StackRadar

CVE-2026-15830

Medium

Advisory

Published 4 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
112
of 17,781 indexed, latest versions
Container images
107
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 112 of 17,781 indexed charts deploy, on 107 images.

Affected packageAffected versionsFixed inImages
djangopypi1.11.11, 1.11.24, 1.11.29, 2.2.13+64 more5.2.17107
OSV records
PYSEC-2026-3717
Also known as
BIT-django-2026-15830

Charts affected

112 by stars
ChartLatestAffected imagesRadar Score
libretimepodzone-chartsVerified publisher0.4.11 of 9See more

libretime podzone-charts 0.4.1

1 of the 9 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-api:latesteae026cc8909
django@4.2.23
5.2.17

Open the chart page →

11,149
reviewboardrock8sVerified publisher0.0.11 of 3See more

reviewboard rock8s 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
beanbag/reviewboard:latest6b840f546e1c
django@4.2.30
5.2.17

Open the chart page →

6,084
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
django@5.2.7
5.2.17

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
django@5.2.8
5.2.17

Open the chart page →

4,499
linkdingrubxkubeVerified publisher1.2.31 of 1See more

linkding rubxkube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.46.20c0a9a04c7eb
django@6.0.7
5.2.17

Open the chart page →

2,051
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
django@6.0.5
5.2.17

Open the chart page →

1,577
safe-stacksafe-global0.1.02 of 9See more

safe-stack safe-global 0.1.0

2 of the 9 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
django@6.0.5
5.2.17
safeglobal/safe-transaction-service:latest80db836cc5d5
django@5.2.15
5.2.17

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
safeglobal/safe-transaction-service:latest80db836cc5d5
django@5.2.15
5.2.17

Open the chart page →

16,620
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
django@4.2.30
5.2.17

Open the chart page →

11,636
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
django@3.0.4
5.2.17

Open the chart page →

8,694
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
django@4.2.16
5.2.17

Open the chart page →

4,731
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-15830.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
django@4.0.5
5.2.17

Open the chart page →

3,392

Container images carrying it

107 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
django@5.2.16
5.2.17
7
cloudve/cloudlaunch-server:latest4a3d7fae90bb
django@3.2.9
5.2.17
3
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
django@1.11.11
5.2.17
2
safeglobal/safe-config-service:latest09a5e495c219
django@6.0.5
5.2.17
2
safeglobal/safe-transaction-service:latest80db836cc5d5
django@5.2.15
5.2.17
2
taigaio/taiga-back:latest4beed8f62c9f
django@3.2.25
5.2.17
2
weblate/weblate:4.2.2-169c160d37a3c
django@3.1.1
5.2.17
2
alexeyr7/sf-test-app:latestdf0b41fdbd53
django@4.0.5
5.2.17
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
django@5.0.14
5.2.17
1
archivebox/archivebox:0.7.41a5a37331091
django@3.1.14
5.2.17
1
baserow/backend:2.3.37c00549b3a6f
django@5.2.15
5.2.17
1
baserow/backend:1.31.1e0b3c8130b91
django@5.0.9
5.2.17
1
baserow/baserow:1.30.1df0c42eb67e8
django@5.0.9
5.2.17
1
beanbag/reviewboard:latest6b840f546e1c
django@4.2.30
5.2.17
1
blackducksoftware/bdba-frontend:2026.6.3b10eaea94fd3
django@5.2.16
5.2.17
1
camerahub/camerahub:0.36.23a5af37dd6e1b
django@3.2.18
5.2.17
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
django@5.2.12
5.2.17
1
codecov/self-hosted-api:24.4.10475cb1c3136
django@4.2.7
5.2.17
1
codecov/self-hosted-worker:24.4.1837f546b479b
django@4.2.11
5.2.17
1
cr0hn/ja-shortener:v0.1.414482d0bc4a1
django@5.2.3
5.2.17
1
datamate/seafile-professional:11.0.202dd66b722464
django@4.2.23
5.2.17
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
django@4.2.11
5.2.17
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
django@5.0.7
5.2.17
1
ddosify/selfhosted_backend:3.2.93c11e3182652
django@4.1.13
5.2.17
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
django@4.1.13
5.2.17
1
ddosify/selfhosted_hammermanager:1.2.471b8768f49bc
django@3.2.24
5.2.17
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
django@4.1.13
5.2.17
1
defectdojo/defectdojo-django:3.3.1b140a89a34e2
django@5.2.16
5.2.17
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
django@3.2.8
5.2.17
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
django@2.2.17
5.2.17
1
galaxy/cloudman-server:lateste5c265fe9fcd
django@4.0.7
5.2.17
1
gethue/hue:4.11.011b649636e68
django@3.2.16
5.2.17
1
gethue/hue:4.10.05702b2c37ff9
django@3.2.4
5.2.17
1
gethue/hue:latest7d5c1b9f8a79
django@4.2.23
5.2.17
1
grafana/oncall:v1.16.5499851658393
django@4.2.22
5.2.17
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
django@2.2.13
5.2.17
1
ha33ona/python:test6affdfc644d0
django@2.2.26
5.2.17
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
django@4.2
5.2.17
1
heartexlabs/label-studio:latestaa461572e8f9
django@5.1.15
5.2.17
1
hhyo/archery:v1.9.11aa41843419e
django@4.1.1
5.2.17
1
improwised/erpnext-worker:v13.4.197280b55cbd4
django@1.11.29
5.2.17
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
django@4.2.27
5.2.17
1
inventree/inventree:1.5.4a946ec09da3e
django@5.2.16
5.2.17
1
kobotoolbox/kobocat:2.022.24ab15679454415
django@2.2.28
5.2.17
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
django@2.2.27
5.2.17
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
django@4.0.5
5.2.17
1
linuxserver/babybuddy:1.10.2f7d7c7704249
django@4.0.2
5.2.17
1
linuxserver/healthchecks:version-v1.20.050792a72fc71
django@3.2
5.2.17
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
django@4.1.7
5.2.17
1
makeplane/backend-commercial:v3.2.0aab6a29da5fe
django@5.2.16
5.2.17
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.