StackRadar

CVE-2026-1703

Low

Advisory

Published 2 Feb 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.0
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,241
of 17,787 indexed, latest versions
Container images
1,190
deployed by those charts
Fix available
1 of 2
affected packages

pip Path Traversal vulnerability

Carried by container images the latest versions of 1,241 of 17,787 indexed charts deploy, on 1,190 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+63 more26.01,183
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 moreno fix listed141
OSV records
DEBIAN-CVE-2026-1703GHSA-6vgw-5pg2-w6jpUBUNTU-CVE-2026-1703
Also known as
PYSEC-2026-1796

Charts affected

1,241 by stars
ChartLatestAffected imagesRadar Score
azure-app-exporterazure-app-exporterVerified publisher0.4.21 of 2See more

azure-app-exporter azure-app-exporter 0.4.2

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
ghcr.io/dodevops/azure-app-exporter/azure-app-exporter:0.1.38b472877847f5
pip@21.2.4
26.0

Open the chart page →

1,790
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
pip@20.2.4
26.0

Open the chart page →

5,521
aks-helloworldazure-sample0.1.11 of 1See more

aks-helloworld azure-sample 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
neilpeterson/aks-helloworld:v1fb47732ef36b
pip@9.0.1
26.0

Open the chart page →

4,270
azure-voteazure-sample0.1.11 of 2See more

azure-vote azure-sample 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
neilpeterson/azure-vote-front:v384062718347c
pip@9.0.1
26.0

Open the chart page →

5,238
azure-vote-osbaazure-sample0.1.01 of 1See more

azure-vote-osba azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
neilpeterson/azure-vote-front:v384062718347c
pip@9.0.1
26.0

Open the chart page →

4,270
osba-container-instances-demoazure-sample0.1.01 of 1See more

osba-container-instances-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
neilpeterson/osba-container-instances-demo:latest6527b05d5d03
pip@9.0.1
26.0

Open the chart page →

3,212
osba-cosmos-mongodb-demoazure-sample0.1.01 of 1See more

osba-cosmos-mongodb-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
pip@9.0.1
26.0

Open the chart page →

2,904
osba-mysql-demoazure-sample0.1.01 of 1See more

osba-mysql-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
neilpeterson/osba-mysql-demo:latest5859d68a6c9f
pip@9.0.2
26.0

Open the chart page →

2,895
osba-storage-demoazure-sample0.1.01 of 1See more

osba-storage-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
neilpeterson/osba-storage-demo:latest29d229ab446e
pip@9.0.1
26.0

Open the chart page →

3,425
osba-text-analytics-demoazure-sample0.1.01 of 1See more

osba-text-analytics-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
neilpeterson/osba-text-analytics-demo:latest969af3cb8466
pip@10.0.1
26.0

Open the chart page →

3,089
twitter-sentimentazure-sample0.1.03 of 3See more

twitter-sentiment azure-sample 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
neilpeterson/chart-tweet:latest64fd8dab075f
pip@9.0.1
26.0
neilpeterson/get-tweet:v28b645ac1a23e
pip@10.0.1
26.0
neilpeterson/process-tweet:latest39ce9f92e899
pip@10.0.1
26.0

Open the chart page →

11,833
backstage-pyactionsbackstage-pyactionsVerified publisher0.1.01 of 1See more

backstage-pyactions backstage-pyactions 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
mawad98/backstage-pyactions:demo99422c56a274
pip@24.0
26.0

Open the chart page →

2,750
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
conduction/balance-registration-varnish:dev07c44005da9d
pip@9.0.1
26.0

Open the chart page →

8,408
pvc-exporterbalihb-pvc-exporterVerified publisher0.2.42 of 2See more

pvc-exporter balihb-pvc-exporter 0.2.4

2 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
balihb/block-pvc-scanner:0.2.45b95e1cf1158
pip@21.2.4
26.0
balihb/pod-pvc-mapping:0.2.4ee48e79f5d76
pip@21.2.4
26.0

Open the chart page →

2,765
bookinfobasictechno0.1.01 of 6See more

bookinfo basictechno 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.17.06668bcf42ef0
pip@20.1.1
26.0

Open the chart page →

20,785
mealiebdclark-helm-chartsVerified publisher0.1.151 of 1See more

mealie bdclark-helm-charts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
pip@25.0.1
26.0

Open the chart page →

4,042
wyoming-piperbdclark-helm-chartsVerified publisher0.1.41 of 1See more

wyoming-piper bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
rhasspy/wyoming-piper:2.5.27d39aafac409
pip@25.1.1
python-pip@25.1.1+dfsg-1
26.0
no fix listed

Open the chart page →

1,176
helm-samplebehnambm-helm-chart1.0.12 of 3See more

helm-sample behnambm-helm-chart 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
behnambm/docker-sample:v1bd3ad88afff9
pip@23.0.1
26.0
library/mysql:8b3b90af2a655
pip@25.3
26.0

Open the chart page →

2,738
pagesberrutig-pages1.0.01 of 3See more

pages berrutig-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,233
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
pip@20.0.2
python-pip@20.0.2-5ubuntu1.6
26.0
no fix listed

Open the chart page →

8,004
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
pip@21.1.2
python-pip@9.0.1-2.3~ubuntu1.18.04.5
26.0
no fix listed

Open the chart page →

22,916
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.0
no fix listed

Open the chart page →

10,171
istio-bookinfobookinfo1.2.21 of 6See more

istio-bookinfo bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.15.00a5eb4795952
pip@19.1.1
26.0

Open the chart page →

18,998
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-rwd:log74ded2d92f07
pip@23.0.1
26.0

Open the chart page →

26,266
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.26.2e271016441af
pip@24.0
26.0

Open the chart page →

7,627
kube-prometheus-stackbook-k8sinfra-v265.5.11 of 6See more

kube-prometheus-stack book-k8sinfra-v2 65.5.1

1 of the 6 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
pip@24.2
26.0

Open the chart page →

6,035
puppetboardbootcVerified publisher0.1.41 of 1See more

puppetboard bootc 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
bootc/puppetboard:1.1.0f1383295e7be
pip@19.2.3
26.0

Open the chart page →

1,292
flaresolverrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

flaresolverr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
pip@24.0
26.0

Open the chart page →

27,282
pagesbrian-pages1.0.01 of 3See more

pages brian-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,233
pagesbrixton-mayuribhavsar23-pages1.0.01 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,233
pagesbrixton-pages1.0.01 of 3See more

pages brixton-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,233
couchpotatobryanalves0.3.01 of 1See more

couchpotato bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
pip@19.3.1
26.0

Open the chart page →

2,018
medusabryanalves0.1.01 of 1See more

medusa bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
linuxserver/medusa:v0.3.9-ls340a5f5114128b
pip@19.2.3
26.0

Open the chart page →

147
sickchillbryanalves0.3.01 of 1See more

sickchill bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
pip@19.3.1
26.0

Open the chart page →

2,505
sickragebryanalves0.1.01 of 1See more

sickrage bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
bryanalves/sickrage:latest42f0a130001d
pip@9.0.0
26.0

Open the chart page →

923
frigatebryopsida0.2.11 of 2See more

frigate bryopsida 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pip@20.3.4
26.0

Open the chart page →

2,573
pagescamden-pages1.0.01 of 3See more

pages camden-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,233
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
pip@22.0.4
26.0

Open the chart page →

2,507
bucket-clonercamptocamp31.0.41 of 1See more

bucket-cloner camptocamp3 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
camptocamp/bucket-cloner:latestacfafc308d88
pip@21.2.1
26.0

Open the chart page →

4,518
ekorrecamptocamp30.1.11 of 1See more

ekorre camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
camptocamp/ekorre:0.1.035c91d5fda04
pip@20.0.2
26.0

Open the chart page →

3,891
pghoardcamptocamp35.8.11 of 1See more

pghoard camptocamp3 5.8.1

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
camptocamp/pghoard:10bff736b15623
pip@18.1
26.0

Open the chart page →

2,813
prometheus-operatorcamptocamp35.15.11 of 5See more

prometheus-operator camptocamp3 5.15.1

1 of the 5 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.0.16899ccd0b1f54
pip@19.0.3
26.0

Open the chart page →

2,490
snow-webhookcamptocamp31.0.01 of 1See more

snow-webhook camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
camptocamp/snow-webhook:latest2924b43dbf40
pip@18.1
26.0

Open the chart page →

1,310
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
pip@24.3.1
26.0

Open the chart page →

10,318
pagescarina-pages1.0.01 of 3See more

pages carina-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,233
pagescarmel-pages-dell1.0.01 of 3See more

pages carmel-pages-dell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,233
castai-hibernatecastaiVerified publisher0.2.121 of 1See more

castai-hibernate castai 0.2.12

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
castai/hibernate:v0.14da62858c8381
pip@23.0.1
26.0

Open the chart page →

1,158
temporalcastaiVerified publisher0.54.21 of 14See more

temporal castai 0.54.2

1 of the 14 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.26.237e2e33dbd7b
pip@24.0
26.0

Open the chart page →

16,197
catalyst-agentscatalyst-agents0.1.301 of 18See more

catalyst-agents catalyst-agents 0.1.30

1 of the 18 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
alpine/k8s:1.32.3eec354133193
pip@25.0.1
26.0

Open the chart page →

14,865
tsoragecetic0.4.111 of 8See more

tsorage cetic 0.4.11

1 of the 8 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.0.1c87b1c07fb53
pip@8.1.2
26.0

Open the chart page →

12,018

Container images carrying it

1,190 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
pip@24.0
26.0
1
ghcr.io/itobey/playlist-mirror:1.0.0601082677a46
pip@25.0.1
26.0
1
ghcr.io/jaydee94/kubeseal-webgui/api:4.5.33cceb9462ae1
pip@25.0.1
26.0
1
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
pip@25.0.1
26.0
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
pip@20.0.2
python-pip@20.0.2-5ubuntu1.11
26.0
no fix listed
1
ghcr.io/kubeshop/k8s-sidecar:ignore-initial-events7f583a36a764
pip@22.2.2
26.0
1
ghcr.io/kubevoip/kubevoip:v0.6.841c603a93642
pip@25.0.1
26.0
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
pip@24.0
26.0
1
ghcr.io/kubiyabot/sdk-py:v1.20.0f108f49570cc
pip@23.1.2
26.0
1
ghcr.io/leoquote/tinyproxy_exporter:master6b4103d88dbb
pip@21.2.4
26.0
1
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
pip@23.2.1
26.0
1
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
pip@25.1.1
26.0
1
ghcr.io/libretime/libretime-analyzer:latest3d5e236216ad
pip@23.0.1
26.0
1
ghcr.io/libretime/libretime-api:latesteae026cc8909
pip@23.0.1
26.0
1
ghcr.io/libretime/libretime-playout:latest71a8706531aa
pip@23.0.1
26.0
1
ghcr.io/libretime/libretime-worker:latestd39ff5272b2e
pip@23.0.1
26.0
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
pip@25.1.1
26.0
1
ghcr.io/linuxserver/mylar3:version-v0.5.3b96f0e97ab3f
pip@21.1.3
26.0
1
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
pip@25.0.1
26.0
1
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
pip@25.0.1
26.0
1
ghcr.io/liturgical-app/liturgical-app:1.2.041f25aded572
pip@25.0.1
26.0
1
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
pip@25.3
26.0
1
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
pip@22.0.4
26.0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pip@24.0
26.0
1
ghcr.io/macropower/kubernetes-python:1.03b805a6a4bec
pip@25.0.1
26.0
1
ghcr.io/mailu/clamav:1.9.5001d30483e4a8
pip@23.0.1
26.0
1
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
pip@25.0.1
26.0
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
pip@25.0.1
26.0
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
pip@25.0.1
26.0
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
pip@23.1
26.0
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
pip@25.0.1
26.0
1
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
pip@25.0.1
26.0
1
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.2.29e36964bce26
pip@21.1.2
26.0
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
pip@23.3.1
26.0
1
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
pip@23.1.2
26.0
1
ghcr.io/mshade/kronic:v0.1.466e3043851cd
pip@24.0
26.0
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
pip@25.3
26.0
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
pip@25.3
26.0
1
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
pip@25.0.1
26.0
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
pip@24.0
26.0
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
pip@25.0.1
26.0
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
pip@24.3.1
26.0
1
ghcr.io/obeone/ollama-exporter:latestf43af285c6e0
pip@24.0
26.0
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
pip@23.0.1
26.0
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
pip@24.0
26.0
1
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
pip@25.0.1
26.0
1
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
pip@25.0.1
26.0
1
ghcr.io/openrelik/openrelik-server:latestce1132261523
pip@25.0.1
26.0
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.