StackRadar

CVE-2026-21860

Medium

Advisory

Published 8 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
307
of 17,781 indexed, latest versions
Container images
303
deployed by those charts
Fix available
1 of 1
affected package

Werkzeug safe_join() allows Windows special device names with compound extensions

Carried by container images the latest versions of 307 of 17,781 indexed charts deploy, on 303 images.

Affected packageAffected versionsFixed inImages
werkzeugpypi0.9.1, 0.11.15, 0.12.2, 0.13+33 more3.1.5303
OSV records
GHSA-87hc-h4r5-73f7
Also known as
PYSEC-2026-2044

Charts affected

307 by stars
ChartLatestAffected imagesRadar Score
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
werkzeug@2.2.3
3.1.5

Open the chart page →

11,367
rook-cephrookOfficialVerified publisher1.20.71 of 2See more

rook-ceph rook 1.20.7

1 of the 2 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
rook/ceph:v1.20.72f970c425617
werkzeug@2.0.3
3.1.5

Open the chart page →

1,447
ceph-csi-cephfsceph-csiOfficialVerified publisher3.17.11 of 6See more

ceph-csi-cephfs ceph-csi 3.17.1

1 of the 6 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
werkzeug@2.0.3
3.1.5

Open the chart page →

4,061
ceph-csi-rbdceph-csiOfficialVerified publisher3.17.11 of 6See more

ceph-csi-rbd ceph-csi 3.17.1

1 of the 6 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
werkzeug@2.0.3
3.1.5

Open the chart page →

4,061
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
werkzeug@3.1.3
3.1.5

Open the chart page →

10,622
locustdeliveryheroVerified publisher0.35.01 of 1See more

locust deliveryhero 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
werkzeug@3.1.2
3.1.5

Open the chart page →

2,800
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
werkzeug@3.1.4
3.1.5

Open the chart page →

19,391
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
werkzeug@1.0.1
3.1.5

Open the chart page →

4,086
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
grafana/oncall:v1.16.5499851658393
werkzeug@3.1.3
3.1.5

Open the chart page →

16,251
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
werkzeug@3.1.4
3.1.5

Open the chart page →

11,384
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
werkzeug@1.0.1
3.1.5

Open the chart page →

4,918
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
werkzeug@2.1.2
3.1.5

Open the chart page →

7,705
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
werkzeug@2.3.8
3.1.5

Open the chart page →

5,987
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
werkzeug@3.0.1
3.1.5

Open the chart page →

6,041
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
werkzeug@1.0.1
3.1.5

Open the chart page →

5,173
supersetcloudposse1.2.01 of 1See more

superset cloudposse 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
werkzeug@0.15.5
3.1.5

Open the chart page →

5,851
frigateblakeblackshear7.8.01 of 1See more

frigate blakeblackshear 7.8.0

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
werkzeug@3.0.3
3.1.5

Open the chart page →

3,004
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.11.11da5c38c6a78
werkzeug@3.0.3
3.1.5

Open the chart page →

6,168
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
werkzeug@0.15.5
3.1.5

Open the chart page →

52,919
geonode-k8sgeonode-k8sVerified publisher2.0.01 of 10See more

geonode-k8s geonode-k8s 2.0.0

1 of the 10 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
geopython/pycsw:3.0.0-beta284662ea6b78b
werkzeug@3.1.4
3.1.5

Open the chart page →

13,953
kubeflowkubeflow1.6.24 of 45See more

kubeflow kubeflow 1.6.2

4 of the 45 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
kserve/models-web-app:v0.8.063ea05e73842
werkzeug@2.1.2
3.1.5
kubeflownotebookswg/jupyter-web-app:v1.6.1d762690e21c1
werkzeug@2.2.2
3.1.5
kubeflownotebookswg/tensorboards-web-app:v1.6.10876fef1973b
werkzeug@2.2.2
3.1.5
kubeflownotebookswg/volumes-web-app:v1.6.17299fa94db15
werkzeug@2.2.2
3.1.5

Open the chart page →

96,941
taigarc-helm-charts0.1.01 of 7See more

taiga rc-helm-charts 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
taigaio/taiga-protected:6.4.036318831b3e7
werkzeug@0.15.6
3.1.5

Open the chart page →

7,255
k8s-telegram-sendertelegram-senderVerified publisher0.0.11 of 1See more

k8s-telegram-sender telegram-sender 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
danuk/telegram-sender:0.0.1026560388070
werkzeug@2.2.2
3.1.5

Open the chart page →

3,048
alerta-webalerta-webVerified publisher0.1.121 of 2See more

alerta-web alerta-web 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
hayk96/alerta-web:9.0.486377705e9e3
werkzeug@3.0.4
3.1.5

Open the chart page →

3,569
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
dpage/pgadmin4:7.537946e4f3e7b
werkzeug@2.2.3
3.1.5

Open the chart page →

14,546
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
redislabs/redisinsight:1.14.0b03ab1426d0d
werkzeug@2.2.3
3.1.5

Open the chart page →

13,874
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
werkzeug@1.0.1
3.1.5

Open the chart page →

10,598
mlflowgetindataVerified publisher0.1.21 of 1See more

mlflow getindata 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
gcr.io/getindata-images-public/mlflow:latest25d6975951f1
werkzeug@3.0.2
3.1.5

Open the chart page →

2,452
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
kobotoolbox/kobocat:2.022.24ab15679454415
werkzeug@2.0.3
3.1.5
kobotoolbox/kpi:2.022.24dbcacc01bccd4
werkzeug@2.0.3
3.1.5

Open the chart page →

18,517
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
werkzeug@3.1.0
3.1.5

Open the chart page →

107,811
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
werkzeug@1.0.1
3.1.5

Open the chart page →

10,730
tensorflow-notebookcloudnativeapp0.1.21 of 1See more

tensorflow-notebook cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
tensorflow/tensorflow:1.6.0-devel1e3172090703
werkzeug@0.14.1
3.1.5

Open the chart page →

36,094
aibrixdanchevVerified publisher0.7.01 of 5See more

aibrix danchev 0.7.0

1 of the 5 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
aibrix/metadata-service:v0.7.063fb81a64377
werkzeug@3.0.6
3.1.5

Open the chart page →

5,274
datacube-explorerdatacube-charts0.5.321 of 1See more

datacube-explorer datacube-charts 0.5.32

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
opendatacube/explorer:latest120457ffcd69
werkzeug@3.1.3
3.1.5

Open the chart page →

4,854
frontenddemo-application0.1.01 of 1See more

frontend demo-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
azhar008/flaskapplication:latesta1e827b0adea
werkzeug@2.0.2
3.1.5

Open the chart page →

3,558
kubedashdevopstalesOfficialVerified publisher4.0.01 of 8See more

kubedash devopstales 4.0.0

1 of the 8 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
devopstales/kubedash:3.1.08bb837da5aec
werkzeug@3.0.6
3.1.5

Open the chart page →

9,205
taigafermosit0.0.111 of 7See more

taiga fermosit 0.0.11

1 of the 7 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
taigaio/taiga-protected:latestfd4568a97a59
werkzeug@0.15.6
3.1.5

Open the chart page →

8,496
pgadmin4folio-org1.2.301 of 1See more

pgadmin4 folio-org 1.2.30

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.22b1f00b8163cf
werkzeug@1.0.1
3.1.5

Open the chart page →

2,034
kube-ops-viewgeek-cookbookVerified publisher1.2.21 of 1See more

kube-ops-view geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:20.4.058221b57d4d2
werkzeug@1.0.1
3.1.5

Open the chart page →

1,848
octoprintgeek-cookbookVerified publisher6.4.21 of 1See more

octoprint geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
octoprint/octoprint:1.6.1ea3bffae2470
werkzeug@1.0.1
3.1.5

Open the chart page →

3,153
IMgrycapOfficialVerified publisher1.8.01 of 3See more

IM grycap 1.8.0

1 of the 3 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
ghcr.io/grycap/im:latest06a16d4f279f
werkzeug@3.1.3
3.1.5

Open the chart page →

4,132
octoprinthalkeye0.1.11 of 1See more

octoprint halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
octoprint/octoprint:1.4.0106c26efcd8a
werkzeug@0.16.1
3.1.5

Open the chart page →

3,608
powerdnsadminhalkeye0.3.11 of 1See more

powerdnsadmin halkeye 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
werkzeug@1.0.1
3.1.5

Open the chart page →

3,345
hasher-matcher-actionerhasher-matcher-actioner1.0.01 of 1See more

hasher-matcher-actioner hasher-matcher-actioner 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
ghcr.io/facebook/threatexchange/hma:1.0.1784d09c6b75a7
werkzeug@3.1.3
3.1.5

Open the chart page →

910
helmuphelmupVerified publisher0.1.01 of 3See more

helmup helmup 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
sirrend/helmup-notifications-service:0.1.3997866417011
werkzeug@3.0.3
3.1.5

Open the chart page →

16,514
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
werkzeug@2.0.3
3.1.5

Open the chart page →

7,129
iris-webappiris-webapp0.2.41 of 2See more

iris-webapp iris-webapp 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
werkzeug@2.3.7
3.1.5

Open the chart page →

11,764
alertmanager-gchat-integrationjulb-meVerified publisher1.0.51 of 1See more

alertmanager-gchat-integration julb-me 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
julb/alertmanager-gchat-integration:1.0.5837c4038a0dd
werkzeug@1.0.1
3.1.5

Open the chart page →

2,110
kronickronic0.1.71 of 1See more

kronic kronic 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
ghcr.io/mshade/kronic:v0.1.466e3043851cd
werkzeug@3.0.1
3.1.5

Open the chart page →

1,062
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-21860.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
werkzeug@3.0.3
3.1.5

Open the chart page →

20,403

Container images carrying it

303 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
kelvinsp/mlflow:1.26.1cd33e6db2a59
werkzeug@2.1.2
3.1.5
1
kennethreitz/httpbin:latest599fe5e50731
werkzeug@0.14.1
3.1.5
1
kfirfer/slackgpt:0.0.15461331bd838e
werkzeug@3.0.1
3.1.5
1
kfserving/models-web-app:v0.6.1f322d6ffdfa3
werkzeug@2.0.1
3.1.5
1
kobotoolbox/kobocat:2.022.24ab15679454415
werkzeug@2.0.3
3.1.5
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
werkzeug@2.0.3
3.1.5
1
kodekloud/webapp-color:latest99c3821ea49b
werkzeug@0.14.1
3.1.5
1
kong/httpbin:latesta6ac46531193
werkzeug@3.1.3
3.1.5
1
kserve/models-web-app:v0.8.063ea05e73842
werkzeug@2.1.2
3.1.5
1
kserve/models-web-app:v0.13.073486345a602
werkzeug@3.0.3
3.1.5
1
kubeflownotebookswg/jupyter-web-app:v1.9.2afb52057c997
werkzeug@3.0.4
3.1.5
1
kubeflownotebookswg/jupyter-web-app:v1.6.1d762690e21c1
werkzeug@2.2.2
3.1.5
1
kubeflownotebookswg/tensorboards-web-app:v1.6.10876fef1973b
werkzeug@2.2.2
3.1.5
1
kubeflownotebookswg/tensorboards-web-app:v1.9.277f07f52a84a
werkzeug@3.0.4
3.1.5
1
kubeflownotebookswg/volumes-web-app:v1.6.17299fa94db15
werkzeug@2.2.2
3.1.5
1
kubeflownotebookswg/volumes-web-app:v1.9.2f63c3e550af3
werkzeug@3.0.4
3.1.5
1
kubesphere/examples-bookinfo-productpage-v1:1.13.0378f49ec9c44
werkzeug@0.13
3.1.5
1
kunchalavikram/connectedcity:v14a559a47579e
werkzeug@1.0.1
3.1.5
1
kunchalavikram/connectedfactory:v152c13fb9b1d9
werkzeug@1.0.1
3.1.5
1
kyso/kyso-nbdime:latest4aa9d38ee81d
werkzeug@2.2.2
3.1.5
1
langgenius/dify-api:1.0.0066035f93856
werkzeug@3.1.3
3.1.5
1
langgenius/dify-api:0.6.11fca918260dd6
werkzeug@3.0.3
3.1.5
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
werkzeug@3.1.4
3.1.5
1
libretranslate/libretranslate:v1.9.61de2d7056bb8
werkzeug@2.3.8
3.1.5
1
linuxserver/beets:1.5.0e36d16f7341c
werkzeug@2.0.2
3.1.5
1
linuxserver/calibre-web:0.6.24241009026e6f
werkzeug@3.1.3
3.1.5
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
werkzeug@1.0.1
3.1.5
1
lmacka/snappass:2.1.293f5c048b7d4
werkzeug@3.1.3
3.1.5
1
lncm/specter-desktop:v0.10.4bca14d04397d
werkzeug@1.0.1
3.1.5
1
localstack/localstack:3.19d278167f2b7
werkzeug@3.0.1
3.1.5
1
locustio/locust:2.24.151d866285170
werkzeug@3.0.1
3.1.5
1
lsstsqre/squash-api:0.5.34879415ec6ac
werkzeug@1.0.1
3.1.5
1
marcinkujawski/flask-app:2.0.1a455017b9d0e
werkzeug@2.0.3
3.1.5
1
miltex/python-api:1.0.0dab12a7748d5
werkzeug@0.16.1
3.1.5
1
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
werkzeug@1.0.1
3.1.5
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
werkzeug@2.2.2
3.1.5
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
werkzeug@2.2.3
3.1.5
1
mshanley80/httpbin2022:latest5b189a70c0fb
werkzeug@2.2.2
3.1.5
1
muhammedgamal/fp23:latest74b4cd69b6fa
werkzeug@3.0.3
3.1.5
1
nabinchhetri/flask-app:v2.0be189fbf3411
werkzeug@2.2.3
3.1.5
1
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
werkzeug@3.0.2
3.1.5
1
neilpeterson/aks-helloworld:v1fb47732ef36b
werkzeug@0.14.1
3.1.5
1
neilpeterson/chart-tweet:latest64fd8dab075f
werkzeug@0.14.1
3.1.5
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
werkzeug@1.0.1
3.1.5
1
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
werkzeug@2.0.3
3.1.5
1
octoprint/octoprint:1.4.0106c26efcd8a
werkzeug@0.16.1
3.1.5
1
octoprint/octoprint:1.6.1ea3bffae2470
werkzeug@1.0.1
3.1.5
1
oled01/automx2:2025.1.105d3e398e675
werkzeug@3.1.3
3.1.5
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
werkzeug@1.0.0
3.1.5
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
werkzeug@0.14.1
3.1.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.