StackRadar

CVE-2026-107727

Low

Advisory

Published 9 Oct 2026In the index since 10 Oct 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.004
27th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3
of 18,090 indexed, latest versions
Container images
3
deployed by those charts
Fix available
1 of 1
affected package

Strawberry legacy graphql-ws retains naturally completed subscription slots

Carried by container images the latest versions of 3 of 18,090 indexed charts deploy, on 3 images.

Affected packageAffected versionsFixed inImages
strawberry-graphqlpypi0.315.7, 0.316.0, 0.327.00.327.23
OSV records
GHSA-m952-2w3f-6r8h

Charts affected

3 by stars
ChartLatestAffected imagesRadar Score
observalobservalVerified publisher1.14.01 of 8See more

observal observal 1.14.0

1 of the 8 container images this version deploys carry CVE-2026-107727.

Container imageDigestPackageFixed in
ghcr.io/observal/observal-api:1.14.05a20125eafd4
strawberry-graphql@0.315.7
0.327.2

Open the chart page →

6,742
plane-enterprisemakeplaneOfficialVerified publisher3.10.51 of 13See more

plane-enterprise makeplane 3.10.5

1 of the 13 container images this version deploys carry CVE-2026-107727.

Container imageDigestPackageFixed in
makeplane/backend-commercial:v3.3.2000b3ea7451a
strawberry-graphql@0.316.0
0.327.2

Open the chart page →

6,956
netboxhelmforgeVerified publisher2.0.31 of 4See more

netbox helmforge 2.0.3

1 of the 4 container images this version deploys carry CVE-2026-107727.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
strawberry-graphql@0.327.0
0.327.2

Open the chart page →

4,906

Container images carrying it

3 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
makeplane/backend-commercial:v3.3.1:v3.3.2000b3ea7451a
strawberry-graphql@0.316.0
0.327.2
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
strawberry-graphql@0.327.0
0.327.2
1
ghcr.io/observal/observal-api:1.14.05a20125eafd4
strawberry-graphql@0.315.7
0.327.2
1

syft 1.42.1 · advisories as of 11 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.