StackRadar

CVE-2026-1703

Low

Advisory

Published 2 Feb 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.0
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,241
of 17,792 indexed, latest versions
Container images
1,189
deployed by those charts
Fix available
1 of 2
affected packages

pip Path Traversal vulnerability

Carried by container images the latest versions of 1,241 of 17,792 indexed charts deploy, on 1,189 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+63 more26.01,182
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 moreno fix listed141
OSV records
DEBIAN-CVE-2026-1703GHSA-6vgw-5pg2-w6jpUBUNTU-CVE-2026-1703
Also known as
PYSEC-2026-1796

Charts affected

1,241 by stars
ChartLatestAffected imagesRadar Score
rundeck-option-providersvtech-public-helm-charts1.0.01 of 2See more

rundeck-option-provider svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
pip@20.2.2
26.0

Open the chart page →

1,428
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
pip@25.1.1
26.0

Open the chart page →

2,397
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
pip@23.0.1
26.0

Open the chart page →

11,285
gtmetrix-bqt3n1.0.01 of 1See more

gtmetrix-bq t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
t3nde/gtmetrix-bq:0.2.0d2939e9a719b
pip@20.1
26.0

Open the chart page →

1,287
take-the-helmtake-the-helm0.1.01 of 1See more

take-the-helm take-the-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
cadmusthefounder/lnd:take-the-helm-0.1.0e596c5fbf80f
pip@22.0.4
26.0

Open the chart page →

805
democharttech-challenge0.1.02 of 4See more

demochart tech-challenge 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
alexvm6/generator:latestfb99ee4f760a
pip@22.3.1
26.0
alexvm6/pythonalex:latest89a05786879c
pip@22.3.1
26.0

Open the chart page →

3,630
rundeck-exportertechpreta0.1.91 of 1See more

rundeck-exporter techpreta 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
phsmith/rundeck-exporter:2.6.10265a7616ae8
pip@22.3.1
26.0

Open the chart page →

1,104
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
pip@8.1.2
26.0

Open the chart page →

4,241
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
pip@23.1.2
26.0

Open the chart page →

21,042
tensor_apptensor-app0.2.22 of 3See more

tensor_app tensor-app 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
pip@23.0.1
26.0
xeladock/mysql_dns:latest4baf531453f1
pip@22.0.2
python-pip@22.0.2+dfsg-1
26.0
no fix listed

Open the chart page →

17,661
krokiteochenglim1.0.11 of 5See more

kroki teochenglim 1.0.1

1 of the 5 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
pip@21.2.4
26.0

Open the chart page →

8,717
pagestest43221.0.01 of 3See more

pages test4322 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,262
flask-contactstest-configmap1.0.12 of 3See more

flask-contacts test-configmap 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0
shashkist/flask-contacts-app:latest581de1fd6084
pip@24.2
26.0

Open the chart page →

5,823
webapp1test-helm-chart-10.1.01 of 1See more

webapp1 test-helm-chart-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
devopsjourney1/mywebapp:latestbd1ec6838570
pip@22.0.4
26.0

Open the chart page →

1,469
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
pip@24.0
26.0

Open the chart page →

4,420
chatqnatest-opea1.0.05 of 11See more

chatqna test-opea 1.0.0

5 of the 11 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
opea/chatqna:1.038c51b791efa
pip@24.2
26.0
opea/embedding-tei:1.05c9639de61c1
pip@24.0
26.0
opea/llm-tgi:1.00c25aab3f106
pip@24.0
26.0
opea/reranking-tei:1.0e48613afb191
pip@24.2
26.0
opea/retriever-redis:1.0eb746b263705
pip@24.0
26.0

Open the chart page →

39,419
codegentest-opea1.0.02 of 5See more

codegen test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
opea/codegen:1.058f91683892d
pip@24.2
26.0
opea/llm-tgi:1.00c25aab3f106
pip@24.0
26.0

Open the chart page →

29,001
codetranstest-opea1.0.02 of 5See more

codetrans test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
opea/codetrans:1.0e2436483b73d
pip@24.2
26.0
opea/llm-tgi:1.00c25aab3f106
pip@24.0
26.0

Open the chart page →

28,574
docsumtest-opea1.0.02 of 5See more

docsum test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
opea/docsum:1.03eaa91849512
pip@24.2
26.0
opea/llm-docsum-tgi:1.002f9e8fa5d71
pip@24.0
26.0

Open the chart page →

29,049
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
pip@24.0
26.0

Open the chart page →

5,223
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
pip@24.2
26.0

Open the chart page →

5,259
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
pip@24.0
26.0

Open the chart page →

4,757
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
pip@24.2
26.0

Open the chart page →

5,023
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
pip@24.0
26.0

Open the chart page →

5,236
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
pip@24.2
26.0

Open the chart page →

9,656
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
pip@24.0
26.0

Open the chart page →

4,404
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
pip@24.2
26.0

Open the chart page →

5,388
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
pip@21.2.4
26.0

Open the chart page →

5,335
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
pysga1996/python-redis-web:latestfdeec30ad482
pip@22.0.4
26.0

Open the chart page →

4,667
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
pip@24.0
26.0

Open the chart page →

1,515
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,262
monitoringthl-chartsVerified publisher0.1.11 of 10See more

monitoring thl-charts 0.1.1

1 of the 10 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.15.61f025ae37b7b
pip@21.2.4
26.0

Open the chart page →

18,940
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

20,262
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.193170069ff0976
pip@20.2.2
26.0

Open the chart page →

4,445
todolist-charttodolist-chart0.1.72 of 10See more

todolist-chart todolist-chart 0.1.7

2 of the 10 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
pip@24.0
26.0
library/mysql:8.07dcddc01f13b
pip@25.3
26.0

Open the chart page →

7,028
test0tohlejezkouska0.1.01 of 2See more

test0 tohlejezkouska 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
devopsjourney1/mywebapp:latestbd1ec6838570
pip@22.0.4
26.0

Open the chart page →

3,330
netbirdtotmicro1.8.21 of 4See more

netbird totmicro 1.8.2

1 of the 4 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
netbirdio/dashboard:v2.22.215a3aab9a345
pip@20.3.4
26.0

Open the chart page →

6,041
traefik-external-dns-controllertraefik-external-dns-operator2.2.01 of 1See more

traefik-external-dns-controller traefik-external-dns-operator 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-controller:2.2.08d27ad8b5f73
pip@24.0
26.0

Open the chart page →

1,506
traefik-external-dns-operatortraefik-external-dns-operator1.0.11 of 1See more

traefik-external-dns-operator traefik-external-dns-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
pip@24.3.1
26.0

Open the chart page →

1,083
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
pip@22.3.1
26.0

Open the chart page →

3,179
orchestratremolo3.1.561 of 5See more

orchestra tremolo 3.1.56

1 of the 5 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
ghcr.io/tremolosecurity/python-slim-nonroot/python3:1.0.094f64e1f40cb
pip@23.1.2
26.0

Open the chart page →

2,882
tfy-grafanatruefoundryVerified publisher0.1.211 of 3See more

tfy-grafana truefoundry 0.1.21

1 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
pip@25.3
26.0

Open the chart page →

1,064
truefoundry-monitoringtruefoundryVerified publisher0.1.61 of 8See more

truefoundry-monitoring truefoundry 0.1.6

1 of the 8 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
pip@25.3
26.0

Open the chart page →

4,549
zookeepertwomartensVerified publisher0.2.21 of 1See more

zookeeper twomartens 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
pip@9.0.3
26.0

Open the chart page →

1,733
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
pip@22.0.4
26.0

Open the chart page →

8,674
phonebook-chartusuladams2Verified publisher0.2.13 of 3See more

phonebook-chart usuladams2 0.2.1

3 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
pip@23.0.1
26.0
paulkellerman/resultserver-app:1.0381eeccb0618
pip@22.3
26.0
paulkellerman/webserver-app:latest5a37b74f61b9
pip@22.3
26.0

Open the chart page →

3,176
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
pip@23.0.1
26.0

Open the chart page →

14,444
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pip@24.3.1
26.0

Open the chart page →

4,777
telegram-rebotvcnngrVerified publisher1.0.02 of 3See more

telegram-rebot vcnngr 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
vcnngr/telegram-login:latest1a849a997b6d
pip@24.0
26.0
vcnngr/telegram-rebot:latest30f1f05e57a6
pip@24.0
26.0

Open the chart page →

5,074
devportalveecode-platform-nextVerified publisher0.1.231 of 1See more

devportal veecode-platform-next 0.1.23

1 of the 1 container images this version deploys carry CVE-2026-1703.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinneda72cf5cb47b8
pip@22.3.1
26.0

Open the chart page →

1,814

Container images carrying it

1,189 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
pip@24.0
26.0
1
ghcr.io/zazukoians/qlever-server:v0.10.11de7869ab46e
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/zazukoians/qlever-ui:v0.10.151a7ec1c2de4
pip@24.0
26.0
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
pip@24.3.1
26.0
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
pip@24.3.1
26.0
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
pip@25.3
26.0
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
pip@24.3.1
26.0
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
pip@24.3.1
26.0
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
pip@24.3.1
26.0
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
pip@9.0.3
26.0
1
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
pip@25.3
26.0
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
pip@22.3.1
26.0
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
pip@23.3.2
26.0
1
quay.io/cephcsi/cephcsi:v3.5.128a674af1df2
pip@9.0.3
26.0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
pip@22.1.2
26.0
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
pip@23.2.1
26.0
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
pip@23.0.1
26.0
1
quay.io/datamattsson/truenas-csp:v3.2.09e58f2127d85
pip@25.0.1
26.0
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
pip@9.0.3
26.0
1
quay.io/evl.ms/argocd-exporter:0.0.136ea8f34aa6b
pip@21.2.4
26.0
1
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
pip@9.0.3
26.0
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
pip@9.0.3
26.0
1
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
pip@9.0.3
26.0
1
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
pip@9.0.3
26.0
1
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
pip@9.0.3
26.0
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pip@25.0.1
26.0
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
pip@25.0.1
26.0
1
quay.io/hpestorage/filex-csi-driver:2.6.4b7f960bbf472
pip@25.3
26.0
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
pip@22.0.4
26.0
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
pip@25.0.1
26.0
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
pip@25.0.1
26.0
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
pip@23.2.1
26.0
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
pip@25.0.1
26.0
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
pip@25.0.1
26.0
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
pip@9.0.3
26.0
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
pip@9.0.3
26.0
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
pip@9.0.3
26.0
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
pip@9.0.3
26.0
1
quay.io/kiali/kiali-operator:v2.32.096c5264d54ab
pip@23.3.2
26.0
1
quay.io/kiwigrid/k8s-sidecar:1.10.718feb3906286
pip@21.0.1
26.0
1
quay.io/kiwigrid/k8s-sidecar:1.15.61f025ae37b7b
pip@21.2.4
26.0
1
quay.io/kiwigrid/k8s-sidecar:1.30.349dcce269568
pip@25.0.1
26.0
1
quay.io/kiwigrid/k8s-sidecar:1.21.0710e23b489c5
pip@22.3.1
26.0
1
quay.io/kiwigrid/k8s-sidecar:1.30.10835d79d8fbae
pip@25.2
26.0
1
quay.io/kiwigrid/k8s-sidecar:1.15.1a25886092fa4
pip@21.2.4
26.0
1
quay.io/kiwigrid/k8s-sidecar:2.6.0a6c101156d42
pip@25.3
26.0
1
quay.io/kiwigrid/k8s-sidecar:1.25.2cb4c638ffb1f
pip@23.2.1
26.0
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
pip@22.3.1
26.0
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
pip@22.3.1
26.0
1
quay.io/maxiv/storageclass-router:0.4.160725dab588c
pip@24.0
26.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.