StackRadar

CVE-2026-13346

Medium

Advisory

Published 29 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,323
of 17,792 indexed, latest versions
Container images
1,271
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,323 of 17,792 indexed charts deploy, on 1,271 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+68 more26.21,264
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 moreno fix listed140
OSV records
DEBIAN-CVE-2026-13346PYSEC-2026-3721UBUNTU-CVE-2026-13346
Also known as
GHSA-qwm4-qh6w-59xr

Charts affected

1,323 by stars
ChartLatestAffected imagesRadar Score
pagescrypticcode-helmchart1.0.01 of 3See more

pages crypticcode-helmchart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.2

Open the chart page →

20,242
wopiservercs3orgOfficialVerified publisher0.9.21 of 1See more

wopiserver cs3org 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
cs3org/wopiserver:v9.4.202a9e78757b4
pip@23.0.1
26.2

Open the chart page →

2,349
csghubcsghubVerified publisher2.5.03See more

csghub csghub 2.5.0

3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.30.2cdb361e67b1b
pip@24.3.1
26.2
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
pip@24.2
26.2
opencsghq/label-studio:v2.5.047e22aa71870
pip@25.1.1
26.2

Open the chart page →

csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
opencsghq/csgship-agentic:v0.4.02cd29671a03e
pip@25.2
26.2
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pip@25.2
26.2

Open the chart page →

11,544
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
pip@25.1.1
26.2

Open the chart page →

6,732
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
pip@23.0.1
26.2

Open the chart page →

13,944
cspconsolecspconsole1.3.112 of 5See more

cspconsole cspconsole 1.3.11

2 of the 5 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
cspconsole/config-provider:1.0.365524a26a6c23
pip@26.0.1
26.2
cspconsole/report-collector:1.0.15839750248193b
pip@24.0
26.2

Open the chart page →

12,394
jupyterhubd4nVerified publisher3.3.72 of 7See more

jupyterhub d4n 3.3.7

2 of the 7 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
pip@24.1.2
26.2
aristidetm/k8s-hub:3.3.7ccb516cb8474
pip@24.0
26.2

Open the chart page →

16,683
daejeon_2-3daejeon2-30.1.01 of 2See more

daejeon_2-3 daejeon2-3 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
clsen2024/daejeon_2-3:latest1156cd87c8fb
pip@23.0.1
26.2

Open the chart page →

1,141
pagesdalston-pages1.0.01 of 3See more

pages dalston-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.2

Open the chart page →

20,242
pagesdaman-dell-kuber1.0.01 of 3See more

pages daman-dell-kuber 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.2

Open the chart page →

20,242
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
pip@23.3.1
26.2

Open the chart page →

6,179
proxmox-exporterdamounVerified publisher1.10.01 of 1See more

proxmox-exporter damoun 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
prompve/prometheus-pve-exporter:3.4.2fcf041f0c24d
pip@23.3.1
26.2

Open the chart page →

1,140
dapr-agentsdapr-agents-devVerified publisher0.1.52 of 31See more

dapr-agents dapr-agents-dev 0.1.5

2 of the 31 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.30.98c06e1ba643a
pip@25.2
26.2
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
pip@25.3
26.2

Open the chart page →

22,355
dask-gatewaydask2026.3.01 of 2See more

dask-gateway dask 2026.3.0

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-gateway-server:2026.3.0afa5a729114e
pip@25.2
26.2

Open the chart page →

2,002
nfs-provisionerdasmeta1.0.31 of 1See more

nfs-provisioner dasmeta 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
pip@19.0.3
26.2

Open the chart page →

2,806
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
pip@25.3
26.2

Open the chart page →

5,142
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
pip@19.3.1
python-pip@9.0.1-2.3~ubuntu1
26.2
no fix listed

Open the chart page →

27,768
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
pip@20.2.3
python-pip@9.0.1-2.3~ubuntu1.18.04.2
26.2
no fix listed

Open the chart page →

18,881
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
pip@19.0.3
python-pip@9.0.1-2.3~ubuntu1
26.2
no fix listed

Open the chart page →

22,445
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
pip@19.3.1
python-pip@9.0.1-2.3~ubuntu1
26.2
no fix listed

Open the chart page →

24,375
pagesdavid-pages1.0.01 of 3See more

pages david-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.2

Open the chart page →

20,242
db-connection-testdb-connection-testVerified publisher0.1.01 of 1See more

db-connection-test db-connection-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
felipecs8/app-db-connection-test:v129e06c9c6385
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.2
no fix listed

Open the chart page →

10,163
pagesdebasish-pages1.0.01 of 3See more

pages debasish-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.2

Open the chart page →

20,242
kube-web-viewdecayofmind0.0.41 of 1See more

kube-web-view decayofmind 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
pip@20.2.3
26.2

Open the chart page →

2,264
intel-gpu-exporterdefault-ghVerified publisher0.1.01 of 1See more

intel-gpu-exporter default-gh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
pip@22.0.2
python-pip@22.0.2+dfsg-1ubuntu0.3
26.2
no fix listed

Open the chart page →

4,849
isponsorblocktvdefault-ghVerified publisher1.0.51 of 1See more

isponsorblocktv default-gh 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/dmunozv04/isponsorblocktv:v2.9.05b8cfa805cb6
pip@25.3
26.2

Open the chart page →

547
linkdingdeimosfr-charts1.0.31 of 1See more

linkding deimosfr-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.35.00c5dddf0b37c
pip@24.2
26.2

Open the chart page →

6,092
mlflowdeliveryheroVerified publisher1.0.101 of 1See more

mlflow deliveryhero 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
pip@20.1
26.2

Open the chart page →

4,422
prometheus-aws-costs-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-aws-costs-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
nachomillangarcia/prometheus_aws_cost_exporter:lateste4ce056f2d6d
pip@18.0
26.2

Open the chart page →

3,553
rds-downscalerdeliveryheroVerified publisher1.0.51 of 1See more

rds-downscaler deliveryhero 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/python:3.7.0-alpine3.8e12594db7297
pip@18.1
26.2

Open the chart page →

574
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
pip@23.0.1
26.2

Open the chart page →

2,328
deployhubdeployhubVerified publisher10.0.4157 of 11See more

deployhub deployhub 10.0.415

7 of the 11 container images this version deploys carry CVE-2026-13346.

Open the chart page →

11,191
testdeploymentapp0.1.01 of 1See more

test deploymentapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
cbanuka/pythonapp:latestc742770d4247
pip@9.0.0
26.2

Open the chart page →

409
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
pip@20.0.2
python-pip@20.0.2-5ubuntu1.9
26.2
no fix listed

Open the chart page →

14,920
design-cataloguedesign-catalogue0.1.01 of 2See more

design-catalogue design-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
pip@20.3.3
26.2

Open the chart page →

2,771
mysqldev-krishan-dhaka-charts1.0.11 of 1See more

mysql dev-krishan-dhaka-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/mysql:8.4b3b90af2a655
pip@25.3
26.2

Open the chart page →

463
devnopesdevnopes0.1.81 of 1See more

devnopes devnopes 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
sokushinbutsu/devnopes:latest0bbd90448671
pip@24.0
26.2

Open the chart page →

462
devops-diplomdevops-diplom-chartVerified publisher0.8.01 of 2See more

devops-diplom devops-diplom-chart 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
alexeyr7/sf-test-app:latestdf0b41fdbd53
pip@22.0.4
26.2

Open the chart page →

2,549
kube-openid-connectdevopstalesVerified publisher1.1.01 of 1See more

kube-openid-connect devopstales 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
devopstales/kube-openid-connector:1.042c40a0e9f1b
pip@22.0.4
26.2

Open the chart page →

1,333
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
pip@24.0
26.2

Open the chart page →

9,685
argocddevtron1.8.11 of 3See more

argocd devtron 1.8.1

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
pip@18.1
26.2

Open the chart page →

10,484
kube-prometheus-stackdevtron19.3.01 of 6See more

kube-prometheus-stack devtron 19.3.0

1 of the 6 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.14.235654389f8a9
pip@21.2.4
26.2

Open the chart page →

8,659
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
pip@24.0
26.2

Open the chart page →

9,685
argocddevtron-labs1.8.11 of 3See more

argocd devtron-labs 1.8.1

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
pip@18.1
26.2

Open the chart page →

10,484
kube-prometheus-stackdevtron-labs19.3.01 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

1 of the 6 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.14.235654389f8a9
pip@21.2.4
26.2

Open the chart page →

8,659
difydify1.0.03 of 4See more

dify dify 1.0.0

3 of the 4 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
pip@25.0.1
26.2
langgenius/dify-plugin-daemon:main-localda995c129e2f
pip@24.0
python-pip@24.0+dfsg-1ubuntu1.3
26.2
no fix listed
langgenius/dify-sandbox:0.2.009b7e8705673
pip@23.0.1
26.2

Open the chart page →

19,399
pagesdipak1.0.01 of 3See more

pages dipak 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.2

Open the chart page →

20,242
alertifydjjudas21Verified publisher0.1.01 of 1See more

alertify djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
djjudas21/alertify:0.1.0ba22be670c37
pip@25.0.1
26.2

Open the chart page →

2,395
autonodelabeldjjudas21Verified publisher0.0.101 of 1See more

autonodelabel djjudas21 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
djjudas21/autonodelabel:0.0.6f17233350c4f
pip@23.1.2
26.2

Open the chart page →

1,303

Container images carrying it

1,271 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
pip@9.0.3
26.2
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pip@25.0.1
26.2
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
pip@25.0.1
26.2
1
quay.io/hpestorage/filex-csi-driver:2.6.4b7f960bbf472
pip@25.3
26.2
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
pip@22.0.4
26.2
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
pip@25.0.1
26.2
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
pip@25.0.1
26.2
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
pip@23.2.1
26.2
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
pip@25.0.1
26.2
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
pip@25.0.1
26.2
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
pip@9.0.3
26.2
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
pip@9.0.3
26.2
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
pip@9.0.3
26.2
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
pip@9.0.3
26.2
1
quay.io/kiali/kiali-operator:v2.32.096c5264d54ab
pip@23.3.2
26.2
1
quay.io/kiwigrid/k8s-sidecar:1.10.718feb3906286
pip@21.0.1
26.2
1
quay.io/kiwigrid/k8s-sidecar:1.15.61f025ae37b7b
pip@21.2.4
26.2
1
quay.io/kiwigrid/k8s-sidecar:2.10.021b9fe7bb29d
pip@26.1.2
26.2
1
quay.io/kiwigrid/k8s-sidecar:1.30.349dcce269568
pip@25.0.1
26.2
1
quay.io/kiwigrid/k8s-sidecar:2.7.3694950d736c8
pip@26.1.1
26.2
1
quay.io/kiwigrid/k8s-sidecar:1.21.0710e23b489c5
pip@22.3.1
26.2
1
quay.io/kiwigrid/k8s-sidecar:1.30.10835d79d8fbae
pip@25.2
26.2
1
quay.io/kiwigrid/k8s-sidecar:1.15.1a25886092fa4
pip@21.2.4
26.2
1
quay.io/kiwigrid/k8s-sidecar:2.6.0a6c101156d42
pip@26.0.1
26.2
1
quay.io/kiwigrid/k8s-sidecar:1.25.2cb4c638ffb1f
pip@23.2.1
26.2
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
pip@26.1.2
26.2
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
pip@22.3.1
26.2
1
quay.io/maxiv/pieeat:0.9.3099715479210
pip@26.0.1
26.2
1
quay.io/maxiv/storageclass-router:0.4.160725dab588c
pip@24.0
26.2
1
quay.io/mongodb/farm-intro-backend:0.11a9ce0b8fbd4
pip@21.2.4
26.2
1
quay.io/netscaler/netscaler-cpx:14.1-66.598602e36d4564
pip@22.0.4
26.2
1
quay.io/netscaler/netscaler-k8s-ingress-controller:4.1.1755b12c2a8440
pip@24.0
26.2
1
quay.io/netscaler/netscaler-k8s-ingress-controller:4.2.26a68453858339
pip@24.0
26.2
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
pip@22.0.4
26.2
1
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
pip@26.1.2
26.2
1
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
pip@23.2.1
26.2
1
quay.io/openshift/origin-cli:4.66722d5041b47
pip@9.0.3
26.2
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
pip@9.0.3
26.2
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
pip@9.0.3
26.2
1
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
pip@22.0.3
26.2
1
quay.io/opsmxpublic/awsgit:v3-js15a6faada3d4
pip@22.0.4
26.2
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
pip@25.3
26.2
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
pip@9.0.3
26.2
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
pip@9.0.3
26.2
1
quay.io/opstree/k8s-sidecar:2.7.126aa9bb3386b
pip@26.0.1
26.2
1
quay.io/opstree/k8s-sidecar:2.7.37075d455b219
pip@26.1.1
26.2
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
pip@25.3
26.2
1
quay.io/ortelius/ms-dep-pkg-cud:main-v10.0.1670-g9abe110c0c881b509a
pip@25.3
26.2
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
pip@25.3
26.2
1
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
pip@25.3
26.2
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.