CVE-2026-0864
MediumAdvisory
Published 23 Jun 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.001
- 3rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 733
- of 17,781 indexed, latest versions
- Container images
- 717
- deployed by those charts
- Fix available
- 7 of 16
- affected packages
Configuration Injection via Carriage Return (\r) in write() method
Carried by container images the latest versions of 733 of 17,781 indexed charts deploy, on 717 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| python3.11deb | 3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more | no fix listed | 181 |
| python3.8deb | 3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more | no fix listed | 100 |
| python3.12deb | 3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+11 more | no fix listed | 89 |
| python3.10deb | 3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+16 more | no fix listed | 80 |
| python3apk | 3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+7 more | 3.12.14-r0, 3.14.7-r0 | 75 |
| python3.13deb | 3.13.5-2, 3.13.5-2+deb13u2, 3.13.5-2+deb13u4, 3.13.7-1ubuntu0.1 | 3.13.5-2+deb13u5 | 74 |
| python2.7deb | 2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 more | no fix listed | 54 |
| python3.6deb | 3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more | no fix listed | 44 |
| python3.5deb | 3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9 | no fix listed | 25 |
| python3.14deb | 3.14.4-1, 3.14.4-1ubuntu0.1, 3.14.4-1ubuntu0.2 | no fix listed | 9 |
| python3.4deb | 3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7 | no fix listed | 7 |
| python-3.14apk | 3.14.2-r2, 3.14.4-r2, 3.14.6-r0 | 3.14.6-r3 | 6 |
| pythonbitnami | 3.11.11-0, 3.12.8-0, 3.13.5-1 | 3.10.21 | 3 |
| python-3.13apk | 3.13.7-r0, 3.13.10-r0, 3.13.12-r2 | 3.13.14-r2 | 3 |
| python-3.12apk | 3.12.0-r1, 3.12.9-r1 | 3.12.13-r10 | 2 |
| python3rpm | 3.12.9-13.azl3 | 3.12.9-14 | 1 |
- OSV records
- ALPINE-CVE-2026-0864BIT-python-2026-0864CGA-3797-65xv-g227CGA-4rwv-hcmp-4f74CGA-7hpc-7m58-8xwhDEBIAN-CVE-2026-0864UBUNTU-CVE-2026-0864AZL-91260
- Also known as
- BIT-libpython-2026-0864, BIT-python-min-2026-0864, CGA-mcc6-wwhc-pmfh, CGA-xjqj-qh8m-vpc4, CGA-xx25-7g6h-c3pm, PSF-2026-29
Charts affected
733 by stars
Container images carrying it
717 by charts deploying them
A fixed version is listed for 7 of the 16 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| checkmk/ | c11b422210c4 | python3.10 | no fix listed | 1 |
| chetangautamm/ | b4b94155ff5a | python3.4 | no fix listed | 1 |
| chetangautamm/ | e7f7049e1544 | python3.8 | no fix listed | 1 |
| cheyang/ | 46cc34755493 | python2.7 python3.5 | no fix listed no fix listed | 1 |
| chiefonboarding/ | 59bc7aa60fe7 | python3.13 | 3.13.5-2+deb13u5 | 1 |
| chocobozzz/ | 052712130691 | python3.13 | 3.13.5-2+deb13u5 | 1 |
| chriseaton/ | 54c3384ce701 | python3.10 | no fix listed | 1 |
| citizenstig/ | b81c818ccb86 | python3.5 | no fix listed | 1 |
| cloudve/ | af56e77ca587 | python3.6 | no fix listed | 1 |
| cloudve/ | d79c1c5881c0 | python3.6 | no fix listed | 1 |
| codedesignplus/ | e336012bc781 | python3.11 | no fix listed | 1 |
| codedesignplus/ | ac84661c605e | python3.11 | no fix listed | 1 |
| copyparty/ | 0a0a8605062c | python3 | 3.12.14-r0 | 1 |
| countly/ | e3c238248f99 | python2.7 python3.8 | no fix listed no fix listed | 1 |
| cybrarist/ | e9e2447ac666 | python3.13 | 3.13.5-2+deb13u5 | 1 |
| cznic/ | fe71c5214fdc | python3.13 | 3.13.5-2+deb13u5 | 1 |
| danialnabiyan1382/ | f96a7ebf1f42 | python3.11 | no fix listed | 1 |
| dariomader/ | d2f4a8c5e690 | python-3.12 | 3.12.13-r10 | 1 |
| daskdev/ | 052630f5ca04 | python3.6 | no fix listed | 1 |
| datamate/ | 2dd66b722464 | python3.10 | no fix listed | 1 |
| deconzcommunity/ | 062de2362641 | python3.11 | no fix listed | 1 |
| deimosfr/ | 284c4040fc6d | python3.13 | 3.13.5-2+deb13u5 | 1 |
| digitalist/ | bc4aeeaea769 | python3 | 3.14.7-r0 | 1 |
| docuseal/ | 7493fd7f6728 | python3 | 3.12.14-r0 | 1 |
| dongjiang1989/ | 4bf9ae391948 | python3.8 | no fix listed | 1 |
| dpage/ | 52cb72a9e3da | python3 | 3.12.14-r0 | 1 |
| dragonflyoss/ | a1b52779c4dd | python3.11 | no fix listed | 1 |
| dragonflyoss/ | edf3e921f4e0 | python3.11 | no fix listed | 1 |
| drumsergio/ | 28244054e1bf | python3.11 | no fix listed | 1 |
| dserio83/ | 6b3d9115fee2 | python3.11 | no fix listed | 1 |
| eclipseaerios/ | e7f5ba0bc64d | python3.13 | 3.13.5-2+deb13u5 | 1 |
| eftechcombr/ | f3d0ed01709e | python3 | 3.12.14-r0 | 1 |
| elastictranscoder/ | b4a0327029e6 | python3.6 | no fix listed | 1 |
| elastictranscoder/ | 5b75d19e2733 | python3.6 | no fix listed | 1 |
| elautoestopista/ | 125ba620d528 | python3 | 3.12.14-r0 | 1 |
| electriccoinco/ | 2ae3a551e111 | python3.13 | 3.13.5-2+deb13u5 | 1 |
| esphome/ | 9ab8cc88b28c | python3.11 | no fix listed | 1 |
| esphome/ | b2c6322700ac | python3.11 | no fix listed | 1 |
| esphome/ | def8b6e4f517 | python3.11 | no fix listed | 1 |
| ethereumex/ | a7603aa8df4c | python2.7 | no fix listed | 1 |
| ethpandaops/ | 1efa2fba6711 | python3.13 | 3.13.5-2+deb13u5 | 1 |
| extrim/ | 9cb7eb5598b6 | python3 | 3.12.14-r0 | 1 |
| felipecs8/ | 29e06c9c6385 | python3.11 | no fix listed | 1 |
| firefart/ | 0d6249906d8c | python3.11 | no fix listed | 1 |
| fiware/ | 29456835bb2c | python3.8 | no fix listed | 1 |
| fiware/ | d551a13e8278 | python3.11 | no fix listed | 1 |
| flanksource/ | 689687a7cf95 | python3.12 | no fix listed | 1 |
| flashcatcloud/ | 42e6ab16472e | python3.12 | no fix listed | 1 |
| fluent/ | e76397ef3983 | python3.11 | no fix listed | 1 |
| flyway/ | 45b5d7cdc75a | python3.8 | no fix listed | 1 |