StackRadar

CVE-2026-31900

Critical

Advisory

Published 11 Mar 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
16
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 16 images.

Affected packageAffected versionsFixed inImages
blackpypi19.10b0, 20.8b1, 21.9b0, 22.12.0+5 more26.3.016
OSV records
PYSEC-2026-2120
Also known as
GHSA-v53h-f6m7-xcgm

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
cosmotech-copilot-apicosmotech-apiVerified publisher0.1.11 of 1See more

cosmotech-copilot-api cosmotech-api 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
black@24.4.2
26.3.0

Open the chart page →

11,205
verbacapverbacapVerified publisher1.0.71 of 1See more

verbacap verbacap 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
black@24.4.2
26.3.0

Open the chart page →

2,233
pbcore-utilcluster-deploy0.0.11 of 1See more

pbcore-util cluster-deploy 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
black@25.11.0
26.3.0

Open the chart page →

9,128
csghubcsghubVerified publisher2.4.32 of 34See more

csghub csghub 2.4.3

2 of the 34 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
black@24.10.0
26.3.0
opencsghq/label-studio:v2.4.0b4e849fcf94a
black@24.8.0
26.3.0

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
opencsghq/csgship-agentic:v0.4.02cd29671a03e
black@24.10.0
26.3.0

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
black@24.8.0
26.3.0

Open the chart page →

6,632
kodiakfikaworks1.1.41 of 2See more

kodiak fikaworks 1.1.4

1 of the 2 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
cdignam/kodiak:v0.54.05a6a55b39cee
black@21.9b0
26.3.0

Open the chart page →

3,892
forms-catalogueforms-catalogue0.1.01 of 2See more

forms-catalogue forms-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
black@20.8b1
26.3.0

Open the chart page →

2,188
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
black@24.8.0
26.3.0

Open the chart page →

3,157
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
black@25.1.0
26.3.0

Open the chart page →

8,405
legendlegend0.1.21 of 1See more

legend legend 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
ghcr.io/grofers/legend:0.1d6e901ad0ebd
black@19.10b0
26.3.0

Open the chart page →

4,067
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
black@22.12.0
26.3.0

Open the chart page →

7,315
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-backend:0.11a9ce0b8fbd4
black@20.8b1
26.3.0

Open the chart page →

6,438
request-registryrequest-registry0.1.01 of 2See more

request-registry request-registry 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
black@20.8b1
26.3.0

Open the chart page →

2,201
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
black@24.10.0
26.3.0

Open the chart page →

3,512
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-31900.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
black@24.10.0
26.3.0

Open the chart page →

4,718

Container images carrying it

16 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
black@24.10.0
26.3.0
2
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
black@25.1.0
26.3.0
1
cdignam/kodiak:v0.54.05a6a55b39cee
black@21.9b0
26.3.0
1
heartexlabs/label-studio:latestaa461572e8f9
black@24.8.0
26.3.0
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
black@24.10.0
26.3.0
1
opencsghq/csgship-agentic:v0.4.02cd29671a03e
black@24.10.0
26.3.0
1
opencsghq/label-studio:v2.5.047e22aa71870
black@24.8.0
26.3.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
black@24.8.0
26.3.0
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
black@24.4.2
26.3.0
1
ghcr.io/grofers/legend:0.1d6e901ad0ebd
black@19.10b0
26.3.0
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
black@24.4.2
26.3.0
1
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
black@22.12.0
26.3.0
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
black@25.11.0
26.3.0
1
quay.io/mongodb/farm-intro-backend:0.11a9ce0b8fbd4
black@20.8b1
26.3.0
1
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
black@20.8b1
26.3.0
1
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
black@20.8b1
26.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.