StackRadar

CVE-2026-102272

High

Advisory

Published 28 Sept 2026In the index since 30 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
138
of 17,957 indexed, latest versions
Container images
137
deployed by those charts
Fix available
1 of 2
affected packages

PyJWT BOM Bypass

Carried by container images the latest versions of 138 of 17,957 indexed charts deploy, on 137 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi2.13.02.14.0104
pyjwtdeb1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+6 moreno fix listed39
OSV records
DEBIAN-CVE-2026-102272GHSA-r6x4-923q-g947UBUNTU-CVE-2026-102272

Charts affected

138 by stars
ChartLatestAffected imagesRadar Score
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
pyjwt@2.7.0-1
no fix listed

Open the chart page →

7,268
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
pyjwt@2.7.0-1
no fix listed

Open the chart page →

7,250
k8s-ai-srek8s-ai-sreVerified publisher3.1.21 of 1See more

k8s-ai-sre k8s-ai-sre 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
mohankrishna999/k8s-ai-agent:3.1.27f980f8c650c
pyjwt@2.13.0
2.14.0

Open the chart page →

534
jupyterhub-chartk8s-jupyterhub0.1.01 of 1See more

jupyterhub-chart k8s-jupyterhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
truebyteinnovationllp/jupyterhub-k8s:5.5.06bf978b96279
pyjwt@2.13.0
2.14.0

Open the chart page →

1,656
uptime-kumakubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

uptime-kuma kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.2.1-slim059b49d64739
pyjwt@2.6.0-1
no fix listed

Open the chart page →

6,973
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
pyjwt@2.6.0-1
no fix listed

Open the chart page →

36,169
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
pyjwt@2.6.0-1
no fix listed

Open the chart page →

36,169
plane-mcp-servermakeplaneVerified publisher1.0.01 of 2See more

plane-mcp-server makeplane 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
makeplane/plane-mcp-server:v0.3.071b7252adef0
pyjwt@2.13.0
2.14.0

Open the chart page →

3,016
mcp-homeassistantmcp-helmVerified publisher0.2.41 of 1See more

mcp-homeassistant mcp-helm 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
voska/hass-mcp:latest7142a431e2c5
pyjwt@2.13.0
2.14.0

Open the chart page →

11,314
miot-harnessmicroboxlabs0.8.01 of 1See more

miot-harness microboxlabs 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
pyjwt@2.13.0
2.14.0

Open the chart page →

1,459
uptime-kumancsaVerified publisher1.7.31 of 1See more

uptime-kuma ncsa 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.5c74379ac4509
pyjwt@2.6.0-1+deb12u1
no fix listed

Open the chart page →

32,727
parcelapp-mcpobeoneVerified publisher0.1.01 of 1See more

parcelapp-mcp obeone 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
pyjwt@2.13.0
2.14.0

Open the chart page →

1,108
paperless-ngxoli-the-devVerified publisher1.1.11 of 1See more

paperless-ngx oli-the-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
pyjwt@2.13.0
2.14.0

Open the chart page →

5,312
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
onyxdotapp/onyx-backend:latest60e83a098ae4
pyjwt@2.13.0
2.14.0

Open the chart page →

7,197
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.018 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

18 of the 40 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
pyjwt@2.13.0
2.14.0
ghcr.io/openrelik/openrelik-server:latestce1132261523
pyjwt@2.13.0
2.14.0
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
pyjwt@2.13.0
2.14.0
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
pyjwt@2.13.0
2.14.0
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.13.0
no fix listed
2.14.0
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
pyjwt@2.13.0
2.14.0
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
pyjwt@2.13.0
2.14.0
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
pyjwt@2.13.0
2.14.0
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
pyjwt@2.13.0
2.14.0
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
pyjwt@2.13.0
2.14.0
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.13.0
no fix listed
2.14.0
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
pyjwt@2.13.0
2.14.0
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
pyjwt@2.13.0
2.14.0
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
pyjwt@2.13.0
2.14.0
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.13.0
no fix listed
2.14.0
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
pyjwt@2.13.0
2.14.0
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.13.0
no fix listed
2.14.0
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
pyjwt@2.13.0
2.14.0

Open the chart page →

230,085
prowlerprowler0.1.11 of 1See more

prowler prowler 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
toniblyx/prowler:stablecf1ee9fc5b67
pyjwt@2.13.0
2.14.0

Open the chart page →

1,492
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
pyjwt@2.13.0
2.14.0

Open the chart page →

7,033
label-studioquench-label-studioVerified publisher0.0.51 of 2See more

label-studio quench-label-studio 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/label-studiodigest-pinnedfcaff9893e42
pyjwt@2.13.0
2.14.0

Open the chart page →

271
ml-stackquench-ml-stackVerified publisher0.0.51 of 5See more

ml-stack quench-ml-stack 0.0.5

1 of the 5 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/label-studiodigest-pinnedfcaff9893e42
pyjwt@2.13.0
2.14.0

Open the chart page →

503
linkdingrubxkubeVerified publisher1.2.41 of 1See more

linkding rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.47.0e35cb50e0581
pyjwt@2.13.0
2.14.0

Open the chart page →

2,334
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
pyjwt@2.6.0-1+deb12u1
no fix listed

Open the chart page →

32,941
runwhen-localrunwhen-contribVerified publisher0.7.01 of 3See more

runwhen-local runwhen-contrib 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
pyjwt@2.13.0
2.14.0

Open the chart page →

3,580
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
pyjwt@2.3.0-1ubuntu0.3
no fix listed

Open the chart page →

8,074
seafileschmitzis13.0.131 of 4See more

seafile schmitzis 13.0.13

1 of the 4 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
schmitzis/monorepo:seafile-13.0-latestf7e51ba2fb07
pyjwt@2.7.0-1ubuntu0.1
no fix listed

Open the chart page →

43,887
uptime-kumaschoenwald1.0.101 of 1See more

uptime-kuma schoenwald 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
pyjwt@2.6.0-1+deb12u1
no fix listed

Open the chart page →

32,738
seafileseafileVerified publisher0.12.11 of 1See more

seafile seafile 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
pyjwt@2.3.0-1ubuntu0.2
no fix listed

Open the chart page →

78,638
search-proxysearch-proxy2026.40.01 of 1See more

search-proxy search-proxy 2026.40.0

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
ghcr.io/unique-ag/ai/search-proxy:2026.40.02bd74586650d
pyjwt@2.13.0
2.14.0

Open the chart page →

1,620
backendsignalen4.25.01 of 4See more

backend signalen 4.25.0

1 of the 4 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
signalen/backend:2.50.1826bb090bc4e4
pyjwt@2.13.0
2.14.0

Open the chart page →

11,542
servicexssl-hep1.8.61 of 16See more

servicex ssl-hep 1.8.6

1 of the 16 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
sslhep/servicex_app:v1.8.6c935e123030d
pyjwt@2.13.0
2.14.0

Open the chart page →

57,809
the0the0Verified publisher0.9.101 of 9See more

the0 the0 0.9.10

1 of the 9 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.9e301fbb8fae0
pyjwt@2.7.0-1ubuntu0.2
no fix listed

Open the chart page →

5,769
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
pyjwt@2.7.0-1
no fix listed

Open the chart page →

46,735
uptime-platformuptime-platformVerified publisher0.1.31 of 3See more

uptime-platform uptime-platform 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
sashastudent/uptime-platform:latest37a82b4e598e
pyjwt@2.13.0
2.14.0

Open the chart page →

784
vaultwardenvaultwarden-helmVerified publisher1.2.71 of 2See more

vaultwarden vaultwarden-helm 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:18.4-system-trixie42708a75345b
pyjwt@2.13.0
2.14.0

Open the chart page →

2,045
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pyjwt@2.7.0-1
no fix listed

Open the chart page →

4,954
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pyjwt@2.3.0-1ubuntu0.2
no fix listed

Open the chart page →

74,963
juicefs-csi-driverwener0.33.01 of 5See more

juicefs-csi-driver wener 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
pyjwt@2.6.0-1+deb12u1
no fix listed

Open the chart page →

9,591
juicefs-csi-driverwenerme0.33.01 of 5See more

juicefs-csi-driver wenerme 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
pyjwt@2.6.0-1+deb12u1
no fix listed

Open the chart page →

9,591
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-102272.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pyjwt@2.3.0-1ubuntu0.3
pyjwt@2.13.0
no fix listed
2.14.0

Open the chart page →

8,586

Container images carrying it

137 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
pyjwt@2.13.0
2.14.0
1
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
pyjwt@2.13.0
2.14.0
1
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
pyjwt@2.13.0
2.14.0
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
pyjwt@2.7.0-1
no fix listed
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
pyjwt@2.7.0-1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
pyjwt@2.13.0
2.14.0
1
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
pyjwt@2.13.0
2.14.0
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
pyjwt@2.13.0
2.14.0
1
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
pyjwt@2.13.0
2.14.0
1
ghcr.io/observal/observal-api:1.13.1153b8b893232
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-server:latestce1132261523
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.13.0
no fix listed
2.14.0
1
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.13.0
no fix listed
2.14.0
1
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.13.0
no fix listed
2.14.0
1
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
pyjwt@2.13.0
2.14.0
1
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.13.0
no fix listed
2.14.0
1
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
pyjwt@2.13.0
2.14.0
1
ghcr.io/open-telemetry/demo:3.1.0-mcp81db69cdd0b6
pyjwt@2.13.0
2.14.0
1
ghcr.io/open-telemetry/demo:3.1.0-agentd0f4ae0b32a8
pyjwt@2.13.0
2.14.0
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
pyjwt@2.13.0
2.14.0
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
pyjwt@2.13.0
2.14.0
1
ghcr.io/securo-finance/securo-backend:0.16.2b1cd83ff7828
pyjwt@2.13.0
2.14.0
1
ghcr.io/unique-ag/ai/search-proxy:2026.40.02bd74586650d
pyjwt@2.13.0
2.14.0
1
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest573542399fe4
pyjwt@2.13.0
2.14.0
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
pyjwt@2.13.0
2.14.0
1
quay.io/stackgres/operator:1.19.282f33ab3fb1e
pyjwt@2.13.0
2.14.0
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.