CVE-2026-1502
MediumAdvisory
Published 10 Apr 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.7
- base score, highest
- EPSS
- 0.006
- 45th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 628
- of 17,781 indexed, latest versions
- Container images
- 607
- deployed by those charts
- Fix available
- 9 of 15
- affected packages
HTTP client proxy tunnel headers not validated for CR/LF
Carried by container images the latest versions of 628 of 17,781 indexed charts deploy, on 607 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| python3.11deb | 3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more | no fix listed | 181 |
| python3.8deb | 3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more | no fix listed | 100 |
| python3.10deb | 3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more | 3.10.12-1~22.04.16 | 71 |
| python3apk | 3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+4 more | 3.12.14-r0 | 63 |
| python2.7deb | 2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 more | no fix listed | 54 |
| python3.12deb | 3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+8 more | 3.12.3-1ubuntu0.15 | 48 |
| python3.6deb | 3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more | no fix listed | 44 |
| python3.13deb | 3.13.5-2, 3.13.5-2+deb13u2, 3.13.5-2+e30, 3.13.7-1ubuntu0.1 | 3.13.5-2+deb13u3, 3.13.5-2+e36 | 34 |
| python3.5deb | 3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9 | no fix listed | 25 |
| python3.4deb | 3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7 | no fix listed | 7 |
| python-3.14apk | 3.14.2-r2, 3.14.4-r2 | 3.14.4-r3 | 5 |
| pythonbitnami | 3.11.11-0, 3.12.8-0, 3.13.5-1 | 3.10.21 | 3 |
| python-3.13apk | 3.13.7-r0, 3.13.10-r0, 3.13.12-r2 | 3.13.13-r2 | 3 |
| python-3.12apk | 3.12.0-r1, 3.12.9-r1 | 3.12.13-r3 | 2 |
| python3.14deb | 3.14.4-1 | 3.14.4-1ubuntu0.1 | 2 |
- OSV records
- ALPINE-CVE-2026-1502BIT-python-2026-1502CGA-67c6-67fc-p42gCGA-67mx-h3fh-x4cqCGA-944x-jfx5-h2p9DEBIAN-CVE-2026-1502UBUNTU-CVE-2026-1502ECHO-6948-71f0-8930
- Also known as
- BIT-libpython-2026-1502, BIT-python-min-2026-1502, CGA-7q5f-rxwg-6762, CGA-f3fh-hj7q-j4cf, CGA-fh47-vhf7-3mpv, PSF-2026-15, USN-8509-1
Charts affected
628 by stars
Container images carrying it
607 by charts deploying them
A fixed version is listed for 9 of the 15 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ptthanh1511/ | 5741cbde85ab | python2.7 | no fix listed | 1 |
| puppet/ | 0b6fd9a6b7da | python3.6 | no fix listed | 1 |
| rancher/ | e66f32d19eb9 | python2.7 python3.5 | no fix listed no fix listed | 1 |
| razorbladex401/ | 6a4d79248e7d | python3.10 | 3.10.12-1~22.04.16 | 1 |
| redimp/ | 778bf30da3da | python3.11 | no fix listed | 1 |
| redis/ | 798ab84d9f26 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| redis/ | 887cf87cc744 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| resouer/ | e2f198b49ba7 | python2.7 python3.4 | no fix listed no fix listed | 1 |
| resurfaceio/ | d5cda2f64109 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| rezachalak/ | 34f694325191 | python3.8 | no fix listed | 1 |
| rhasspy/ | 69b7f797ae3a | python3.11 | no fix listed | 1 |
| rhasspy/ | e532f0dbc6b2 | python3.11 | no fix listed | 1 |
| rhasspy/ | 308b7959a925 | python3.11 | no fix listed | 1 |
| rocketadmin/ | 10955ef540b9 | python3.11 | no fix listed | 1 |
| roundcube/ | 17d9d9580962 | python3.13 | 3.13.5-2+deb13u3 | 1 |
| ryuunosukeds3/ | c0398f13e8a9 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| saidsef/ | f17f7c435891 | python3 | 3.12.14-r0 | 1 |
| santisbon/ | c4e994ca4540 | python3.11 | no fix listed | 1 |
| santisbon/ | e807283f8d69 | python3.11 | no fix listed | 1 |
| santisbon/ | 8ee3a1697227 | python3.11 | no fix listed | 1 |
| sashafefler/ | f96d7804c0ca | python3.11 | no fix listed | 1 |
| scholtz2/ | f12ce1cfb72e | python3.10 | 3.10.12-1~22.04.16 | 1 |
| scholtz2/ | 5aaa5d4ab8b8 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| scholtz2/ | 64966de56d9f | python3.10 | 3.10.12-1~22.04.16 | 1 |
| scholtz2/ | e9af7d8ff6bb | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| scholtz2/ | 1ec63eca86b6 | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| scholtz2/ | 70263d8fab5b | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| scholtz2/ | 3a3b3d3277d2 | python3.14 | 3.14.4-1ubuntu0.1 | 1 |
| scholtz2/ | 6770214bc881 | python3.14 | 3.14.4-1ubuntu0.1 | 1 |
| scrapinghub/ | a5f89bc84606 | python3.6 | no fix listed | 1 |
| seafileltd/ | 6693911bcc40 | python3.8 | no fix listed | 1 |
| seafileltd/ | 70628f29c663 | python3.8 | no fix listed | 1 |
| seafileltd/ | 7ac833196f60 | python3.8 | no fix listed | 1 |
| seafileltd/ | d0c66e4621bd | python3.10 | 3.10.12-1~22.04.16 | 1 |
| seafileltd/ | ed0fcda5e6a9 | python3.8 | no fix listed | 1 |
| seldonio/ | 1d0da98a2d76 | python2.7 | no fix listed | 1 |
| semaphoreui/ | e9260bfa8255 | python3 | 3.12.14-r0 | 1 |
| shaowenchen/ | 315444f703f4 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| signalen/ | 760256000738 | python3.11 | no fix listed | 1 |
| sismics/ | f4b0ef019cf1 | python3.6 | no fix listed | 1 |
| sissbruecker/ | a222fb777e1f | python3.11 | no fix listed | 1 |
| snipe/ | 141ebf2386fe | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| snipe/ | 55fb7636a98c | python3.8 | no fix listed | 1 |
| socialmediamacroscope/ | 70fb11d4f531 | python3.8 | no fix listed | 1 |
| socialmediamacroscope/ | 19d3d26d53ee | python3.6 | no fix listed | 1 |
| socialmediamacroscope/ | 6418f9bdb4d2 | python3.11 | no fix listed | 1 |
| socialmediamacroscope/ | f508216be63c | python3.6 | no fix listed | 1 |
| socialmediamacroscope/ | b351c21422e6 | python3.11 | no fix listed | 1 |
| socialmediamacroscope/ | ca863306314b | python3.11 | no fix listed | 1 |
| socialmediamacroscope/ | fa490acac2f8 | python3.11 | no fix listed | 1 |