May 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
107
of 17,781 indexed, latest versions
Container images
100
deployed by those charts
Fix available
1 of 1
affected package

Vert.x has a DoS via unbounded server-side SNI SslContext cache growth

Carried by container images the latest versions of 107 of 17,781 indexed charts deploy, on 100 images.

Affected packageAffected versionsFixed inImages
vertx-coremaven4.3.4, 4.3.7, 4.3.8, 4.4.4+24 more4.5.27, 5.0.12100
OSV records
GHSA-3g76-f9xq-8vp6

Charts affected

107 by stars
ChartLatestAffected imagesRadar Score
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6860.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
vertx-core@4.3.4
no fix listed

Open the chart page →

6,443
strimzi-user-operatorspartan0.4.01 of 1See more

strimzi-user-operator spartan 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-6860.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.45.158c727cd2e68
vertx-core@4.5.13
4.5.27

Open the chart page →

1,836
teku-validatorstakewise4.3.21 of 2See more

teku-validator stakewise 4.3.2

1 of the 2 container images this version deploys carry CVE-2026-6860.

Container imageDigestPackageFixed in
consensys/teku:25.4.1bf6ecd2ea716
vertx-core@4.5.14
4.5.27

Open the chart page →

3,153
wonder-mesh-netstrrl-helm2026.629.01 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

1 of the 3 container images this version deploys carry CVE-2026-6860.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.009a381c715ab
vertx-core@4.5.10
4.5.27

Open the chart page →

5,063
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-6860.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.1.4044a457e0498
vertx-core@4.5.11
4.5.27

Open the chart page →

45,239
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-6860.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
vertx-core@4.5.22
4.5.27

Open the chart page →

7,624
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-6860.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
vertx-core@4.3.4
no fix listed

Open the chart page →

6,016

Container images carrying it

100 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
codeurjc/server:v1.0310bea5b1ee7
vertx-core@4.3.4
no fix listed
8
mastercloudapps/server:v2.23f3d24dfe2686
vertx-core@4.3.4
no fix listed
4
quay.io/strimzi/operator:0.37.052f376e64b9b
vertx-core@4.4.4
no fix listed
4
airbyte/workload-launcher:2.2.0119be7bfb719
vertx-core@4.5.24
4.5.27
2
apache/druid:37.0.00116fb802786
vertx-core@4.5.24
4.5.27
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
vertx-core@4.5.25
4.5.27
2
quay.io/keycloak/keycloak:26.1.4044a457e0498
vertx-core@4.5.11
4.5.27
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
vertx-core@4.3.4
no fix listed
2
quay.io/strimzi/operator:0.39.002f6f143fc6d
vertx-core@4.5.0
4.5.27
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
vertx-core@4.5.14
4.5.27
2
airbyte/bootloader:2.2.0f71cf4e185d5
vertx-core@4.5.24
4.5.27
1
airbyte/cron:2.2.0d97b67a1346d
vertx-core@4.5.24
4.5.27
1
airbyte/server:2.2.070e125498a1c
vertx-core@4.5.24
4.5.27
1
airbyte/worker:2.2.08060b88b29c8
vertx-core@4.5.24
4.5.27
1
airbyte/workload-api-server:2.2.042093cff86e9
vertx-core@4.5.24
4.5.27
1
aktosecurity/akto-threat-detection-backend:latest15ebb75b94dc
vertx-core@4.5.11
4.5.27
1
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
vertx-core@4.5.11
4.5.27
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
vertx-core@4.3.8
no fix listed
1
apachepulsar/pulsar:3.0.79c9947de139d
vertx-core@4.5.10
4.5.27
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
vertx-core@4.3.7
no fix listed
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
vertx-core@4.3.7
no fix listed
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
vertx-core@4.3.7
no fix listed
1
athou/commafeed:6.2.0-postgresql5e388351df1a
vertx-core@4.5.24
4.5.27
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
vertx-core@4.3.4
no fix listed
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
vertx-core@4.5.7
4.5.27
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
vertx-core@4.5.18
4.5.27
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
vertx-core@4.3.8
no fix listed
1
consensys/teku:latest3a4f5761ae1c
vertx-core@4.5.24
4.5.27
1
consensys/teku:25.4.1bf6ecd2ea716
vertx-core@4.5.14
4.5.27
1
consensys/web3signer:latestf146a51a1ba3
vertx-core@4.5.26
4.5.27
1
epam/ai-dial-admin-backend:0.20.00ac5be78d7c2
vertx-core@4.5.24
4.5.27
1
esperotech/yaade:latest24d2d692d948
vertx-core@4.5.1
4.5.27
1
factorhouse/factor-platform:96.414728f9fd80f
vertx-core@4.5.24
4.5.27
1
factorhouse/kpow:96.4f9ce9b16b3a7
vertx-core@4.5.24
4.5.27
1
factorhouse/kpow-ce:96.466b08cc9e943
vertx-core@4.5.24
4.5.27
1
folioci/edge-connexion:latestb4863d135524
vertx-core@5.0.7
5.0.12
1
folioci/edge-ncip:lateste760dbb81d1a
vertx-core@5.0.8
5.0.12
1
folioci/edge-oai-pmh:latesteedfcbc29792
vertx-core@5.0.5
5.0.12
1
folioci/edge-orders:latest1ef654ee9f23
vertx-core@5.0.11
5.0.12
1
folioci/edge-patron:latest682b852e056d
vertx-core@5.0.5
5.0.12
1
folioci/mod-authtoken:latest995a25a33133
vertx-core@4.5.13
4.5.27
1
folioci/mod-codex-mux:latestd4138abfd30d
vertx-core@4.3.4
no fix listed
1
folioci/mod-configuration:latestdd0cdc89670a
vertx-core@5.0.11
5.0.12
1
folioci/mod-copycat:latest1513fad2b799
vertx-core@5.0.10
5.0.12
1
folioci/mod-courses:latest68ca414f5596
vertx-core@5.0.6
5.0.12
1
folioci/mod-data-import-converter-storage:latest3028f333778f
vertx-core@4.3.4
no fix listed
1
folioci/mod-email:latest79ea8e2e7ebf
vertx-core@5.0.6
5.0.12
1
folioci/mod-erm-usage-harvester:latest2d6767933c59
vertx-core@5.0.10
5.0.12
1
folioci/mod-eusage-reports:latest15de67587091
vertx-core@5.0.8
5.0.12
1
folioci/mod-feesfines:latestfe3a7049f2fb
vertx-core@5.0.5
5.0.12
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.