StackRadar

CVE-2026-103001

Medium

Advisory

Published 30 Sept 2026In the index since 1 Oct 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
119
of 17,966 indexed, latest versions
Container images
126
deployed by those charts
Fix available
None
affected package

PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse

Carried by container images the latest versions of 119 of 17,966 indexed charts deploy, on 126 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi2.11.0, 2.12.0, 2.12.1, 2.13.0no fix listed126
OSV records
GHSA-gvp8-978c-rx2q

Charts affected

119 by stars
ChartLatestAffected imagesRadar Score
miot-harnessmicroboxlabs0.8.01 of 1See more

miot-harness microboxlabs 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
pyjwt@2.13.0
no fix listed

Open the chart page →

1,566
parcelapp-mcpobeoneVerified publisher0.1.01 of 1See more

parcelapp-mcp obeone 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
pyjwt@2.13.0
no fix listed

Open the chart page →

1,183
octantisoctantis0.1.01 of 1See more

octantis octantis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/vinny1892/octantis:latest45459c0910fc
pyjwt@2.12.1
no fix listed

Open the chart page →

3,033
paperless-ngxoli-the-devVerified publisher1.1.11 of 1See more

paperless-ngx oli-the-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
pyjwt@2.13.0
no fix listed

Open the chart page →

5,464
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
onyxdotapp/onyx-backend:latest60e83a098ae4
pyjwt@2.13.0
no fix listed

Open the chart page →

7,423
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.018 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

18 of the 40 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-server:latestce1132261523
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
pyjwt@2.13.0
no fix listed

Open the chart page →

229,002
prowlerprowler0.1.11 of 1See more

prowler prowler 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
toniblyx/prowler:stablecf1ee9fc5b67
pyjwt@2.13.0
no fix listed

Open the chart page →

1,598
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
pyjwt@2.13.0
no fix listed

Open the chart page →

7,198
linkdingrubxkubeVerified publisher1.2.41 of 1See more

linkding rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.47.0e35cb50e0581
pyjwt@2.13.0
no fix listed

Open the chart page →

2,460
runwhen-localrunwhen-contribVerified publisher0.7.01 of 3See more

runwhen-local runwhen-contrib 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
pyjwt@2.13.0
no fix listed

Open the chart page →

3,709
search-proxysearch-proxy2026.40.01 of 1See more

search-proxy search-proxy 2026.40.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/unique-ag/ai/search-proxy:2026.40.02bd74586650d
pyjwt@2.13.0
no fix listed

Open the chart page →

1,728
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pyjwt@2.12.0
no fix listed

Open the chart page →

5,789
backendsignalen4.25.01 of 4See more

backend signalen 4.25.0

1 of the 4 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
signalen/backend:2.50.1826bb090bc4e4
pyjwt@2.13.0
no fix listed

Open the chart page →

11,735
srebotsrebot0.14.01 of 2See more

srebot srebot 0.14.0

1 of the 2 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
pyjwt@2.11.0
no fix listed

Open the chart page →

1,779
servicexssl-hep1.8.61 of 16See more

servicex ssl-hep 1.8.6

1 of the 16 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
sslhep/servicex_app:v1.8.6c935e123030d
pyjwt@2.13.0
no fix listed

Open the chart page →

59,300
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
pyjwt@2.12.1
no fix listed

Open the chart page →

3,499
uptime-platformuptime-platformVerified publisher0.1.31 of 3See more

uptime-platform uptime-platform 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
sashastudent/uptime-platform:latest37a82b4e598e
pyjwt@2.13.0
no fix listed

Open the chart page →

859
vaultwardenvaultwarden-helmVerified publisher1.2.71 of 2See more

vaultwarden vaultwarden-helm 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:18.4-system-trixie42708a75345b
pyjwt@2.13.0
no fix listed

Open the chart page →

2,175
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pyjwt@2.13.0
no fix listed

Open the chart page →

8,734

Container images carrying it

126 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mohankrishna999/k8s-ai-agent:3.1.27f980f8c650c
pyjwt@2.13.0
no fix listed
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
pyjwt@2.12.1
no fix listed
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
pyjwt@2.12.1
no fix listed
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
pyjwt@2.13.0
no fix listed
1
onyxdotapp/onyx-backend:latest60e83a098ae4
pyjwt@2.13.0
no fix listed
1
opennode/waldur-mastermind:8.1.24c82b15d9042
pyjwt@2.13.0
no fix listed
1
pretix/standalone:2026.7.05df3b7aa852e
pyjwt@2.13.0
no fix listed
1
prowlercloud/prowler-api:5.31.14f252d579be2
pyjwt@2.13.0
no fix listed
1
rtlabsio/clamav-rest:1.0.7be3e45ab4edd
pyjwt@2.13.0
no fix listed
1
sashastudent/uptime-platform:latest37a82b4e598e
pyjwt@2.13.0
no fix listed
1
signalen/backend:2.50.1826bb090bc4e4
pyjwt@2.13.0
no fix listed
1
sissbruecker/linkding:1.47.0e35cb50e0581
pyjwt@2.13.0
no fix listed
1
sslhep/servicex_app:v1.8.6c935e123030d
pyjwt@2.13.0
no fix listed
1
tombursch/kitchenowl-backend:v0.7.104a7ed693531b
pyjwt@2.13.0
no fix listed
1
toniblyx/prowler:stablecf1ee9fc5b67
pyjwt@2.13.0
no fix listed
1
truebyteinnovationllp/jupyterhub-k8s:5.5.06bf978b96279
pyjwt@2.13.0
no fix listed
1
voska/hass-mcp:latest7142a431e2c5
pyjwt@2.13.0
no fix listed
1
weblate/weblate:2026.9.1.2f0be5b122b38
pyjwt@2.13.0
no fix listed
1
wger/server:2.71c5789b93bfe
pyjwt@2.13.0
no fix listed
1
zenmldocker/zenml-server:0.97.0aaa74934d606
pyjwt@2.13.0
no fix listed
1
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pyjwt@2.13.0
no fix listed
1
ghcr.io/abcdesktopio/pyos:4.4.alpine_latest5c43e3d66d2e
pyjwt@2.13.0
no fix listed
1
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
pyjwt@2.11.0
no fix listed
1
ghcr.io/argonix-io/argonix-api:0.5.6dd18f26c9673
pyjwt@2.13.0
no fix listed
1
ghcr.io/berriai/litellm:1.102.0:main-stable32cfd7a427f6
pyjwt@2.13.0
no fix listed
1
ghcr.io/berriai/litellm:1.103.1df15400b5b80
pyjwt@2.13.0
no fix listed
1
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
pyjwt@2.13.0
no fix listed
1
ghcr.io/cloudnative-pg/postgresql:18899d3ed526b6
pyjwt@2.13.0
no fix listed
1
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latest6f2ea2aae300
pyjwt@2.13.0
no fix listed
1
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
pyjwt@2.13.0
no fix listed
1
ghcr.io/getsentry/snuba:26.7.210f8d164109b
pyjwt@2.13.0
no fix listed
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
pyjwt@2.11.0
no fix listed
1
ghcr.io/goauthentik/server:2026.8.3ab9b4e8cc4ab
pyjwt@2.13.0
no fix listed
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
pyjwt@2.13.0
no fix listed
1
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
pyjwt@2.13.0
no fix listed
1
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
pyjwt@2.13.0
no fix listed
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
pyjwt@2.11.0
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
pyjwt@2.13.0
no fix listed
1
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
pyjwt@2.13.0
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
pyjwt@2.13.0
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
pyjwt@2.12.1
no fix listed
1
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
pyjwt@2.13.0
no fix listed
1
ghcr.io/observal/observal-api:1.13.1153b8b893232
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-server:latestce1132261523
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
pyjwt@2.13.0
no fix listed
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.