StackRadar

CVE-2026-102930

High

Advisory

Published 18 Sept 2026In the index since 1 Oct 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
140
of 18,026 indexed, latest versions
Container images
175
deployed by those charts
Fix available
1 of 2
affected packages

virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use

Carried by container images the latest versions of 140 of 18,026 indexed charts deploy, on 175 images.

Affected packageAffected versionsFixed inImages
virtualenvpypi1.11.4, 15.1.0, 16.3.0, 16.6.0+58 more21.7.12175
python-virtualenvdeb1.11.4-1ubuntu1, 20.0.17-1ubuntu0.3, 20.17.1+ds-1, 20.25.0+ds-2+1 moreno fix listed10
OSV records
DEBIAN-CVE-2026-102930GHSA-94p9-xgh2-xp45UBUNTU-CVE-2026-102930
Also known as
PYSEC-2026-4011

Charts affected

140 by stars
ChartLatestAffected imagesRadar Score
log-servicekrateo1.0.01 of 1See more

log-service krateo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/log-service:1.0.0b431a8154be0
virtualenv@20.15.1
21.7.12

Open the chart page →

5,570
notification-servicekrateo1.1.61 of 1See more

notification-service krateo 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/notification-service:1.1.6f9eeac1d7e47
virtualenv@20.16.6
21.7.12

Open the chart page →

5,300
pipeline-servicekrateo1.1.21 of 1See more

pipeline-service krateo 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/pipeline-service:1.1.25e6ad7395921
virtualenv@20.17.1
21.7.12

Open the chart page →

4,669
provider-servicekrateo1.0.81 of 1See more

provider-service krateo 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/provider-service:1.0.8014ed41cb6e5
virtualenv@20.16.6
21.7.12

Open the chart page →

5,140
secret-servicekrateo1.1.41 of 1See more

secret-service krateo 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/secret-service:1.1.4292bd05fb781
virtualenv@20.16.6
21.7.12

Open the chart page →

5,127
service-deploymentkrateo0.1.61 of 1See more

service-deployment krateo 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/service-deployment:0.1.541fb833f36ee
virtualenv@20.17.1
21.7.12

Open the chart page →

5,004
template-servicekrateo1.2.131 of 1See more

template-service krateo 1.2.13

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/template-service:1.2.139f82e7cb2348
virtualenv@20.23.1
21.7.12

Open the chart page →

6,526
terminal-clientkrateo0.1.31 of 1See more

terminal-client krateo 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/terminal-client:0.1.36c7c965e739c
virtualenv@20.26.3
21.7.12

Open the chart page →

7,302
terminal-serverkrateo0.1.61 of 1See more

terminal-server krateo 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/terminal-server:0.1.3f5fd8ba6fea3
virtualenv@20.26.3
21.7.12

Open the chart page →

7,241
lnbitskronkltdVerified publisher0.1.01 of 1See more

lnbits kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
lnbitsdocker/lnbits-legend:latest26fae6327477
virtualenv@20.25.0
21.7.12

Open the chart page →

2,008
kube-janitorkube-janitor0.3.31 of 1See more

kube-janitor kube-janitor 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
hjacobs/kube-janitor:23.7.0fbb303ed463c
virtualenv@20.23.1
21.7.12

Open the chart page →

4,643
forkliftkubevirt-forkliftVerified publisher0.3.01 of 2See more

forklift kubevirt-forklift 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
quay.io/kubev2v/forklift-operator:release-2.1200312252b07e
virtualenv@21.7.0
21.7.12

Open the chart page →

1,755
large-systems-djangolarge-systems-djangoVerified publisher1.0.01 of 1See more

large-systems-django large-systems-django 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ha33ona/python:test6affdfc644d0
virtualenv@20.17.1
21.7.12

Open the chart page →

5,539
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
virtualenv@21.7.0
21.7.12

Open the chart page →

3,310
lnbitslnbits0.2.11 of 1See more

lnbits lnbits 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
virtualenv@20.21.1
21.7.12

Open the chart page →

2,766
meerschaummeerschaumVerified publisher0.2.01 of 1See more

meerschaum meerschaum 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
bmeares/meerschaum:2.8.48e9c5bacaa82
virtualenv@20.29.1
21.7.12

Open the chart page →

6,454
servicesmicroslacVerified publisher0.4.07 of 8See more

services microslac 0.4.0

7 of the 8 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
microslac/auth:latest5c1eb1f5c64d
virtualenv@20.25.0
21.7.12
microslac/chat:latest417317e4e4e8
virtualenv@20.25.1
21.7.12
microslac/client:latestff6d6c7968dd
virtualenv@20.25.1
21.7.12
microslac/conversations:latest1b24afcd71ff
virtualenv@20.25.0
21.7.12
microslac/realtime:latest7bde633b4158
virtualenv@20.25.1
21.7.12
microslac/teams:latest0f75997fcbe5
virtualenv@20.25.0
21.7.12
microslac/users:latest216ea6832a56
virtualenv@20.25.0
21.7.12

Open the chart page →

34,113
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
virtualenv@20.20.0
21.7.12

Open the chart page →

6,409
headphonesnicholaswildeVerified publisher1.0.11 of 1See more

headphones nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/headphones:version-58edc60443f2d40be460
virtualenv@20.8.1
21.7.12

Open the chart page →

1,859
automx2oleds-helm-chartsVerified publisher1.0.51 of 1See more

automx2 oleds-helm-charts 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
oled01/automx2:2025.1.105d3e398e675
virtualenv@20.31.2
21.7.12

Open the chart page →

5,795
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
openwhisk/kafkaprovider:2.1.063dc3d2a0904
virtualenv@16.7.6
21.7.12

Open the chart page →

106,828
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.05 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

5 of the 40 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
python-virtualenv@20.25.0+ds-2
virtualenv@20.25.0+ds
no fix listed
21.7.12
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
python-virtualenv@20.25.0+ds-2
virtualenv@20.25.0+ds
no fix listed
21.7.12
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
python-virtualenv@20.25.0+ds-2
virtualenv@20.25.0+ds
no fix listed
21.7.12
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
python-virtualenv@20.25.0+ds-2
virtualenv@20.25.0+ds
no fix listed
21.7.12
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
python-virtualenv@20.25.0+ds-2
virtualenv@20.25.0+ds
no fix listed
21.7.12

Open the chart page →

234,921
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
virtualenv@20.35.4
21.7.12

Open the chart page →

5,779
phronetisphronetis0.1.271 of 2See more

phronetis phronetis 0.1.27

1 of the 2 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
knspar/phronetis:0.1.4609499d2dc91a
virtualenv@20.31.2
21.7.12

Open the chart page →

17,646
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
virtualenv@20.24.5
21.7.12

Open the chart page →

13,898
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
virtualenv@20.26.4
21.7.12

Open the chart page →

23,519
kubecostradar-baseVerified publisher1.0.01 of 7See more

kubecost radar-base 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
virtualenv@20.29.2
21.7.12

Open the chart page →

11,115
revwallet-apirevwallet0.7.121 of 1See more

revwallet-api revwallet 0.7.12

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
arthurjguerra18/revwallet:v0.7.12f540af20b307
virtualenv@20.26.3
21.7.12

Open the chart page →

6,383
kube-web-viewrlex0.5.01 of 1See more

kube-web-view rlex 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:23.8.0431f1bf013d0
virtualenv@20.24.3
21.7.12

Open the chart page →

5,295
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
virtualenv@20.27.1
21.7.12

Open the chart page →

10,735
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
virtualenv@20.29.3
21.7.12

Open the chart page →

3,954
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
virtualenv@20.29.3
21.7.12

Open the chart page →

5,860
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
virtualenv@20.25.0
21.7.12

Open the chart page →

11,442
backendsignalen4.25.01 of 4See more

backend signalen 4.25.0

1 of the 4 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
signalen/backend:2.50.1826bb090bc4e4
virtualenv@21.7.10
21.7.12

Open the chart page →

14,069
home-assistantsmall-hack2.1.01 of 1See more

home-assistant small-hack 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.3.10e091dfce306
virtualenv@21.1.0
21.7.12

Open the chart page →

4,850
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
virtualenv@20.21.1
21.7.12

Open the chart page →

6,485
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
virtualenv@20.29.3
21.7.12

Open the chart page →

9,558
downscalersqream-chartsVerified publisher1.0.01 of 1See more

downscaler sqream-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.05d328c003efe
virtualenv@20.19.0
21.7.12

Open the chart page →

1,219
servicexssl-hep1.8.610 of 16See more

servicex ssl-hep 1.8.6

10 of the 16 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
sslhep/servicex_app:v1.8.6c935e123030d
virtualenv@20.39.1
21.7.12
sslhep/servicex_code_gen_atlas_xaod:v1.8.67827e689caa5
virtualenv@20.39.1
21.7.12
sslhep/servicex_code_gen_func_adl_uproot:v1.8.62d6843be2d8d
virtualenv@20.39.1
21.7.12
sslhep/servicex_code_gen_python:v1.8.696805be717ff
virtualenv@20.39.1
21.7.12
sslhep/servicex_code_gen_raw_uproot:v1.8.61494a81a474b
virtualenv@20.39.1
21.7.12
sslhep/servicex_code_gen_topcp:v1.8.6f7faf8c6c3e4
virtualenv@20.39.1
21.7.12
sslhep/servicex-did-finder:v1.8.6e15e68307d33
virtualenv@20.39.1
21.7.12
sslhep/servicex-did-finder-cernopendata:v1.8.623a80e40ab18
virtualenv@20.39.1
21.7.12
sslhep/servicex-did-finder-xrootd:v1.8.69a9fb17458f1
virtualenv@20.39.1
21.7.12
sslhep/x509-secrets:v1.8.634e1c87cea8a
virtualenv@20.39.1
21.7.12

Open the chart page →

61,380
restful-distributed-lock-managerstakaterVerified publisher1.0.41 of 1See more

restful-distributed-lock-manager stakater 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-102930.

Container imageDigestPackageFixed in
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
virtualenv@15.1.0
21.7.12

Open the chart page →

4,566

Container images carrying it

175 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
virtualenv@16.3.0
21.7.12
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
virtualenv@16.7.9
21.7.12
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
virtualenv@16.7.9
21.7.12
1
lnbitsdocker/lnbits-legend:latest26fae6327477
virtualenv@20.25.0
21.7.12
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
virtualenv@20.21.1
21.7.12
1
localstack/localstack:3.19d278167f2b7
virtualenv@20.25.0
21.7.12
1
loeken/home-assistant:2026.5.14ce6abc553b3
virtualenv@21.3.1
21.7.12
1
microslac/auth:latest5c1eb1f5c64d
virtualenv@20.25.0
21.7.12
1
microslac/chat:latest417317e4e4e8
virtualenv@20.25.1
21.7.12
1
microslac/client:latestff6d6c7968dd
virtualenv@20.25.1
21.7.12
1
microslac/conversations:latest1b24afcd71ff
virtualenv@20.25.0
21.7.12
1
microslac/realtime:latest7bde633b4158
virtualenv@20.25.1
21.7.12
1
microslac/teams:latest0f75997fcbe5
virtualenv@20.25.0
21.7.12
1
microslac/users:latest216ea6832a56
virtualenv@20.25.0
21.7.12
1
milesmcc/shynet:v0.13.1ba54f7797a6b
virtualenv@20.21.1
21.7.12
1
milesmcc/shynet:v0.12.0e821e31140f7
virtualenv@20.12.0
21.7.12
1
mshanley80/httpbin2022:latest5b189a70c0fb
virtualenv@20.17.1
21.7.12
1
oled01/automx2:2025.1.105d3e398e675
virtualenv@20.31.2
21.7.12
1
opencsghq/agenticflow:ee-v0.6.5-241cba9c366f1
virtualenv@20.32.0
21.7.12
1
opennode/waldur-mastermind:8.1.24c82b15d9042
virtualenv@21.7.4
21.7.12
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
virtualenv@20.7.2
21.7.12
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
virtualenv@20.7.2
21.7.12
1
openwhisk/kafkaprovider:2.1.063dc3d2a0904
virtualenv@16.7.6
21.7.12
1
pangeo/base-notebook:2024.01.155fbe688a4f80
virtualenv@20.25.0
21.7.12
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
virtualenv@20.24.5
21.7.12
1
pretix/standalone:2026.7.05df3b7aa852e
python-virtualenv@20.31.2+ds-1+deb13u1
virtualenv@20.31.2
no fix listed
21.7.12
1
rdavidoff/twitch-channel-points-miner-v2:1.8.67ae4c5135771
virtualenv@20.24.3
21.7.12
1
redash/redash:25.8.000d813437db5
virtualenv@20.32.0
21.7.12
1
redash/redash:26.3.0c5c9148f5c38
virtualenv@20.29.3
21.7.12
1
redislabs/redisearch:2.4.1433561794c5c8
virtualenv@20.16.3
21.7.12
1
runx1/opta-agent:latest0ca3867d3200
virtualenv@20.14.1
21.7.12
1
signalen/backend:2.50.1826bb090bc4e4
virtualenv@21.7.10
21.7.12
1
sslhep/servicex_app:v1.8.6c935e123030d
virtualenv@20.39.1
21.7.12
1
sslhep/servicex_code_gen_atlas_xaod:v1.8.67827e689caa5
virtualenv@20.39.1
21.7.12
1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.62d6843be2d8d
virtualenv@20.39.1
21.7.12
1
sslhep/servicex_code_gen_python:v1.8.696805be717ff
virtualenv@20.39.1
21.7.12
1
sslhep/servicex_code_gen_raw_uproot:v1.8.61494a81a474b
virtualenv@20.39.1
21.7.12
1
sslhep/servicex_code_gen_topcp:v1.8.6f7faf8c6c3e4
virtualenv@20.39.1
21.7.12
1
sslhep/servicex-did-finder:v1.8.6e15e68307d33
virtualenv@20.39.1
21.7.12
1
sslhep/servicex-did-finder-cernopendata:v1.8.623a80e40ab18
virtualenv@20.39.1
21.7.12
1
sslhep/servicex-did-finder-xrootd:v1.8.69a9fb17458f1
virtualenv@20.39.1
21.7.12
1
sslhep/x509-secrets:v1.8.634e1c87cea8a
virtualenv@20.39.1
21.7.12
1
stackstorm/st2actionrunner:3.888235ba70cad
virtualenv@20.4.0
21.7.12
1
stackstorm/st2api:3.86f56d239d280
virtualenv@20.4.0
21.7.12
1
stackstorm/st2auth:3.833ecfda16608
virtualenv@20.4.0
21.7.12
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
virtualenv@20.4.0
21.7.12
1
stackstorm/st2notifier:3.8f190a6212195
virtualenv@20.4.0
21.7.12
1
stackstorm/st2rulesengine:3.8259503496ff9
virtualenv@20.4.0
21.7.12
1
stackstorm/st2scheduler:3.8b1de2055c362
virtualenv@20.4.0
21.7.12
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
virtualenv@20.4.0
21.7.12
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.