CVE-2026-1299
MediumAdvisory
Published 23 Jan 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.0
- base score, highest
- EPSS
- 0.005
- 44th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 512
- of 17,781 indexed, latest versions
- Container images
- 494
- deployed by those charts
- Fix available
- 9 of 14
- affected packages
email BytesGenerator header injection due to unquoted newlines
Carried by container images the latest versions of 512 of 17,781 indexed charts deploy, on 494 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| python3.11deb | 3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+4 more | 3.11.2-6+deb12u7 | 145 |
| python3.8deb | 3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more | no fix listed | 100 |
| python3.10deb | 3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more | 3.10.12-1~22.04.16 | 71 |
| python2.7deb | 2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 more | no fix listed | 54 |
| python3.12deb | 3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+8 more | 3.12.3-1ubuntu0.15 | 48 |
| python3.6deb | 3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more | no fix listed | 44 |
| python3.5deb | 3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9 | no fix listed | 25 |
| python3.13deb | 3.13.5-2, 3.13.5-2+e30, 3.13.7-1ubuntu0.1 | 3.13.5-2+deb13u1, 3.13.5-2+e36 | 23 |
| python3.4deb | 3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7 | no fix listed | 7 |
| python-3.14apk | 3.14.2-r2 | 3.14.3-r1 | 4 |
| pythonbitnami | 3.11.11-0, 3.12.8-0, 3.13.5-1 | 3.10.20 | 3 |
| python-3.12apk | 3.12.0-r1, 3.12.9-r1 | 3.12.12-r5 | 2 |
| python-3.13apk | 3.13.7-r0, 3.13.10-r0 | 3.13.12-r1 | 2 |
| python3-corerpm | 3.6.15-150300.10.97.1 | 3.6.15-150300.10.109.1 | 1 |
- OSV records
- BIT-python-2026-1299CGA-3hhm-jg5q-r9v7CGA-c9h2-43g4-m56xCGA-cgx7-5h45-6xr5DEBIAN-CVE-2026-1299UBUNTU-CVE-2026-1299ECHO-addc-a9aa-706bSUSE-SU-2026:1090-1
- Also known as
- BIT-libpython-2026-1299, BIT-python-min-2026-1299, CGA-hw3w-x7mm-rxvx, CGA-jhj2-w2wm-p9wv, CGA-mg73-w7j6-v3ff, PSF-2026-8, USN-8509-1
Charts affected
512 by stars
Container images carrying it
494 by charts deploying them
A fixed version is listed for 9 of the 14 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| knspar/ | 0c4f0543ee58 | python3.11 | 3.11.2-6+deb12u7 | 1 |
| kong/ | a6ac46531193 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| kubeoperator/ | be8f0d624640 | python3.6 | no fix listed | 1 |
| kubeovn/ | 6722b54eb5c0 | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| kusionstack/ | 126c8f0b0976 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| laly9999/ | dd0e503913e1 | python3.11 | 3.11.2-6+deb12u7 | 1 |
| langgenius/ | 3c694329357b | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| langgenius/ | 8269050f192e | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| library/ | b095ff3248c6 | python2.7 | no fix listed | 1 |
| library/ | 588609d76b21 | python3.11 | 3.11.2-6+deb12u7 | 1 |
| library/ | b7faa1653c39 | python3.13 | 3.13.5-2+deb13u1 | 1 |
| library/ | 8f693eaa7e0a | python3.11 | 3.11.2-6+deb12u7 | 1 |
| library/ | d41127070014 | python3.11 | 3.11.2-6+deb12u7 | 1 |
| library/ | da5aee29682d | python3.13 | 3.13.5-2+deb13u1 | 1 |
| library/ | 1b0f675d2f24 | python3.8 | no fix listed | 1 |
| library/ | b6dd45cc35b3 | python3.6 | no fix listed | 1 |
| library/ | 4d0bb287d87b | python3.11 | 3.11.2-6+deb12u7 | 1 |
| library/ | 8ae66efb09a2 | python3.11 | 3.11.2-6+deb12u7 | 1 |
| linuxserver/ | a847b5b2d860 | python2.7 python3.6 | no fix listed no fix listed | 1 |
| linuxserver/ | 241009026e6f | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| linuxserver/ | 938810eca3d3 | python3.8 | no fix listed | 1 |
| linuxserver/ | b801bbcf6386 | python2.7 | no fix listed | 1 |
| linuxserver/ | 0ac871624394 | python3.6 | no fix listed | 1 |
| linuxserver/ | 2ce561a95e7b | python3.6 | no fix listed | 1 |
| linuxserver/ | f93d2560e233 | python3.6 | no fix listed | 1 |
| logiqai/ | 65b996bc7bdc | python3.11 | 3.11.2-6+deb12u7 | 1 |
| longhornio/ | 5b0bc1b88f0c | python3-core | 3.6.15-150300.10.109.1 | 1 |
| longhornio/ | dca34321452c | python3.8 | no fix listed | 1 |
| longhornio/ | ede61fe2a472 | python3.6 | no fix listed | 1 |
| louislam/ | 059b49d64739 | python3.11 | 3.11.2-6+deb12u7 | 1 |
| louislam/ | 4c364ef96aad | python3.11 | 3.11.2-6+deb12u7 | 1 |
| louislam/ | 9865163f92c1 | python3.11 | 3.11.2-6+deb12u7 | 1 |
| lsstsqre/ | b75bf8aaafa4 | python2.7 python3.8 | no fix listed no fix listed | 1 |
| makersquad/ | a40dd258c527 | python3.11 | 3.11.2-6+deb12u7 | 1 |
| mbround18/ | 70bd4da591cd | python3.10 | 3.10.12-1~22.04.16 | 1 |
| mediagis/ | 7923a8e67197 | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| mediagis/ | c15e941485ef | python3.8 | no fix listed | 1 |
| mediagis/ | d0eae7b51374 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| middlewareeng/ | 747d880812f1 | python3.11 | 3.11.2-6+deb12u7 | 1 |
| mindsdb/ | 163011c09299 | python3.13 | 3.13.5-2+deb13u1 | 1 |
| mintproject/ | 02260d20a21f | python3.11 | 3.11.2-6+deb12u7 | 1 |
| mlikiowa/ | 1336a777f9a4 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| moreillon/ | d7d4a5463525 | python3.11 | 3.11.2-6+deb12u7 | 1 |
| moreillon/ | e8fd856e593d | python3.11 | 3.11.2-6+deb12u7 | 1 |
| moreillon/ | 3caa8f710ee0 | python3.11 | 3.11.2-6+deb12u7 | 1 |
| moreillon/ | d2ee0423b797 | python3.11 | 3.11.2-6+deb12u7 | 1 |
| mshanley80/ | 5b189a70c0fb | python3.8 | no fix listed | 1 |
| muhammedgamal/ | 74b4cd69b6fa | python3.11 | 3.11.2-6+deb12u7 | 1 |
| muluder/ | 43b597a93da7 | python2.7 python3.5 | no fix listed no fix listed | 1 |
| netboxcommunity/ | 3d652dca5351 | python3.10 | 3.10.12-1~22.04.16 | 1 |