StackRadar

CVE-2026-32597

High

Advisory

Published 13 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
19th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
243
of 17,781 indexed, latest versions
Container images
236
deployed by those charts
Fix available
2 of 2
affected packages

PyJWT accepts unknown `crit` header extensions

Carried by container images the latest versions of 243 of 17,781 indexed charts deploy, on 236 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi1.4.2, 1.5.3, 1.6.1, 1.6.4+14 more2.12.0236
pyjwtdeb1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.6.0-1+1 more1.7.1-2ubuntu2.1+esm1, 2.3.0-1ubuntu0.3, 2.6.0-1+deb12u1, 2.7.0-1ubuntu0.118
OSV records
DEBIAN-CVE-2026-32597GHSA-752w-5fwx-jx9fUBUNTU-CVE-2026-32597
Also known as
PYSEC-2026-120, USN-8133-1

Charts affected

243 by stars
ChartLatestAffected imagesRadar Score
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
pyjwt@2.6.0
2.12.0

Open the chart page →

30,159
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
pyjwt@2.8.0
2.12.0

Open the chart page →

11,367
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
pyjwt@2.10.1
2.12.0

Open the chart page →

5,366
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
pyjwt@2.4.0
2.12.0

Open the chart page →

9,145
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
pyjwt@2.8.0
2.12.0

Open the chart page →

10,622
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.11 of 2See more

stackgres-operator stackgres-charts 1.19.1

1 of the 2 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
quay.io/stackgres/operator:1.19.1f241b0b20326
pyjwt@2.9.0
2.12.0

Open the chart page →

2,119
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
grafana/oncall:v1.16.5499851658393
pyjwt@2.10.1
2.12.0

Open the chart page →

16,251
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
pyjwt@2.10.1
2.12.0

Open the chart page →

11,384
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
pyjwt@2.3.0
2.12.0

Open the chart page →

7,705
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
pyjwt@2.4.0
2.12.0

Open the chart page →

5,987
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
pyjwt@2.8.0
2.12.0

Open the chart page →

6,041
supersetcloudposse1.2.01 of 1See more

superset cloudposse 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
pyjwt@1.7.1
2.12.0

Open the chart page →

5,851
openclawopenclawVerified publisher1.91.31 of 2See more

openclaw openclaw 1.91.3

1 of the 2 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
pyjwt@2.7.0
2.12.0

Open the chart page →

2,977
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
pyjwt@2.7.0
2.12.0

Open the chart page →

4,556
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
openmined/syft-backend:0.9.5b72f74a68b32
pyjwt@2.10.1
2.12.0

Open the chart page →

17,245
uptime-kumaduyet0.1.71 of 1See more

uptime-kuma duyet 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.18.5a84767d7934f
pyjwt@1.7.0
2.12.0

Open the chart page →

4,515
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.11.11da5c38c6a78
pyjwt@2.8.0
2.12.0

Open the chart page →

6,168
fadicetic0.3.13 of 25See more

fadi cetic 0.3.1

3 of the 25 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
pyjwt@1.7.1
2.12.0
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
pyjwt@1.7.1
2.12.0
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
pyjwt@1.7.1
2.12.0

Open the chart page →

52,919
daskhubdask2024.1.12 of 9See more

daskhub dask 2024.1.1

2 of the 9 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
pangeo/base-notebook:2024.01.155fbe688a4f80
pyjwt@2.8.0
2.12.0
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
pyjwt@2.8.0
2.12.0

Open the chart page →

14,094
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.6.0
2.3.0-1ubuntu0.3
2.12.0

Open the chart page →

27,267
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
pyjwt@2.7.0
2.12.0

Open the chart page →

9,460
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
pyjwt@2.7.0-1
pyjwt@2.7.0
2.7.0-1ubuntu0.1
2.12.0
apache/hertzbeat-collector:1.8.0a2bab1be574c
pyjwt@2.7.0-1
pyjwt@2.7.0
2.7.0-1ubuntu0.1
2.12.0

Open the chart page →

14,000
taigarc-helm-charts0.1.01 of 7See more

taiga rc-helm-charts 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
taigaio/taiga-back:6.4.29f97323cc150
pyjwt@2.1.0
2.12.0

Open the chart page →

7,255
netboxstartechnicaVerified publisher5.1.01 of 4See more

netbox startechnica 5.1.0

1 of the 4 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
pyjwt@2.8.0
2.12.0

Open the chart page →

1,650
alerta-webalerta-webVerified publisher0.1.121 of 2See more

alerta-web alerta-web 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
hayk96/alerta-web:9.0.486377705e9e3
pyjwt@2.10.1
2.12.0

Open the chart page →

3,569
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
pyjwt@2.8.0
2.12.0

Open the chart page →

17,404
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
dpage/pgadmin4:7.537946e4f3e7b
pyjwt@2.7.0
2.12.0

Open the chart page →

14,546
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
pyjwt@2.10.1
2.12.0

Open the chart page →

4,634
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
flagsmith/flagsmith-api:v2.6.0fd58556339a4
pyjwt@1.7.1
2.12.0

Open the chart page →

6,868
kobotoolboxone-acre-fundVerified publisher0.7.41 of 9See more

kobotoolbox one-acre-fund 0.7.4

1 of the 9 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
kobotoolbox/kpi:2.022.24dbcacc01bccd4
pyjwt@2.3.0
2.12.0

Open the chart page →

18,517
open-zaakopen-zaak0.8.01 of 3See more

open-zaak open-zaak 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
openzaak/open-zaak:1.6.02ca2ea6e0ae9
pyjwt@2.3.0
2.12.0

Open the chart page →

4,045
mealieth-chartsVerified publisher0.5.11 of 1See more

mealie th-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
pyjwt@2.10.1
2.12.0

Open the chart page →

3,804
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.01 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
pyjwt@2.10.1
2.12.0

Open the chart page →

12,037
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
pyjwt@2.0.1
2.12.0

Open the chart page →

12,046
clearml-servingallegroaiVerified publisher1.6.22 of 9See more

clearml-serving allegroai 1.6.2

2 of the 9 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
pyjwt@2.4.0
2.12.0
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
pyjwt@2.4.0
2.12.0

Open the chart page →

17,877
anteonanteonVerified publisher2.6.42 of 13See more

anteon anteon 2.6.4

2 of the 13 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
pyjwt@2.9.0
2.12.0
ddosify/selfhosted_backend:3.2.93c11e3182652
pyjwt@2.8.0
2.12.0

Open the chart page →

22,202
tikaapache-tika3.2.21 of 1See more

tika apache-tika 3.2.2

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
apache/tika:3.2.2.0-fullffab324253ed
pyjwt@2.10.1
2.12.0

Open the chart page →

437
squestchristianhuthVerified publisher6.6.71 of 4See more

squest christianhuth 6.6.7

1 of the 4 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
pyjwt@2.10.1
2.12.0

Open the chart page →

9,971
syncstorage-rschristianhuthVerified publisher6.1.11 of 2See more

syncstorage-rs christianhuth 6.1.1

1 of the 2 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/porelli/firefox-sync:syncstorage-rs-mysql-0.18.27d244e514216
pyjwt@2.10.1
2.12.0

Open the chart page →

693
pgbenchcloudnative-pgVerified publisher0.1.01 of 1See more

pgbench cloudnative-pg 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
pyjwt@2.6.0
2.12.0

Open the chart page →

2,713
cosmotech-copilot-apicosmotech-apiVerified publisher0.1.11 of 1See more

cosmotech-copilot-api cosmotech-api 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
pyjwt@2.8.0
2.12.0

Open the chart page →

11,205
paperless-ngxcrystalnetVerified publisher0.2.221 of 3See more

paperless-ngx crystalnet 0.2.22

1 of the 3 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
pyjwt@2.9.0
2.12.0

Open the chart page →

13,761
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
pyjwt@1.7.1
2.12.0

Open the chart page →

4,568
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
pyjwt@1.7.1
2.12.0

Open the chart page →

7,984
dominodominoVerified publisher0.1.111 of 3See more

domino domino 0.1.11

1 of the 3 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
pyjwt@2.4.0
2.12.0

Open the chart page →

8,823
archerydoubanVerified publisher0.4.31 of 6See more

archery douban 0.4.3

1 of the 6 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
hhyo/archery:v1.9.11aa41843419e
pyjwt@2.5.0
2.12.0

Open the chart page →

5,853
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.6.0
2.3.0-1ubuntu0.3
2.12.0

Open the chart page →

10,858
craftycontrollerdrewburr-labs-helm-chartsVerified publisher0.3.01 of 1See more

craftycontroller drewburr-labs-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
pyjwt@2.8.0
2.12.0

Open the chart page →

3,671
taigafermosit0.0.111 of 7See more

taiga fermosit 0.0.11

1 of the 7 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
pyjwt@2.10.1
2.12.0

Open the chart page →

8,496
obicogabe565Verified publisher0.6.01 of 3See more

obico gabe565 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-32597.

Container imageDigestPackageFixed in
ghcr.io/gabe565/obico/web:latesta5c1daef46c0
pyjwt@2.10.1
2.12.0

Open the chart page →

1,965

Container images carrying it

236 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pyjwt@2.6.0
2.12.0
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
pyjwt@2.10.1
2.12.0
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
pyjwt@2.10.1
2.12.0
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
pyjwt@2.8.0
2.12.0
1
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
pyjwt@2.7.0
2.12.0
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
pyjwt@2.10.1
2.12.0
1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
pyjwt@2.7.0
2.12.0
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
pyjwt@2.7.0
2.12.0
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
pyjwt@2.7.0
2.12.0
1
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
pyjwt@2.7.0
2.12.0
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
pyjwt@2.9.0
2.12.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
pyjwt@2.9.0
2.12.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
pyjwt@2.10.1
2.12.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
pyjwt@2.10.1
2.12.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
pyjwt@2.10.1
2.12.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
pyjwt@2.10.1
2.12.0
1
ghcr.io/porelli/firefox-sync:syncstorage-rs-mysql-0.18.27d244e514216
pyjwt@2.10.1
2.12.0
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
pyjwt@2.11.0
2.12.0
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
pyjwt@2.10.1
2.12.0
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
pyjwt@2.9.0
2.12.0
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
pyjwt@2.10.1
2.12.0
1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
pyjwt@2.4.0
2.12.0
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
pyjwt@2.8.0
2.12.0
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
pyjwt@2.10.1
2.12.0
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
pyjwt@2.9.0
2.12.0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
pyjwt@2.4.0
2.12.0
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
pyjwt@2.10.1
2.12.0
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
pyjwt@2.3.0
2.12.0
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
pyjwt@2.8.0
2.12.0
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
pyjwt@2.4.0
2.12.0
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
pyjwt@2.10.1
2.12.0
1
quay.io/stackgres/operator:1.19.1f241b0b20326
pyjwt@2.9.0
2.12.0
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
pyjwt@2.8.0
2.12.0
1
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
pyjwt@1.7.1
2.12.0
1
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
pyjwt@1.7.1
2.12.0
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
pyjwt@2.10.1
2.12.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.