StackRadar

CVE-2026-27199

Medium

Advisory

Published 19 Feb 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
310
of 17,781 indexed, latest versions
Container images
306
deployed by those charts
Fix available
1 of 1
affected package

Werkzeug safe_join() allows Windows special device names

Carried by container images the latest versions of 310 of 17,781 indexed charts deploy, on 306 images.

Affected packageAffected versionsFixed inImages
werkzeugpypi0.9.1, 0.11.15, 0.12.2, 0.13+34 more3.1.6306
OSV records
GHSA-29vq-49wr-vm6x
Also known as
PYSEC-2026-2320

Charts affected

310 by stars
ChartLatestAffected imagesRadar Score
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
werkzeug@2.2.3
3.1.6

Open the chart page →

11,367
rook-cephrookOfficialVerified publisher1.20.71 of 2See more

rook-ceph rook 1.20.7

1 of the 2 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
rook/ceph:v1.20.72f970c425617
werkzeug@2.0.3
3.1.6

Open the chart page →

1,447
ceph-csi-cephfsceph-csiOfficialVerified publisher3.17.11 of 6See more

ceph-csi-cephfs ceph-csi 3.17.1

1 of the 6 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
werkzeug@2.0.3
3.1.6

Open the chart page →

4,061
ceph-csi-rbdceph-csiOfficialVerified publisher3.17.11 of 6See more

ceph-csi-rbd ceph-csi 3.17.1

1 of the 6 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
werkzeug@2.0.3
3.1.6

Open the chart page →

4,061
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
werkzeug@3.1.3
3.1.6

Open the chart page →

10,622
locustdeliveryheroVerified publisher0.35.01 of 1See more

locust deliveryhero 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
werkzeug@3.1.2
3.1.6

Open the chart page →

2,800
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
werkzeug@3.1.4
3.1.6

Open the chart page →

19,391
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
werkzeug@1.0.1
3.1.6

Open the chart page →

4,086
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
grafana/oncall:v1.16.5499851658393
werkzeug@3.1.3
3.1.6

Open the chart page →

16,251
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
werkzeug@3.1.4
3.1.6

Open the chart page →

11,384
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
werkzeug@1.0.1
3.1.6

Open the chart page →

4,918
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
werkzeug@2.1.2
3.1.6

Open the chart page →

7,705
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
werkzeug@2.3.8
3.1.6

Open the chart page →

5,987
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
werkzeug@3.0.1
3.1.6

Open the chart page →

6,041
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
werkzeug@1.0.1
3.1.6

Open the chart page →

5,173
supersetcloudposse1.2.01 of 1See more

superset cloudposse 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
werkzeug@0.15.5
3.1.6

Open the chart page →

5,851
frigateblakeblackshear7.8.01 of 1See more

frigate blakeblackshear 7.8.0

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
werkzeug@3.0.3
3.1.6

Open the chart page →

3,004
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.11.11da5c38c6a78
werkzeug@3.0.3
3.1.6

Open the chart page →

6,168
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
werkzeug@0.15.5
3.1.6

Open the chart page →

52,919
geonode-k8sgeonode-k8sVerified publisher2.0.01 of 10See more

geonode-k8s geonode-k8s 2.0.0

1 of the 10 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
geopython/pycsw:3.0.0-beta284662ea6b78b
werkzeug@3.1.4
3.1.6

Open the chart page →

13,953
kubeflowkubeflow1.6.24 of 45See more

kubeflow kubeflow 1.6.2

4 of the 45 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
kserve/models-web-app:v0.8.063ea05e73842
werkzeug@2.1.2
3.1.6
kubeflownotebookswg/jupyter-web-app:v1.6.1d762690e21c1
werkzeug@2.2.2
3.1.6
kubeflownotebookswg/tensorboards-web-app:v1.6.10876fef1973b
werkzeug@2.2.2
3.1.6
kubeflownotebookswg/volumes-web-app:v1.6.17299fa94db15
werkzeug@2.2.2
3.1.6

Open the chart page →

96,941
taigarc-helm-charts0.1.01 of 7See more

taiga rc-helm-charts 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
taigaio/taiga-protected:6.4.036318831b3e7
werkzeug@0.15.6
3.1.6

Open the chart page →

7,255
k8s-telegram-sendertelegram-senderVerified publisher0.0.11 of 1See more

k8s-telegram-sender telegram-sender 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
danuk/telegram-sender:0.0.1026560388070
werkzeug@2.2.2
3.1.6

Open the chart page →

3,048
alerta-webalerta-webVerified publisher0.1.121 of 2See more

alerta-web alerta-web 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
hayk96/alerta-web:9.0.486377705e9e3
werkzeug@3.0.4
3.1.6

Open the chart page →

3,569
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
dpage/pgadmin4:7.537946e4f3e7b
werkzeug@2.2.3
3.1.6

Open the chart page →

14,546
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
redislabs/redisinsight:1.14.0b03ab1426d0d
werkzeug@2.2.3
3.1.6

Open the chart page →

13,874
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
werkzeug@1.0.1
3.1.6

Open the chart page →

10,598
mlflowgetindataVerified publisher0.1.21 of 1See more

mlflow getindata 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
gcr.io/getindata-images-public/mlflow:latest25d6975951f1
werkzeug@3.0.2
3.1.6

Open the chart page →

2,452
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
kobotoolbox/kobocat:2.022.24ab15679454415
werkzeug@2.0.3
3.1.6
kobotoolbox/kpi:2.022.24dbcacc01bccd4
werkzeug@2.0.3
3.1.6

Open the chart page →

18,517
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
werkzeug@3.1.0
3.1.6

Open the chart page →

107,811
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
werkzeug@1.0.1
3.1.6

Open the chart page →

10,730
tensorflow-notebookcloudnativeapp0.1.21 of 1See more

tensorflow-notebook cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
tensorflow/tensorflow:1.6.0-devel1e3172090703
werkzeug@0.14.1
3.1.6

Open the chart page →

36,094
aibrixdanchevVerified publisher0.7.01 of 5See more

aibrix danchev 0.7.0

1 of the 5 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
aibrix/metadata-service:v0.7.063fb81a64377
werkzeug@3.0.6
3.1.6

Open the chart page →

5,274
datacube-explorerdatacube-charts0.5.321 of 1See more

datacube-explorer datacube-charts 0.5.32

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
opendatacube/explorer:latest120457ffcd69
werkzeug@3.1.3
3.1.6

Open the chart page →

4,854
frontenddemo-application0.1.01 of 1See more

frontend demo-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
azhar008/flaskapplication:latesta1e827b0adea
werkzeug@2.0.2
3.1.6

Open the chart page →

3,558
kubedashdevopstalesOfficialVerified publisher4.0.01 of 8See more

kubedash devopstales 4.0.0

1 of the 8 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
devopstales/kubedash:3.1.08bb837da5aec
werkzeug@3.0.6
3.1.6

Open the chart page →

9,205
taigafermosit0.0.111 of 7See more

taiga fermosit 0.0.11

1 of the 7 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
taigaio/taiga-protected:latestfd4568a97a59
werkzeug@0.15.6
3.1.6

Open the chart page →

8,496
pgadmin4folio-org1.2.301 of 1See more

pgadmin4 folio-org 1.2.30

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.22b1f00b8163cf
werkzeug@1.0.1
3.1.6

Open the chart page →

2,034
kube-ops-viewgeek-cookbookVerified publisher1.2.21 of 1See more

kube-ops-view geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:20.4.058221b57d4d2
werkzeug@1.0.1
3.1.6

Open the chart page →

1,848
octoprintgeek-cookbookVerified publisher6.4.21 of 1See more

octoprint geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
octoprint/octoprint:1.6.1ea3bffae2470
werkzeug@1.0.1
3.1.6

Open the chart page →

3,153
IMgrycapOfficialVerified publisher1.8.01 of 3See more

IM grycap 1.8.0

1 of the 3 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
ghcr.io/grycap/im:latest06a16d4f279f
werkzeug@3.1.3
3.1.6

Open the chart page →

4,132
octoprinthalkeye0.1.11 of 1See more

octoprint halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
octoprint/octoprint:1.4.0106c26efcd8a
werkzeug@0.16.1
3.1.6

Open the chart page →

3,608
powerdnsadminhalkeye0.3.11 of 1See more

powerdnsadmin halkeye 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
werkzeug@1.0.1
3.1.6

Open the chart page →

3,345
hasher-matcher-actionerhasher-matcher-actioner1.0.01 of 1See more

hasher-matcher-actioner hasher-matcher-actioner 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
ghcr.io/facebook/threatexchange/hma:1.0.1784d09c6b75a7
werkzeug@3.1.3
3.1.6

Open the chart page →

910
helmuphelmupVerified publisher0.1.01 of 3See more

helmup helmup 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
sirrend/helmup-notifications-service:0.1.3997866417011
werkzeug@3.0.3
3.1.6

Open the chart page →

16,514
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
werkzeug@2.0.3
3.1.6

Open the chart page →

7,129
iris-webappiris-webapp0.2.41 of 2See more

iris-webapp iris-webapp 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
werkzeug@2.3.7
3.1.6

Open the chart page →

11,764
alertmanager-gchat-integrationjulb-meVerified publisher1.0.51 of 1See more

alertmanager-gchat-integration julb-me 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
julb/alertmanager-gchat-integration:1.0.5837c4038a0dd
werkzeug@1.0.1
3.1.6

Open the chart page →

2,110
kronickronic0.1.71 of 1See more

kronic kronic 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
ghcr.io/mshade/kronic:v0.1.466e3043851cd
werkzeug@3.0.1
3.1.6

Open the chart page →

1,062
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-27199.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
werkzeug@3.0.3
3.1.6

Open the chart page →

20,403

Container images carrying it

306 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
aristidetm/basic-notebook:3.6.5469dbc951224
werkzeug@3.0.3
3.1.6
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
werkzeug@3.0.3
3.1.6
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
werkzeug@1.0.1
3.1.6
1
assistiot/fl_local_operations_inference:latest0518b63a2e69
werkzeug@2.3.6
3.1.6
1
assistiot/fl_training_collector:latest792715dd3084
werkzeug@2.0.2
3.1.6
1
assistiot/resource-provisioning_api:1.0.044a37b00d4f8
werkzeug@2.0.2
3.1.6
1
assistiot/resource-provisioning_im:1.0.0a942dc14030a
werkzeug@2.0.2
3.1.6
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
werkzeug@3.0.2
3.1.6
1
assistiot/traffic-classification_api:2.0.0e32b87786142
werkzeug@2.0.2
3.1.6
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
werkzeug@2.2.3
3.1.6
1
avinash263/pyredis263:latestaa2b8727f1a6
werkzeug@2.3.6
3.1.6
1
azhar008/flaskapplication:latesta1e827b0adea
werkzeug@2.0.2
3.1.6
1
badsmoke/wunderground_exporter:0.0.5c54c004f24cc
werkzeug@1.0.1
3.1.6
1
behnambm/docker-sample:v1bd3ad88afff9
werkzeug@3.0.1
3.1.6
1
benbusby/whoogle-search:0.5.4f77f7e6e4ad2
werkzeug@0.16.0
3.1.6
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
werkzeug@1.0.1
3.1.6
1
bmeares/meerschaum:2.8.48e9c5bacaa82
werkzeug@3.0.6
3.1.6
1
bootc/puppetboard:1.1.0f1383295e7be
werkzeug@1.0.0
3.1.6
1
buntha/mlflow:2.1.1154542cc3083
werkzeug@2.2.2
3.1.6
1
camptocamp/ekorre:0.1.035c91d5fda04
werkzeug@1.0.0
3.1.6
1
cbanuka/pythonapp:latestc742770d4247
werkzeug@1.0.1
3.1.6
1
ceph/daemon:latest-nautilus90f30824a96e
werkzeug@0.9.1
3.1.6
1
chandanteekinavar/findery-market-product-service:1.0c49ff7c141c0
werkzeug@2.0.1
3.1.6
1
cheyang/distributed-tf:1.6.046cc34755493
werkzeug@0.14.1
3.1.6
1
chorss/docker-pgadmin4:4.115c549cacb8ab
werkzeug@0.15.5
3.1.6
1
citizenstig/httpbin:latestb81c818ccb86
werkzeug@0.11.15
3.1.6
1
ciuse99/suggestarr:v1.0.20d72768245ef5
werkzeug@3.1.3
3.1.6
1
ckan/ckan-base-datapusher:0.0.2184d11924549f
werkzeug@2.3.8
3.1.6
1
cleveritcz/opencve:1.5.0c75c1636e0b7
werkzeug@1.0.1
3.1.6
1
clsen2024/daejeon_2-3:latest1156cd87c8fb
werkzeug@3.0.3
3.1.6
1
craigwillis/c2metadata-bd:latestae317d7e4724
werkzeug@1.0.1
3.1.6
1
cspconsole/report-collector:1.0.15839750248193b
werkzeug@3.1.5
3.1.6
1
dalibo/explain.dalibo.com:2.20.12a0b749c2f7f
werkzeug@2.2.2
3.1.6
1
danuk/telegram-sender:0.0.1026560388070
werkzeug@2.2.2
3.1.6
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
werkzeug@1.0.1
3.1.6
1
datawire/aes:1.13.62beb65062c8b
werkzeug@1.0.1
3.1.6
1
datawire/aes:3.11.195ec30b3c732
werkzeug@3.0.3
3.1.6
1
datawire/emissary:3.12.21f67a1292d2a
werkzeug@3.0.3
3.1.6
1
datawire/emissary:2.0.2-ea9716efbdd24b
werkzeug@1.0.1
3.1.6
1
deepflowce/deepflow-app:v6.2.6.5a1888d35e787
werkzeug@1.0.1
3.1.6
1
devopsgoofy/k8s-platform:latestad865312099f
werkzeug@3.0.1
3.1.6
1
devopstales/kubedash:3.1.08bb837da5aec
werkzeug@3.0.6
3.1.6
1
devopstales/kube-openid-connector:1.042c40a0e9f1b
werkzeug@2.0.3
3.1.6
1
djjudas21/alertify:0.1.0ba22be670c37
werkzeug@3.1.3
3.1.6
1
djjudas21/ecowitt-exporter:2.2.073aab45ef10d
werkzeug@2.3.8
3.1.6
1
djjudas21/liturgical-colour-app:0.7.2954935971d42
werkzeug@3.1.3
3.1.6
1
dpage/pgadmin4:8.418cd5711fc9a
werkzeug@2.3.8
3.1.6
1
dpage/pgadmin4:7.537946e4f3e7b
werkzeug@2.2.3
3.1.6
1
dpage/pgadmin4:9.11.050700ac17936
werkzeug@3.1.4
3.1.6
1
dpage/pgadmin4:9.252cb72a9e3da
werkzeug@3.1.3
3.1.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.