StackRadar

CVE-2026-102267

High

Advisory

Published 28 Sept 2026In the index since 30 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.002
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
379
of 17,957 indexed, latest versions
Container images
377
deployed by those charts
Fix available
1 of 2
affected packages

PyJWT: PyJWKClient follows redirects when fetching JWKS

Carried by container images the latest versions of 379 of 17,957 indexed charts deploy, on 377 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi1.4.2, 1.5.3, 1.6.1, 1.6.4+17 more2.14.0377
pyjwtdeb1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+6 moreno fix listed39
OSV records
DEBIAN-CVE-2026-102267GHSA-9v7f-9g4p-ffgjUBUNTU-CVE-2026-102267
Trending
Rank 48 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

379 by stars
ChartLatestAffected imagesRadar Score
dmaap-listenersmo-helm-chart6.0.01 of 3See more

dmaap-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

86,389
elasticsearchsmo-helm-chart6.0.01 of 5See more

elasticsearch smo-helm-chart 6.0.0

1 of the 5 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

85,362
mariadb-initsmo-helm-chart6.0.01 of 2See more

mariadb-init smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

85,362
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

86,389
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

86,389
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

86,389
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

85,362
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

85,362
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

86,389
smtpsmtpVerified publisher1.3.31 of 1See more

smtp smtp 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
pyjwt@2.10.1
2.14.0

Open the chart page →

1,705
srebotsrebot0.14.01 of 2See more

srebot srebot 0.14.0

1 of the 2 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
pyjwt@2.11.0
2.14.0

Open the chart page →

1,687
servicexssl-hep1.8.61 of 16See more

servicex ssl-hep 1.8.6

1 of the 16 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
sslhep/servicex_app:v1.8.6c935e123030d
pyjwt@2.13.0
2.14.0

Open the chart page →

57,809
artifactory-cleanupsubshellVerified publisher1.0.11 of 1See more

artifactory-cleanup subshell 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
devopshq/artifactory-cleanup:1.0.1830e093bffa91
pyjwt@2.10.1
2.14.0

Open the chart page →

2,779
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
pyjwt@2.9.0
2.14.0

Open the chart page →

4,782
uptime-kumasupporttools2.6.01 of 3See more

uptime-kuma supporttools 2.6.0

1 of the 3 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
supporttools/uptime-kuma:v2.6f8a49ed65809
pyjwt@1.7.0
2.14.0

Open the chart page →

4,465
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
pyjwt@2.12.1
2.14.0

Open the chart page →

3,446
the0the0Verified publisher0.9.101 of 9See more

the0 the0 0.9.10

1 of the 9 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.9e301fbb8fae0
pyjwt@2.7.0-1ubuntu0.2
pyjwt@2.7.0
no fix listed
2.14.0

Open the chart page →

5,769
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
pyjwt@2.4.0
2.14.0

Open the chart page →

9,013
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.14.0

Open the chart page →

46,735
uptime-platformuptime-platformVerified publisher0.1.31 of 3See more

uptime-platform uptime-platform 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
sashastudent/uptime-platform:latest37a82b4e598e
pyjwt@2.13.0
2.14.0

Open the chart page →

784
vaultwardenvaultwarden-helmVerified publisher1.2.71 of 2See more

vaultwarden vaultwarden-helm 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:18.4-system-trixie42708a75345b
pyjwt@2.13.0
2.14.0

Open the chart page →

2,045
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
2.14.0

Open the chart page →

5,256
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.14.0

Open the chart page →

4,954
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
no fix listed
2.14.0

Open the chart page →

74,963
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
pyjwt@2.10.1
2.14.0

Open the chart page →

5,967
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pyjwt@2.4.0
2.14.0

Open the chart page →

7,486
juicefs-csi-driverwener0.33.01 of 5See more

juicefs-csi-driver wener 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
2.14.0

Open the chart page →

9,591
juicefs-csi-driverwenerme0.33.01 of 5See more

juicefs-csi-driver wenerme 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
2.14.0

Open the chart page →

9,591
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-102267.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pyjwt@2.3.0-1ubuntu0.3
pyjwt@2.13.0
no fix listed
2.14.0

Open the chart page →

8,586

Container images carrying it

377 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
amundsendev/amundsen-frontend:2.1.169e7915e61c1
pyjwt@1.7.1
2.14.0
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.14.0
1
apache/airflow:2.8.4-python3.964e58748b6b9
pyjwt@2.8.0
2.14.0
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
pyjwt@2.9.0
2.14.0
1
apache/airflow:2.8.1e5560ad0b86e
pyjwt@2.8.0
2.14.0
1
apache/hertzbeat:1.8.075d48a62748f
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.14.0
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.14.0
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
pyjwt@2.2.0
2.14.0
1
apache/superset:4.0.1ab9467fd712c
pyjwt@2.4.0
2.14.0
1
apache/tika:latest-full80072bb73dd3
pyjwt@2.10.1-4ubuntu1
pyjwt@2.10.1
no fix listed
2.14.0
1
apache/tika:3.2.2.0-fullffab324253ed
pyjwt@2.10.1
2.14.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pyjwt@2.10.1
2.14.0
1
aristidetm/k8s-hub:3.3.7ccb516cb8474
pyjwt@2.8.0
2.14.0
1
baserow/backend:2.3.37c00549b3a6f
pyjwt@2.13.0
2.14.0
1
baserow/backend:1.31.1e0b3c8130b91
pyjwt@2.8.0
2.14.0
1
baserow/baserow:1.30.1df0c42eb67e8
pyjwt@2.8.0
2.14.0
1
bcgovimages/aries-cloudagent:py36-1.16-1_0.7.4faa2e2d21916
pyjwt@2.4.0
2.14.0
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
pyjwt@2.13.0
2.14.0
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pyjwt@2.10.1
2.14.0
1
bmeares/meerschaum:2.8.48e9c5bacaa82
pyjwt@2.10.1
2.14.0
1
boky/postfix:5.1.0:v5.1.0aafc77238423
pyjwt@2.10.1
2.14.0
1
buntha/mlflow:2.1.1154542cc3083
pyjwt@2.6.0
2.14.0
1
burakince/mlflow:3.16.0ab4b566644b9
pyjwt@2.13.0
2.14.0
1
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.14.0
1
cdignam/kodiak:v0.54.05a6a55b39cee
pyjwt@1.7.1
2.14.0
1
ceph/daemon:latest-nautilus90f30824a96e
pyjwt@1.5.3
2.14.0
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
pyjwt@2.10.1
2.14.0
1
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
pyjwt@2.13.0
2.14.0
1
ckan/ckan-base:2.12.087ecf3f27ad6
pyjwt@2.13.0
2.14.0
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
pyjwt@2.6.0
2.14.0
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
pyjwt@2.6.0
2.14.0
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
pyjwt@2.6.0
2.14.0
1
codecov/self-hosted-api:24.4.10475cb1c3136
pyjwt@2.8.0
2.14.0
1
codecov/self-hosted-worker:24.4.1837f546b479b
pyjwt@2.4.0
2.14.0
1
dagster/dagster-cloud-agent:1.13.24e29285673c2c
pyjwt@2.13.0
2.14.0
1
datadog/agent:7.22.08f20e56b5311
pyjwt@1.7.1
2.14.0
1
datadog/agent:6aad9994de6a7
pyjwt@1.7.1
2.14.0
1
datamate/seafile-professional:11.0.202dd66b722464
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.6.0
no fix listed
2.14.0
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
pyjwt@2.8.0
2.14.0
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
pyjwt@2.9.0
2.14.0
1
ddosify/selfhosted_backend:3.2.93c11e3182652
pyjwt@2.8.0
2.14.0
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
pyjwt@2.8.0
2.14.0
1
decisionrules/ai-engine:latest557dea1373aa
pyjwt@2.13.0
2.14.0
1
defectdojo/defectdojo-django:3.3.3006516f0f62086
pyjwt@2.13.0
2.14.0
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
pyjwt@2.10.1
2.14.0
1
dpage/pgadmin4:8.418cd5711fc9a
pyjwt@2.8.0
2.14.0
1
dpage/pgadmin4:7.537946e4f3e7b
pyjwt@2.7.0
2.14.0
1
dpage/pgadmin4:9.11.050700ac17936
pyjwt@2.10.1
2.14.0
1
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
2.14.0
1
dpage/pgadmin4:8.13561c1f8f99f2
pyjwt@2.9.0
2.14.0
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.