StackRadar

CVE-2026-103001

Medium

Advisory

Published 30 Sept 2026In the index since 1 Oct 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
119
of 17,966 indexed, latest versions
Container images
126
deployed by those charts
Fix available
None
affected package

PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse

Carried by container images the latest versions of 119 of 17,966 indexed charts deploy, on 126 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi2.11.0, 2.12.0, 2.12.1, 2.13.0no fix listed126
OSV records
GHSA-gvp8-978c-rx2q

Charts affected

119 by stars
ChartLatestAffected imagesRadar Score
miot-harnessmicroboxlabs0.8.01 of 1See more

miot-harness microboxlabs 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
pyjwt@2.13.0
no fix listed

Open the chart page →

1,566
parcelapp-mcpobeoneVerified publisher0.1.01 of 1See more

parcelapp-mcp obeone 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
pyjwt@2.13.0
no fix listed

Open the chart page →

1,183
octantisoctantis0.1.01 of 1See more

octantis octantis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/vinny1892/octantis:latest45459c0910fc
pyjwt@2.12.1
no fix listed

Open the chart page →

3,033
paperless-ngxoli-the-devVerified publisher1.1.11 of 1See more

paperless-ngx oli-the-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
pyjwt@2.13.0
no fix listed

Open the chart page →

5,464
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
onyxdotapp/onyx-backend:latest60e83a098ae4
pyjwt@2.13.0
no fix listed

Open the chart page →

7,423
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.018 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

18 of the 40 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-server:latestce1132261523
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
pyjwt@2.13.0
no fix listed
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
pyjwt@2.13.0
no fix listed

Open the chart page →

229,002
prowlerprowler0.1.11 of 1See more

prowler prowler 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
toniblyx/prowler:stablecf1ee9fc5b67
pyjwt@2.13.0
no fix listed

Open the chart page →

1,598
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
pyjwt@2.13.0
no fix listed

Open the chart page →

7,198
linkdingrubxkubeVerified publisher1.2.41 of 1See more

linkding rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.47.0e35cb50e0581
pyjwt@2.13.0
no fix listed

Open the chart page →

2,460
runwhen-localrunwhen-contribVerified publisher0.7.01 of 3See more

runwhen-local runwhen-contrib 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
pyjwt@2.13.0
no fix listed

Open the chart page →

3,709
search-proxysearch-proxy2026.40.01 of 1See more

search-proxy search-proxy 2026.40.0

1 of the 1 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/unique-ag/ai/search-proxy:2026.40.02bd74586650d
pyjwt@2.13.0
no fix listed

Open the chart page →

1,728
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pyjwt@2.12.0
no fix listed

Open the chart page →

5,789
backendsignalen4.25.01 of 4See more

backend signalen 4.25.0

1 of the 4 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
signalen/backend:2.50.1826bb090bc4e4
pyjwt@2.13.0
no fix listed

Open the chart page →

11,735
srebotsrebot0.14.01 of 2See more

srebot srebot 0.14.0

1 of the 2 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
pyjwt@2.11.0
no fix listed

Open the chart page →

1,779
servicexssl-hep1.8.61 of 16See more

servicex ssl-hep 1.8.6

1 of the 16 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
sslhep/servicex_app:v1.8.6c935e123030d
pyjwt@2.13.0
no fix listed

Open the chart page →

59,300
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
pyjwt@2.12.1
no fix listed

Open the chart page →

3,499
uptime-platformuptime-platformVerified publisher0.1.31 of 3See more

uptime-platform uptime-platform 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
sashastudent/uptime-platform:latest37a82b4e598e
pyjwt@2.13.0
no fix listed

Open the chart page →

859
vaultwardenvaultwarden-helmVerified publisher1.2.71 of 2See more

vaultwarden vaultwarden-helm 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:18.4-system-trixie42708a75345b
pyjwt@2.13.0
no fix listed

Open the chart page →

2,175
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-103001.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pyjwt@2.13.0
no fix listed

Open the chart page →

8,734

Container images carrying it

126 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
pyjwt@2.13.0
no fix listed
4
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
pyjwt@2.13.0
no fix listed
3
ghcr.io/home-assistant/home-assistant:2026.9.43e6710a7ab2a
pyjwt@2.13.0
no fix listed
3
ghcr.io/paperless-ngx/paperless-ngx:3.2.15fa76604a81d
pyjwt@2.13.0
no fix listed
3
gisaia/agate:0.19.0c191afa61caf
pyjwt@2.13.0
no fix listed
2
gisaia/airs:0.19.08b88432c8d1f
pyjwt@2.13.0
no fix listed
2
gisaia/aproc-service:0.19.086e69fdc9d9e
pyjwt@2.13.0
no fix listed
2
gisaia/fam:0.19.0ff9526c6276c
pyjwt@2.13.0
no fix listed
2
ilum/api:6.7.3624fd09528c8
pyjwt@2.13.0
no fix listed
2
langflowai/langflow:latest79c02794adeb
pyjwt@2.13.0
no fix listed
2
memgraph/memgraph:3.13.1bd3fe13228f4
pyjwt@2.13.0
no fix listed
2
nousresearch/hermes-agent:v2026.9.24fca358f12efd
pyjwt@2.13.0
no fix listed
2
ghcr.io/cloudnative-pg/postgresql:18.4-system-trixie42708a75345b
pyjwt@2.13.0
no fix listed
2
ghcr.io/home-assistant/home-assistant:2026.9.3:latestd89226851697
pyjwt@2.13.0
no fix listed
2
acryldata/datahub-actions:v1.7.0.1c5fd70130157
pyjwt@2.13.0
no fix listed
1
agentarea/agentarea-api:latest38fcf6657f5f
pyjwt@2.13.0
no fix listed
1
agentarea/agentarea-worker:latest06a5ef356770
pyjwt@2.13.0
no fix listed
1
aibrix/metadata-service:v0.7.063fb81a64377
pyjwt@2.13.0
no fix listed
1
akeyless/base:latest759e4289fae8
pyjwt@2.12.0
no fix listed
1
akeyless/gateway:5.4.0d4768a9b089c
pyjwt@2.13.0
no fix listed
1
baserow/backend:2.3.37c00549b3a6f
pyjwt@2.13.0
no fix listed
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
pyjwt@2.13.0
no fix listed
1
burakince/mlflow:3.16.0ab4b566644b9
pyjwt@2.13.0
no fix listed
1
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
pyjwt@2.13.0
no fix listed
1
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
pyjwt@2.13.0
no fix listed
1
ckan/ckan-base:2.12.087ecf3f27ad6
pyjwt@2.13.0
no fix listed
1
dagster/dagster-cloud-agent:1.13.24e29285673c2c
pyjwt@2.13.0
no fix listed
1
decisionrules/ai-engine:latest557dea1373aa
pyjwt@2.13.0
no fix listed
1
defectdojo/defectdojo-django:3.3.3006516f0f62086
pyjwt@2.13.0
no fix listed
1
frankescobar/allure-docker-service:latestdc171ec796d5
pyjwt@2.13.0
no fix listed
1
gluufederation/cloudtools:4.5.17-1fe944d2e5d0f
pyjwt@2.13.0
no fix listed
1
healthchecks/healthchecks:latestaa08a61b0dcf
pyjwt@2.13.0
no fix listed
1
helmforge/fastmcp-server:0.2.061f759a1421f
pyjwt@2.12.1
no fix listed
1
helmforge/fastmcp-server:0.11.2fcb7017327d6
pyjwt@2.12.1
no fix listed
1
homeassistant/home-assistant:2026.75a531753cea9
pyjwt@2.12.1
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
pyjwt@2.12.1
no fix listed
1
inventree/inventree:1.5.6b61e6a7534bf
pyjwt@2.13.0
no fix listed
1
jertel/elastalert2:2.31.03cbf63f9b7dc
pyjwt@2.13.0
no fix listed
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
pyjwt@2.12.1
no fix listed
1
langflowai/langflow:1.12.334055a07d446
pyjwt@2.13.0
no fix listed
1
langgenius/dify-api:1.16.1dcefa5f7c47c
pyjwt@2.13.0
no fix listed
1
linuxserver/healthchecks:4.4.2026092108a37bd6dcf2
pyjwt@2.13.0
no fix listed
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pyjwt@2.12.0
no fix listed
1
loeken/home-assistant:2026.5.14ce6abc553b3
pyjwt@2.12.1
no fix listed
1
makeplane/backend-commercial:v3.3.0f587597c46b5
pyjwt@2.13.0
no fix listed
1
makeplane/plane-mcp-server:v0.3.071b7252adef0
pyjwt@2.13.0
no fix listed
1
mathesar/mathesar:0.12.0091757cb01fe
pyjwt@2.13.0
no fix listed
1
mawad98/backstage-pyactions:demo99422c56a274
pyjwt@2.12.1
no fix listed
1
memgraph/mcp-memgraph:0.1.13ecdf7faea3f7
pyjwt@2.12.1
no fix listed
1
mindsdb/mindsdb:latest163011c09299
pyjwt@2.12.0
no fix listed
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.