StackRadar

CVE-2024-56326

High

Advisory

Published 23 Dec 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
374
of 17,781 indexed, latest versions
Container images
401
deployed by those charts
Fix available
3 of 3
affected packages

Jinja has a sandbox breakout through indirect reference to format method

Carried by container images the latest versions of 374 of 17,781 indexed charts deploy, on 401 images.

Affected packageAffected versionsFixed inImages
jinja2pypi2.7.2, 2.8, 2.8.1, 2.9.4+16 more3.1.5401
jinja2deb2.7.2-2, 2.10.1-2, 3.0.3-1, 3.0.3-1ubuntu0.1+1 more2.7.2-2ubuntu0.1~esm6, 2.10.1-2ubuntu0.4, 3.0.3-1ubuntu0.313
py3-jinja2apk3.1.2-r23.1.5-r01
OSV records
GHSA-q2x7-8rv6-6q7hUBUNTU-CVE-2024-56326ALPINE-CVE-2024-56326
Also known as
PYSEC-2026-1475, USN-7244-1, USN-7343-1

Charts affected

374 by stars
ChartLatestAffected imagesRadar Score
remla23-team17remla23-team171.0.02 of 2See more

remla23-team17 remla23-team17 1.0.0

2 of the 2 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
ghcr.io/remla23-team17/app:1.0.05816dbddf47d
jinja2@3.1.2
3.1.5
ghcr.io/remla23-team17/model-service:1.0.0aa59fe2c4f6a
jinja2@3.1.2
3.1.5

Open the chart page →

4,447
reportportalreportportal5.7.22 of 8See more

reportportal reportportal 5.7.2

2 of the 8 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
reportportal/service-auto-analyzer:5.7.295ada4a216ce
jinja2@3.1.2
3.1.5
reportportal/service-metrics-gatherer:1.1.202a0e6dc11161
jinja2@3.1.2
3.1.5

Open the chart page →

25,737
request-registryrequest-registry0.1.01 of 2See more

request-registry request-registry 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
jinja2@2.11.3
3.1.5

Open the chart page →

2,201
revwallet-apirevwallet0.7.121 of 1See more

revwallet-api revwallet 0.7.12

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
arthurjguerra18/revwallet:v0.7.12f540af20b307
jinja2@3.1.4
3.1.5

Open the chart page →

5,790
bookinforgnu1.0.01 of 7See more

bookinfo rgnu 1.0.0

1 of the 7 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.14.022a0410f35a8
jinja2@2.10
3.1.5

Open the chart page →

20,462
httpbinrgnu1.0.01 of 1See more

httpbin rgnu 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
citizenstig/httpbin:latestb81c818ccb86
jinja2@2.9.4
3.1.5

Open the chart page →

11,422
istio-bookinforgnu1.0.21 of 7See more

istio-bookinfo rgnu 1.0.2

1 of the 7 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.14.022a0410f35a8
jinja2@2.10
3.1.5

Open the chart page →

20,462
istio-helloworldrgnu1.0.12 of 2See more

istio-helloworld rgnu 1.0.1

2 of the 2 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
istio/examples-helloworld-v1:latest328b237e4fb1
jinja2@3.1.3
3.1.5
istio/examples-helloworld-v2:latest0a7f02b2c7c9
jinja2@3.1.3
3.1.5

Open the chart page →

9,418
kube-web-viewrlex0.5.01 of 1See more

kube-web-view rlex 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:23.8.0431f1bf013d0
jinja2@3.1.2
3.1.5

Open the chart page →

4,908
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
jinja2@3.1.4
3.1.5

Open the chart page →

9,607
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
jinja2@3.1.3
3.1.5

Open the chart page →

10,209
pgadminsb-helm-charts0.3.01 of 1See more

pgadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.13561c1f8f99f2
jinja2@3.1.4
3.1.5

Open the chart page →

1,713
sealed-secrets-uisealed-secrets-uiVerified publisher0.0.81 of 1See more

sealed-secrets-ui sealed-secrets-ui 0.0.8

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
jinja2@3.1.4
3.1.5

Open the chart page →

4,707
seldon-core-loadtestingseldon0.2.01 of 1See more

seldon-core-loadtesting seldon 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
seldonio/locust-core:0.81d0da98a2d76
jinja2@2.10.1
3.1.5

Open the chart page →

23,007
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
jinja2@3.0.2
3.1.5

Open the chart page →

21,997
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.4.01bbda887bc53
jinja2@2.9.6
3.1.5

Open the chart page →

10,967
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
jinja2@3.1.2
py3-jinja2@3.1.2-r2
3.1.5
3.1.5-r0

Open the chart page →

3,337
first-chartshashkist-test0.1.01 of 3See more

first-chart shashkist-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
jinja2@3.1.4
3.1.5

Open the chart page →

3,045
classificationsignalen4.24.01 of 1See more

classification signalen 4.24.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
signalen/classification:ad60447d1733473e30ab0a3ba53d58141cc1d2509496ae672877
jinja2@2.11.2
3.1.5

Open the chart page →

1,553
frigatesmarthallVerified publisher1.0.61 of 1See more

frigate smarthall 1.0.6

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
jinja2@3.1.2
3.1.5

Open the chart page →

2,243
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
jinja2@3.1.3
3.1.5

Open the chart page →

5,565
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
jinja2@3.0.3-1
jinja2@3.0.3
3.0.3-1ubuntu0.3
3.1.5

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
jinja2@3.0.3-1ubuntu0.1
jinja2@3.0.3
3.0.3-1ubuntu0.3
3.1.5

Open the chart page →

13,079
speedtest-exporterspeedtest-exporter0.2.21 of 1See more

speedtest-exporter speedtest-exporter 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.5.4f1064d49124c
jinja2@3.1.2
3.1.5

Open the chart page →

741
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
jinja2@3.1.4
3.1.5

Open the chart page →

2,416
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
jinja2@2.10.1
3.1.5

Open the chart page →

2,060
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
jinja2@3.1.4
3.1.5

Open the chart page →

20,223
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
jinja2@2.11.2
3.1.5

Open the chart page →

3,044
storageclass-routerstorageclass-routerVerified publisher0.4.11 of 1See more

storageclass-router storageclass-router 0.4.1

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
quay.io/maxiv/storageclass-router:0.4.160725dab588c
jinja2@3.1.3
3.1.5

Open the chart page →

1,058
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
jinja2@3.1.4
3.1.5

Open the chart page →

10,134
studygovernorstudy-governorVerified publisher0.1.381 of 3See more

studygovernor study-governor 0.1.38

1 of the 3 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
jinja2@3.1.2
3.1.5

Open the chart page →

1,447
csv-viewsvtech-public-helm-charts1.0.01 of 1See more

csv-view svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
svtechnmaa/svtech_csv:v1.0.1b9d7ecf8de24
jinja2@3.0.3
3.1.5

Open the chart page →

1,220
icinga2svtech-public-helm-charts1.0.01 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
jinja2@3.0.3
3.1.5

Open the chart page →

5,511
icinga2-reportsvtech-public-helm-charts1.0.01 of 1See more

icinga2-report svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
trungkien210493/icinga2-report:v1.7.12cc8c3763c4c
jinja2@2.11.2
3.1.5

Open the chart page →

1,779
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
jinja2@3.0.3
3.1.5

Open the chart page →

18,756
rundeck-option-providersvtech-public-helm-charts1.0.01 of 2See more

rundeck-option-provider svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
jinja2@3.0.3
3.1.5

Open the chart page →

1,428
democharttech-challenge0.1.01 of 4See more

demochart tech-challenge 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
alexvm6/pythonalex:latest89a05786879c
jinja2@3.1.2
3.1.5

Open the chart page →

3,632
krokiteochenglim1.0.11 of 5See more

kroki teochenglim 1.0.1

1 of the 5 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
jinja2@3.0.3
3.1.5

Open the chart page →

8,715
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
jinja2@3.1.4
3.1.5

Open the chart page →

5,704
webapp1test-helm-chart-10.1.01 of 1See more

webapp1 test-helm-chart-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
devopsjourney1/mywebapp:latestbd1ec6838570
jinja2@3.1.2
3.1.5

Open the chart page →

1,469
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
jinja2@3.1.3
3.1.5

Open the chart page →

4,393
chatqnatest-opea1.0.03 of 11See more

chatqna test-opea 1.0.0

3 of the 11 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
jinja2@3.1.3
3.1.5
opea/reranking-tei:1.0e48613afb191
jinja2@3.1.3
3.1.5
opea/retriever-redis:1.0eb746b263705
jinja2@3.1.3
3.1.5

Open the chart page →

39,090
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
opea/llm-docsum-tgi:1.002f9e8fa5d71
jinja2@3.1.3
3.1.5

Open the chart page →

28,858
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
jinja2@3.1.3
3.1.5

Open the chart page →

5,185
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
jinja2@3.1.3
3.1.5

Open the chart page →

5,221
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
jinja2@3.1.3
3.1.5

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
jinja2@3.1.3
3.1.5

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
jinja2@3.1.3
3.1.5

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
jinja2@3.1.3
3.1.5

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-56326.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
jinja2@3.1.4
3.1.5

Open the chart page →

5,350

Container images carrying it

401 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
clsen2024/daejeon_2-3:latest1156cd87c8fb
jinja2@3.1.4
3.1.5
1
clsen2024/gwangju_2-3:service-b-10ba9eff852c5
jinja2@3.1.4
3.1.5
1
clsen2024/gwangju_2-3:service-a-151b1d45961cd
jinja2@3.1.4
3.1.5
1
clsen2024/gwangju_2-3:service-c-1efb1586c8299
jinja2@3.1.4
3.1.5
1
codecov/self-hosted-worker:24.4.1837f546b479b
jinja2@3.1.3
3.1.5
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
jinja2@2.11.2
3.1.5
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
jinja2@2.11.2
3.1.5
1
confluentinc/cp-kafka:5.4.01bbda887bc53
jinja2@2.9.6
3.1.5
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
jinja2@2.11.3
3.1.5
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
jinja2@3.1.4
3.1.5
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
jinja2@2.11.3
3.1.5
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
jinja2@2.9.6
3.1.5
1
confluentinc/cp-kafka:7.5.1dc9b972db002
jinja2@2.11.3
3.1.5
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
jinja2@2.11.2
3.1.5
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
jinja2@2.11.2
3.1.5
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
jinja2@3.1.3
3.1.5
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
jinja2@2.11.2
3.1.5
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
jinja2@2.11.2
3.1.5
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
jinja2@2.11.3
3.1.5
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
jinja2@3.1.4
3.1.5
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
jinja2@2.11.2
3.1.5
1
craigwillis/c2metadata-bd:latestae317d7e4724
jinja2@2.11.2
3.1.5
1
danuk/telegram-sender:0.0.1026560388070
jinja2@3.1.2
3.1.5
1
daskdev/dask:1.1.04ecd7bc35500
jinja2@2.10
3.1.5
1
daskdev/dask-notebook:1.1.0052630f5ca04
jinja2@2.10
3.1.5
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
jinja2@2.11.2
3.1.5
1
datawire/aes:1.13.62beb65062c8b
jinja2@2.11.2
3.1.5
1
datawire/aes:3.11.195ec30b3c732
jinja2@3.1.4
3.1.5
1
datawire/emissary:3.12.21f67a1292d2a
jinja2@3.1.4
3.1.5
1
datawire/emissary:2.0.2-ea9716efbdd24b
jinja2@2.11.2
3.1.5
1
ddosify/selfhosted_hammermanager:1.2.471b8768f49bc
jinja2@3.1.3
3.1.5
1
deepflowce/deepflow-app:v6.2.6.5a1888d35e787
jinja2@2.11.3
3.1.5
1
devopsgoofy/k8s-platform:latestad865312099f
jinja2@3.1.2
3.1.5
1
devopstales/kube-openid-connector:1.042c40a0e9f1b
jinja2@3.1.1
3.1.5
1
dinutac/jinja2docker:2.1.89340dde8a8a4
jinja2@3.1.2
3.1.5
1
douz/helpdesk:latest4384103d0219
jinja2@3.1.2
3.1.5
1
dpage/pgadmin4:8.418cd5711fc9a
jinja2@3.1.3
3.1.5
1
dpage/pgadmin4:7.537946e4f3e7b
jinja2@3.1.2
3.1.5
1
dpage/pgadmin4:8.13561c1f8f99f2
jinja2@3.1.4
3.1.5
1
dpage/pgadmin4:4.5a5a656e1d5fd
jinja2@2.10.1
3.1.5
1
dpage/pgadmin4:4.22b1f00b8163cf
jinja2@2.11.2
3.1.5
1
drgrove/mtls-server:v0.14.2361721759a2b
jinja2@2.10.1
3.1.5
1
dysnix/pritunl:v1.29-r819951e3e7a32
jinja2@2.10.1
3.1.5
1
elastichq/elasticsearch-hq:latestbb3bd22c2b87
jinja2@2.10.3
3.1.5
1
errbotio/errbot:6.1.900ee4e0953ab
jinja2@3.0.3
3.1.5
1
evk02/mlflow:2.2.1ef6ff257ef35
jinja2@3.1.2
3.1.5
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
jinja2@3.1.2
3.1.5
1
fiware/bae-activation-service:v0.0.33e3ec88d59ed
jinja2@2.11.2
3.1.5
1
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
jinja2@3.1.2
3.1.5
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
jinja2@2.11.2
3.1.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.