StackRadar

CVE-2026-15308

High

Advisory

Published 9 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
870
of 17,787 indexed, latest versions
Container images
901
deployed by those charts
Fix available
17 of 18
affected packages

Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations

Carried by container images the latest versions of 870 of 17,787 indexed charts deploy, on 901 images.

Affected packageAffected versionsFixed inImages
python-3.14apk3.14.2-r2, 3.14.4-r2, 3.14.6-r03.14.6-r46
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-13.10.213
python-3.13apk3.13.7-r0, 3.13.10-r0, 3.13.12-r23.13.14-r33
python-3.12apk3.12.0-r1, 3.12.9-r13.12.14-r22
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more3.11.0~rc1-1~22.04.1+esm2181
python3rpm3.6.8-15.1.el8, 3.6.8-23.el8, 3.6.8-24.el8_2, 3.6.8-24.el8_2.2+28 more0:3.6.8-77.el8_10, 0:3.6.8-77.el8_10.rocky.0, 3.12.14-1137
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more3.8.10-0ubuntu1~20.04.18+esm7100
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3+11 more3.12.3-1ubuntu0.1786
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+16 more3.10.12-1~22.04.1880
python3apk3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+7 more3.12.14-r0, 3.14.7-r075
python3.13deb3.13.5-2, 3.13.5-2+deb13u2, 3.13.5-2+deb13u4, 3.13.5-2+deb13u5no fix listed75
python3.9rpm3.9.16-1.el9, 3.9.16-1.el9_2.1, 3.9.16-1.el9_2.2, 3.9.18-1.el9_3.1+15 more0:3.9.25-7.el9_8.255
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more3.6.9-1~18.04ubuntu1.13+esm1044
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+9 more2.7.6-8ubuntu0.6+esm30, 2.7.12-1ubuntu0~16.04.18+esm22, 2.7.17-1~18.04ubuntu1.13+esm15, 2.7.18-13ubuntu1.5+esm943
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.93.5.2-2ubuntu0~16.04.13+esm2525
python3.14deb3.14.4-1, 3.14.4-1ubuntu0.13.14.4-1ubuntu0.28
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.73.4.3-1ubuntu1~14.04.7+esm217
python3.12rpm3.12.5-2.el9_5.20:3.12.13-3.el9_8.11
OSV records
ALPINE-CVE-2026-15308BIT-python-2026-15308CGA-2v5h-4pjx-m2vpCGA-7fq5-cfqp-92mfCGA-8wxj-3m53-wmwrDEBIAN-CVE-2026-15308RHSA-2026:39320RHSA-2026:39771RHSA-2026:39798RLSA-2026:39320RLSA-2026:39798UBUNTU-CVE-2026-15308AZL-92271
Also known as
BIT-libpython-2026-15308, BIT-python-min-2026-15308, CGA-qq9v-hh37-fr79, CGA-vh53-c7h5-695j, CGA-xm2p-hf9g-qw3m, PSF-2026-33, RHSA-2026:50064, RHSA-2026:50065, RHSA-2026:50816, USN-8744-1

Charts affected

870 by stars
ChartLatestAffected imagesRadar Score
paperlesshpVerified publisher0.1.11 of 5See more

paperless hp 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.3467097317623a
python3.13@3.13.5-2+deb13u2
no fix listed

Open the chart page →

26,579
hammerspace-csihscsi1.2.81 of 6See more

hammerspace-csi hscsi 1.2.8

1 of the 6 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
hammerspaceinc/csi-plugin:v1.2.8-rc2395bee4504fc
python3.9@3.9.21-2.el9_6.1
0:3.9.25-7.el9_8.2

Open the chart page →

4,440
httpbin2022httpbin2022Verified publisher0.1.11 of 1See more

httpbin2022 httpbin2022 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
mshanley80/httpbin2022:latest5b189a70c0fb
python3.8@3.8.10-0ubuntu1~20.04.6
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

8,732
eoloplanthttpd-eoloplant0.1.02 of 7See more

eoloplant httpd-eoloplant 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
python3@3.6.8-48.el8_7
0:3.6.8-77.el8_10
library/rabbitmq:3.9-management8a279e9396a8
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.18

Open the chart page →

32,336
nexus3huangchengwu-helm-chart0.1.01 of 1See more

nexus3 huangchengwu-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
sonatype/nexus3:3.53.04bd975493104
python3@3.6.8-48.el8_7.1
0:3.6.8-77.el8_10

Open the chart page →

4,462
hydrahydraVerified publisher0.9.51 of 2See more

hydra hydra 0.9.5

1 of the 2 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
python3.11@3.11.2-6+deb12u6
no fix listed

Open the chart page →

9,038
isolated-vmhydraVerified publisher0.9.41 of 1See more

isolated-vm hydra 0.9.4

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
python3.11@3.11.2-6+deb12u6
no fix listed

Open the chart page →

7,749
hyperglance-helmhyperglance-helmVerified publisher10.0.53 of 6See more

hyperglance-helm hyperglance-helm 10.0.5

3 of the 6 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
hyperglance/init:wildfly467ad8491bc3
python3.10@3.10.12-1~22.04.15
3.10.12-1~22.04.18
hyperglance/init:postgres9fd5faf1fe80
python3.10@3.10.12-1~22.04.15
3.10.12-1~22.04.18
hyperglance/init:apacheb2f8c6d52623
python3.10@3.10.12-1~22.04.15
3.10.12-1~22.04.18

Open the chart page →

11,171
ibexaibexaVerified publisher3.11.11 of 10See more

ibexa ibexa 3.11.1

1 of the 10 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
boky/postfix:4.4.0f3f247fd4252
python3.11@3.11.2-6+deb12u5
no fix listed

Open the chart page →

5,770
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ibmcom/microclimate-theia:lateste17bdccc5030
python2.7@2.7.12-1ubuntu0~16.04.2
2.7.12-1ubuntu0~16.04.18+esm22

Open the chart page →

57,728
ibm-object-storage-pluginibm-charts1.1.52 of 2See more

ibm-object-storage-plugin ibm-charts 1.1.5

2 of the 2 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
python3@3.6.8-23.el8
0:3.6.8-77.el8_10
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
python3@3.6.8-23.el8
0:3.6.8-77.el8_10

Open the chart page →

12,460
ibm-skydive-devibm-charts1.1.21 of 1See more

ibm-skydive-dev ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ibmcom/skydive:0.22.0395e60cc6e3d
python2.7@2.7.15~rc1-1ubuntu0.1
2.7.17-1~18.04ubuntu1.13+esm15

Open the chart page →

12,632
ibm-swift-sampleibm-charts1.1.21 of 1See more

ibm-swift-sample ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ibmcom/icp-swift-sample:latestb5d8c6714dbc
python2.7@2.7.12-1ubuntu0~16.04.3
python3.5@3.5.2-2ubuntu0~16.04.4
2.7.12-1ubuntu0~16.04.18+esm22
3.5.2-2ubuntu0~16.04.13+esm25

Open the chart page →

25,184
ibm-ws-dyn-agent-devibm-charts1.0.01 of 1See more

ibm-ws-dyn-agent-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
python3.5@3.5.2-2ubuntu0~16.04.4
3.5.2-2ubuntu0~16.04.13+esm25

Open the chart page →

19,309
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
python3.9@3.9.25-3.el9_7.2
0:3.9.25-7.el9_8.2

Open the chart page →

3,181
eoloserverihuertas2021-vmartinp2021-helm0.1.02 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
python3@3.6.8-48.el8_7
0:3.6.8-77.el8_10
library/rabbitmq:3.9-management8a279e9396a8
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.18

Open the chart page →

27,812
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.17

Open the chart page →

9,032
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:1.2.0e4770285aaf7
python3.8@3.8.10-0ubuntu1~20.04.1
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

37,844
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
python3.11@3.11.2-6+deb12u6
no fix listed

Open the chart page →

11,838
plausible-analyticsimioVerified publisher0.4.21 of 5See more

plausible-analytics imio 0.4.2

1 of the 5 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v3.0.114c1afde21d6
python3@3.12.10-r0
3.12.14-r0

Open the chart page →

10,152
kore-boardimprowisedVerified publisher0.5.81 of 4See more

kore-board improwised 0.5.8

1 of the 4 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
python3.6@3.6.9-1~18.04ubuntu1.9
3.6.9-1~18.04ubuntu1.13+esm10

Open the chart page →

16,226
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.18

Open the chart page →

10,542
gmaintelVerified publisher0.1.01 of 1See more

gma intel 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

7,697
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

18,137
map5gintelVerified publisher1.0.01 of 1See more

map5g intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

7,697
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization-streaming:3.01a89327e499b
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

11,123
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
python3.11@3.11.2-6
no fix listed

Open the chart page →

16,558
inventreeinventreeOfficialVerified publisher0.4.281 of 2See more

inventree inventree 0.4.28

1 of the 2 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
inventree/inventree:1.5.4a946ec09da3e
python3.13@3.13.5-2+deb13u4
no fix listed

Open the chart page →

5,757
daveit-at-mOfficialVerified publisher0.2.157 of 11See more

dave it-at-m 0.2.15

7 of the 11 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
python3.9@3.9.25-7.el9_8
0:3.9.25-7.el9_8.2
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
python3.9@3.9.25-7.el9_8
0:3.9.25-7.el9_8.2
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
python3.9@3.9.23-2.el9
0:3.9.25-7.el9_8.2
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
python3.9@3.9.25-7.el9_8
0:3.9.25-7.el9_8.2
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
python3.9@3.9.25-7.el9_8
0:3.9.25-7.el9_8.2
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
python3.9@3.9.25-7.el9_8
0:3.9.25-7.el9_8.2
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal:10.0.0d352df1b94b6
python3.9@3.9.25-7.el9_8
0:3.9.25-7.el9_8.2

Open the chart page →

15,245
kf-app-eaiit-at-mOfficialVerified publisher0.1.71 of 1See more

kf-app-eai it-at-m 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
python3.9@3.9.21-2.el9_6.2
0:3.9.25-7.el9_8.2

Open the chart page →

1,965
wjh-rechnerit-at-mOfficialVerified publisher1.0.41 of 1See more

wjh-rechner it-at-m 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
python3.9@3.9.18-1.el9_3.1
0:3.9.25-7.el9_8.2

Open the chart page →

3,487
zammad-ldap-syncit-at-mVerified publisher0.6.51 of 1See more

zammad-ldap-sync it-at-m 0.6.5

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
python3.9@3.9.25-7.el9_8
0:3.9.25-7.el9_8.2

Open the chart page →

1,364
tekton-git-listeneritsmethemojoVerified publisher0.1.11 of 1See more

tekton-git-listener itsmethemojo 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
library/buildpack-deps:scmac978b783657
python3.13@3.13.5-2+deb13u4
no fix listed

Open the chart page →

2,178
thehiveittrident-oss0.1.01 of 6See more

thehive ittrident-oss 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
library/cassandra:4.0093ee8ee5eb2
python3.11@3.11.2-6+deb12u8
no fix listed

Open the chart page →

6,037
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
python3.12@3.12.3-1
3.12.3-1ubuntu0.17

Open the chart page →

45,392
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
python3.11@3.11.2-6+deb12u5
no fix listed

Open the chart page →

10,816
jasperjasperVerified publisher1.0.2031 of 2See more

jasper jasper 1.0.203

1 of the 2 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
python3.11@3.11.2-6+deb12u8
no fix listed

Open the chart page →

9,148
jx-app-anchorejenkins-x0.0.41 of 2See more

jx-app-anchore jenkins-x 0.0.4

1 of the 2 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.7.1ed9b3badd17c
python3@3.6.8-15.1.el8
0:3.6.8-77.el8_10

Open the chart page →

9,853
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
python3@3.6.8-23.el8
0:3.6.8-77.el8_10

Open the chart page →

12,856
dayz-dedicated-server-razorbladex401jespernohrVerified publisher1.0.31 of 1See more

dayz-dedicated-server-razorbladex401 jespernohr 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
razorbladex401/dayz:latest6a4d79248e7d
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.18

Open the chart page →

5,256
homebridgejespernohrVerified publisher0.2.01 of 1See more

homebridge jespernohr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
python3.12@3.12.3-1ubuntu0.16
3.12.3-1ubuntu0.17

Open the chart page →

2,203
discord-experiencebotjfwenischVerified publisher0.7.41 of 1See more

discord-experiencebot jfwenisch 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
python3.6@3.6.9-1~18.04ubuntu1.12
3.6.9-1~18.04ubuntu1.13+esm10

Open the chart page →

7,842
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
python3.12@3.12.3-1ubuntu0.3
3.12.3-1ubuntu0.17

Open the chart page →

6,648
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
python3.12@3.12.3-1ubuntu0.3
3.12.3-1ubuntu0.17

Open the chart page →

6,629
proxmox-exporterjhofer-cloud1.4.01 of 1See more

proxmox-exporter jhofer-cloud 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
prompve/prometheus-pve-exporter:3.10.04867684c0a93
python3@3.14.5-r0
3.14.7-r0

Open the chart page →

349
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
python3.11@3.11.2-6+deb12u3
no fix listed

Open the chart page →

22,665
shinsei-managerjtektVerified publisher0.2.04 of 8See more

shinsei-manager jtekt 0.2.0

4 of the 8 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
python3.11@3.11.2-6+deb12u6
no fix listed
moreillon/group-manager:latest3caa8f710ee0
python3.11@3.11.2-6+deb12u6
no fix listed
moreillon/user-manager:v5.0.2e1c9bfab5c16
python3.11@3.11.2-6
no fix listed
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
python3.11@3.11.2-6
no fix listed

Open the chart page →

59,560
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
python3.11@3.11.2-6
no fix listed

Open the chart page →

16,626
palworld-serverk8s-chartsVerified publisher1.2.11 of 1See more

palworld-server k8s-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.5.0b4ac9ee22483
python3.13@3.13.5-2+deb13u2
no fix listed

Open the chart page →

3,433
valheim-serverk8s-chartsVerified publisher1.3.01 of 1See more

valheim-server k8s-charts 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-15308.

Container imageDigestPackageFixed in
mbround18/valheim:3.1.070bd4da591cd
python3.10@3.10.12-1~22.04.9
3.10.12-1~22.04.18

Open the chart page →

6,136

Container images carrying it

901 by charts deploying them

A fixed version is listed for 17 of the 18 affected packages.

Container imageDigestPackageFixed inUsed by
kubearmor/kubearmor:stablea08141311045
python3@3.12.13-r0
3.12.14-r0
1
kubearmor/kubearmor-init:stable236ade6e67b1
python3@3.12.13-r0
3.12.14-r0
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
python3.6@3.6.9-1~18.04ubuntu1
3.6.9-1~18.04ubuntu1.13+esm10
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.17
1
kubeshop/bitnami-mongodb:8.3.8d48b172d99d8
python3.12@3.12.3-1ubuntu0.15
3.12.3-1ubuntu0.17
1
kusionstack/kusion:v0.14.0126c8f0b0976
python3.10@3.10.12-1~22.04.8
3.10.12-1~22.04.18
1
laly9999/node-app:1dd0e503913e1
python3.11@3.11.2-6+deb12u6
no fix listed
1
lancachenet/monolithic:latest37f28b362c93
python3.12@3.12.3-1ubuntu0.16
3.12.3-1ubuntu0.17
1
langgenius/dify-api:1.16.1dcefa5f7c47c
python3.11@3.11.2-6+deb12u8
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
python3.12@3.12.3-1ubuntu0.13
3.12.3-1ubuntu0.17
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
python3.12@3.12.3-1ubuntu0.9
3.12.3-1ubuntu0.17
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
python3.12@3.12.3-1ubuntu0.16
3.12.3-1ubuntu0.17
1
library/buildpack-deps:scmac978b783657
python3.13@3.13.5-2+deb13u4
no fix listed
1
library/cassandra:4.0093ee8ee5eb2
python3.11@3.11.2-6+deb12u8
no fix listed
1
library/golang:latest512690a56605
python3.13@3.13.5-2+deb13u4
no fix listed
1
library/nextcloud:31.0.6-apache588609d76b21
python3.11@3.11.2-6+deb12u6
no fix listed
1
library/nextcloud:31.0.10-apacheb7faa1653c39
python3.13@3.13.5-2
no fix listed
1
library/nextcloud:34.0.4-apachede4ad9389386
python3.13@3.13.5-2+deb13u4
no fix listed
1
library/node:208f693eaa7e0a
python3.11@3.11.2-6+deb12u6
no fix listed
1
library/node:latestf5d1cc40abc1
python3.13@3.13.5-2+deb13u4
no fix listed
1
library/python:3.1070c9cc675605
python3.13@3.13.5-2+deb13u4
no fix listed
1
library/python:3.8d41127070014
python3.11@3.11.2-6+deb12u3
no fix listed
1
library/python:3.9da5aee29682d
python3.13@3.13.5-2
no fix listed
1
library/rabbitmq:3.11.5-management1b0f675d2f24
python3.8@3.8.10-0ubuntu1~20.04.6
3.8.10-0ubuntu1~20.04.18+esm7
1
library/rabbitmq:3.7-managementb6dd45cc35b3
python3.6@3.6.9-1~18.04ubuntu1.1
3.6.9-1~18.04ubuntu1.13+esm10
1
library/redmine:6.1.204ac44a2595b
python3.13@3.13.5-2+deb13u2
no fix listed
1
library/varnish:7.5.04d0bb287d87b
python3.11@3.11.2-6+deb12u5
no fix listed
1
library/wordpress:6.4.3-apache8ae66efb09a2
python3.11@3.11.2-6
no fix listed
1
library/znc:1.10.1c731c6a9b8b6
python3@3.12.13-r0
3.12.14-r0
1
linode/linode-blockstorage-csi-driver:v1.1.409f3282bf53d
python3@3.12.13-r0
3.12.14-r0
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
python2.7@2.7.17-1~18.04ubuntu1.6
python3.6@3.6.9-1~18.04ubuntu1.4
2.7.17-1~18.04ubuntu1.13+esm15
3.6.9-1~18.04ubuntu1.13+esm10
1
linuxserver/calibre-web:0.6.24241009026e6f
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.17
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm7
1
linuxserver/codimd:latestb801bbcf6386
python2.7@2.7.17-1~18.04ubuntu1.2
2.7.17-1~18.04ubuntu1.13+esm15
1
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
python3@3.12.10-r1
3.12.14-r0
1
linuxserver/deluge:18.04.10ac871624394
python3.6@3.6.9-1~18.04ubuntu1.4
3.6.9-1~18.04ubuntu1.13+esm10
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
python3.6@3.6.9-1~18.04ubuntu1.4
3.6.9-1~18.04ubuntu1.13+esm10
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
python3.6@3.6.9-1~18.04ubuntu1.4
3.6.9-1~18.04ubuntu1.13+esm10
1
linuxserver/qbittorrent:5.2.2dd24a5f3db32
python3@3.12.13-r0
3.12.14-r0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
python-3.13@3.13.12-r2
3.13.14-r3
1
loeken/jellyfin:10.11.87efbc24e47b0
python3@3.12.13-r0
3.12.14-r0
1
logiqai/flash:v3.10.265b996bc7bdc
python3.11@3.11.2-6+deb12u3
no fix listed
1
longhornio/longhorn-manager:v1.2.3dca34321452c
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
python3.6@3.6.9-1~18.04ubuntu1.4
3.6.9-1~18.04ubuntu1.13+esm10
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
python3.11@3.11.2-6+deb12u6
no fix listed
1
louislam/uptime-kuma:2.5.33e24e96c89ef
python3.11@3.11.2-6+deb12u7
no fix listed
1
louislam/uptime-kuma:2.0.24c364ef96aad
python3.11@3.11.2-6+deb12u6
no fix listed
1
louislam/uptime-kuma:2.4.091e963bfda56
python3.11@3.11.2-6+deb12u7
no fix listed
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
python3.11@3.11.2-6+deb12u6
no fix listed
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.