StackRadar

CVE-2026-103001

Medium

Advisory

Published 30 Sept 2026In the index since 1 Oct 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
119
of 17,966 indexed, latest versions
Container images
126
deployed by those charts
Fix available
None
affected package

PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse

Carried by container images the latest versions of 119 of 17,966 indexed charts deploy, on 126 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi2.11.0, 2.12.0, 2.12.1, 2.13.0no fix listed126
OSV records
GHSA-gvp8-978c-rx2q

Charts affected

119 by stars
ChartLatestAffected imagesRadar Score
miot-harnessmicroboxlabs0.8.01 of 1See more

miot-harness microboxlabs 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
pyjwt@2.13.0
no fix listed

Open the chart page →

1,566
parcelapp-mcpobeoneVerified publisher0.1.01 of 1See more

parcelapp-mcp obeone 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
pyjwt@2.13.0
no fix listed

Open the chart page →

1,183
octantisoctantis0.1.01 of 1See more

octantis octantis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/vinny1892/octantis:latest45459c0910fc
pyjwt@2.12.1
no fix listed

Open the chart page →

3,033
paperless-ngxoli-the-devVerified publisher1.1.11 of 1See more

paperless-ngx oli-the-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
pyjwt@2.13.0
no fix listed

Open the chart page →

5,464
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
onyxdotapp/onyx-backend:latest60e83a098ae4
pyjwt@2.13.0
no fix listed

Open the chart page →

7,423
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.018 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

18 of the 40 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-server:latestce1132261523
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
pyjwt@2.13.0
no fix listed

Open the chart page →

229,002
prowlerprowler0.1.11 of 1See more

prowler prowler 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
toniblyx/prowler:stablecf1ee9fc5b67
pyjwt@2.13.0
no fix listed

Open the chart page →

1,598
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
pyjwt@2.13.0
no fix listed

Open the chart page →

7,198
linkdingrubxkubeVerified publisher1.2.41 of 1See more

linkding rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.47.0e35cb50e0581
pyjwt@2.13.0
no fix listed

Open the chart page →

2,460
runwhen-localrunwhen-contribVerified publisher0.7.01 of 3See more

runwhen-local runwhen-contrib 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
pyjwt@2.13.0
no fix listed

Open the chart page →

3,709
search-proxysearch-proxy2026.40.01 of 1See more

search-proxy search-proxy 2026.40.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/unique-ag/ai/search-proxy:2026.40.02bd74586650d
pyjwt@2.13.0
no fix listed

Open the chart page →

1,728
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pyjwt@2.12.0
no fix listed

Open the chart page →

5,789
backendsignalen4.25.01 of 4See more

backend signalen 4.25.0

1 of the 4 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
signalen/backend:2.50.1826bb090bc4e4
pyjwt@2.13.0
no fix listed

Open the chart page →

11,735
srebotsrebot0.14.01 of 2See more

srebot srebot 0.14.0

1 of the 2 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
pyjwt@2.11.0
no fix listed

Open the chart page →

1,779
servicexssl-hep1.8.61 of 16See more

servicex ssl-hep 1.8.6

1 of the 16 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
sslhep/servicex_app:v1.8.6c935e123030d
pyjwt@2.13.0
no fix listed

Open the chart page →

59,300
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
pyjwt@2.12.1
no fix listed

Open the chart page →

3,499
uptime-platformuptime-platformVerified publisher0.1.31 of 3See more

uptime-platform uptime-platform 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
sashastudent/uptime-platform:latest37a82b4e598e
pyjwt@2.13.0
no fix listed

Open the chart page →

859
vaultwardenvaultwarden-helmVerified publisher1.2.71 of 2See more

vaultwarden vaultwarden-helm 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:18.4-system-trixie42708a75345b
pyjwt@2.13.0
no fix listed

Open the chart page →

2,175
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pyjwt@2.13.0
no fix listed

Open the chart page →

8,734

Container images carrying it

126 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
pyjwt@2.13.0
no fix listed
1
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
pyjwt@2.13.0
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-mcp81db69cdd0b6
pyjwt@2.13.0
no fix listed
1
ghcr.io/open-telemetry/demo:3.1.0-agentd0f4ae0b32a8
pyjwt@2.13.0
no fix listed
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
pyjwt@2.13.0
no fix listed
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
pyjwt@2.13.0
no fix listed
1
ghcr.io/securo-finance/securo-backend:0.16.2b1cd83ff7828
pyjwt@2.13.0
no fix listed
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
pyjwt@2.11.0
no fix listed
1
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
pyjwt@2.12.1
no fix listed
1
ghcr.io/unique-ag/ai/search-proxy:2026.40.02bd74586650d
pyjwt@2.13.0
no fix listed
1
ghcr.io/vinny1892/octantis:latest45459c0910fc
pyjwt@2.12.1
no fix listed
1
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest573542399fe4
pyjwt@2.13.0
no fix listed
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pyjwt@2.12.1
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
pyjwt@2.13.0
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
pyjwt@2.12.1
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
pyjwt@2.12.1
no fix listed
1
quay.io/stackgres/operator:1.19.282f33ab3fb1e
pyjwt@2.13.0
no fix listed
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.