StackRadar

CVE-2026-26007

High

Advisory

Published 10 Feb 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
474
of 17,787 indexed, latest versions
Container images
468
deployed by those charts
Fix available
2 of 2
affected packages

cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves

Carried by container images the latest versions of 474 of 17,787 indexed charts deploy, on 468 images.

Affected packageAffected versionsFixed inImages
cryptographypypi1.7.2, 1.9, 2.1.4, 2.2.2+68 more46.0.5468
python-cryptographydeb2.1.4-1ubuntu1.2, 2.1.4-1ubuntu1.3, 2.1.4-1ubuntu1.4, 2.8-3ubuntu0.1+8 more2.1.4-1ubuntu1.4+esm3, 2.8-3ubuntu0.3+esm2, 3.4.8-1ubuntu2.3, 41.0.7-4ubuntu0.341
OSV records
GHSA-r6ph-v2qm-q3c2UBUNTU-CVE-2026-26007DEBIAN-CVE-2026-26007
Also known as
PYSEC-2026-2141, USN-8087-1, USN-8087-3

Charts affected

474 by stars
ChartLatestAffected imagesRadar Score
scribesynapse0.2.161 of 7See more

scribe synapse 0.2.16

1 of the 7 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
cryptography@37.0.2
46.0.5

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
cryptography@37.0.2
46.0.5

Open the chart page →

1,955
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
46.0.5

Open the chart page →

17,461
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
supabase/realtime:latestd3aa0c86c7b3
cryptography@43.0.0
46.0.5

Open the chart page →

9,556
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
cryptography@42.0.7
46.0.5

Open the chart page →

1,515
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
cryptography@41.0.7
46.0.5

Open the chart page →

7,248
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
cryptography@39.0.1
46.0.5

Open the chart page →

3,164
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
cryptography@38.0.1
46.0.5

Open the chart page →

8,607
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
cryptography@41.0.7
python-cryptography@41.0.7-4build3
46.0.5
41.0.7-4ubuntu0.3

Open the chart page →

45,239
phonebook-chartusuladams2Verified publisher0.2.11 of 3See more

phonebook-chart usuladams2 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
46.0.5

Open the chart page →

3,176
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
cryptography@44.0.2
46.0.5

Open the chart page →

4,768
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
cryptography@41.0.7
python-cryptography@41.0.7-4ubuntu0.1
46.0.5
41.0.7-4ubuntu0.3

Open the chart page →

4,305
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
cryptography@3.4.8
python-cryptography@3.4.8-1ubuntu2.1
46.0.5
3.4.8-1ubuntu2.3

Open the chart page →

13,459
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
cryptography@43.0.3
46.0.5

Open the chart page →

7,628
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
cryptography@44.0.1
46.0.5

Open the chart page →

5,484
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
cryptography@3.3.2
46.0.5

Open the chart page →

11,119
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
cryptography@42.0.4
46.0.5

Open the chart page →

7,085
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
cryptography@38.0.4
python-cryptography@38.0.4-3+deb12u1
46.0.5
no fix listed

Open the chart page →

9,117
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
46.0.5

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
46.0.5

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
cryptography@35.0.0
46.0.5

Open the chart page →

2,643
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
cryptography@44.0.2
46.0.5

Open the chart page →

570
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
46.0.5

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-26007.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
46.0.5

Open the chart page →

1,636

Container images carrying it

468 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
cryptography@44.0.3
46.0.5
1
ghcr.io/kokuwaio/gcloud-mysql:v3.2.1963098135c550
cryptography@42.0.7
46.0.5
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
cryptography@43.0.3
46.0.5
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
cryptography@44.0.3
46.0.5
1
ghcr.io/linuxserver/pyload:version-5de90278d3c87933a5fd
cryptography@3.3.2
46.0.5
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
cryptography@42.0.8
46.0.5
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
cryptography@41.0.7
46.0.5
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
cryptography@41.0.7
46.0.5
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
cryptography@46.0.3
46.0.5
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
cryptography@42.0.6
46.0.5
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
cryptography@46.0.3
46.0.5
1
ghcr.io/olivetin/olivetin:2025.2.19a89958921526
cryptography@41.0.7
46.0.5
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
cryptography@44.0.0
46.0.5
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
cryptography@41.0.7
46.0.5
1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
cryptography@41.0.7
46.0.5
1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
cryptography@41.0.7
46.0.5
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
cryptography@41.0.7
46.0.5
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
cryptography@41.0.7
46.0.5
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
cryptography@41.0.7
46.0.5
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
cryptography@41.0.7
46.0.5
1
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
cryptography@41.0.7
46.0.5
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
cryptography@43.0.3
46.0.5
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
cryptography@43.0.1
46.0.5
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
cryptography@44.0.3
46.0.5
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
cryptography@44.0.3
46.0.5
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
cryptography@44.0.3
46.0.5
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
cryptography@37.0.4
46.0.5
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
cryptography@41.0.7
46.0.5
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
cryptography@44.0.3
46.0.5
1
ghcr.io/plausible/community-edition:v3.0.114c1afde21d6
cryptography@44.0.0
46.0.5
1
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
cryptography@42.0.7
46.0.5
1
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
cryptography@42.0.7
46.0.5
1
ghcr.io/porelli/firefox-sync:syncstorage-rs-mysql-0.18.27d244e514216
cryptography@43.0.1
46.0.5
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
cryptography@46.0.0
46.0.5
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
cryptography@46.0.3
46.0.5
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
cryptography@44.0.0
46.0.5
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
cryptography@43.0.1
46.0.5
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
cryptography@44.0.0
46.0.5
1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
cryptography@39.0.1
46.0.5
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
cryptography@38.0.4
python-cryptography@38.0.4-3
46.0.5
no fix listed
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
cryptography@43.0.3
46.0.5
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
cryptography@42.0.4
46.0.5
1
mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.76e43ba0bd009
cryptography@42.0.5
46.0.5
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
cryptography@45.0.6
46.0.5
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
cryptography@43.0.3
46.0.5
1
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
cryptography@43.0.1
46.0.5
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
cryptography@41.0.7
46.0.5
1
quay.io/ceph/ceph:v21.1.05ff3692d2f3f
cryptography@43.0.0
46.0.5
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
cryptography@37.0.2
46.0.5
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
cryptography@41.0.3
46.0.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.