StackRadar

CVE-2026-32597

High

Advisory

Published 13 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
19th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
243
of 17,781 indexed, latest versions
Container images
236
deployed by those charts
Fix available
2 of 2
affected packages

PyJWT accepts unknown `crit` header extensions

Carried by container images the latest versions of 243 of 17,781 indexed charts deploy, on 236 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi1.4.2, 1.5.3, 1.6.1, 1.6.4+14 more2.12.0236
pyjwtdeb1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.6.0-1+1 more1.7.1-2ubuntu2.1+esm1, 2.3.0-1ubuntu0.3, 2.6.0-1+deb12u1, 2.7.0-1ubuntu0.118
OSV records
DEBIAN-CVE-2026-32597GHSA-752w-5fwx-jx9fUBUNTU-CVE-2026-32597
Also known as
PYSEC-2026-120, USN-8133-1

Charts affected

243 by stars
ChartLatestAffected imagesRadar Score
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
pyjwt@2.10.1
2.12.0

Open the chart page →

6,583
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
pyjwt@2.10.1
2.12.0

Open the chart page →

4,749
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
pyjwt@2.10.1
2.12.0

Open the chart page →

3,854
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
pyjwt@2.5.0
2.12.0

Open the chart page →

22,084
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
pyjwt@2.9.0
2.12.0

Open the chart page →

21,211
request-registryrequest-registry0.1.01 of 2See more

request-registry request-registry 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
pyjwt@1.7.1
2.12.0

Open the chart page →

2,201
imgtagrotationalVerified publisher0.2.01 of 1See more

imgtag rotational 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
pyjwt@2.10.1
2.12.0

Open the chart page →

3,312
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
pyjwt@2.10.1
2.12.0

Open the chart page →

7,436
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
pyjwt@2.10.1
2.12.0

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
pyjwt@2.10.1
2.12.0

Open the chart page →

4,499
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
pyjwt@2.6.0
2.12.0

Open the chart page →

30,219
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
pyjwt@2.3.0
2.12.0

Open the chart page →

7,295
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
pyjwt@1.7.0
2.12.0

Open the chart page →

4,744
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
pyjwt@2.8.0
2.12.0

Open the chart page →

10,209
pgadminsb-helm-charts0.3.01 of 1See more

pgadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.13561c1f8f99f2
pyjwt@2.9.0
2.12.0

Open the chart page →

1,713
syncstorageschichtelVerified publisher0.1.11 of 1See more

syncstorage schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
mozilla/syncstorage-rs:0.15.893752877dced
pyjwt@2.8.0
2.12.0

Open the chart page →

1,318
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
pyjwt@1.7.1
2.12.0

Open the chart page →

8,694
aafsmo-helm-chart6.0.01 of 14See more

aaf smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.12.0

Open the chart page →

25,769
aaismo-helm-chart6.0.01 of 14See more

aai smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.12.0

Open the chart page →

25,803
dmaap-listenersmo-helm-chart6.0.01 of 3See more

dmaap-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.12.0

Open the chart page →

25,769
elasticsearchsmo-helm-chart6.0.01 of 5See more

elasticsearch smo-helm-chart 6.0.0

1 of the 5 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.12.0

Open the chart page →

24,776
mariadb-initsmo-helm-chart6.0.01 of 2See more

mariadb-init smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.12.0

Open the chart page →

24,776
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.12.0

Open the chart page →

25,769
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.12.0

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.12.0

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.12.0

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.12.0

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.12.0

Open the chart page →

25,769
smtpsmtpVerified publisher1.3.31 of 1See more

smtp smtp 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
pyjwt@2.10.1
2.12.0

Open the chart page →

1,437
srebotsrebot0.14.01 of 2See more

srebot srebot 0.14.0

1 of the 2 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
pyjwt@2.11.0
2.12.0

Open the chart page →

1,542
artifactory-cleanupsubshellVerified publisher1.0.11 of 1See more

artifactory-cleanup subshell 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
devopshq/artifactory-cleanup:1.0.1830e093bffa91
pyjwt@2.10.1
2.12.0

Open the chart page →

2,534
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
pyjwt@2.9.0
2.12.0

Open the chart page →

4,731
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
pyjwt@2.7.0
2.12.0

Open the chart page →

7,248
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
pyjwt@2.4.0
2.12.0

Open the chart page →

8,607
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
pyjwt@2.7.0-1
pyjwt@2.7.0
2.7.0-1ubuntu0.1
2.12.0

Open the chart page →

45,239
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
2.12.0

Open the chart page →

4,768
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pyjwt@2.7.0-1
pyjwt@2.7.0
2.7.0-1ubuntu0.1
2.12.0

Open the chart page →

4,305
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
2.3.0-1ubuntu0.3
2.12.0

Open the chart page →

13,459
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
pyjwt@2.10.1
2.12.0

Open the chart page →

5,484
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pyjwt@2.4.0
2.12.0

Open the chart page →

7,085
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
pyjwt@2.6.0
2.12.0

Open the chart page →

9,117
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyjwt@1.6.1
2.12.0

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyjwt@1.6.1
2.12.0

Open the chart page →

11,784

Container images carrying it

236 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
pyjwt@2.8.0
2.12.0
1
statcan/ckan:2.93921305425b8
pyjwt@1.7.1
2.12.0
1
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
pyjwt@2.6.0
2.12.0
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
pyjwt@2.6.0
2.12.0
1
taigaio/taiga-back:6.4.29f97323cc150
pyjwt@2.1.0
2.12.0
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
2.3.0-1ubuntu0.3
2.12.0
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
2.3.0-1ubuntu0.3
2.12.0
1
timescale/timescaledb-ha:pg16d7db8f1085a3
pyjwt@2.3.0
2.12.0
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
2.3.0-1ubuntu0.3
2.12.0
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
pyjwt@2.3.0-1
pyjwt@2.3.0
2.3.0-1ubuntu0.3
2.12.0
1
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
pyjwt@2.9.0
2.12.0
1
trueosiris/vrising:latest9356f98ad561
pyjwt@2.3.0
2.12.0
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
2.3.0-1ubuntu0.3
2.12.0
1
vabene1111/recipes:2.3.50f8d061895e9
pyjwt@2.10.1
2.12.0
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
pyjwt@2.3.0
2.12.0
1
wazuh/wazuh-manager:4.11.11da5c38c6a78
pyjwt@2.8.0
2.12.0
1
wazuh/wazuh-manager:4.14.45a065930682d
pyjwt@2.10.1
2.12.0
1
wazuh/wazuh-manager:4.14.3f09282d281f6
pyjwt@2.10.1
2.12.0
1
weblate/weblate:3.11.3-182848df56ecd
pyjwt@1.7.1
2.12.0
1
yetiplatform/yeti:2.9.09bcbe2650a14
pyjwt@2.10.1
2.12.0
1
yetiplatform/yeti:latest9c3006cedcca
pyjwt@2.10.1
2.12.0
1
zepai/knowledge-graph-mcp:v0.2.16ab0ee79926b
pyjwt@2.10.1
2.12.0
1
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
pyjwt@2.10.1
2.12.0
1
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
pyjwt@2.7.0
2.12.0
1
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
pyjwt@2.11.0
2.12.0
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
pyjwt@2.9.0
2.12.0
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
pyjwt@2.7.0
2.12.0
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
pyjwt@2.7.0
2.12.0
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pyjwt@2.7.0-1
pyjwt@2.7.0
2.7.0-1ubuntu0.1
2.12.0
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
pyjwt@2.10.1
2.12.0
1
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
pyjwt@2.6.0
2.12.0
1
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
pyjwt@2.10.1
2.12.0
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
pyjwt@2.8.0
2.12.0
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
pyjwt@2.4.0
2.12.0
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
pyjwt@2.4.0
2.12.0
1
ghcr.io/dodevops/azure-app-exporter/azure-app-exporter:0.1.38b472877847f5
pyjwt@2.8.0
2.12.0
1
ghcr.io/eslupmi/impulse:v3.7.03ded1b7ebca0
pyjwt@2.10.1
2.12.0
1
ghcr.io/gabe565/obico/web:latesta5c1daef46c0
pyjwt@2.10.1
2.12.0
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
pyjwt@2.11.0
2.12.0
1
ghcr.io/grycap/im:latest06a16d4f279f
pyjwt@2.10.1
2.12.0
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
pyjwt@2.10.1
2.12.0
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
pyjwt@2.10.1
2.12.0
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
pyjwt@2.3.0
2.12.0
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
pyjwt@2.8.0
2.12.0
1
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
pyjwt@2.10.1
2.12.0
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
pyjwt@2.10.1
2.12.0
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
pyjwt@2.11.0
2.12.0
1
ghcr.io/iisas/domino-rest:latest3009350bfc11
pyjwt@2.10.1
2.12.0
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
pyjwt@2.7.0-1
pyjwt@2.7.0
2.7.0-1ubuntu0.1
2.12.0
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
pyjwt@2.7.0-1
pyjwt@2.7.0
2.7.0-1ubuntu0.1
2.12.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.