StackRadar

CVE-2026-104843

Medium

Advisory

Published 5 Oct 2026In the index since 6 Oct 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
15
of 18,035 indexed, latest versions
Container images
12
deployed by those charts
Fix available
2 of 2
affected packages

uv: Path traversal on Windows through wheel extraction

Carried by container images the latest versions of 15 of 18,035 indexed charts deploy, on 12 images.

Affected packageAffected versionsFixed inImages
uvcargo0.12.7, 0.12.8, 0.12.9, 0.12.10+4 more0.12.1811
uvpypi0.12.7, 0.12.8, 0.12.10, 0.12.12+2 more0.12.188
OSV records
GHSA-2cv4-cqwr-gwf7

Charts affected

15 by stars
ChartLatestAffected imagesRadar Score
datahubdatahubVerified publisher1.1.61 of 4See more

datahub datahub 1.1.6

1 of the 4 container images this version deploys carry CVE-2026-104843.

Container imageDigestPackageFixed in
acryldata/datahub-actions:v1.7.0.1c5fd70130157
uv@0.12.9
0.12.18

Open the chart page →

1,486
prefect-serverprefectVerified publisher2026.10.61630151 of 2See more

prefect-server prefect 2026.10.6163015

1 of the 2 container images this version deploys carry CVE-2026-104843.

Container imageDigestPackageFixed in
prefecthq/prefect:3.8.8-python3.1119463f92420b
uv@0.12.10
0.12.18

Open the chart page →

5,969
paperless-ngxpaperless-ngxVerified publisher0.3.231 of 3See more

paperless-ngx paperless-ngx 0.3.23

1 of the 3 container images this version deploys carry CVE-2026-104843.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.2.15fa76604a81d
uv@0.12.16
0.12.18

Open the chart page →

9,020
paperlesszekker6Verified publisher11.10.01 of 1See more

paperless zekker6 11.10.0

1 of the 1 container images this version deploys carry CVE-2026-104843.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.2.15fa76604a81d
uv@0.12.16
0.12.18

Open the chart page →

4,924
music-assistantbdclark-helm-chartsVerified publisher0.4.131 of 1See more

music-assistant bdclark-helm-charts 0.4.13

1 of the 1 container images this version deploys carry CVE-2026-104843.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.10.3885872224fa5
uv@0.12.13
uv@0.12.13
0.12.18
0.12.18

Open the chart page →

4,548
csghubcsghubVerified publisher2.5.01 of 34See more

csghub csghub 2.5.0

1 of the 34 container images this version deploys carry CVE-2026-104843.

Container imageDigestPackageFixed in
opencsghq/csgbot:v0.6.9-ee7d0271e26521
uv@0.12.13
uv@0.12.13
0.12.18
0.12.18

Open the chart page →

59,100
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-104843.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
uv@0.12.10
uv@0.12.10
0.12.18
0.12.18

Open the chart page →

2,695
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-104843.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:main-local7d2fb04baf44
uv@0.12.17
uv@0.12.17
0.12.18
0.12.18

Open the chart page →

56,729
supersethelm-charts-nr1.1.31 of 1See more

superset helm-charts-nr 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-104843.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
uv@0.12.10
uv@0.12.10
0.12.18
0.12.18

Open the chart page →

2,695
archiveboxhelmforgeVerified publisher1.1.131 of 1See more

archivebox helmforge 1.1.13

1 of the 1 container images this version deploys carry CVE-2026-104843.

Container imageDigestPackageFixed in
archivebox/archivebox:0.9.708c21bb233130
uv@0.12.17
0.12.18

Open the chart page →

5,809
chiefonboardinghelmforgeVerified publisher1.1.151 of 3See more

chiefonboarding helmforge 1.1.15

1 of the 3 container images this version deploys carry CVE-2026-104843.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
uv@0.12.12
uv@0.12.12
0.12.18
0.12.18

Open the chart page →

8,103
supersethelmforgeVerified publisher1.3.81 of 5See more

superset helmforge 1.3.8

1 of the 5 container images this version deploys carry CVE-2026-104843.

Container imageDigestPackageFixed in
apache/superset:6.1.016b50bbef664
uv@0.12.10
uv@0.12.10
0.12.18
0.12.18

Open the chart page →

5,978
parcelapp-mcpobeoneVerified publisher0.1.01 of 1See more

parcelapp-mcp obeone 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-104843.

Container imageDigestPackageFixed in
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
uv@0.12.9
0.12.18

Open the chart page →

1,230
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-104843.

Container imageDigestPackageFixed in
yetiplatform/yeti:2.9.09bcbe2650a14
uv@0.12.7
uv@0.12.7
0.12.18
0.12.18

Open the chart page →

235,082
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2026-104843.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
uv@0.12.8
uv@0.12.8
0.12.18
0.12.18

Open the chart page →

8,085

Container images carrying it

12 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apache/superset:6.1.0:latest16b50bbef664
uv@0.12.10
uv@0.12.10
0.12.18
0.12.18
3
ghcr.io/paperless-ngx/paperless-ngx:3.2.15fa76604a81d
uv@0.12.16
0.12.18
2
acryldata/datahub-actions:v1.7.0.1c5fd70130157
uv@0.12.9
0.12.18
1
archivebox/archivebox:0.9.708c21bb233130
uv@0.12.17
0.12.18
1
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
uv@0.12.12
uv@0.12.12
0.12.18
0.12.18
1
langgenius/dify-plugin-daemon:main-local7d2fb04baf44
uv@0.12.17
uv@0.12.17
0.12.18
0.12.18
1
opencsghq/csgbot:v0.6.9-ee7d0271e26521
uv@0.12.13
uv@0.12.13
0.12.18
0.12.18
1
prefecthq/prefect:3.8.8-python3.1119463f92420b
uv@0.12.10
0.12.18
1
yetiplatform/yeti:2.9.09bcbe2650a14
uv@0.12.7
uv@0.12.7
0.12.18
0.12.18
1
yetiplatform/yeti:latest9c3006cedcca
uv@0.12.8
uv@0.12.8
0.12.18
0.12.18
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
uv@0.12.13
uv@0.12.13
0.12.18
0.12.18
1
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
uv@0.12.9
0.12.18
1

syft 1.42.1 · advisories as of 7 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.