StackRadar

CVE-2026-1703

Low

Advisory

Published 2 Feb 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.0
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,232
of 17,787 indexed, latest versions
Container images
1,182
deployed by those charts
Fix available
1 of 2
affected packages

pip Path Traversal vulnerability

Carried by container images the latest versions of 1,232 of 17,787 indexed charts deploy, on 1,182 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+63 more26.01,175
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+24 moreno fix listed139
OSV records
DEBIAN-CVE-2026-1703GHSA-6vgw-5pg2-w6jpUBUNTU-CVE-2026-1703
Also known as
PYSEC-2026-1796

Charts affected

1,232 by stars
ChartLatestAffected imagesRadar Score
osba-container-instances-demoazure-sample0.1.01 of 1See more

osba-container-instances-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
neilpeterson/osba-container-instances-demo:latest6527b05d5d03
pip@9.0.1
26.0

Open the chart page →

3,212
osba-cosmos-mongodb-demoazure-sample0.1.01 of 1See more

osba-cosmos-mongodb-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
pip@9.0.1
26.0

Open the chart page →

2,904
osba-mysql-demoazure-sample0.1.01 of 1See more

osba-mysql-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
neilpeterson/osba-mysql-demo:latest5859d68a6c9f
pip@9.0.2
26.0

Open the chart page →

2,895
osba-storage-demoazure-sample0.1.01 of 1See more

osba-storage-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
neilpeterson/osba-storage-demo:latest29d229ab446e
pip@9.0.1
26.0

Open the chart page →

3,425
osba-text-analytics-demoazure-sample0.1.01 of 1See more

osba-text-analytics-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
neilpeterson/osba-text-analytics-demo:latest969af3cb8466
pip@10.0.1
26.0

Open the chart page →

3,089
twitter-sentimentazure-sample0.1.03 of 3See more

twitter-sentiment azure-sample 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
neilpeterson/chart-tweet:latest64fd8dab075f
pip@9.0.1
26.0
neilpeterson/get-tweet:v28b645ac1a23e
pip@10.0.1
26.0
neilpeterson/process-tweet:latest39ce9f92e899
pip@10.0.1
26.0

Open the chart page →

11,833
backstage-pyactionsbackstage-pyactionsVerified publisher0.1.01 of 1See more

backstage-pyactions backstage-pyactions 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
mawad98/backstage-pyactions:demo99422c56a274
pip@24.0
26.0

Open the chart page →

2,738
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
conduction/balance-registration-varnish:dev07c44005da9d
pip@9.0.1
26.0

Open the chart page →

8,408
pvc-exporterbalihb-pvc-exporterVerified publisher0.2.42 of 2See more

pvc-exporter balihb-pvc-exporter 0.2.4

2 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
balihb/block-pvc-scanner:0.2.45b95e1cf1158
pip@21.2.4
26.0
balihb/pod-pvc-mapping:0.2.4ee48e79f5d76
pip@21.2.4
26.0

Open the chart page →

2,765
bookinfobasictechno0.1.01 of 6See more

bookinfo basictechno 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.17.06668bcf42ef0
pip@20.1.1
26.0

Open the chart page →

20,671
mealiebdclark-helm-chartsVerified publisher0.1.151 of 1See more

mealie bdclark-helm-charts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
pip@25.0.1
26.0

Open the chart page →

4,028
wyoming-piperbdclark-helm-chartsVerified publisher0.1.41 of 1See more

wyoming-piper bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
rhasspy/wyoming-piper:2.5.27d39aafac409
pip@25.1.1
python-pip@25.1.1+dfsg-1
26.0
no fix listed

Open the chart page →

1,170
helm-samplebehnambm-helm-chart1.0.12 of 3See more

helm-sample behnambm-helm-chart 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
behnambm/docker-sample:v1bd3ad88afff9
pip@23.0.1
26.0
library/mysql:8b3b90af2a655
pip@25.3
26.0

Open the chart page →

2,727
pagesberrutig-pages1.0.01 of 3See more

pages berrutig-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,190
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
pip@20.0.2
python-pip@20.0.2-5ubuntu1.6
26.0
no fix listed

Open the chart page →

7,956
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
pip@21.1.2
python-pip@9.0.1-2.3~ubuntu1.18.04.5
26.0
no fix listed

Open the chart page →

22,891
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.0
no fix listed

Open the chart page →

10,145
istio-bookinfobookinfo1.2.21 of 6See more

istio-bookinfo bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.15.00a5eb4795952
pip@19.1.1
26.0

Open the chart page →

18,980
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-rwd:log74ded2d92f07
pip@23.0.1
26.0

Open the chart page →

26,996
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.26.2e271016441af
pip@24.0
26.0

Open the chart page →

8,323
kube-prometheus-stackbook-k8sinfra-v265.5.11 of 6See more

kube-prometheus-stack book-k8sinfra-v2 65.5.1

1 of the 6 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
pip@24.2
26.0

Open the chart page →

6,036
puppetboardbootcVerified publisher0.1.41 of 1See more

puppetboard bootc 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
bootc/puppetboard:1.1.0f1383295e7be
pip@19.2.3
26.0

Open the chart page →

1,292
flaresolverrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

flaresolverr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
pip@24.0
26.0

Open the chart page →

27,274
pagesbrian-pages1.0.01 of 3See more

pages brian-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,190
pagesbrixton-mayuribhavsar23-pages1.0.01 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,190
pagesbrixton-pages1.0.01 of 3See more

pages brixton-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,190
couchpotatobryanalves0.3.01 of 1See more

couchpotato bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
pip@19.3.1
26.0

Open the chart page →

2,018
medusabryanalves0.1.01 of 1See more

medusa bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
linuxserver/medusa:v0.3.9-ls340a5f5114128b
pip@19.2.3
26.0

Open the chart page →

147
sickchillbryanalves0.3.01 of 1See more

sickchill bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
pip@19.3.1
26.0

Open the chart page →

2,504
sickragebryanalves0.1.01 of 1See more

sickrage bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
bryanalves/sickrage:latest42f0a130001d
pip@9.0.0
26.0

Open the chart page →

923
frigatebryopsida0.2.11 of 2See more

frigate bryopsida 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pip@20.3.4
26.0

Open the chart page →

2,573
pagescamden-pages1.0.01 of 3See more

pages camden-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,190
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
pip@22.0.4
26.0

Open the chart page →

2,507
bucket-clonercamptocamp31.0.41 of 1See more

bucket-cloner camptocamp3 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
camptocamp/bucket-cloner:latestacfafc308d88
pip@21.2.1
26.0

Open the chart page →

4,518
ekorrecamptocamp30.1.11 of 1See more

ekorre camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
camptocamp/ekorre:0.1.035c91d5fda04
pip@20.0.2
26.0

Open the chart page →

3,891
pghoardcamptocamp35.8.11 of 1See more

pghoard camptocamp3 5.8.1

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
camptocamp/pghoard:10bff736b15623
pip@18.1
26.0

Open the chart page →

2,813
prometheus-operatorcamptocamp35.15.11 of 5See more

prometheus-operator camptocamp3 5.15.1

1 of the 5 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.0.16899ccd0b1f54
pip@19.0.3
26.0

Open the chart page →

2,490
snow-webhookcamptocamp31.0.01 of 1See more

snow-webhook camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
camptocamp/snow-webhook:latest2924b43dbf40
pip@18.1
26.0

Open the chart page →

1,310
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
pip@24.3.1
26.0

Open the chart page →

10,776
pagescarina-pages1.0.01 of 3See more

pages carina-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,190
pagescarmel-pages-dell1.0.01 of 3See more

pages carmel-pages-dell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,190
castai-hibernatecastaiVerified publisher0.2.121 of 1See more

castai-hibernate castai 0.2.12

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
castai/hibernate:v0.14da62858c8381
pip@23.0.1
26.0

Open the chart page →

1,146
temporalcastaiVerified publisher0.54.21 of 14See more

temporal castai 0.54.2

1 of the 14 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.26.237e2e33dbd7b
pip@24.0
26.0

Open the chart page →

16,198
catalyst-agentscatalyst-agents0.1.301 of 18See more

catalyst-agents catalyst-agents 0.1.30

1 of the 18 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
alpine/k8s:1.32.3eec354133193
pip@25.0.1
26.0

Open the chart page →

15,027
tsoragecetic0.4.111 of 8See more

tsorage cetic 0.4.11

1 of the 8 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.0.1c87b1c07fb53
pip@8.1.2
26.0

Open the chart page →

12,018
opencvecfi20170.1.22 of 7See more

opencve cfi2017 0.1.2

2 of the 7 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
pip@24.3.1
26.0
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
pip@25.0.1
26.0

Open the chart page →

15,371
pypi-servercgsimmons0.1.01 of 1See more

pypi-server cgsimmons 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
pypiserver/pypiserver:v1.3.2303ac89b2aa2
pip@19.3.1
26.0

Open the chart page →

506
ctk-walkthroughchaostoolkit-walkthrough0.1.03 of 3See more

ctk-walkthrough chaostoolkit-walkthrough 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
chaostoolkit/back:latest734f3af86125
pip@20.2.4
26.0
chaostoolkit/front:latest7f4a7eb9f7df
pip@20.2.4
26.0
chaostoolkit/middle:latestb95ba4961cfc
pip@20.3
26.0

Open the chart page →

5,557
suggestarrcharliecharts0.4.41 of 1See more

suggestarr charliecharts 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
ciuse99/suggestarr:v1.0.20d72768245ef5
pip@24.3.1
26.0

Open the chart page →

1,126
chart-appchart-app0.3.01 of 2See more

chart-app chart-app 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
pip@25.3
26.0

Open the chart page →

1,775

Container images carrying it

1,182 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
pip@19.1.1
26.0
1
ihatemoney/ihatemoney:5.2.0457fda1feb32
pip@22.0.4
26.0
1
ilum/streamlit-example:1.0.0ce5dcdeb22ba
pip@25.2
26.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
pip@21.1.2
26.0
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
pip@20.0.2
python-pip@20.0.2-5ubuntu1.6
26.0
no fix listed
1
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
pip@21.1.3
26.0
1
irakli/ms-hello-python:latest9e7a91ba9ae0
pip@22.2.2
26.0
1
istio/examples-bookinfo-productpage-v1:1.17.06668bcf42ef0
pip@20.1.1
26.0
1
istio/examples-helloworld-v1:latest328b237e4fb1
pip@23.2.1
26.0
1
istio/examples-helloworld-v2:latest0a7f02b2c7c9
pip@23.2.1
26.0
1
jaedb/iris:latest048cfbf58d57
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.0
no fix listed
1
jakuboskera/guestbook:v0.3.04989afa06e74
pip@21.2.4
26.0
1
jakuboskera/todo:v0.2.3714b1adbbc2d
pip@21.2.4
26.0
1
jamoos/kweather:history163e2e8a6e87
pip@23.0.1
26.0
1
jertel/elastalert2:2.2.34dcc0ef93efc
pip@21.2.4
26.0
1
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
pip@23.0.1
26.0
1
jmferrer/azure-devops-agent:latest030f68ec6998
pip@9.0.3
26.0
1
john19968010/fastapi-template:latest31a90f6bd69c
pip@22.3.1
26.0
1
jonasal/devpi-server:6.17.0-alpineec1eee99a18d
pip@25.3
26.0
1
josh5/unmanic:0.2.64d49c4816260
pip@22.0.2
python-pip@22.0.2+dfsg-1ubuntu0.4
26.0
no fix listed
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
pip@23.0.1
26.0
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
pip@23.0.1
26.0
1
julb/alertmanager-gchat-integration:1.0.5837c4038a0dd
pip@21.0.1
26.0
1
julb/http-reqtrace:1.1.00806409af397
pip@20.2.4
26.0
1
julb/kubernetes-configmap-sync:1.1.0d7d8836366ad
pip@20.2.4
26.0
1
jupyterhub/jupyterhub:5.4.63974ba945e65
pip@24.0
python-pip@24.0+dfsg-1ubuntu1.3
26.0
no fix listed
1
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
pip@23.1.2
26.0
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
pip@20.3.3
python-pip@20.0.2-5ubuntu1.1
26.0
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
pip@21.3.1
python-pip@20.0.2-5ubuntu1.6
26.0
no fix listed
1
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
pip@23.1.2
26.0
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
pip@20.2.4
26.0
1
jvstein/bitcoin-prometheus-exporter:v0.5.07cc385d038b1
pip@20.0.2
26.0
1
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
pip@20.2.3
26.0
1
kelvinsp/mlflow:1.26.1cd33e6db2a59
pip@21.1.3
26.0
1
kennethreitz/httpbin:latest599fe5e50731
pip@9.0.1
python-pip@9.0.1-2.3~ubuntu1
26.0
no fix listed
1
kfirfer/elasticsearch-cacher:0.0.1cf81d0959256
pip@24.3.1
26.0
1
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
pip@23.2.1
26.0
1
kfirfer/kibana-index-pattern-updater:1.0.12e88cfcec5c93
pip@20.3.3
26.0
1
kfirfer/percona-xtradb-healthcheck:0.0.1ef7b909a8e6b
pip@20.2.4
26.0
1
kfirfer/scripts:0.0.2481e5c4e5d70e
pip@22.3.1
26.0
1
kfirfer/slackgpt:0.0.15461331bd838e
pip@23.2.1
26.0
1
kfserving/models-web-app:v0.6.1f322d6ffdfa3
pip@21.2.4
26.0
1
kinseii/wazuh-agent:4.14.17160eb143728
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.0
no fix listed
1
kiwigrid/k8s-sidecar:1.1.03e86186656d3
pip@20.2.3
26.0
1
kiwigrid/k8s-sidecar:1.3.065095a82d4a1
pip@20.2.4
26.0
1
kiwigrid/k8s-sidecar:0.0.186eb52513d59e
pip@19.1.1
26.0
1
kiwigrid/k8s-sidecar:1.12.089739be9ff38
pip@21.0.1
26.0
1
kiwigrid/k8s-sidecar:0.0.16899ccd0b1f54
pip@19.0.3
26.0
1
kiwigrid/k8s-sidecar:0.1.20af151f677a63
pip@19.2.1
26.0
1
kiwigrid/k8s-sidecar:1.27.6db85bd553253
pip@24.2
26.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.