StackRadar

CVE-2026-102996

High

Advisory

Published 1 Oct 2026In the index since 2 Oct 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,985 indexed, latest versions
Container images
21
deployed by those charts
Fix available
1 of 1
affected package

pypdf: Possible large memory usage when parsing font data

Carried by container images the latest versions of 20 of 17,985 indexed charts deploy, on 21 images.

Affected packageAffected versionsFixed inImages
pypdfpypi5.0.1, 5.1.0, 5.3.0, 5.4.0+9 more6.18.121
OSV records
GHSA-g9cg-prrw-2r8q
Also known as
PYSEC-2026-4155

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
datahubdatahubVerified publisher1.1.61 of 4See more

datahub datahub 1.1.6

1 of the 4 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
acryldata/datahub-actions:v1.7.0.1c5fd70130157
pypdf@6.16.2
6.18.1

Open the chart page →

1,374
difydify-helmVerified publisher0.38.02 of 11See more

dify dify-helm 0.38.0

2 of the 11 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
pypdf@6.14.2
6.18.1
langgenius/dify-api:1.16.1dcefa5f7c47c
pypdf@6.14.2
6.18.1

Open the chart page →

71,544
litellm-helmlitellm1.103.21 of 2See more

litellm-helm litellm 1.103.2

1 of the 2 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm:1.103.2f63fb81b831b
pypdf@6.16.2
6.18.1

Open the chart page →

5,656
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
pypdf@6.4.2
6.18.1

Open the chart page →

5,308
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
pretix/standalone:2026.7.05df3b7aa852e
pypdf@6.5.0
6.18.1

Open the chart page →

11,525
litellmalareira0.3.01 of 1See more

litellm alareira 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm:main-stable32cfd7a427f6
pypdf@6.16.2
6.18.1

Open the chart page →

442
argonix-apiargonix0.5.61 of 4See more

argonix-api argonix 0.5.6

1 of the 4 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:0.5.6dd18f26c9673
pypdf@6.14.2
6.18.1

Open the chart page →

5,637
calibre-web-automatedcalibre-web-automated1.0.01 of 1See more

calibre-web-automated calibre-web-automated 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
crocodilestick/calibre-web-automated:v4.0.6c31a738b6d5e
pypdf@6.6.2
6.18.1

Open the chart page →

7,112
calibre-webcharts-derwitt-devVerified publisher1.1.31 of 1See more

calibre-web charts-derwitt-dev 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/calibre-web:1.1.2953aa0935251
pypdf@6.10.2
6.18.1

Open the chart page →

5,456
csghubcsghubVerified publisher2.5.01 of 34See more

csghub csghub 2.5.0

1 of the 34 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6.5-241cba9c366f1
pypdf@5.1.0
6.18.1

Open the chart page →

53,977
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
pypdf@5.3.0
6.18.1

Open the chart page →

55,895
rag-apihajowielandVerified publisher1.0.01 of 1See more

rag-api hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latest6f2ea2aae300
pypdf@6.14.2
6.18.1

Open the chart page →

1,658
inventreeinventreeOfficialVerified publisher0.4.301 of 2See more

inventree inventree 0.4.30

1 of the 2 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
inventree/inventree:1.5.6b61e6a7534bf
pypdf@6.15.0
6.18.1

Open the chart page →

5,994
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pypdf@5.4.0
6.18.1

Open the chart page →

9,405
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
onyxdotapp/onyx-backend:latest60e83a098ae4
pypdf@6.15.0
6.18.1

Open the chart page →

7,617
opds-shelfopds-shelfVerified publisher0.4.01 of 3See more

opds-shelf opds-shelf 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:latest0767226fcf20
pypdf@6.10.2
6.18.1

Open the chart page →

5,191
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
pypdf@6.10.2
6.18.1

Open the chart page →

8,781
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pypdf@6.9.0
6.18.1

Open the chart page →

5,973
backendsignalen4.25.01 of 4See more

backend signalen 4.25.0

1 of the 4 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
signalen/backend:2.50.1826bb090bc4e4
pypdf@6.18.0
6.18.1

Open the chart page →

11,868
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-102996.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
pypdf@5.0.1
6.18.1

Open the chart page →

8,620

Container images carrying it

21 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
acryldata/datahub-actions:v1.7.0.1c5fd70130157
pypdf@6.16.2
6.18.1
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pypdf@5.4.0
6.18.1
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
pypdf@6.10.2
6.18.1
1
crocodilestick/calibre-web-automated:v4.0.6c31a738b6d5e
pypdf@6.6.2
6.18.1
1
inventree/inventree:1.5.6b61e6a7534bf
pypdf@6.15.0
6.18.1
1
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
pypdf@6.14.2
6.18.1
1
langgenius/dify-api:1.0.0066035f93856
pypdf@5.3.0
6.18.1
1
langgenius/dify-api:1.16.1dcefa5f7c47c
pypdf@6.14.2
6.18.1
1
linuxserver/calibre-web:0.6.24241009026e6f
pypdf@5.0.1
6.18.1
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pypdf@6.9.0
6.18.1
1
onyxdotapp/onyx-backend:latest60e83a098ae4
pypdf@6.15.0
6.18.1
1
opencsghq/agenticflow:ee-v0.6.5-241cba9c366f1
pypdf@5.1.0
6.18.1
1
pretix/standalone:2026.7.05df3b7aa852e
pypdf@6.5.0
6.18.1
1
signalen/backend:2.50.1826bb090bc4e4
pypdf@6.18.0
6.18.1
1
ghcr.io/argonix-io/argonix-api:0.5.6dd18f26c9673
pypdf@6.14.2
6.18.1
1
ghcr.io/berriai/litellm:1.102.0:main-stable32cfd7a427f6
pypdf@6.16.2
6.18.1
1
ghcr.io/berriai/litellm:1.103.2f63fb81b831b
pypdf@6.16.2
6.18.1
1
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latest6f2ea2aae300
pypdf@6.14.2
6.18.1
1
ghcr.io/linuxserver/calibre-web:latest0767226fcf20
pypdf@6.10.2
6.18.1
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
pypdf@6.4.2
6.18.1
1
ghcr.io/wittdennis/calibre-web:1.1.2953aa0935251
pypdf@6.10.2
6.18.1
1

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.