StackRadar

CVE-2026-13346

Medium

Advisory

Published 29 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,326
of 17,790 indexed, latest versions
Container images
1,276
deployed by those charts
Fix available
2 of 3
affected packages

Security update for python313-pip

Carried by container images the latest versions of 1,326 of 17,790 indexed charts deploy, on 1,276 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+68 more26.21,270
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 moreno fix listed139
python313-piprpm24.2-150700.1.124.2-150700.3.3.12
OSV records
DEBIAN-CVE-2026-13346PYSEC-2026-3721UBUNTU-CVE-2026-13346SUSE-SU-2026:4030-1
Also known as
GHSA-qwm4-qh6w-59xr

Charts affected

1,326 by stars
ChartLatestAffected imagesRadar Score
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
pip@26.1.2
26.2

Open the chart page →

7,265
speech-to-phraseandrenarchyVerified publisher1.3.01 of 1See more

speech-to-phrase andrenarchy 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.2
no fix listed

Open the chart page →

3,872
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
pip@25.3
26.2

Open the chart page →

5,516
ansible-playbook-operatoransible-playbook-operatorVerified publisher0.1.71 of 1See more

ansible-playbook-operator ansible-playbook-operator 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
pip@26.0.1
26.2

Open the chart page →

1,340
ddosifyanteonVerified publisher1.7.53 of 13See more

ddosify anteon 1.7.5

3 of the 13 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
pip@24.0
26.2
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
pip@24.0
26.2
ddosify/selfhosted_hammermanager:1.2.471b8768f49bc
pip@22.0.4
26.2

Open the chart page →

25,720
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
pip@9.0.3
26.2

Open the chart page →

2,454
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
pip@19.0.3
26.2

Open the chart page →

2,730
sensitive-dataapicheck1.0.01 of 1See more

sensitive-data apicheck 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
bbvalabs/sensitive-data:1.0.13ea299ae63c0
pip@21.0.1
26.2

Open the chart page →

1,843
app-mobilityappmo0.1.01 of 5See more

app-mobility appmo 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
pip@9.0.3
26.2

Open the chart page →

12,520
pgadminappscodeVerified publisher2026.3.301 of 1See more

pgadmin appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.11.050700ac17936
pip@25.3
26.2

Open the chart page →

1,565
maxscaleappuio2.0.11 of 1See more

maxscale appuio 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
pip@9.0.3
26.2

Open the chart page →

2,902
snappassappuio1.0.01 of 3See more

snappass appuio 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
samueldg/snappass:latest3987195edbe6
pip@19.3.1
26.2

Open the chart page →

1,488
argocd-ecr-updaterargocd-ecr-updater4.1.01 of 1See more

argocd-ecr-updater argocd-ecr-updater 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
odaniait/aws-kubectl:latest3fff8a8570ec
pip@20.0.2
26.2

Open the chart page →

1,511
aias-servicesarlas-stackVerified publisher28.8.01 of 5See more

aias-services arlas-stack 28.8.0

1 of the 5 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
gisaia/aproc-service:0.18.1ac6564921994
pip@26.1.2
26.2

Open the chart page →

1,001
arlas-aiasarlas-stackVerified publisher28.8.02 of 22See more

arlas-aias arlas-stack 28.8.0

2 of the 22 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
gisaia/aproc-service:0.18.1ac6564921994
pip@26.1.2
26.2
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
pip@25.1.1
26.2

Open the chart page →

40,411
pgadminarunalakmalVerified publisher0.1.01 of 1See more

pgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pip@20.3.4
26.2

Open the chart page →

2,418
swdpgadminarunalakmalVerified publisher0.1.01 of 1See more

swdpgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pip@20.3.4
26.2

Open the chart page →

2,418
itera-lmaarzu1.34.601 of 6See more

itera-lma arzu 1.34.60

1 of the 6 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.19.26a8671702d6f
pip@22.1.2
26.2

Open the chart page →

8,608
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
pip@21.2.3
26.2
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
pip@21.2.3
26.2

Open the chart page →

22,677
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
assistiot/authorization_db:latestc3adbab6a3e7
pip@20.2.4
26.2

Open the chart page →

5,536
automatedconfigurationassist-iot-automated-configuration1.0.02 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.5.1dc9b972db002
pip@20.2.4
26.2
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
pip@20.2.4
26.2

Open the chart page →

14,725
fllocaloperationsassist-iot-fl-local-operations1.1.01 of 3See more

fllocaloperations assist-iot-fl-local-operations 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
assistiot/fl_local_operations_inference:latest0518b63a2e69
pip@23.2.1
26.2

Open the chart page →

3,786
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
assistiot/fl_repository:latest0fce3ea719a5
pip@20.1.1
26.2

Open the chart page →

4,367
trainingcollectorassist-iot-fl-training-collector1.1.01 of 1See more

trainingcollector assist-iot-fl-training-collector 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
assistiot/fl_training_collector:latest792715dd3084
pip@23.2.1
26.2

Open the chart page →

1,719
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
pip@9.0.3
26.2

Open the chart page →

12,799
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pip@20.3.4
26.2

Open the chart page →

10,101
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
pip@23.3.1
python-pip@22.0.2+dfsg-1ubuntu0.4
26.2
no fix listed

Open the chart page →

18,331
resource-provisioningassist-iot-resource-provisioning1.0.04 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

4 of the 7 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
assistiot/resource-provisioning_api:1.0.044a37b00d4f8
pip@23.0.1
26.2
assistiot/resource-provisioning_im:1.0.0a942dc14030a
pip@23.0.1
26.2
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
pip@20.3.4
26.2
library/mysql:5.74bc6bc963e6d
pip@23.0.1
26.2

Open the chart page →

8,042
smartorchestratorassist-iot-smart-orchestrator4.0.04 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

4 of the 14 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
pip@23.0.1
26.2
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
pip@23.0.1
26.2
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.2
no fix listed
library/mysql:5.74bc6bc963e6d
pip@23.0.1
26.2

Open the chart page →

42,460
traffic-classificationassist-iot-traffic-classification2.0.01 of 2See more

traffic-classification assist-iot-traffic-classification 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
assistiot/traffic-classification_api:2.0.0e32b87786142
pip@23.0.1
26.2

Open the chart page →

1,165
videoaugmentationassist-iot-video-augmentation0.1.01 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
pip@23.0.1
python-pip@20.0.2-5ubuntu1.8
26.2
no fix listed

Open the chart page →

13,986
phonebook-chartasumankamberoglu0.1.53 of 3See more

phonebook-chart asumankamberoglu 0.1.5

3 of the 3 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
pip@23.0.1
26.2
paulkellerman/resultserver-app:1.0381eeccb0618
pip@22.3
26.2
paulkellerman/webserver-app:latest5a37b74f61b9
pip@22.3
26.2

Open the chart page →

3,176
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
pip@23.3.2
26.2

Open the chart page →

8,555
shynetatrox0.1.11 of 1See more

shynet atrox 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.12.0e821e31140f7
pip@21.2.4
26.2

Open the chart page →

5,507
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/k8s-sidecar:ignore-initial-events7f583a36a764
pip@22.2.2
26.2

Open the chart page →

5,074
aws-ecr-credentialaws-ecr-credentialVerified publisher1.5.21 of 1See more

aws-ecr-credential aws-ecr-credential 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
architectminds/aws-kubectl:1.19735e59a1085
pip@19.2.1
26.2

Open the chart page →

1,437
ecr-exporteraws-exportersVerified publisher0.2.41 of 1See more

ecr-exporter aws-exporters 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/aws-exporters/prometheus-ecr-exporter:0.1.442b0c87470d6
pip@20.3.4
26.2

Open the chart page →

1,622
inspector-exporteraws-exportersVerified publisher0.0.21 of 1See more

inspector-exporter aws-exporters 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/aws-exporters/prometheus-inspector-exporter:0.0.29c7c11293b3c
pip@20.3.4
26.2

Open the chart page →

1,622
aws-secrets-synchronizeraws-secrets-synchronizer0.2.11 of 1See more

aws-secrets-synchronizer aws-secrets-synchronizer 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/reezogit/aws-secrets-synchronizer:0.2.1111ed7cf7b39
pip@23.2.1
26.2

Open the chart page →

955
axosyslog-collectoraxosyslogVerified publisher0.8.11 of 1See more

axosyslog-collector axosyslog 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/axoflow/axosyslog:4.5.0aa7831e207cd
pip@23.3.1
26.2

Open the chart page →

1,515
azure-advanced-backupazure-advanced-backup0.4.11 of 1See more

azure-advanced-backup azure-advanced-backup 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
pip@22.0.4
26.2

Open the chart page →

4,568
azure-app-exporterazure-app-exporterVerified publisher0.4.21 of 2See more

azure-app-exporter azure-app-exporter 0.4.2

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
ghcr.io/dodevops/azure-app-exporter/azure-app-exporter:0.1.38b472877847f5
pip@21.2.4
26.2

Open the chart page →

1,790
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
pip@20.2.4
26.2

Open the chart page →

5,521
aks-helloworldazure-sample0.1.11 of 1See more

aks-helloworld azure-sample 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
neilpeterson/aks-helloworld:v1fb47732ef36b
pip@9.0.1
26.2

Open the chart page →

4,270
azure-voteazure-sample0.1.11 of 2See more

azure-vote azure-sample 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
neilpeterson/azure-vote-front:v384062718347c
pip@9.0.1
26.2

Open the chart page →

5,238
azure-vote-osbaazure-sample0.1.01 of 1See more

azure-vote-osba azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
neilpeterson/azure-vote-front:v384062718347c
pip@9.0.1
26.2

Open the chart page →

4,270
osba-container-instances-demoazure-sample0.1.01 of 1See more

osba-container-instances-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
neilpeterson/osba-container-instances-demo:latest6527b05d5d03
pip@9.0.1
26.2

Open the chart page →

3,212
osba-cosmos-mongodb-demoazure-sample0.1.01 of 1See more

osba-cosmos-mongodb-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
pip@9.0.1
26.2

Open the chart page →

2,904
osba-mysql-demoazure-sample0.1.01 of 1See more

osba-mysql-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
neilpeterson/osba-mysql-demo:latest5859d68a6c9f
pip@9.0.2
26.2

Open the chart page →

2,895
osba-storage-demoazure-sample0.1.01 of 1See more

osba-storage-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13346.

Container imageDigestPackageFixed in
neilpeterson/osba-storage-demo:latest29d229ab446e
pip@9.0.1
26.2

Open the chart page →

3,425

Container images carrying it

1,276 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/opstree/k8s-sidecar:2.7.126aa9bb3386b
pip@26.0.1
26.2
1
quay.io/opstree/k8s-sidecar:2.7.37075d455b219
pip@26.1.1
26.2
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
pip@25.3
26.2
1
quay.io/ortelius/ms-dep-pkg-cud:main-v10.0.1670-g9abe110c0c881b509a
pip@25.3
26.2
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
pip@25.3
26.2
1
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
pip@25.3
26.2
1
quay.io/ortelius/ms-scorecard:main-v10.0.1276-g966a8a43337e52fdd4
pip@25.3
26.2
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
pip@25.3
26.2
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
pip@25.3
26.2
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
pip@24.0
26.2
1
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
pip@22.3.1
26.2
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
pip@20.2.4
26.2
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
pip@21.2.4
26.2
1
quay.io/stackgres/operator:1.19.1f241b0b20326
pip@23.2.1
26.2
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
pip@23.0.1
26.2
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
pip@26.1.2
python-pip@24.0+dfsg-1ubuntu1.3
26.2
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
pip@25.0.1
26.2
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
pip@25.0.1
26.2
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
pip@9.0.3
26.2
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
pip@20.0.2
python-pip@20.0.2-5ubuntu1.1
26.2
no fix listed
1
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
pip@20.3.3
26.2
1
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
pip@21.2.4
26.2
1
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
pip@21.2.4
26.2
1
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
pip@22.0.4
26.2
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
pip@23.3.2
26.2
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
pip@25.0.1
26.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.