CVE-2026-19672
MediumAdvisory
Published 19 Aug 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.3
- base score, highest
- EPSS
- 0.004
- 34th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 682
- of 17,781 indexed, latest versions
- Container images
- 661
- deployed by those charts
- Fix available
- 1 of 16
- affected packages
tarfile extraction filter bypass allows creation of directories outside the destination
Carried by container images the latest versions of 682 of 17,781 indexed charts deploy, on 661 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| python3.11deb | 3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more | no fix listed | 181 |
| python3.8deb | 3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more | no fix listed | 100 |
| python3.12deb | 3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+11 more | no fix listed | 89 |
| python3.10deb | 3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+16 more | no fix listed | 80 |
| python3.13deb | 3.13.5-2, 3.13.5-2+deb13u2, 3.13.5-2+deb13u4, 3.13.5-2+e30 | 3.13.5-2+e35 | 74 |
| python2.7deb | 2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 more | no fix listed | 54 |
| python3.6deb | 3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more | no fix listed | 44 |
| python3.5deb | 3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9 | no fix listed | 25 |
| python3.14deb | 3.14.4-1, 3.14.4-1ubuntu0.1, 3.14.4-1ubuntu0.2 | no fix listed | 9 |
| python3.4deb | 3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7 | no fix listed | 7 |
| pythonbitnami | 3.11.11-0, 3.12.8-0, 3.13.5-1 | no fix listed | 3 |
| python-3.13apk | 3.13.7-r0, 3.13.10-r0, 3.13.12-r2, 3.13.15-r1+3 more | no fix listed | 13 |
| python-3.14apk | 3.14.2-r2, 3.14.4-r2, 3.14.6-r0, 3.14.7-r1+2 more | no fix listed | 9 |
| python-3.12apk | 3.12.0-r1, 3.12.9-r1, 3.12.14-r2, 3.12.14-r6 | no fix listed | 8 |
| python3rpm | 3.12.9-13.azl3 | no fix listed | 1 |
| python-3.11apk | 3.11.16-r5 | no fix listed | 1 |
- OSV records
- BIT-python-2026-19672DEBIAN-CVE-2026-19672UBUNTU-CVE-2026-19672AZL-97038CGA-36r3-9m2m-pwvxCGA-886h-2jwh-vv2cCGA-c57p-3r5x-qrh7CGA-hfj2-mp2q-f7xhECHO-85b0-6a57-a5e5
- Also known as
- BIT-libpython-2026-19672, BIT-python-min-2026-19672, CGA-g5hg-ff68-3vg3, CGA-g6mx-fpqr-hm2w, CGA-r8pg-rhff-66jc, CGA-vrrp-w2qr-mw5c, PSF-2026-38
Charts affected
682 by stars
Container images carrying it
661 by charts deploying them
A fixed version is listed for 1 of the 16 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| mediagis/ | c15e941485ef | python3.8 | no fix listed | 1 |
| mediagis/ | d0eae7b51374 | python3.10 | no fix listed | 1 |
| middlewareeng/ | 747d880812f1 | python3.11 | no fix listed | 1 |
| mindsdb/ | 163011c09299 | python3.13 | no fix listed | 1 |
| mintproject/ | 02260d20a21f | python3.11 | no fix listed | 1 |
| mlikiowa/ | 1336a777f9a4 | python3.10 | no fix listed | 1 |
| moreillon/ | d7d4a5463525 | python3.11 | no fix listed | 1 |
| moreillon/ | e8fd856e593d | python3.11 | no fix listed | 1 |
| moreillon/ | 3caa8f710ee0 | python3.11 | no fix listed | 1 |
| moreillon/ | d2ee0423b797 | python3.11 | no fix listed | 1 |
| mshanley80/ | 5b189a70c0fb | python3.8 | no fix listed | 1 |
| muhammedgamal/ | 74b4cd69b6fa | python3.11 | no fix listed | 1 |
| muluder/ | 43b597a93da7 | python2.7 python3.5 | no fix listed no fix listed | 1 |
| netboxcommunity/ | 3d652dca5351 | python3.10 | no fix listed | 1 |
| netboxcommunity/ | 91b823a05cb5 | python3.14 | no fix listed | 1 |
| netdata/ | c45c71eb23ff | python3.13 | no fix listed | 1 |
| netskopeprivateaccess/ | 93e2fd164a93 | python3.10 | no fix listed | 1 |
| nousresearch/ | e0df6adebddf | python3.13 | no fix listed | 1 |
| offchainlabs/ | 9f779fa84b7b | python3.11 | no fix listed | 1 |
| offchainlabs/ | e95865866129 | python3.11 | no fix listed | 1 |
| oled01/ | 05d3e398e675 | python python3.11 | no fix listed no fix listed | 1 |
| omecproject/ | 28a90cc26716 | python2.7 | no fix listed | 1 |
| omecproject/ | bcc5f19fd676 | python3.6 | no fix listed | 1 |
| omecproject/ | 5715e5648aa0 | python2.7 python3.5 | no fix listed no fix listed | 1 |
| omecproject/ | d109a8e57e71 | python2.7 python3.5 | no fix listed no fix listed | 1 |
| oneuptime/ | 6b2d98713711 | python3.11 | no fix listed | 1 |
| opea/ | 2bee4eb66f3e | python3.11 | no fix listed | 1 |
| opea/ | 3ef121f34610 | python3.11 | no fix listed | 1 |
| opea/ | 7f854e9bffaf | python3.11 | no fix listed | 1 |
| opea/ | 249afad3d268 | python3.11 | no fix listed | 1 |
| openbas/ | a277796d9724 | python3.11 | no fix listed | 1 |
| opendatacube/ | 120457ffcd69 | python3.12 | no fix listed | 1 |
| opendatacube/ | 5d810e8504b8 | python3.6 | no fix listed | 1 |
| opendatacube/ | 91870111837c | python3.6 | no fix listed | 1 |
| opendatacube/ | 1b90cdf68831 | python3.6 | no fix listed | 1 |
| opendatacube/ | 80df355a660b | python3.10 | no fix listed | 1 |
| openebs/ | a39ef27ea28b | python3.13 | no fix listed | 1 |
| openelevation/ | 82fb21612e86 | python3.8 | no fix listed | 1 |
| openkm/ | 3bc465a7461b | python3.8 | no fix listed | 1 |
| openmined/ | b72f74a68b32 | python-3.12 | no fix listed | 1 |
| opennode/ | 4c82b15d9042 | python3.13 | no fix listed | 1 |
| openproject/ | 88dc1359dfb5 | python3.11 | no fix listed | 1 |
| openstackhelm/ | f728510bab3c | python3.8 | no fix listed | 1 |
| openstackhelm/ | e07d75953d2e | python3.8 | no fix listed | 1 |
| openthread/ | f307f59f6432 | python2.7 python3.6 | no fix listed no fix listed | 1 |
| openvino/ | 1e7cd1d70cc1 | python3.12 | no fix listed | 1 |
| openvino/ | 70596d34ff93 | python3.12 | no fix listed | 1 |
| openvpn/ | 2253c10ec652 | python3.12 | no fix listed | 1 |
| openwhisk/ | c80dba0de3aa | python2.7 | no fix listed | 1 |
| opsmx11/ | 5c50ca123d88 | python3.4 | no fix listed | 1 |