StackRadar

CVE-2026-15308

High

Advisory

Published 9 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
870
of 17,787 indexed, latest versions
Container images
901
deployed by those charts
Fix available
17 of 18
affected packages

Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations

Carried by container images the latest versions of 870 of 17,787 indexed charts deploy, on 901 images.

Affected packageAffected versionsFixed inImages
python-3.14apk3.14.2-r2, 3.14.4-r2, 3.14.6-r03.14.6-r46
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-13.10.213
python-3.13apk3.13.7-r0, 3.13.10-r0, 3.13.12-r23.13.14-r33
python-3.12apk3.12.0-r1, 3.12.9-r13.12.14-r22
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more3.11.0~rc1-1~22.04.1+esm2181
python3rpm3.6.8-15.1.el8, 3.6.8-23.el8, 3.6.8-24.el8_2, 3.6.8-24.el8_2.2+28 more0:3.6.8-77.el8_10, 0:3.6.8-77.el8_10.rocky.0, 3.12.14-1137
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more3.8.10-0ubuntu1~20.04.18+esm7100
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3+11 more3.12.3-1ubuntu0.1786
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+16 more3.10.12-1~22.04.1880
python3apk3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+7 more3.12.14-r0, 3.14.7-r075
python3.13deb3.13.5-2, 3.13.5-2+deb13u2, 3.13.5-2+deb13u4, 3.13.5-2+deb13u5no fix listed75
python3.9rpm3.9.16-1.el9, 3.9.16-1.el9_2.1, 3.9.16-1.el9_2.2, 3.9.18-1.el9_3.1+15 more0:3.9.25-7.el9_8.255
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more3.6.9-1~18.04ubuntu1.13+esm1044
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+9 more2.7.6-8ubuntu0.6+esm30, 2.7.12-1ubuntu0~16.04.18+esm22, 2.7.17-1~18.04ubuntu1.13+esm15, 2.7.18-13ubuntu1.5+esm943
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.93.5.2-2ubuntu0~16.04.13+esm2525
python3.14deb3.14.4-1, 3.14.4-1ubuntu0.13.14.4-1ubuntu0.28
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.73.4.3-1ubuntu1~14.04.7+esm217
python3.12rpm3.12.5-2.el9_5.20:3.12.13-3.el9_8.11
OSV records
ALPINE-CVE-2026-15308BIT-python-2026-15308CGA-2v5h-4pjx-m2vpCGA-7fq5-cfqp-92mfCGA-8wxj-3m53-wmwrDEBIAN-CVE-2026-15308RHSA-2026:39320RHSA-2026:39771RHSA-2026:39798RLSA-2026:39320RLSA-2026:39798UBUNTU-CVE-2026-15308AZL-92271
Also known as
BIT-libpython-2026-15308, BIT-python-min-2026-15308, CGA-qq9v-hh37-fr79, CGA-vh53-c7h5-695j, CGA-xm2p-hf9g-qw3m, PSF-2026-33, RHSA-2026:50064, RHSA-2026:50065, RHSA-2026:50816, USN-8744-1

Charts affected

870 by stars
ChartLatestAffected imagesRadar Score
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

22,146
piepieVerified publisher0.11.11 of 1See more

pie pie 0.11.1

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/topolvm/pie:0.18.0aa467443e407
python3.10@3.10.12-1~22.04.17
3.10.12-1~22.04.18

Open the chart page →

2,149
firehose-ethereumpinaxVerified publisher0.3.21 of 2See more

firehose-ethereum pinax 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.17

Open the chart page →

7,149
subgraph-oraclepinaxVerified publisher0.0.11 of 1See more

subgraph-oracle pinax 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
python3.11@3.11.2-6+deb12u2
no fix listed

Open the chart page →

11,373
substreams-sink-kvpinaxVerified publisher0.0.41 of 1See more

substreams-sink-kv pinax 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
python3.8@3.8.10-0ubuntu1~20.04.13
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

6,695
substreams-sink-nooppinaxVerified publisher0.0.31 of 1See more

substreams-sink-noop pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
python3.8@3.8.10-0ubuntu1~20.04.13
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

6,641
substreams-tier-2pinaxVerified publisher0.0.81 of 1See more

substreams-tier-2 pinax 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.17

Open the chart page →

4,938
pingdom-operatorpingdom-operator0.0.201 of 1See more

pingdom-operator pingdom-operator 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
python3.11@3.11.2-6+deb12u2
no fix listed

Open the chart page →

11,017
planectlplanectlVerified publisher0.7.01 of 10See more

planectl planectl 0.7.0

1 of the 10 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
library/node:208f693eaa7e0a
python3.11@3.11.2-6+deb12u6
no fix listed

Open the chart page →

25,626
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
python3@3.6.8-15.1.el8
0:3.6.8-77.el8_10

Open the chart page →

11,153
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
python3@3.6.8-51.el8_8.1
0:3.6.8-77.el8_10

Open the chart page →

12,754
pod-birdspod-birds0.1.01 of 1See more

pod-birds pod-birds 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
teknas09/bird-pod:latest12a1fa85c4aa
python3.11@3.11.2-6
no fix listed

Open the chart page →

11,680
Practica_4_helmpr04helm0.1.02 of 7See more

Practica_4_helm pr04helm 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
python3@3.6.8-48.el8_7
0:3.6.8-77.el8_10
library/rabbitmq:3.9-management8a279e9396a8
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.18

Open the chart page →

27,649
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
library/rabbitmq:3-management-alpine606d8c0d6b3c
python3@3.12.12-r0
3.12.14-r0

Open the chart page →

28,495
priceapp-chartpriceapp0.1.01 of 1See more

priceapp-chart priceapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ildarmukhametzyanov/priceapp:0.115d23720a3ee
python3.11@3.11.2-6
no fix listed

Open the chart page →

6,932
prismeai-appsprismeai0.7.11 of 4See more

prismeai-apps prismeai 0.7.1

1 of the 4 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
python3@3.12.12-r0
3.12.14-r0

Open the chart page →

2,752
prismeai-coreprismeai1.12.11 of 7See more

prismeai-core prismeai 1.12.1

1 of the 7 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
python3@3.12.12-r0
3.12.14-r0

Open the chart page →

3,271
game-serverpvillaverdeVerified publisher1.0.51 of 1See more

game-server pvillaverde 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/itzg/minecraft-server:latestc1a267d9ed6d
python3.12@3.12.3-1ubuntu0.16
3.12.3-1ubuntu0.17

Open the chart page →

4,315
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
python3.11@3.11.2-6
no fix listed

Open the chart page →

12,652
mychartpythonweb0.1.01 of 1See more

mychart pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
python3.11@3.11.2-6
no fix listed

Open the chart page →

11,400
mypythonpythonweb0.1.01 of 1See more

mypython pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
python3.11@3.11.2-6
no fix listed

Open the chart page →

11,400
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
python3.11@3.11.2-6+deb12u6
no fix listed

Open the chart page →

7,691
rada-platformrada-platform0.1.03 of 7See more

rada-platform rada-platform 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
python3.11@3.11.2-6+deb12u3
no fix listed
trinodb/trino:45038c6f24ab1a4
python3.9@3.9.18-3.el9
0:3.9.25-7.el9_8.2
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
python3.9@3.9.18-3.el9_4.1
0:3.9.25-7.el9_8.2

Open the chart page →

20,812
kubecostradar-baseVerified publisher1.0.01 of 7See more

kubecost radar-base 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
python3.9@3.9.21-1.el9_5
0:3.9.25-7.el9_8.2

Open the chart page →

9,389
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
python3@3.6.8-56.el8_9.3
0:3.6.8-77.el8_10

Open the chart page →

5,269
radar-kafkaradar-baseVerified publisher0.4.11 of 2See more

radar-kafka radar-base 0.4.1

1 of the 2 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
python3.9@3.9.21-1.el9_5
0:3.9.25-7.el9_8.2

Open the chart page →

4,236
strimzi-kafka-operatorradar-baseVerified publisher0.46.01 of 1See more

strimzi-kafka-operator radar-base 0.46.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
python3.9@3.9.21-1.el9_5
0:3.9.25-7.el9_8.2

Open the chart page →

1,968
rawfile-localpvrawfile0.15.21 of 6See more

rawfile-localpv rawfile 0.15.2

1 of the 6 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
openebs/rawfile-localpv:v0.15.2a39ef27ea28b
python3.13@3.13.5-2+deb13u4
no fix listed

Open the chart page →

2,794
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

15,583
ibm-mongodb-enterprise-helmredhat0.3.01 of 1See more

ibm-mongodb-enterprise-helm redhat 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ibmcom/ibm-enterprise-mongodb-ppc64le:4.4d28bf361327a
python3@3.6.8-31.el8
0:3.6.8-77.el8_10

Open the chart page →

12,248
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
python3@3.6.8-39.el8_4.1
0:3.6.8-77.el8_10

Open the chart page →

15,290
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
python3@3.6.8-39.el8_4.1
0:3.6.8-77.el8_10

Open the chart page →

15,290
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
python3@3.6.8-24.el8_2
0:3.6.8-77.el8_10

Open the chart page →

11,437
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
python3@3.6.8-47.el8_6.4
0:3.6.8-77.el8_10

Open the chart page →

16,060
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
python3@3.6.8-37.el8
0:3.6.8-77.el8_10

Open the chart page →

29,226
redminerestic-pvc-backupVerified publisher0.2.61 of 1See more

redmine restic-pvc-backup 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
python3.13@3.13.5-2+deb13u4
no fix listed

Open the chart page →

4,252
esphomeretsamedocVerified publisher2026.2.51 of 1See more

esphome retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
esphome/esphome:2024.3.09ab8cc88b28c
python3.11@3.11.2-6
no fix listed

Open the chart page →

6,562
httpbinrgnu1.0.01 of 1See more

httpbin rgnu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
citizenstig/httpbin:latestb81c818ccb86
python3.5@3.5.2-2ubuntu0~16.04.1
3.5.2-2ubuntu0~16.04.13+esm25

Open the chart page →

11,437
rhbk-neurofacerhbk-neurofaceVerified publisher1.0.02 of 4See more

rhbk-neuroface rhbk-neuroface 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
python3.9@3.9.25-7.el9_8
0:3.9.25-7.el9_8.2
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
python3.9@3.9.25-2.el9_7
0:3.9.25-7.el9_8.2

Open the chart page →

3,837
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
python3.11@3.11.2-6+deb12u4
no fix listed

Open the chart page →

15,623
reviewboardrock8sVerified publisher0.0.11 of 3See more

reviewboard rock8s 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
beanbag/reviewboard:latest6b840f546e1c
python3.10@3.10.12-1~22.04.17
python3.11@3.11.0~rc1-1~22.04.1
3.10.12-1~22.04.18
3.11.0~rc1-1~22.04.1+esm2

Open the chart page →

6,154
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
python3.10@3.10.6-1~22.04.2
3.10.12-1~22.04.18

Open the chart page →

12,999
devtron-enterpriseromholdings48.0.02 of 28See more

devtron-enterprise romholdings 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
python3.11@3.11.2-6
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
python3.11@3.11.2-6+deb12u6
no fix listed

Open the chart page →

66,542
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
python3.11@3.11.2-6
no fix listed

Open the chart page →

31,447
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

11,957
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
python3.10@3.10.12-1~22.04.15
3.10.12-1~22.04.18

Open the chart page →

7,491
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
python3@3.12.11-r0
3.12.14-r0

Open the chart page →

5,338
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
python3.12@3.12.3-1ubuntu0.12
3.12.3-1ubuntu0.17

Open the chart page →

6,293
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
python3.11@3.11.2-6+deb12u7
no fix listed

Open the chart page →

29,870
runwhen-localrunwhen-contribVerified publisher0.6.171 of 3See more

runwhen-local runwhen-contrib 0.6.17

1 of the 3 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
python3.13@3.13.5-2+deb13u4
no fix listed

Open the chart page →

3,673

Container images carrying it

901 by charts deploying them

A fixed version is listed for 17 of the 18 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
python3@3.6.8-67.el8_10
0:3.6.8-77.el8_10
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
python3.9@3.9.19-8.el9_5.1
0:3.9.25-7.el9_8.2
1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
python3.9@3.9.19-8.el9_5.1
0:3.9.25-7.el9_8.2
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
python3.8@3.8.5-1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
python3.11@3.11.2-6
no fix listed
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
python3.9@3.9.18-3.el9_4.5
0:3.9.25-7.el9_8.2
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
python3.9@3.9.18-3.el9_4.5
0:3.9.25-7.el9_8.2
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
python3@3.6.8-56.el8_9.3
0:3.6.8-77.el8_10
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
python3@3.6.8-56.el8_9
0:3.6.8-77.el8_10
1
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
python3@3.12.13-r0
3.12.14-r0
1
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
python3.13@3.13.5-2+deb13u4
no fix listed
1
quay.io/backube/volsync:0.16.00d03a6aad575
python3.9@3.9.25-7.el9_8
0:3.9.25-7.el9_8.2
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
python3@3.6.8-51.el8_8.1
0:3.6.8-77.el8_10
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
python3@3.6.8-37.el8
0:3.6.8-77.el8_10
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
python3@3.6.8-37.el8
0:3.6.8-77.el8_10
1
quay.io/everythingascode/apishift:v0.3.08fbbcd23b902
python3.9@3.9.25-7.el9_8
0:3.9.25-7.el9_8.2
1
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
python3.9@3.9.21-1.el9_5
0:3.9.25-7.el9_8.2
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
python3.6@3.6.9-1~18.04ubuntu1.8
3.6.9-1~18.04ubuntu1.13+esm10
1
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
python3@3.6.8-76.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
python3@3.6.8-45.el8
0:3.6.8-77.el8_10
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
python3@3.6.8-41.el8
0:3.6.8-77.el8_10
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
python3@3.6.8-67.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
python3@3.6.8-67.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
python3@3.6.8-45.el8
0:3.6.8-77.el8_10
1
quay.io/fiware/orion-ld:1.10.0b7ee7569a9a8
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
python3@3.6.8-39.el8_4
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-account:1.18.06b25aac03414
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-product-inventory:1.18.03a5d6dd30f1d
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-product-ordering-management:1.18.042c81c291f6f
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-quote:1.18.0d9ca3a334352
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-resource-catalog:1.18.0b0d853627c59
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-resource-function-activation:1.18.062a5acb63fd1
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-resource-inventory:1.18.0553b4a47730b
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-resource-order-management:1.18.0dd1778ad6203
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-service-catalog:1.18.074b0fad9e155
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-service-inventory:1.18.04be54e8cb5c0
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-service-order-management:1.18.0d2091785d544
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-software-management:1.18.01b74a2f7ba67
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/tmforum-usage-management:1.18.042f190c42926
python3@3.6.8-70.el8_10
0:3.6.8-77.el8_10
1
quay.io/fiware/trusted-issuers-list:0.9.13c886ce5c056
python3.9@3.9.21-2.el9_6.1
0:3.9.25-7.el9_8.2
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
python3@3.6.8-45.el8
0:3.6.8-77.el8_10
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
python3@3.6.8-48.el8_7
0:3.6.8-77.el8_10
1
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
python3@3.6.8-48.el8_7
0:3.6.8-77.el8_10
1
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
python3@3.6.8-48.el8_7
0:3.6.8-77.el8_10
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.