StackRadar

CVE-2026-103001

Medium

Advisory

Published 30 Sept 2026In the index since 1 Oct 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
119
of 17,966 indexed, latest versions
Container images
126
deployed by those charts
Fix available
None
affected package

PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse

Carried by container images the latest versions of 119 of 17,966 indexed charts deploy, on 126 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi2.11.0, 2.12.0, 2.12.1, 2.13.0no fix listed126
OSV records
GHSA-gvp8-978c-rx2q

Charts affected

119 by stars
ChartLatestAffected imagesRadar Score
akeyless-gatewayakeyless-services-helmVerified publisher3.6.01 of 2See more

akeyless-gateway akeyless-services-helm 3.6.0

1 of the 2 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
akeyless/gateway:5.4.0d4768a9b089c
pyjwt@2.13.0
no fix listed

Open the chart page →

1,606
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest573542399fe4
pyjwt@2.13.0
no fix listed

Open the chart page →

7,390
litellmalareira0.3.01 of 1See more

litellm alareira 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm:main-stable32cfd7a427f6
pyjwt@2.13.0
no fix listed

Open the chart page →

310
allure-docker-helm-chartallure-service-chartVerified publisher0.1.01 of 2See more

allure-docker-helm-chart allure-service-chart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:latestdc171ec796d5
pyjwt@2.13.0
no fix listed

Open the chart page →

4,099
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
pyjwt@2.13.0
no fix listed

Open the chart page →

6,557
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
pyjwt@2.13.0
no fix listed

Open the chart page →

8,115
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
pyjwt@2.11.0
no fix listed

Open the chart page →

6,151
argonix-apiargonix0.5.61 of 4See more

argonix-api argonix 0.5.6

1 of the 4 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:0.5.6dd18f26c9673
pyjwt@2.13.0
no fix listed

Open the chart page →

5,490
aias-servicesarlas-stackVerified publisher28.9.04 of 5See more

aias-services arlas-stack 28.9.0

4 of the 5 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
gisaia/agate:0.19.0c191afa61caf
pyjwt@2.13.0
no fix listed
gisaia/airs:0.19.08b88432c8d1f
pyjwt@2.13.0
no fix listed
gisaia/aproc-service:0.19.086e69fdc9d9e
pyjwt@2.13.0
no fix listed
gisaia/fam:0.19.0ff9526c6276c
pyjwt@2.13.0
no fix listed

Open the chart page →

565
arlas-aiasarlas-stackVerified publisher28.9.04 of 22See more

arlas-aias arlas-stack 28.9.0

4 of the 22 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
gisaia/agate:0.19.0c191afa61caf
pyjwt@2.13.0
no fix listed
gisaia/airs:0.19.08b88432c8d1f
pyjwt@2.13.0
no fix listed
gisaia/aproc-service:0.19.086e69fdc9d9e
pyjwt@2.13.0
no fix listed
gisaia/fam:0.19.0ff9526c6276c
pyjwt@2.13.0
no fix listed

Open the chart page →

42,910
backstage-pyactionsbackstage-pyactionsVerified publisher0.1.01 of 1See more

backstage-pyactions backstage-pyactions 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
mawad98/backstage-pyactions:demo99422c56a274
pyjwt@2.12.1
no fix listed

Open the chart page →

3,149
mealiebdclark-helm-chartsVerified publisher0.1.151 of 1See more

mealie bdclark-helm-charts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
pyjwt@2.13.0
no fix listed

Open the chart page →

4,760
opencvecfi20170.1.21 of 7See more

opencve cfi2017 0.1.2

1 of the 7 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
pyjwt@2.13.0
no fix listed

Open the chart page →

16,932
kitchenowlchart-kitchenowl0.1.131 of 2See more

kitchenowl chart-kitchenowl 0.1.13

1 of the 2 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.104a7ed693531b
pyjwt@2.13.0
no fix listed

Open the chart page →

2,983
paperless-ngxcharts-derwitt-devVerified publisher2.1.51 of 1See more

paperless-ngx charts-derwitt-dev 2.1.5

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.2.15fa76604a81d
pyjwt@2.13.0
no fix listed

Open the chart page →

4,533
timetaggerchristianhuthVerified publisher2.2.01 of 1See more

timetagger christianhuth 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
pyjwt@2.11.0
no fix listed

Open the chart page →

2,258
galaxycloudve6.8.81 of 3See more

galaxy cloudve 6.8.8

1 of the 3 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pyjwt@2.12.1
no fix listed

Open the chart page →

6,130
authentikcluster-deploy0.2.01 of 1See more

authentik cluster-deploy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
pyjwt@2.13.0
no fix listed

Open the chart page →

3,016
decisionrules-ocpdecisionrules-ocpVerified publisher0.1.01 of 4See more

decisionrules-ocp decisionrules-ocp 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
decisionrules/ai-engine:latest557dea1373aa
pyjwt@2.13.0
no fix listed

Open the chart page →

2,136
healthchecksdoubanVerified publisher1.0.101 of 2See more

healthchecks douban 1.0.10

1 of the 2 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
healthchecks/healthchecks:latestaa08a61b0dcf
pyjwt@2.13.0
no fix listed

Open the chart page →

2,116
home-assistantegebackVerified publisher2.0.351 of 1See more

home-assistant egeback 2.0.35

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
pyjwt@2.13.0
no fix listed

Open the chart page →

2,617
fluxcd-helm-upgraderfluxcd-helm-upgraderVerified publisher0.7.71 of 1See more

fluxcd-helm-upgrader fluxcd-helm-upgrader 0.7.7

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
pyjwt@2.12.1
no fix listed

Open the chart page →

2,627
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
pyjwt@2.13.0
no fix listed

Open the chart page →

4,105
flyte-devboxflyte0.1.01 of 14See more

flyte-devbox flyte 0.1.0

1 of the 14 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
pyjwt@2.13.0
no fix listed

Open the chart page →

8,866
forgejoforgejo-captnbp-helm1.2.61 of 2See more

forgejo forgejo-captnbp-helm 1.2.6

1 of the 2 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:18.4-system-trixie42708a75345b
pyjwt@2.13.0
no fix listed

Open the chart page →

2,175
geomapfishgeomapfish0.8.01 of 3See more

geomapfish geomapfish 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
pyjwt@2.13.0
no fix listed

Open the chart page →

7,146
guacamoleguacamole1.0.01 of 4See more

guacamole guacamole 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:18899d3ed526b6
pyjwt@2.13.0
no fix listed

Open the chart page →

4,474
rag-apihajowielandVerified publisher1.0.01 of 1See more

rag-api hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latest6f2ea2aae300
pyjwt@2.13.0
no fix listed

Open the chart page →

1,511
helixhelix1.4.31 of 2See more

helix helix 1.4.3

1 of the 2 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
pyjwt@2.12.1
no fix listed

Open the chart page →

6,241
chiefonboardinghelmforgeVerified publisher1.1.151 of 3See more

chiefonboarding helmforge 1.1.15

1 of the 3 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
pyjwt@2.13.0
no fix listed

Open the chart page →

7,786
ckanhelmforgeVerified publisher1.3.91 of 6See more

ckan helmforge 1.3.9

1 of the 6 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ckan/ckan-base:2.12.087ecf3f27ad6
pyjwt@2.13.0
no fix listed

Open the chart page →

10,326
fastmcp-serverhelmforgeVerified publisher1.7.41 of 1See more

fastmcp-server helmforge 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.11.2fcb7017327d6
pyjwt@2.12.1
no fix listed

Open the chart page →

3,772
hermes-agenthelmforgeVerified publisher1.0.11 of 1See more

hermes-agent helmforge 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.9.24fca358f12efd
pyjwt@2.13.0
no fix listed

Open the chart page →

6,235
jupyterhubhelmforgeVerified publisher1.0.61 of 3See more

jupyterhub helmforge 1.0.6

1 of the 3 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
pyjwt@2.12.1
no fix listed

Open the chart page →

6,013
langflowhelmforgeVerified publisher2.0.21 of 1See more

langflow helmforge 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
langflowai/langflow:1.12.334055a07d446
pyjwt@2.13.0
no fix listed

Open the chart page →

318
mcp-serverhelmforgeVerified publisher1.0.01 of 1See more

mcp-server helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.2.061f759a1421f
pyjwt@2.12.1
no fix listed

Open the chart page →

3,940
netboxhelmforgeVerified publisher2.0.21 of 4See more

netbox helmforge 2.0.2

1 of the 4 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
pyjwt@2.12.1
no fix listed

Open the chart page →

4,349
paperlesshpVerified publisher0.1.21 of 5See more

paperless hp 0.1.2

1 of the 5 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
pyjwt@2.13.0
no fix listed

Open the chart page →

30,498
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
pyjwt@2.13.0
no fix listed

Open the chart page →

2,612
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
pyjwt@2.12.1
no fix listed

Open the chart page →

19,848
inventreeinventreeOfficialVerified publisher0.4.301 of 2See more

inventree inventree 0.4.30

1 of the 2 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
inventree/inventree:1.5.6b61e6a7534bf
pyjwt@2.13.0
no fix listed

Open the chart page →

5,820
k8s-ai-srek8s-ai-sreVerified publisher3.1.21 of 1See more

k8s-ai-sre k8s-ai-sre 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
mohankrishna999/k8s-ai-agent:3.1.27f980f8c650c
pyjwt@2.13.0
no fix listed

Open the chart page →

588
jupyterhub-chartk8s-jupyterhub0.1.01 of 1See more

jupyterhub-chart k8s-jupyterhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
truebyteinnovationllp/jupyterhub-k8s:5.5.06bf978b96279
pyjwt@2.13.0
no fix listed

Open the chart page →

1,803
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
pyjwt@2.11.0
no fix listed

Open the chart page →

5,138
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
pyjwt@2.12.1
no fix listed

Open the chart page →

7,907
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
pyjwt@2.12.0
no fix listed

Open the chart page →

10,835
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
pyjwt@2.12.1
no fix listed

Open the chart page →

2,902
plane-mcp-servermakeplaneVerified publisher1.0.01 of 2See more

plane-mcp-server makeplane 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
makeplane/plane-mcp-server:v0.3.071b7252adef0
pyjwt@2.13.0
no fix listed

Open the chart page →

3,176
mcp-homeassistantmcp-helmVerified publisher0.2.41 of 1See more

mcp-homeassistant mcp-helm 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
voska/hass-mcp:latest7142a431e2c5
pyjwt@2.13.0
no fix listed

Open the chart page →

11,372
memgraph-mcpmemgraphVerified publisher1.0.01 of 1See more

memgraph-mcp memgraph 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
memgraph/mcp-memgraph:0.1.13ecdf7faea3f7
pyjwt@2.12.1
no fix listed

Open the chart page →

2,043

Container images carrying it

126 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
pyjwt@2.13.0
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-mcp81db69cdd0b6
pyjwt@2.13.0
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-agentd0f4ae0b32a8
pyjwt@2.13.0
no fix listed
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
pyjwt@2.13.0
no fix listed
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
pyjwt@2.13.0
no fix listed
1
ghcr.io/securo-finance/securo-backend:0.16.2b1cd83ff7828
pyjwt@2.13.0
no fix listed
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
pyjwt@2.11.0
no fix listed
1
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
pyjwt@2.12.1
no fix listed
1
ghcr.io/unique-ag/ai/search-proxy:2026.40.02bd74586650d
pyjwt@2.13.0
no fix listed
1
ghcr.io/vinny1892/octantis:latest45459c0910fc
pyjwt@2.12.1
no fix listed
1
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest573542399fe4
pyjwt@2.13.0
no fix listed
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pyjwt@2.12.1
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
pyjwt@2.13.0
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
pyjwt@2.12.1
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
pyjwt@2.12.1
no fix listed
1
quay.io/stackgres/operator:1.19.282f33ab3fb1e
pyjwt@2.13.0
no fix listed
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.