StackRadar

CVE-2025-71176

Medium

Advisory

Published 22 Jan 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
72
of 17,781 indexed, latest versions
Container images
70
deployed by those charts
Fix available
1 of 1
affected package

pytest has vulnerable tmpdir handling

Carried by container images the latest versions of 72 of 17,781 indexed charts deploy, on 70 images.

Affected packageAffected versionsFixed inImages
pytestpypi3.5.0, 3.5.1, 4.6.9, 5.0.1+27 more9.0.370
OSV records
GHSA-6w46-j5rx-g56g
Also known as
PYSEC-2026-1845

Charts affected

72 by stars
ChartLatestAffected imagesRadar Score
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
pytest@6.0.2
9.0.3

Open the chart page →

16,417
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
pytest@7.4.2
9.0.3

Open the chart page →

6,447
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pytest@8.3.5
9.0.3

Open the chart page →

8,405
lightlyticslightlytics0.1.211 of 2See more

lightlytics lightlytics 0.1.21

1 of the 2 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
pytest@8.3.4
9.0.3

Open the chart page →

5,354
calendar-apiliturgical0.1.51 of 1See more

calendar-api liturgical 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
pytest@8.4.1
9.0.3

Open the chart page →

1,556
liturgical-apiliturgical0.2.111 of 1See more

liturgical-api liturgical 0.2.11

1 of the 1 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
pytest@9.0.2
9.0.3

Open the chart page →

1,004
lnbitslnbits0.2.11 of 1See more

lnbits lnbits 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
pytest@7.2.1
9.0.3

Open the chart page →

1,949
parent-chartmid-proje0.1.01 of 3See more

parent-chart mid-proje 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
youssef11gaber10/flask-service:latest9c727fcfde76
pytest@7.4.0
9.0.3

Open the chart page →

1,773
elasticsearch2ncsaVerified publisher0.2.21 of 2See more

elasticsearch2 ncsa 0.2.2

1 of the 2 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
elastichq/elasticsearch-hq:latestbb3bd22c2b87
pytest@5.0.1
9.0.3

Open the chart page →

4,911
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
pytest@7.4.2
9.0.3

Open the chart page →

109,294
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
pytest@9.0.2
9.0.3

Open the chart page →

4,749
powerdnspuckpuck2.0.01 of 4See more

powerdns puckpuck 2.0.0

1 of the 4 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
pschiffe/pdns-admin:0.4.137ebba8c2b8f
pytest@7.2.1
9.0.3

Open the chart page →

4,616
request-registryrequest-registry0.1.01 of 2See more

request-registry request-registry 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
pytest@6.2.5
9.0.3

Open the chart page →

2,201
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
pytest@8.3.3
9.0.3

Open the chart page →

9,607
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
pytest@8.3.5
9.0.3

Open the chart page →

3,512
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
pytest@8.3.5
9.0.3

Open the chart page →

4,718
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
pytest@8.3.5
9.0.3

Open the chart page →

7,436
syncstorageschichtelVerified publisher0.1.11 of 1See more

syncstorage schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
mozilla/syncstorage-rs:0.15.893752877dced
pytest@8.2.0
9.0.3

Open the chart page →

1,318
classificationsignalen4.24.01 of 1See more

classification signalen 4.24.0

1 of the 1 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
signalen/classification:ad60447d1733473e30ab0a3ba53d58141cc1d2509496ae672877
pytest@5.4.3
9.0.3

Open the chart page →

1,553
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
pytest@6.1.2
9.0.3

Open the chart page →

4,086
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
pytest@6.1.1
9.0.3

Open the chart page →

2,643
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-71176.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
pytest@7.2.1
9.0.3

Open the chart page →

5,846

Container images carrying it

70 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
sirrend/helmup-engine:0.1.13699e79e3d4e2
pytest@7.4.3
9.0.3
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
pytest@7.4.2
9.0.3
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
pytest@6.2.5
9.0.3
1
youssef11gaber10/flask-service:latest9c727fcfde76
pytest@7.4.0
9.0.3
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
pytest@8.3.5
9.0.3
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
pytest@9.0.2
9.0.3
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
pytest@7.1.2
9.0.3
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
pytest@7.4.3
9.0.3
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
pytest@9.0.2
9.0.3
1
ghcr.io/jaydee94/kubeseal-webgui/api:4.5.33cceb9462ae1
pytest@8.4.0
9.0.3
1
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
pytest@8.4.1
9.0.3
1
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
pytest@9.0.2
9.0.3
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
pytest@9.0.2
9.0.3
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
pytest@8.1.1
9.0.3
1
ghcr.io/porelli/firefox-sync:syncstorage-rs-mysql-0.18.27d244e514216
pytest@8.3.5
9.0.3
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
pytest@8.4.2
9.0.3
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
pytest@8.3.4
9.0.3
1
quay.io/hpestorage/filex-csi-driver:2.6.4b7f960bbf472
pytest@7.2.0
9.0.3
1
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
pytest@6.2.5
9.0.3
1
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
pytest@6.2.5
9.0.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.