StackRadar

CVE-2026-32875

High

Advisory

Published 18 Mar 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
33
deployed by those charts
Fix available
1 of 1
affected package

UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 33 images.

Affected packageAffected versionsFixed inImages
ujsonpypi5.5.0, 5.6.0, 5.7.0, 5.8.0+2 more5.12.033
OSV records
GHSA-c8rr-9gxc-jprv
Also known as
PYSEC-2026-2292

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
stackstorm-hastackstormVerified publisher1.1.011 of 17See more

stackstorm-ha stackstorm 1.1.0

11 of the 17 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
ujson@5.8.0
5.12.0
stackstorm/st2api:3.86f56d239d280
ujson@5.8.0
5.12.0
stackstorm/st2auth:3.833ecfda16608
ujson@5.8.0
5.12.0
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
ujson@5.8.0
5.12.0
stackstorm/st2notifier:3.8f190a6212195
ujson@5.8.0
5.12.0
stackstorm/st2rulesengine:3.8259503496ff9
ujson@5.8.0
5.12.0
stackstorm/st2scheduler:3.8b1de2055c362
ujson@5.8.0
5.12.0
stackstorm/st2sensorcontainer:3.8b1a338f64773
ujson@5.8.0
5.12.0
stackstorm/st2stream:3.81c8904a3bf67
ujson@5.8.0
5.12.0
stackstorm/st2timersengine:3.81bf35bfaf00c
ujson@5.8.0
5.12.0
stackstorm/st2workflowengine:3.819fdfffdbba8
ujson@5.8.0
5.12.0

Open the chart page →

96,419
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
ujson@5.11.0
5.12.0

Open the chart page →

4,634
clearml-servingallegroaiVerified publisher1.6.21 of 9See more

clearml-serving allegroai 1.6.2

1 of the 9 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
ujson@5.7.0
5.12.0

Open the chart page →

17,877
helmuphelmupVerified publisher0.1.01 of 3See more

helmup helmup 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
ujson@5.10.0
5.12.0

Open the chart page →

16,514
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
ujson@5.11.0
5.12.0

Open the chart page →

12,397
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
ujson@5.10.0
5.12.0

Open the chart page →

20,403
csghubcsghubVerified publisher2.4.32 of 34See more

csghub csghub 2.4.3

2 of the 34 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
ujson@5.10.0
5.12.0
opencsghq/label-studio:v2.4.0b4e849fcf94a
ujson@5.8.0
5.12.0

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
ujson@5.10.0
5.12.0

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
ujson@5.8.0
5.12.0

Open the chart page →

6,632
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
ujson@5.10.0
5.12.0

Open the chart page →

16,604
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
ujson@5.10.0
5.12.0

Open the chart page →

19,224
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
ujson@5.6.0
5.12.0

Open the chart page →

4,085
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
ujson@5.11.0
5.12.0

Open the chart page →

8,923
gwangju_2-3gwangju2-30.1.03 of 5See more

gwangju_2-3 gwangju2-3 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
clsen2024/gwangju_2-3:service-b-10ba9eff852c5
ujson@5.10.0
5.12.0
clsen2024/gwangju_2-3:service-a-151b1d45961cd
ujson@5.10.0
5.12.0
clsen2024/gwangju_2-3:service-c-1efb1586c8299
ujson@5.10.0
5.12.0

Open the chart page →

6,491
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
ujson@5.10.0
5.12.0

Open the chart page →

4,647
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
ujson@5.8.0
5.12.0

Open the chart page →

3,157
pavkrzwiatrzyk0.0.31 of 1See more

pav krzwiatrzyk 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
witcherek7/pav:0.0.342a744f29ac0
ujson@5.6.0
5.12.0

Open the chart page →

1,132
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
ujson@5.5.0
5.12.0

Open the chart page →

43,341
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
ujson@5.11.0
5.12.0

Open the chart page →

4,749
prefect-agentprefectVerified publisher2024.8.301638221 of 1See more

prefect-agent prefect 2024.8.30163822

1 of the 1 container images this version deploys carry CVE-2026-32875.

Container imageDigestPackageFixed in
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
ujson@5.10.0
5.12.0

Open the chart page →

5,451

Container images carrying it

33 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
ujson@5.7.0
5.12.0
1
aristidetm/basic-notebook:3.6.5469dbc951224
ujson@5.10.0
5.12.0
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
ujson@5.11.0
5.12.0
1
clsen2024/gwangju_2-3:service-b-10ba9eff852c5
ujson@5.10.0
5.12.0
1
clsen2024/gwangju_2-3:service-a-151b1d45961cd
ujson@5.10.0
5.12.0
1
clsen2024/gwangju_2-3:service-c-1efb1586c8299
ujson@5.10.0
5.12.0
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
ujson@5.6.0
5.12.0
1
gethue/hue:latest7d5c1b9f8a79
ujson@5.11.0
5.12.0
1
heartexlabs/label-studio:latestaa461572e8f9
ujson@5.8.0
5.12.0
1
langgenius/dify-api:1.0.0066035f93856
ujson@5.10.0
5.12.0
1
langgenius/dify-api:0.6.11fca918260dd6
ujson@5.10.0
5.12.0
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
ujson@5.5.0
5.12.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
ujson@5.10.0
5.12.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
ujson@5.10.0
5.12.0
1
opencsghq/label-studio:v2.5.047e22aa71870
ujson@5.8.0
5.12.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
ujson@5.8.0
5.12.0
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
ujson@5.10.0
5.12.0
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
ujson@5.10.0
5.12.0
1
stackstorm/st2actionrunner:3.888235ba70cad
ujson@5.8.0
5.12.0
1
stackstorm/st2api:3.86f56d239d280
ujson@5.8.0
5.12.0
1
stackstorm/st2auth:3.833ecfda16608
ujson@5.8.0
5.12.0
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
ujson@5.8.0
5.12.0
1
stackstorm/st2notifier:3.8f190a6212195
ujson@5.8.0
5.12.0
1
stackstorm/st2rulesengine:3.8259503496ff9
ujson@5.8.0
5.12.0
1
stackstorm/st2scheduler:3.8b1de2055c362
ujson@5.8.0
5.12.0
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
ujson@5.8.0
5.12.0
1
stackstorm/st2stream:3.81c8904a3bf67
ujson@5.8.0
5.12.0
1
stackstorm/st2timersengine:3.81bf35bfaf00c
ujson@5.8.0
5.12.0
1
stackstorm/st2workflowengine:3.819fdfffdbba8
ujson@5.8.0
5.12.0
1
witcherek7/pav:0.0.342a744f29ac0
ujson@5.6.0
5.12.0
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
ujson@5.10.0
5.12.0
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
ujson@5.11.0
5.12.0
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
ujson@5.11.0
5.12.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.