StackRadar

CVE-2026-102269

Medium

Advisory

Published 28 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
379
of 17,957 indexed, latest versions
Container images
377
deployed by those charts
Fix available
1 of 2
affected packages

PyJWT: Non-canonical signature segments enable raw-token revocation bypass

Carried by container images the latest versions of 379 of 17,957 indexed charts deploy, on 377 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi1.4.2, 1.5.3, 1.6.1, 1.6.4+17 more2.14.0377
pyjwtdeb1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+6 moreno fix listed39
OSV records
DEBIAN-CVE-2026-102269GHSA-hxm8-2xgr-2p9mUBUNTU-CVE-2026-102269

Charts affected

379 by stars
ChartLatestAffected imagesRadar Score
dmaap-listenersmo-helm-chart6.0.01 of 3See more

dmaap-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

86,389
elasticsearchsmo-helm-chart6.0.01 of 5See more

elasticsearch smo-helm-chart 6.0.0

1 of the 5 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

85,362
mariadb-initsmo-helm-chart6.0.01 of 2See more

mariadb-init smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

85,362
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

86,389
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

86,389
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

86,389
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

85,362
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

85,362
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.14.0

Open the chart page →

86,389
smtpsmtpVerified publisher1.3.31 of 1See more

smtp smtp 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
pyjwt@2.10.1
2.14.0

Open the chart page →

1,705
srebotsrebot0.14.01 of 2See more

srebot srebot 0.14.0

1 of the 2 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
pyjwt@2.11.0
2.14.0

Open the chart page →

1,687
servicexssl-hep1.8.61 of 16See more

servicex ssl-hep 1.8.6

1 of the 16 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
sslhep/servicex_app:v1.8.6c935e123030d
pyjwt@2.13.0
2.14.0

Open the chart page →

57,809
artifactory-cleanupsubshellVerified publisher1.0.11 of 1See more

artifactory-cleanup subshell 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
devopshq/artifactory-cleanup:1.0.1830e093bffa91
pyjwt@2.10.1
2.14.0

Open the chart page →

2,779
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
pyjwt@2.9.0
2.14.0

Open the chart page →

4,782
uptime-kumasupporttools2.6.01 of 3See more

uptime-kuma supporttools 2.6.0

1 of the 3 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
supporttools/uptime-kuma:v2.6f8a49ed65809
pyjwt@1.7.0
2.14.0

Open the chart page →

4,465
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
pyjwt@2.12.1
2.14.0

Open the chart page →

3,446
the0the0Verified publisher0.9.101 of 9See more

the0 the0 0.9.10

1 of the 9 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.9e301fbb8fae0
pyjwt@2.7.0-1ubuntu0.2
pyjwt@2.7.0
no fix listed
2.14.0

Open the chart page →

5,769
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
pyjwt@2.4.0
2.14.0

Open the chart page →

9,013
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.14.0

Open the chart page →

46,735
uptime-platformuptime-platformVerified publisher0.1.31 of 3See more

uptime-platform uptime-platform 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
sashastudent/uptime-platform:latest37a82b4e598e
pyjwt@2.13.0
2.14.0

Open the chart page →

784
vaultwardenvaultwarden-helmVerified publisher1.2.71 of 2See more

vaultwarden vaultwarden-helm 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:18.4-system-trixie42708a75345b
pyjwt@2.13.0
2.14.0

Open the chart page →

2,045
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
2.14.0

Open the chart page →

5,256
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.14.0

Open the chart page →

4,954
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
no fix listed
2.14.0

Open the chart page →

74,963
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
pyjwt@2.10.1
2.14.0

Open the chart page →

5,967
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pyjwt@2.4.0
2.14.0

Open the chart page →

7,486
juicefs-csi-driverwener0.33.01 of 5See more

juicefs-csi-driver wener 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
2.14.0

Open the chart page →

9,591
juicefs-csi-driverwenerme0.33.01 of 5See more

juicefs-csi-driver wenerme 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
2.14.0

Open the chart page →

9,591
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-102269.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pyjwt@2.3.0-1ubuntu0.3
pyjwt@2.13.0
no fix listed
2.14.0

Open the chart page →

8,586

Container images carrying it

377 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.14.0
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.14.0
1
ghcr.io/linuxserver/papermerge:version-v2.0.198ba2dd3f0bd
pyjwt@2.4.0
2.14.0
1
ghcr.io/linuxserver/sickchill:2021.5.10-1-ls63a607452a692a
pyjwt@2.1.0
2.14.0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pyjwt@2.6.0
2.14.0
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
pyjwt@2.10.1
2.14.0
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
pyjwt@2.13.0
2.14.0
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
pyjwt@2.10.1
2.14.0
1
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
pyjwt@2.13.0
2.14.0
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
pyjwt@2.8.0
2.14.0
1
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
pyjwt@2.7.0
2.14.0
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
pyjwt@2.13.0
2.14.0
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
pyjwt@2.12.1
2.14.0
1
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
pyjwt@2.13.0
2.14.0
1
ghcr.io/observal/observal-api:1.13.1153b8b893232
pyjwt@2.13.0
2.14.0
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
pyjwt@2.10.1
2.14.0
1
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-server:latestce1132261523
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.13.0
no fix listed
2.14.0
1
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.14.0
1
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.14.0
1
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.14.0
1
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
pyjwt@2.13.0
2.14.0
1
ghcr.io/open-telemetry/demo:3.1.0-mcp81db69cdd0b6
pyjwt@2.13.0
2.14.0
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
pyjwt@2.9.0
2.14.0
1
ghcr.io/open-telemetry/demo:3.1.0-agentd0f4ae0b32a8
pyjwt@2.13.0
2.14.0
1
ghcr.io/open-webui/mcpo:git-39b4867f06525afac6b
pyjwt@2.10.1
2.14.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
pyjwt@2.9.0
2.14.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
pyjwt@2.10.1
2.14.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
pyjwt@2.10.1
2.14.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
pyjwt@2.10.1
2.14.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
pyjwt@2.8.0
2.14.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
pyjwt@2.10.1
2.14.0
1
ghcr.io/porelli/firefox-sync:syncstorage-rs-mysql-0.18.27d244e514216
pyjwt@2.10.1
2.14.0
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
pyjwt@2.13.0
2.14.0
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
pyjwt@2.13.0
2.14.0
1
ghcr.io/securo-finance/securo-backend:0.16.2b1cd83ff7828
pyjwt@2.13.0
2.14.0
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
pyjwt@2.11.0
2.14.0
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
pyjwt@2.10.1
2.14.0
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.