StackRadar

CVE-2026-13346

Medium

Advisory

Published 29 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,335
of 17,787 indexed, latest versions
Container images
1,286
deployed by those charts
Fix available
2 of 3
affected packages

Security update for python313-pip

Carried by container images the latest versions of 1,335 of 17,787 indexed charts deploy, on 1,286 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+68 more26.21,279
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 moreno fix listed141
python313-piprpm24.2-150700.1.124.2-150700.3.3.12
OSV records
DEBIAN-CVE-2026-13346PYSEC-2026-3721UBUNTU-CVE-2026-13346SUSE-SU-2026:4030-1
Also known as
GHSA-qwm4-qh6w-59xr

Charts affected

1,335 by stars
ChartLatestAffected imagesRadar Score
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
conduction/conduction-ui-varnish:dev5f5add2c12e0
pip@9.0.1
26.2

Open the chart page →

12,906
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
pip@21.3.1
26.2

Open the chart page →

5,958
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
conduction/contactmoment-component-varnish:deve3546b97faea
pip@9.0.1
26.2

Open the chart page →

8,408
bitcoincosmicrocks2.0.31 of 2See more

bitcoin cosmicrocks 2.0.3

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/esomore/bitcoin-prometheus-exporter:masterded173632986
pip@25.0.1
26.2

Open the chart page →

926
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
pip@24.2
26.2

Open the chart page →

14,587
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
kfserving/models-web-app:v0.6.1f322d6ffdfa3
pip@21.2.4
26.2

Open the chart page →

3,830
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
pip@9.0.3
26.2
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
pip@9.0.3
26.2
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
pip@9.0.3
26.2
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
pip@9.0.3
26.2
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
pip@9.0.3
26.2
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
pip@9.0.3
26.2
confluentinc/cp-zookeeper:6.1.078c190f4472c
pip@9.0.3
26.2

Open the chart page →

58,856
couchpotatocronce0.0.11 of 1See more

couchpotato cronce 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
pip@19.0.1
26.2

Open the chart page →

3,871
pagescrypticcode-helmchart1.0.01 of 3See more

pages crypticcode-helmchart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.2

Open the chart page →

20,233
wopiservercs3orgOfficialVerified publisher0.9.21 of 1See more

wopiserver cs3org 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
cs3org/wopiserver:v9.4.202a9e78757b4
pip@23.0.1
26.2

Open the chart page →

2,348
csghubcsghubVerified publisher2.4.34 of 34See more

csghub csghub 2.4.3

4 of the 34 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.30.2cdb361e67b1b
pip@24.3.1
26.2
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pip@25.0.1
26.2
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
pip@24.2
26.2
opencsghq/label-studio:v2.4.0b4e849fcf94a
pip@25.1.1
26.2

Open the chart page →

59,131
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
opencsghq/csgship-agentic:v0.4.02cd29671a03e
pip@25.2
26.2
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pip@25.2
26.2

Open the chart page →

11,402
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
pip@25.1.1
26.2

Open the chart page →

6,532
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
pip@23.0.1
26.2

Open the chart page →

13,937
cspconsolecspconsole1.3.112 of 5See more

cspconsole cspconsole 1.3.11

2 of the 5 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
cspconsole/config-provider:1.0.365524a26a6c23
pip@26.0.1
26.2
cspconsole/report-collector:1.0.15839750248193b
pip@24.0
26.2

Open the chart page →

11,891
jupyterhubd4nVerified publisher3.3.72 of 7See more

jupyterhub d4n 3.3.7

2 of the 7 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
pip@24.1.2
26.2
aristidetm/k8s-hub:3.3.7ccb516cb8474
pip@24.0
26.2

Open the chart page →

16,632
daejeon_2-3daejeon2-30.1.01 of 2See more

daejeon_2-3 daejeon2-3 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
clsen2024/daejeon_2-3:latest1156cd87c8fb
pip@23.0.1
26.2

Open the chart page →

1,140
pagesdalston-pages1.0.01 of 3See more

pages dalston-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.2

Open the chart page →

20,233
pagesdaman-dell-kuber1.0.01 of 3See more

pages daman-dell-kuber 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.2

Open the chart page →

20,233
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
pip@23.3.1
26.2

Open the chart page →

6,178
proxmox-exporterdamounVerified publisher1.10.01 of 1See more

proxmox-exporter damoun 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
prompve/prometheus-pve-exporter:3.4.2fcf041f0c24d
pip@23.3.1
26.2

Open the chart page →

1,140
dapr-agentsdapr-agents-devVerified publisher0.1.52 of 31See more

dapr-agents dapr-agents-dev 0.1.5

2 of the 31 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.30.98c06e1ba643a
pip@25.2
26.2
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
pip@25.3
26.2

Open the chart page →

22,223
dask-gatewaydask2026.3.01 of 2See more

dask-gateway dask 2026.3.0

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-gateway-server:2026.3.0afa5a729114e
pip@25.2
26.2

Open the chart page →

1,994
nfs-provisionerdasmeta1.0.31 of 1See more

nfs-provisioner dasmeta 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
pip@19.0.3
26.2

Open the chart page →

2,806
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
pip@25.3
26.2

Open the chart page →

4,914
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
pip@19.3.1
python-pip@9.0.1-2.3~ubuntu1
26.2
no fix listed

Open the chart page →

27,749
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
pip@20.2.3
python-pip@9.0.1-2.3~ubuntu1.18.04.2
26.2
no fix listed

Open the chart page →

18,884
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
pip@19.0.3
python-pip@9.0.1-2.3~ubuntu1
26.2
no fix listed

Open the chart page →

22,425
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
pip@19.3.1
python-pip@9.0.1-2.3~ubuntu1
26.2
no fix listed

Open the chart page →

24,356
pagesdavid-pages1.0.01 of 3See more

pages david-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.2

Open the chart page →

20,233
db-connection-testdb-connection-testVerified publisher0.1.01 of 1See more

db-connection-test db-connection-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
felipecs8/app-db-connection-test:v129e06c9c6385
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.2
no fix listed

Open the chart page →

10,116
pagesdebasish-pages1.0.01 of 3See more

pages debasish-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.2

Open the chart page →

20,233
kube-web-viewdecayofmind0.0.41 of 1See more

kube-web-view decayofmind 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
pip@20.2.3
26.2

Open the chart page →

2,264
intel-gpu-exporterdefault-ghVerified publisher0.1.01 of 1See more

intel-gpu-exporter default-gh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
pip@22.0.2
python-pip@22.0.2+dfsg-1ubuntu0.3
26.2
no fix listed

Open the chart page →

4,846
isponsorblocktvdefault-ghVerified publisher1.0.51 of 1See more

isponsorblocktv default-gh 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/dmunozv04/isponsorblocktv:v2.9.05b8cfa805cb6
pip@25.3
26.2

Open the chart page →

546
linkdingdeimosfr-charts1.0.31 of 1See more

linkding deimosfr-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.35.00c5dddf0b37c
pip@24.2
26.2

Open the chart page →

5,656
mlflowdeliveryheroVerified publisher1.0.101 of 1See more

mlflow deliveryhero 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
pip@20.1
26.2

Open the chart page →

4,422
prometheus-aws-costs-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-aws-costs-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
nachomillangarcia/prometheus_aws_cost_exporter:lateste4ce056f2d6d
pip@18.0
26.2

Open the chart page →

3,553
rds-downscalerdeliveryheroVerified publisher1.0.51 of 1See more

rds-downscaler deliveryhero 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/python:3.7.0-alpine3.8e12594db7297
pip@18.1
26.2

Open the chart page →

574
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
pip@23.0.1
26.2

Open the chart page →

2,214
deployhubdeployhubVerified publisher10.0.4157 of 11See more

deployhub deployhub 10.0.415

7 of the 11 container images this version deploys carry CVE-2026-13346.

Open the chart page →

11,161
testdeploymentapp0.1.01 of 1See more

test deploymentapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
cbanuka/pythonapp:latestc742770d4247
pip@9.0.0
26.2

Open the chart page →

409
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
pip@20.0.2
python-pip@20.0.2-5ubuntu1.9
26.2
no fix listed

Open the chart page →

14,910
design-cataloguedesign-catalogue0.1.01 of 2See more

design-catalogue design-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
pip@20.3.3
26.2

Open the chart page →

2,771
mysqldev-krishan-dhaka-charts1.0.11 of 1See more

mysql dev-krishan-dhaka-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/mysql:8.4b3b90af2a655
pip@25.3
26.2

Open the chart page →

463
devnopesdevnopes0.1.81 of 1See more

devnopes devnopes 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
sokushinbutsu/devnopes:latest0bbd90448671
pip@24.0
26.2

Open the chart page →

462
devops-diplomdevops-diplom-chartVerified publisher0.8.01 of 2See more

devops-diplom devops-diplom-chart 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
alexeyr7/sf-test-app:latestdf0b41fdbd53
pip@22.0.4
26.2

Open the chart page →

2,549
kube-openid-connectdevopstalesVerified publisher1.1.01 of 1See more

kube-openid-connect devopstales 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
devopstales/kube-openid-connector:1.042c40a0e9f1b
pip@22.0.4
26.2

Open the chart page →

1,333
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
pip@24.0
26.2

Open the chart page →

9,152
argocddevtron1.8.11 of 3See more

argocd devtron 1.8.1

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
pip@18.1
26.2

Open the chart page →

10,468

Container images carrying it

1,286 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
kubeflownotebookswg/tensorboards-web-app:v1.6.10876fef1973b
pip@22.0.4
26.2
1
kubeflownotebookswg/tensorboards-web-app:v1.9.277f07f52a84a
pip@23.0.1
26.2
1
kubeflownotebookswg/volumes-web-app:v1.6.17299fa94db15
pip@22.0.4
26.2
1
kubeflownotebookswg/volumes-web-app:v1.9.2f63c3e550af3
pip@23.0.1
26.2
1
kubesphere/examples-bookinfo-productpage-v1:1.13.0378f49ec9c44
pip@19.1.1
26.2
1
kubitodev/traefik-ip-whitelist-sync:1.0.2aa24869319bf
pip@22.0.4
26.2
1
kunchalavikram/connectedcity:v14a559a47579e
pip@19.0.1
26.2
1
kunchalavikram/connectedfactory:v152c13fb9b1d9
pip@19.0.1
26.2
1
kusionstack/kusion:v0.14.0126c8f0b0976
pip@22.0.2
python-pip@22.0.2+dfsg-1ubuntu0.5
26.2
no fix listed
1
kyovint/kyoimgtransactions:1.0.048c19e3ae9a3
pip@24.0
26.2
1
kyovint/kyoimgusers:1.0.080084149156e
pip@24.0
26.2
1
kyso/kyso-nbdime:latest4aa9d38ee81d
pip@22.3.1
26.2
1
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
pip@25.0.1
26.2
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
pip@25.0.1
26.2
1
langgenius/dify-api:1.0.0066035f93856
pip@25.0.1
26.2
1
langgenius/dify-api:1.16.1dcefa5f7c47c
pip@25.0.1
26.2
1
langgenius/dify-api:0.6.11fca918260dd6
pip@23.0.1
26.2
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
pip@24.0
python-pip@24.0+dfsg-1ubuntu1.3
26.2
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
pip@24.0
python-pip@24.0+dfsg-1ubuntu1.3
26.2
no fix listed
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
pip@24.0
python-pip@24.0+dfsg-1ubuntu1.3
26.2
no fix listed
1
langgenius/dify-sandbox:0.2.124e65e8a351a2
pip@23.0.1
26.2
1
langgenius/dify-sandbox:0.2.15750e1111426e
pip@26.0.1
26.2
1
lib42/deluge:20c4d1d326f95
pip@22.3.1
26.2
1
library/crate:4.7.0c7984a05e15b
pip@9.0.3
26.2
1
library/influxdb:3.10.5-core695a8063ff10
pip@26.1.2
26.2
1
library/influxdb:3.11.2-enterprise6ce2bf22499b
pip@26.1.2
26.2
1
library/mysql:8.4.113466ba4a4828
pip@25.3
26.2
1
library/mysql:885b9bf2e29cf
pip@25.3
26.2
1
library/mysql:8.4.108dbcf531a03a
pip@25.3
26.2
1
library/mysql:8.0.41bf577825b52a
pip@24.2
26.2
1
library/python:3.8-alpine3d93b1f77efc
pip@23.0.1
26.2
1
library/python:3.1070c9cc675605
pip@23.0.1
26.2
1
library/python:3.11-slim9534e5a8e315
pip@24.0
26.2
1
library/python:3.12-alpineb64631e04e49
pip@25.0.1
26.2
1
library/python:3.8d41127070014
pip@23.0.1
26.2
1
library/python:3.9da5aee29682d
pip@23.0.1
26.2
1
library/python:3.12.9-bullseyeed4450bab88f
pip@24.3.1
26.2
1
library/python:3.14.3-alpine3.23faee120f7885
pip@25.3
26.2
1
librenms/librenms:24.11.00920bc9117a8
pip@24.3.1
26.2
1
librenms/librenms:22.4.14f1f3d667cc7
pip@22.0.4
26.2
1
libretranslate/libretranslate:v1.9.61de2d7056bb8
pip@24.0
26.2
1
linuxserver/babybuddy:1.10.2f7d7c7704249
pip@22.1
26.2
1
linuxserver/beets:1.5.0e36d16f7341c
pip@21.3.1
26.2
1
linuxserver/calibre-web:0.6.24241009026e6f
pip@25.2
python-pip@24.0+dfsg-1ubuntu1.2
26.2
no fix listed
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
pip@21.2.4
26.2
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
pip@19.0.1
26.2
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
pip@19.3.1
26.2
1
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
pip@25.1.1
26.2
1
linuxserver/healthchecks:version-v1.20.050792a72fc71
pip@21.1.1
26.2
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
pip@23.0.1
26.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.