StackRadar

CVE-2026-21441

High

Advisory

Published 7 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.9
base score, highest
EPSS
0.030
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
836
of 17,790 indexed, latest versions
Container images
892
deployed by those charts
Fix available
5 of 5
affected packages

Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)

Carried by container images the latest versions of 836 of 17,790 indexed charts deploy, on 892 images.

Affected packageAffected versionsFixed inImages
py3-pipapk25.0.1-r0, 25.2-r0, 26.0.1-r126.1.1-r03
urllib3pypi1.22, 1.23, 1.24, 1.24.1+47 more2.6.3863
python-pipdeb9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1, 9.0.1-2.3~ubuntu1.18.04.2, 9.0.1-2.3~ubuntu1.18.04.4+14 more9.0.1-2.3~ubuntu1.18.04.8+esm860
python-urllib3deb1.22-1ubuntu0.18.04.1, 1.22-1ubuntu0.18.04.2, 1.25.8-2ubuntu0.1, 1.25.8-2ubuntu0.2+8 more1.25.8-2ubuntu0.4+esm3, 1.26.5-1~exp1+deb11u3, 1.26.5-1~exp1ubuntu0.5, 1.26.12-1+deb12u3+1 more52
py3-urllib3apk1.26.18-r1, 1.26.20-r01.26.18-r2, 1.26.20-r14
OSV records
ALPINE-CVE-2026-21441CGA-295m-5rcj-2qm6CGA-7cp6-w84v-cpfxDEBIAN-CVE-2026-21441GHSA-38jv-5279-wg99UBUNTU-CVE-2026-21441DLA-4446-1
Also known as
CGA-hqjr-j69p-ch46, CGA-rh7x-c7j6-9qqm, DSA-6102-2, PYSEC-2026-1996, USN-7955-1, USN-7955-2, USN-8010-1

Charts affected

836 by stars
ChartLatestAffected imagesRadar Score
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
urllib3@1.26.15
2.6.3

Open the chart page →

5,456
pecanncsaVerified publisher0.6.21 of 15See more

pecan ncsa 0.6.2

1 of the 15 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
pecan/monitor:1.7.273b2074f3fec
urllib3@1.24.3
2.6.3

Open the chart page →

14,156
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
urllib3@1.26.1
2.6.3

Open the chart page →

55,728
smilencsaVerified publisher1.1.016 of 23See more

smile ncsa 1.1.0

16 of the 23 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
socialmediamacroscope/autophrase:0.1.570fb11d4f531
urllib3@1.26.16
2.6.3
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
urllib3@1.26.15
2.6.3
socialmediamacroscope/classification_split:0.1.24bfda60829fe
urllib3@1.26.15
2.6.3
socialmediamacroscope/classification_train:0.1.207477060bba8
urllib3@1.26.15
2.6.3
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
urllib3@1.26.15
2.6.3
socialmediamacroscope/clowder_create_dataset:0.1.09b4211832429
urllib3@1.26.15
2.6.3
socialmediamacroscope/clowder_create_space:0.1.0999f2ff2c128
urllib3@1.26.15
2.6.3
socialmediamacroscope/clowder_list:0.1.051cb17626519
urllib3@2.0.2
2.6.3
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
urllib3@1.26.16
2.6.3
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
python-pip@9.0.1-2.3~ubuntu1.18.04.8
urllib3@1.24.3
9.0.1-2.3~ubuntu1.18.04.8+esm8
2.6.3
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
urllib3@1.26.18
2.6.3
socialmediamacroscope/image_crawler:0.1.2f508216be63c
python-pip@9.0.1-2.3~ubuntu1.18.04.8
urllib3@1.24.3
9.0.1-2.3~ubuntu1.18.04.8+esm8
2.6.3
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
urllib3@1.26.16
2.6.3
socialmediamacroscope/preprocessing:0.1.3ca863306314b
urllib3@1.26.16
2.6.3
socialmediamacroscope/screen_name_prompt:0.1.2724f3f5702e0
urllib3@1.26.15
2.6.3
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
urllib3@1.26.16
2.6.3

Open the chart page →

109,730
uptime-kumancsaVerified publisher1.7.21 of 1See more

uptime-kuma ncsa 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
urllib3@1.26.12
2.6.3

Open the chart page →

30,326
netbirdnetbird1.9.01 of 4See more

netbird netbird 1.9.0

1 of the 4 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
netbirdio/dashboard:v2.13.188b5fb704a8c
urllib3@1.26.5
2.6.3

Open the chart page →

6,415
neuralbank-stackneuralbank-stack0.1.01 of 4See more

neuralbank-stack neuralbank-stack 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
urllib3@1.26.5
2.6.3

Open the chart page →

5,279
neurofaceneurofaceVerified publisher1.4.22 of 3See more

neuroface neuroface 1.4.2

2 of the 3 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
urllib3@1.26.5
2.6.3
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
urllib3@1.26.5
2.6.3

Open the chart page →

7,464
nfl-walletnfl-walletVerified publisher0.1.31 of 4See more

nfl-wallet nfl-wallet 0.1.3

1 of the 4 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
urllib3@1.24.2
2.6.3

Open the chart page →

13,373
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
urllib3@1.26.12
2.6.3

Open the chart page →

22,735
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
python-pip@9.0.1-2.3~ubuntu1.18.04.1
9.0.1-2.3~ubuntu1.18.04.8+esm8

Open the chart page →

27,684
object-clonerobject-clonerVerified publisher2.0.01 of 1See more

object-cloner object-cloner 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
ghcr.io/ideamixes/object-cloner:2.0.031030fd2f192
urllib3@2.0.4
2.6.3

Open the chart page →

1,587
ocellusaiocellusaiVerified publisher0.1.121 of 2See more

ocellusai ocellusai 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
urllib3@1.26.20
2.6.3

Open the chart page →

1,184
lensoci-ai-incubations0.1.141 of 16See more

lens oci-ai-incubations 0.1.14

1 of the 16 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
urllib3@2.5.0
2.6.3

Open the chart page →

17,134
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
urllib3@2.2.3
2.6.3

Open the chart page →

5,826
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
python-pip@22.0.2+dfsg-1ubuntu0.3
no fix listed

Open the chart page →

9,062
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
urllib3@1.25.9
2.6.3

Open the chart page →

18,032
comacopencord1.0.03 of 9See more

comac opencord 1.0.0

3 of the 9 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
urllib3@1.25.3
2.6.3
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
urllib3@1.22
2.6.3
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
urllib3@1.22
2.6.3

Open the chart page →

88,653
comac-platformopencord0.0.172 of 11See more

comac-platform opencord 0.0.17

2 of the 11 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
urllib3@1.25.3
2.6.3
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
urllib3@1.22
2.6.3

Open the chart page →

26,246
nem-monitoringopencord1.3.221 of 9See more

nem-monitoring opencord 1.3.22

1 of the 9 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.20af151f677a63
urllib3@1.25.3
2.6.3

Open the chart page →

4,619
omec-control-planeopencord0.1.311 of 8See more

omec-control-plane opencord 0.1.31

1 of the 8 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
omecproject/mme-exporter:paging-latestbcc5f19fd676
python-pip@9.0.1-2.3~ubuntu1.18.04.1
9.0.1-2.3~ubuntu1.18.04.8+esm8

Open the chart page →

40,825
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
urllib3@1.22
2.6.3

Open the chart page →

12,626
sebaopencord1.0.04 of 17See more

seba opencord 1.0.0

4 of the 17 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
voltha/voltha-cli:1.6.0c4e41e92f046
urllib3@1.22
2.6.3
voltha/voltha-netconf:1.6.037f80524c207
urllib3@1.22
2.6.3
voltha/voltha-ofagent:1.6.09ee8c1f4428c
urllib3@1.22
2.6.3
voltha/voltha-voltha:1.6.0ff596b62de59
urllib3@1.22
2.6.3

Open the chart page →

93,946
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
urllib3@2.3.0
2.6.3

Open the chart page →

11,051
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
urllib3@2.2.1
2.6.3

Open the chart page →

12,185
bpjstk-serviceopenshift1.0.01 of 6See more

bpjstk-service openshift 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
urllib3@1.24.2
2.6.3

Open the chart page →

35,116
canvas-oamportalopenshift4.0.01 of 1See more

canvas-oamportal openshift 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
gurolakman/oam:4.0.0ed8fd2062548
urllib3@1.24.2
2.6.3

Open the chart page →

7,519
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
urllib3@2.5.0
2.6.3
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
urllib3@2.2.1
2.6.3

Open the chart page →

19,051
exporteropenshift1.0.473 of 3See more

exporter openshift 1.0.47

3 of the 3 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
urllib3@1.24.2
2.6.3
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
urllib3@1.26.5
2.6.3
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
urllib3@1.26.5
2.6.3

Open the chart page →

13,041
hamiopenshift2.10.0-r0-openshift.c4e22e881 of 2See more

hami openshift 2.10.0-r0-openshift.c4e22e88

1 of the 2 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
ghcr.io/dynamia-ai/hami-enterprise:v2.10.0-r0-openshift.c4e22e88745504757300
urllib3@1.24.2
2.6.3

Open the chart page →

4,756
kb-cloud-installeropenshift2.1.351 of 1See more

kb-cloud-installer openshift 2.1.35

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
urllib3@1.26.5
2.6.3

Open the chart page →

4,170
kite-agentopenshift1.0.01 of 1See more

kite-agent openshift 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
urllib3@1.24.2
2.6.3

Open the chart page →

5,863
orion-ldopenshift1.0.31 of 2See more

orion-ld openshift 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
urllib3@1.24.2
2.6.3

Open the chart page →

14,727
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
urllib3@1.26.5
2.6.3

Open the chart page →

8,643
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
urllib3@1.24.2
2.6.3

Open the chart page →

13,612
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
urllib3@1.24.2
2.6.3

Open the chart page →

11,740
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
urllib3@1.24.2
2.6.3

Open the chart page →

13,573
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
urllib3@1.24.2
2.6.3

Open the chart page →

13,556
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
urllib3@1.24.2
2.6.3

Open the chart page →

13,460
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
urllib3@1.24.2
2.6.3

Open the chart page →

13,105
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
python-pip@9.0.1-2.3~ubuntu1.18.04.4
urllib3@1.25.11
9.0.1-2.3~ubuntu1.18.04.8+esm8
2.6.3

Open the chart page →

36,252
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.07 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

7 of the 40 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
yetiplatform/yeti:2.9.09bcbe2650a14
urllib3@2.4.0
2.6.3
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
python-pip@24.0+dfsg-1ubuntu1.3
urllib3@2.0.7
no fix listed
2.6.3
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
python-pip@24.0+dfsg-1ubuntu1.3
urllib3@2.0.7
no fix listed
2.6.3
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
python-pip@24.0+dfsg-1ubuntu1.3
urllib3@2.0.7
no fix listed
2.6.3
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
urllib3@2.0.7
2.6.3
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
python-pip@24.0+dfsg-1ubuntu1.3
urllib3@2.0.7
no fix listed
2.6.3
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
python-pip@24.0+dfsg-1ubuntu1.3
urllib3@2.0.7
no fix listed
2.6.3

Open the chart page →

72,547
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
urllib3@2.4.0
2.6.3

Open the chart page →

6,679
pgaot-container-kit1.0.31 of 6See more

pga ot-container-kit 1.0.3

1 of the 6 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.26.1b8d5067137fe
urllib3@1.26.18
2.6.3

Open the chart page →

5,143
vmot-container-kit0.0.31 of 7See more

vm ot-container-kit 0.0.3

1 of the 7 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
urllib3@2.2.1
2.6.3

Open the chart page →

5,418
devpiowan-charts0.1.01 of 1See more

devpi owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
owanio1992/devpi:6.16.04ade8e1e4d7e
urllib3@2.5.0
2.6.3

Open the chart page →

513
ctfdpascaliskeVerified publisher2.0.01 of 1See more

ctfd pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
ghcr.io/ctfd/ctfd:3.8.2870e396fddf8
urllib3@2.6.0
2.6.3

Open the chart page →

2,393
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
urllib3@2.6.2
2.6.3

Open the chart page →

4,805
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
urllib3@2.6.2
2.6.3

Open the chart page →

3,877
plausiblepascaliskeVerified publisher2.0.01 of 1See more

plausible pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-21441.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
py3-urllib3@1.26.18-r1
urllib3@1.26.18
1.26.18-r2
2.6.3

Open the chart page →

960

Container images carrying it

892 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
urllib3@1.24.2
2.6.3
1
ghcr.io/cunningpike/fediblockhole:0.4.22abc5f0350dc
urllib3@1.26.14
2.6.3
1
ghcr.io/dask/dask:2024.1.0080150de7d86
urllib3@2.0.4
2.6.3
1
ghcr.io/dask/dask-gateway-server:2024.1.0881e7acfc5a0
urllib3@2.1.0
2.6.3
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
urllib3@2.1.0
2.6.3
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
urllib3@1.26.18
2.6.3
1
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
urllib3@1.26.7
2.6.3
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
python-pip@24.0+dfsg-1ubuntu1.1
urllib3@2.2.3
no fix listed
2.6.3
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
urllib3@1.26.7
2.6.3
1
ghcr.io/dodevops/azure-app-exporter/azure-app-exporter:0.1.38b472877847f5
urllib3@2.2.2
2.6.3
1
ghcr.io/dynamia-ai/hami-enterprise:v2.10.0-r0-openshift.c4e22e88745504757300
urllib3@1.24.2
2.6.3
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
urllib3@2.2.2
2.6.3
1
ghcr.io/facebook/threatexchange/hma:1.0.1784d09c6b75a7
urllib3@2.4.0
2.6.3
1
ghcr.io/flaresolverr/flaresolverr:v3.3.16088412db1051
urllib3@2.2.1
2.6.3
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
urllib3@2.5.0
2.6.3
1
ghcr.io/flaresolverr/flaresolverr:v3.3.21f104ee51e512
urllib3@2.2.2
2.6.3
1
ghcr.io/gabe565/obico/web:latesta5c1daef46c0
urllib3@2.3.0
2.6.3
1
ghcr.io/grofers/legend:0.1d6e901ad0ebd
urllib3@1.25.11
2.6.3
1
ghcr.io/grycap/im:latest06a16d4f279f
urllib3@2.5.0
2.6.3
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
python-urllib3@1.25.8-2ubuntu0.1
urllib3@1.25.8
1.25.8-2ubuntu0.4+esm3
2.6.3
1
ghcr.io/hemslo/chat-search:latest39d48995a5bd
urllib3@2.2.2
2.6.3
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
urllib3@1.26.20
2.6.3
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
urllib3@2.6.2
2.6.3
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
urllib3@1.26.9
2.6.3
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
urllib3@1.26.18
2.6.3
1
ghcr.io/home-operations/bazarr:1.5.680cb090162b4
urllib3@2.2.3
2.6.3
1
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
urllib3@2.4.0
2.6.3
1
ghcr.io/hoverkraft-tech/ovh-snapshoter/app:0.4.1010d271f08ab3
urllib3@2.2.3
2.6.3
1
ghcr.io/ideamixes/object-cloner:2.0.031030fd2f192
urllib3@2.0.4
2.6.3
1
ghcr.io/iisas/domino-rest:latest3009350bfc11
urllib3@2.5.0
2.6.3
1
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
urllib3@2.1.0
2.6.3
1
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
urllib3@2.6.2
2.6.3
1
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
urllib3@2.0.7
2.6.3
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
urllib3@1.26.5
2.6.3
1
ghcr.io/jaydee94/kubeseal-webgui/api:4.5.33cceb9462ae1
urllib3@2.4.0
2.6.3
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
urllib3@1.26.11
2.6.3
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
urllib3@1.26.5
2.6.3
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
urllib3@1.26.7
2.6.3
1
ghcr.io/kokuwaio/gcloud-mysql:v3.2.1963098135c550
urllib3@1.26.18
2.6.3
1
ghcr.io/kubeshop/k8s-sidecar:ignore-initial-events7f583a36a764
urllib3@1.26.12
2.6.3
1
ghcr.io/kubiyabot/sdk-py:v1.20.0f108f49570cc
urllib3@2.2.3
2.6.3
1
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
urllib3@2.0.4
2.6.3
1
ghcr.io/libretime/libretime-analyzer:latest3d5e236216ad
urllib3@2.5.0
2.6.3
1
ghcr.io/libretime/libretime-api:latesteae026cc8909
urllib3@2.5.0
2.6.3
1
ghcr.io/libretime/libretime-playout:latest71a8706531aa
urllib3@2.5.0
2.6.3
1
ghcr.io/libretime/libretime-worker:latestd39ff5272b2e
urllib3@2.5.0
2.6.3
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
urllib3@2.4.0
2.6.3
1
ghcr.io/linuxserver/mylar3:version-v0.5.3b96f0e97ab3f
urllib3@1.26.2
2.6.3
1
ghcr.io/linuxserver/tvheadend:version-eb59284b66c4c9e18e40
urllib3@1.25.9
2.6.3
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.