CVE-2026-3276
MediumAdvisory
Published 3 Jun 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.3
- base score, highest
- EPSS
- 0.005
- 40th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 580
- of 17,781 indexed, latest versions
- Container images
- 557
- deployed by those charts
- Fix available
- 10 of 16
- affected packages
Potential DoS via quadratic complexity in unicodedata.normalize()
Carried by container images the latest versions of 580 of 17,781 indexed charts deploy, on 557 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| python3.11deb | 3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more | no fix listed | 181 |
| python3.8deb | 3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more | no fix listed | 100 |
| python3.10deb | 3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more | 3.10.12-1~22.04.16 | 71 |
| python2.7deb | 2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 more | no fix listed | 54 |
| python3.12deb | 3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+8 more | 3.12.3-1ubuntu0.15 | 48 |
| python3.6deb | 3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more | no fix listed | 44 |
| python3.13deb | 3.13.5-2, 3.13.5-2+deb13u2, 3.13.5-2+e30, 3.13.7-1ubuntu0.1 | 3.13.5-2+deb13u3, 3.13.5-2+e36 | 34 |
| python3.5deb | 3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9 | no fix listed | 25 |
| python3apk | 3.12.12-r0, 3.14.3-r0, 3.14.5-r0, 3.14.5-r1 | 3.14.7-r0 | 12 |
| python3.4deb | 3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7 | no fix listed | 7 |
| python-3.14apk | 3.14.2-r2, 3.14.4-r2 | 3.14.6-r0 | 5 |
| pythonbitnami | 3.11.11-0, 3.12.8-0, 3.13.5-1 | 3.10.21 | 3 |
| python-3.13apk | 3.13.7-r0, 3.13.10-r0, 3.13.12-r2 | 3.13.14-r0 | 3 |
| python-3.12apk | 3.12.0-r1, 3.12.9-r1 | 3.12.13-r8 | 2 |
| python3.14deb | 3.14.4-1 | 3.14.4-1ubuntu0.1 | 2 |
| python3rpm | 3.12.9-13.azl3 | 3.12.9-14 | 1 |
- OSV records
- ALPINE-CVE-2026-3276BIT-python-2026-3276CGA-698r-r6xg-jhcrCGA-fxc6-vp6h-gfxxCGA-g99p-cv4c-h3m9DEBIAN-CVE-2026-3276UBUNTU-CVE-2026-3276AZL-89466ECHO-3bd2-a10b-bc48
- Also known as
- BIT-libpython-2026-3276, BIT-python-min-2026-3276, CGA-j778-9cjq-6hm2, CGA-q294-94q5-6qv5, CGA-xvwf-hrxf-jcvh, PSF-2026-25, USN-8509-1
Charts affected
580 by stars
Container images carrying it
557 by charts deploying them
A fixed version is listed for 10 of the 16 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| oomk8s/ | 875814cc853d | python2.7 python3.5 | no fix listed no fix listed | 11 |
| library/ | 8a279e9396a8 | python3.10 | 3.10.12-1~22.04.16 | 10 |
| library/ | e582c0bc7766 | python3.12 | 3.12.3-1ubuntu0.15 | 8 |
| oomk8s/ | 7daa08b81954 | python2.7 python3.5 | no fix listed no fix listed | 6 |
| quay.io/ | 95d6f0e05636 | python3.11 | no fix listed | 6 |
| hyperledger/ | 4ce6f43ded2e | python2.7 python3.5 | no fix listed no fix listed | 4 |
| hyperledger/ | f6c724592abf | python2.7 python3.5 | no fix listed no fix listed | 4 |
| jaegertracing/ | d48d6dab2c65 | python3.10 | 3.10.12-1~22.04.16 | 4 |
| library/ | c3f70098e01d | python3.10 | 3.10.12-1~22.04.16 | 4 |
| cloudve/ | 4a3d7fae90bb | python3.8 | no fix listed | 3 |
| dgraph/ | 3b55ea83fffe | python3.8 | no fix listed | 3 |
| library/ | be23f54a88d3 | python3.11 | no fix listed | 3 |
| omecproject/ | d59ccb138ffb | python2.7 | no fix listed | 3 |
| prompve/ | 4867684c0a93 | python3 | 3.14.7-r0 | 3 |
| selenium/ | 02f251d48d5f | python3.8 | no fix listed | 3 |
| quay.io/ | 2b6db27eaf3d | python3.10 | 3.10.12-1~22.04.16 | 3 |
| quay.io/ | 709c7da19c5a | python3.11 | no fix listed | 3 |
| alpine/ | 048f8d9c8cc7 | python3 | 3.14.7-r0 | 2 |
| apache/ | ae0b86d3c4d0 | python3.12 | 3.12.3-1ubuntu0.15 | 2 |
| cfssl/ | c9018c2ddf0b | python3.11 | no fix listed | 2 |
| freeradius/ | 21c8bfa904d8 | python2.7 | no fix listed | 2 |
| gjeanmart/ | 926264c8f2d1 | python3.11 | no fix listed | 2 |
| hookiesolutions/ | 0629694246ba | python3.8 | no fix listed | 2 |
| istio/ | dbb7726d1bf0 | python3.6 | no fix listed | 2 |
| istio/ | a78b7a165744 | python3.6 | no fix listed | 2 |
| library/ | 5aa8400b4b3b | python2.7 | no fix listed | 2 |
| library/ | 7cbcec0086ac | python3.10 | 3.10.12-1~22.04.16 | 2 |
| library/ | eedf63967cdb | python3.11 | no fix listed | 2 |
| library/ | 935b3f84c1e4 | python3.12 | 3.12.3-1ubuntu0.15 | 2 |
| library/ | f020c06da226 | python3.10 | 3.10.12-1~22.04.16 | 2 |
| lightstep/ | 11c5569aaf3b | python3.5 | no fix listed | 2 |
| louislam/ | 917318f9d7be | python3.11 | no fix listed | 2 |
| louislam/ | 9aeb4e51d038 | python3.11 | no fix listed | 2 |
| louislam/ | a8610b3b4c38 | python3.11 | no fix listed | 2 |
| moreillon/ | e1c9bfab5c16 | python3.11 | no fix listed | 2 |
| obolnetwork/ | 278c7e2897b6 | python3.13 | 3.13.5-2+deb13u3 | 2 |
| omecproject/ | cfdb566dd949 | python2.7 python3.5 | no fix listed no fix listed | 2 |
| opendatacube/ | 668cbb41473c | python3.12 | 3.12.3-1ubuntu0.15 | 2 |
| qichenxu4pd/ | f3a8502bc21b | python3.11 | no fix listed | 2 |
| redis/ | 1c5f43fddcdd | python3.10 | 3.10.12-1~22.04.16 | 2 |
| redis/ | 72035434f455 | python3.10 | 3.10.12-1~22.04.16 | 2 |
| redis/ | e44b2b49d059 | python3.10 | 3.10.12-1~22.04.16 | 2 |
| smartedge/ | 4cd63c22ce36 | python3.8 | no fix listed | 2 |
| streamnative/ | 0e6d7aa3ef32 | python3.8 | no fix listed | 2 |
| svtechnmaa/ | b2987abe57d3 | python3.10 | 3.10.12-1~22.04.16 | 2 |
| tzahi12345/ | 2f943d584711 | python3.10 | 3.10.12-1~22.04.16 | 2 |
| uffizzi/ | 0344805f267b | python3.11 | no fix listed | 2 |
| vdiogov/ | 6945f84f0058 | python3.11 | no fix listed | 2 |
| wurstmeister/ | 7a7fd44a7210 | python2.7 python3.4 | no fix listed no fix listed | 2 |
| ghcr.io/ | 82d0b161161d | python3.12 | 3.12.3-1ubuntu0.15 | 2 |