StackRadar

CVE-2026-15830

Medium

Advisory

Published 4 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
112
of 17,781 indexed, latest versions
Container images
107
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 112 of 17,781 indexed charts deploy, on 107 images.

Affected packageAffected versionsFixed inImages
djangopypi1.11.11, 1.11.24, 1.11.29, 2.2.13+64 more5.2.17107
OSV records
PYSEC-2026-3717
Also known as
BIT-django-2026-15830

Charts affected

112 by stars
ChartLatestAffected imagesRadar Score
libretimepodzone-chartsVerified publisher0.4.11 of 9See more

libretime podzone-charts 0.4.1

1 of the 9 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-api:latesteae026cc8909
django@4.2.23
5.2.17

Open the chart page →

11,149
reviewboardrock8sVerified publisher0.0.11 of 3See more

reviewboard rock8s 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
beanbag/reviewboard:latest6b840f546e1c
django@4.2.30
5.2.17

Open the chart page →

6,084
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
django@5.2.7
5.2.17

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
django@5.2.8
5.2.17

Open the chart page →

4,499
linkdingrubxkubeVerified publisher1.2.31 of 1See more

linkding rubxkube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.46.20c0a9a04c7eb
django@6.0.7
5.2.17

Open the chart page →

2,051
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
django@6.0.5
5.2.17

Open the chart page →

1,577
safe-stacksafe-global0.1.02 of 9See more

safe-stack safe-global 0.1.0

2 of the 9 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
django@6.0.5
5.2.17
safeglobal/safe-transaction-service:latest80db836cc5d5
django@5.2.15
5.2.17

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
safeglobal/safe-transaction-service:latest80db836cc5d5
django@5.2.15
5.2.17

Open the chart page →

16,620
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
django@4.2.30
5.2.17

Open the chart page →

11,636
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
django@3.0.4
5.2.17

Open the chart page →

8,694
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
django@4.2.16
5.2.17

Open the chart page →

4,731
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
django@4.0.5
5.2.17

Open the chart page →

3,392

Container images carrying it

107 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mathesar/mathesar:0.12.0091757cb01fe
django@4.2.29
5.2.17
1
milesmcc/shynet:v0.13.1ba54f7797a6b
django@4.1.10
5.2.17
1
milesmcc/shynet:v0.12.0e821e31140f7
django@3.2.10
5.2.17
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
django@1.11.24
5.2.17
1
netboxcommunity/netbox:v3.2.83d652dca5351
django@4.0.7
5.2.17
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
django@4.2.11
5.2.17
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
django@4.2.30
5.2.17
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
django@1.11.11
5.2.17
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
django@5.0.3
5.2.17
1
opencsghq/label-studio:v2.5.047e22aa71870
django@5.1.15
5.2.17
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
django@5.1.15
5.2.17
1
opennode/waldur-mastermind:8.1.24c82b15d9042
django@6.0.7
5.2.17
1
openzaak/open-notificaties:1.3.02e65313b9b10
django@3.2.12
5.2.17
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
django@3.2.12
5.2.17
1
pretix/standalone:2026.7.05df3b7aa852e
django@5.2.16
5.2.17
1
prowlercloud/prowler-api:5.31.14f252d579be2
django@5.1.15
5.2.17
1
psono/psono-server:5.0.03b974b43ea03
django@4.2.16
5.2.17
1
recordsansible/ara-api:latest9dfd6e18f474
django@5.2.16
5.2.17
1
redislabs/redisinsight:1.14.0b03ab1426d0d
django@4.1.7
5.2.17
1
seafileltd/seafile-mc:9.0.106693911bcc40
django@3.2.14
5.2.17
1
seafileltd/seafile-mc:10.0.170628f29c663
django@3.2.16
5.2.17
1
seafileltd/seafile-mc:9.0.97ac833196f60
django@3.2.14
5.2.17
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
django@4.2.15
5.2.17
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
django@2.2.14
5.2.17
1
signalen/backend:2.50.14760256000738
django@4.2.30
5.2.17
1
sissbruecker/linkding:1.46.20c0a9a04c7eb
django@6.0.7
5.2.17
1
sissbruecker/linkding:1.35.00c5dddf0b37c
django@5.1.1
5.2.17
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
django@5.1.10
5.2.17
1
swisscomcloud/esc-vm-scheduler-web:latestb6639d1a922e
django@3.2.16
5.2.17
1
taigaio/taiga-back:6.4.29f97323cc150
django@2.2.24
5.2.17
1
vabene1111/recipes:2.3.50f8d061895e9
django@5.2.8
5.2.17
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
django@3.2.11
5.2.17
1
weblate/weblate:3.11.3-182848df56ecd
django@3.0.4
5.2.17
1
wger/server:2.6997ead43aabd
django@6.0.6
5.2.17
1
ghcr.io/argonix-io/argonix-api:1.0.068e17a8aaa40
django@6.0.7
5.2.17
1
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
django@5.2.11
5.2.17
1
ghcr.io/gabe565/obico/web:latesta5c1daef46c0
django@4.0.10
5.2.17
1
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
django@5.2.14
5.2.17
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
django@5.2.11
5.2.17
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
django@5.2.15
5.2.17
1
ghcr.io/libretime/libretime-api:latesteae026cc8909
django@4.2.23
5.2.17
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
django@5.1.4
5.2.17
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
django@5.0.4
5.2.17
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
django@5.1.1
5.2.17
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
django@5.2.7
5.2.17
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
django@5.2.7
5.2.17
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
django@5.2.7
5.2.17
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
django@4.0.6
5.2.17
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
django@4.2.7
5.2.17
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
django@5.2.7
5.2.17
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.