StackRadar

CVE-2023-33733

High

Advisory

Published 5 Jun 2023In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.021
81st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5
of 17,781 indexed, latest versions
Container images
6
deployed by those charts
Fix available
1 of 1
affected package

Reportlab vulnerable to remote code execution

Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 6 images.

Affected packageAffected versionsFixed inImages
reportlabpypi3.4.0, 3.5.34, 3.5.57, 3.6.3+2 more3.6.136
OSV records
GHSA-9q9m-c65c-37pq
Also known as
PYSEC-2026-1871

Charts affected

5 by stars
ChartLatestAffected imagesRadar Score
paperlessgeek-cookbookVerified publisher9.2.01 of 1See more

paperless geek-cookbook 9.2.0

1 of the 1 container images this version deploys carry CVE-2023-33733.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
reportlab@3.6.11
3.6.13

Open the chart page →

3,924
check-mkcloudnativeapp0.2.11 of 1See more

check-mk cloudnativeapp 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-33733.

Container imageDigestPackageFixed in
nlmacamp/check_mk:latest5dbb8589f824
reportlab@3.4.0
3.6.13

Open the chart page →

2,408
yadmscronce0.3.02 of 2See more

yadms cronce 0.3.0

2 of the 2 container images this version deploys carry CVE-2023-33733.

Container imageDigestPackageFixed in
mcronce/yadms-ftp:latestf820ef2e3c26
reportlab@3.5.34
3.6.13
mcronce/yadms-web:latestc03c1c7f5aa9
reportlab@3.5.57
3.6.13

Open the chart page →

2,500
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-33733.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
reportlab@3.6.12
3.6.13

Open the chart page →

7,685
krokiteochenglim1.0.11 of 5See more

kroki teochenglim 1.0.1

1 of the 5 container images this version deploys carry CVE-2023-33733.

Container imageDigestPackageFixed in
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
reportlab@3.6.3
3.6.13

Open the chart page →

8,715

Container images carrying it

6 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
anujdatar/cups:25.07.01685df04a643b
reportlab@3.6.12
3.6.13
1
mcronce/yadms-ftp:latestf820ef2e3c26
reportlab@3.5.34
3.6.13
1
mcronce/yadms-web:latestc03c1c7f5aa9
reportlab@3.5.57
3.6.13
1
nlmacamp/check_mk:latest5dbb8589f824
reportlab@3.4.0
3.6.13
1
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
reportlab@3.6.3
3.6.13
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
reportlab@3.6.11
3.6.13
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.