StackRadar

CVE-2026-22701

Medium

Advisory

Published 10 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
126
of 17,781 indexed, latest versions
Container images
144
deployed by those charts
Fix available
2 of 2
affected packages

filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock

Carried by container images the latest versions of 126 of 17,781 indexed charts deploy, on 144 images.

Affected packageAffected versionsFixed inImages
filelockpypi3.0.12, 3.3.2, 3.4.1, 3.4.2+22 more3.20.3144
python-filelockdeb3.9.0-1, 3.13.1-1, 3.18.0-1+deb13u13.9.0-1+deb12u1, 3.13.1-1ubuntu0.1~esm17
OSV records
DEBIAN-CVE-2026-22701GHSA-qmgc-5h2g-mvrwUBUNTU-CVE-2026-22701
Also known as
PYSEC-2026-1374, USN-7999-1

Charts affected

126 by stars
ChartLatestAffected imagesRadar Score
revwallet-apirevwallet0.7.121 of 1See more

revwallet-api revwallet 0.7.12

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
arthurjguerra18/revwallet:v0.7.12f540af20b307
filelock@3.15.4
3.20.3

Open the chart page →

5,790
kube-web-viewrlex0.5.01 of 1See more

kube-web-view rlex 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:23.8.0431f1bf013d0
filelock@3.12.2
3.20.3

Open the chart page →

4,908
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
filelock@3.16.1
3.20.3

Open the chart page →

9,607
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
filelock@3.18.0
3.20.3

Open the chart page →

3,512
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
filelock@3.18.0
3.20.3

Open the chart page →

4,718
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
filelock@3.20.0
3.20.3

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
filelock@3.20.0
3.20.3

Open the chart page →

4,499
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
filelock@3.13.1
3.20.3

Open the chart page →

10,209
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
filelock@3.0.12
3.20.3

Open the chart page →

8,694
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
filelock@3.13.3
3.20.3

Open the chart page →

5,565
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
filelock@3.18.0
3.20.3

Open the chart page →

7,901
downscalersqream-chartsVerified publisher1.0.01 of 1See more

downscaler sqream-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.05d328c003efe
filelock@3.9.0
3.20.3

Open the chart page →

1,009
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
filelock@3.13.1
3.20.3

Open the chart page →

4,393
chatqnatest-opea1.0.04 of 11See more

chatqna test-opea 1.0.0

4 of the 11 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
filelock@3.13.1
3.20.3
opea/llm-tgi:1.00c25aab3f106
filelock@3.16.1
3.20.3
opea/reranking-tei:1.0e48613afb191
filelock@3.13.1
3.20.3
opea/retriever-redis:1.0eb746b263705
filelock@3.13.1
3.20.3

Open the chart page →

39,090
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
filelock@3.16.1
3.20.3

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
filelock@3.16.1
3.20.3

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
opea/llm-docsum-tgi:1.002f9e8fa5d71
filelock@3.13.1
3.20.3

Open the chart page →

28,858
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
filelock@3.13.1
3.20.3

Open the chart page →

5,185
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
filelock@3.13.1
3.20.3

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
filelock@3.16.1
3.20.3

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
filelock@3.13.1
3.20.3

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
filelock@3.13.1
3.20.3

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
filelock@3.13.1
3.20.3

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
filelock@3.13.1
3.20.3

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
filelock@3.16.1
3.20.3

Open the chart page →

5,350
wallarm-node-nextwallarmVerified publisher0.5.31 of 2See more

wallarm-node-next wallarm 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-22701.

Container imageDigestPackageFixed in
wallarm/node-helpers:5.0.2-1097cadc42336
filelock@3.13.4
3.20.3

Open the chart page →

2,408

Container images carrying it

144 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
wallarm/node-helpers:5.0.2-1097cadc42336
filelock@3.13.4
3.20.3
1
weblate/weblate:3.11.3-182848df56ecd
filelock@3.0.12
3.20.3
1
yetiplatform/yeti:2.9.09bcbe2650a14
filelock@3.18.0
3.20.3
1
yetiplatform/yeti:latest9c3006cedcca
filelock@3.18.0
3.20.3
1
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
filelock@3.18.0
3.20.3
1
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
filelock@3.17.0
3.20.3
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
filelock@3.19.1
3.20.3
1
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
filelock@3.16.1
3.20.3
1
ghcr.io/hemslo/chat-search:latest39d48995a5bd
filelock@3.15.4
3.20.3
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
filelock@3.17.0
3.20.3
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
filelock@3.20.1
3.20.3
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
filelock@3.6.0
3.20.3
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
filelock@3.13.1
3.20.3
1
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
filelock@3.13.1
3.20.3
1
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
filelock@3.20.1
3.20.3
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
filelock@3.13.3
3.20.3
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
filelock@3.20.0
3.20.3
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
filelock@3.14.0
3.20.3
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
filelock@3.13.1
python-filelock@3.13.1-1
3.20.3
3.13.1-1ubuntu0.1~esm1
1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
filelock@3.13.1
python-filelock@3.13.1-1
3.20.3
3.13.1-1ubuntu0.1~esm1
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
filelock@3.13.1
python-filelock@3.13.1-1
3.20.3
3.13.1-1ubuntu0.1~esm1
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
filelock@3.13.1
python-filelock@3.13.1-1
3.20.3
3.13.1-1ubuntu0.1~esm1
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
filelock@3.13.1
python-filelock@3.13.1-1
3.20.3
3.13.1-1ubuntu0.1~esm1
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
filelock@3.16.1
3.20.3
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
filelock@3.20.0
3.20.3
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
filelock@3.20.0
3.20.3
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
filelock@3.20.0
3.20.3
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
filelock@3.7.1
3.20.3
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
filelock@3.13.1
3.20.3
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
filelock@3.20.0
3.20.3
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
filelock@3.17.0
3.20.3
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
filelock@3.20.0
3.20.3
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
filelock@3.16.1
3.20.3
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
filelock@3.18.0
3.20.3
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
filelock@3.13.1
3.20.3
1
quay.io/hpestorage/filex-csi-driver:2.6.4b7f960bbf472
filelock@3.19.1
3.20.3
1
quay.io/kiali/kiali-operator:v2.31.0f837d8f25545
filelock@3.18.0
3.20.3
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
filelock@3.20.1
3.20.3
1
quay.io/ortelius/ms-dep-pkg-cud:main-v10.0.1670-g9abe110c0c881b509a
filelock@3.20.1
3.20.3
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
filelock@3.20.1
3.20.3
1
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
filelock@3.20.1
3.20.3
1
quay.io/ortelius/ms-scorecard:main-v10.0.1276-g966a8a43337e52fdd4
filelock@3.20.1
3.20.3
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
filelock@3.20.1
3.20.3
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
filelock@3.20.1
3.20.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.