StackRadar

CVE-2026-102274

Medium

Advisory

Published 28 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.004
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
229
of 17,957 indexed, latest versions
Container images
227
deployed by those charts
Fix available
1 of 2
affected packages

PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set

Carried by container images the latest versions of 229 of 17,957 indexed charts deploy, on 227 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi2.9.0, 2.10.1, 2.11.0, 2.12.0+2 more2.14.0197
pyjwtdeb1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+6 moreno fix listed39
OSV records
DEBIAN-CVE-2026-102274GHSA-w6j9-cwv2-h6wqUBUNTU-CVE-2026-102274

Charts affected

229 by stars
ChartLatestAffected imagesRadar Score
linkdingrubxkubeVerified publisher1.2.41 of 1See more

linkding rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.47.0e35cb50e0581
pyjwt@2.13.0
2.14.0

Open the chart page →

2,334
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
pyjwt@2.6.0-1+deb12u1
no fix listed

Open the chart page →

32,941
runwhen-localrunwhen-contribVerified publisher0.7.01 of 3See more

runwhen-local runwhen-contrib 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
pyjwt@2.13.0
2.14.0

Open the chart page →

3,580
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
pyjwt@2.3.0-1ubuntu0.3
no fix listed

Open the chart page →

8,074
pgadminsb-helm-charts0.3.01 of 1See more

pgadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.13561c1f8f99f2
pyjwt@2.9.0
2.14.0

Open the chart page →

1,857
seafileschmitzis13.0.131 of 4See more

seafile schmitzis 13.0.13

1 of the 4 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
schmitzis/monorepo:seafile-13.0-latestf7e51ba2fb07
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.10.1
no fix listed
2.14.0

Open the chart page →

43,887
uptime-kumaschoenwald1.0.101 of 1See more

uptime-kuma schoenwald 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
pyjwt@2.6.0-1+deb12u1
no fix listed

Open the chart page →

32,738
seafileseafileVerified publisher0.12.11 of 1See more

seafile seafile 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
pyjwt@2.3.0-1ubuntu0.2
no fix listed

Open the chart page →

78,638
search-proxysearch-proxy2026.40.01 of 1See more

search-proxy search-proxy 2026.40.0

1 of the 1 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
ghcr.io/unique-ag/ai/search-proxy:2026.40.02bd74586650d
pyjwt@2.13.0
2.14.0

Open the chart page →

1,620
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pyjwt@2.12.0
2.14.0

Open the chart page →

5,657
backendsignalen4.25.01 of 4See more

backend signalen 4.25.0

1 of the 4 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
signalen/backend:2.50.1826bb090bc4e4
pyjwt@2.13.0
2.14.0

Open the chart page →

11,542
home-assistantsmall-hack2.1.01 of 1See more

home-assistant small-hack 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.3.10e091dfce306
pyjwt@2.10.1
2.14.0

Open the chart page →

4,396
smtpsmtpVerified publisher1.3.31 of 1See more

smtp smtp 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
pyjwt@2.10.1
2.14.0

Open the chart page →

1,705
srebotsrebot0.14.01 of 2See more

srebot srebot 0.14.0

1 of the 2 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
pyjwt@2.11.0
2.14.0

Open the chart page →

1,687
servicexssl-hep1.8.61 of 16See more

servicex ssl-hep 1.8.6

1 of the 16 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
sslhep/servicex_app:v1.8.6c935e123030d
pyjwt@2.13.0
2.14.0

Open the chart page →

57,809
artifactory-cleanupsubshellVerified publisher1.0.11 of 1See more

artifactory-cleanup subshell 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
devopshq/artifactory-cleanup:1.0.1830e093bffa91
pyjwt@2.10.1
2.14.0

Open the chart page →

2,779
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
pyjwt@2.9.0
2.14.0

Open the chart page →

4,782
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
pyjwt@2.12.1
2.14.0

Open the chart page →

3,446
the0the0Verified publisher0.9.101 of 9See more

the0 the0 0.9.10

1 of the 9 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.9e301fbb8fae0
pyjwt@2.7.0-1ubuntu0.2
no fix listed

Open the chart page →

5,769
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
pyjwt@2.7.0-1
no fix listed

Open the chart page →

46,735
uptime-platformuptime-platformVerified publisher0.1.31 of 3See more

uptime-platform uptime-platform 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
sashastudent/uptime-platform:latest37a82b4e598e
pyjwt@2.13.0
2.14.0

Open the chart page →

784
vaultwardenvaultwarden-helmVerified publisher1.2.71 of 2See more

vaultwarden vaultwarden-helm 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:18.4-system-trixie42708a75345b
pyjwt@2.13.0
2.14.0

Open the chart page →

2,045
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
2.14.0

Open the chart page →

5,256
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pyjwt@2.7.0-1
no fix listed

Open the chart page →

4,954
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pyjwt@2.3.0-1ubuntu0.2
no fix listed

Open the chart page →

74,963
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
pyjwt@2.10.1
2.14.0

Open the chart page →

5,967
juicefs-csi-driverwener0.33.01 of 5See more

juicefs-csi-driver wener 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
pyjwt@2.6.0-1+deb12u1
no fix listed

Open the chart page →

9,591
juicefs-csi-driverwenerme0.33.01 of 5See more

juicefs-csi-driver wenerme 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
pyjwt@2.6.0-1+deb12u1
no fix listed

Open the chart page →

9,591
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-102274.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pyjwt@2.3.0-1ubuntu0.3
pyjwt@2.13.0
no fix listed
2.14.0

Open the chart page →

8,586

Container images carrying it

227 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ckan/ckan-base:2.12.087ecf3f27ad6
pyjwt@2.13.0
2.14.0
1
dagster/dagster-cloud-agent:1.13.24e29285673c2c
pyjwt@2.13.0
2.14.0
1
datamate/seafile-professional:11.0.202dd66b722464
pyjwt@2.3.0-1ubuntu0.2
no fix listed
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
pyjwt@2.9.0
2.14.0
1
decisionrules/ai-engine:latest557dea1373aa
pyjwt@2.13.0
2.14.0
1
defectdojo/defectdojo-django:3.3.3006516f0f62086
pyjwt@2.13.0
2.14.0
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
pyjwt@2.10.1
2.14.0
1
dpage/pgadmin4:9.11.050700ac17936
pyjwt@2.10.1
2.14.0
1
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
2.14.0
1
dpage/pgadmin4:8.13561c1f8f99f2
pyjwt@2.9.0
2.14.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
pyjwt@1.7.1-2ubuntu2.1
pyjwt@2.9.0
no fix listed
2.14.0
1
flanksource/batch-runner:v1.0.44689687a7cf95
pyjwt@2.10.1
2.14.0
1
frankescobar/allure-docker-service:2.35.14154286c0209
pyjwt@2.10.1
2.14.0
1
frankescobar/allure-docker-service:latestdc171ec796d5
pyjwt@2.13.0
2.14.0
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pyjwt@2.10.1
2.14.0
1
gluufederation/cloudtools:4.5.17-1fe944d2e5d0f
pyjwt@2.13.0
2.14.0
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
pyjwt@2.10.1
2.14.0
1
grafana/oncall:v1.16.5499851658393
pyjwt@2.10.1
2.14.0
1
hayk96/alerta-web:9.0.486377705e9e3
pyjwt@2.10.1
2.14.0
1
healthchecks/healthchecks:latestaa08a61b0dcf
pyjwt@2.13.0
2.14.0
1
heartexlabs/label-studio:latestaa461572e8f9
pyjwt@2.10.1
2.14.0
1
helmforge/fastmcp-server:0.2.061f759a1421f
pyjwt@2.12.1
2.14.0
1
helmforge/fastmcp-server:0.11.2fcb7017327d6
pyjwt@2.12.1
2.14.0
1
homeassistant/home-assistant:2026.75a531753cea9
pyjwt@2.12.1
2.14.0
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
pyjwt@2.12.1
2.14.0
1
inventree/inventree:1.5.6b61e6a7534bf
pyjwt@2.13.0
2.14.0
1
jertel/elastalert2:2.31.03cbf63f9b7dc
pyjwt@2.13.0
2.14.0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
pyjwt@2.12.1
2.14.0
1
langflowai/langflow:1.12.334055a07d446
pyjwt@2.13.0
2.14.0
1
langgenius/dify-api:1.16.1dcefa5f7c47c
pyjwt@2.13.0
2.14.0
1
linuxserver/healthchecks:4.4.2026092108a37bd6dcf2
pyjwt@2.13.0
2.14.0
1
linuxserver/medusa:v1.0.26-ls29002137158996f
pyjwt@2.10.1
2.14.0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pyjwt@2.12.0
2.14.0
1
loeken/home-assistant:2026.5.14ce6abc553b3
pyjwt@2.12.1
2.14.0
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
pyjwt@2.6.0-1
no fix listed
1
louislam/uptime-kuma:2.0.24c364ef96aad
pyjwt@2.6.0-1
no fix listed
1
louislam/uptime-kuma:2.4.091e963bfda56
pyjwt@2.6.0-1+deb12u1
no fix listed
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
pyjwt@2.6.0-1
no fix listed
1
makeplane/backend-commercial:v3.3.0f587597c46b5
pyjwt@2.13.0
2.14.0
1
makeplane/plane-mcp-server:v0.3.071b7252adef0
pyjwt@2.13.0
2.14.0
1
mathesar/mathesar:0.12.0091757cb01fe
pyjwt@2.13.0
2.14.0
1
mawad98/backstage-pyactions:demo99422c56a274
pyjwt@2.12.1
2.14.0
1
memgraph/mcp-memgraph:0.1.13ecdf7faea3f7
pyjwt@2.12.1
2.14.0
1
mindsdb/mindsdb:latest163011c09299
pyjwt@2.12.0
2.14.0
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
pyjwt@2.10.1
2.14.0
1
mohankrishna999/k8s-ai-agent:3.1.27f980f8c650c
pyjwt@2.13.0
2.14.0
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
pyjwt@2.12.1
2.14.0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
pyjwt@2.12.1
2.14.0
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
pyjwt@2.13.0
2.14.0
1
onyxdotapp/onyx-backend:latest60e83a098ae4
pyjwt@2.13.0
2.14.0
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.