StackRadar

CVE-2026-34591

Medium

Advisory

Published 1 Apr 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
28
of 17,781 indexed, latest versions
Container images
44
deployed by those charts
Fix available
1 of 2
affected packages

Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write

Carried by container images the latest versions of 28 of 17,781 indexed charts deploy, on 44 images.

Affected packageAffected versionsFixed inImages
poetrypypi1.4.2, 1.5.1, 1.6.1, 1.7.1+10 more2.3.344
poetrydeb1.8.2+dfsg-1ubuntu2no fix listed5
OSV records
GHSA-2599-h6xx-hpxpUBUNTU-CVE-2026-34591
Also known as
PYSEC-2026-2260

Charts affected

28 by stars
ChartLatestAffected imagesRadar Score
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
poetry@1.5.1
2.3.3

Open the chart page →

4,293
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
poetry@1.8.3
2.3.3

Open the chart page →

5,987
squestchristianhuthVerified publisher6.6.71 of 4See more

squest christianhuth 6.6.7

1 of the 4 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
poetry@1.8.0
2.3.3

Open the chart page →

9,971
hpe-greenlake-file-csi-driverhpe-storageVerified publisher2.6.41 of 7See more

hpe-greenlake-file-csi-driver hpe-storage 2.6.4

1 of the 7 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
quay.io/hpestorage/filex-csi-driver:2.6.4b7f960bbf472
poetry@1.8.3
2.3.3

Open the chart page →

6,095
kuma-ingress-watcherkuma-ingress-watcherVerified publisher1.4.01 of 1See more

kuma-ingress-watcher kuma-ingress-watcher 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
poetry@2.0.1
2.3.3

Open the chart page →

2,662
locustlocustVerified publisher0.1.41 of 1See more

locust locust 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
hansehe/locust:1.1.0bc8e45262bc4
poetry@1.7.1
2.3.3

Open the chart page →

2,757
airbyteairbyte-v2Verified publisher2.2.01 of 10See more

airbyte airbyte-v2 2.2.0

1 of the 10 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
airbyte/manifest-server:7.23.73b3a670af168
poetry@2.0.1
2.3.3

Open the chart page →

12,473
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
poetry@1.4.2
2.3.3

Open the chart page →

2,507
kube-ops-viewchristianhuthVerified publisher8.3.31 of 1See more

kube-ops-view christianhuth 8.3.3

1 of the 1 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:23.5.0a4fae38f93d7
poetry@1.4.2
2.3.3

Open the chart page →

1,227
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
poetry@2.1.4
2.3.3

Open the chart page →

5,062
deployhubdeployhubVerified publisher10.0.4157 of 11See more

deployhub deployhub 10.0.415

7 of the 11 container images this version deploys carry CVE-2026-34591.

Open the chart page →

11,160
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
poetry@1.8.4
2.3.3

Open the chart page →

9,607
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
poetry@1.8.4
2.3.3

Open the chart page →

9,607
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
poetry@2.0.1
2.3.3

Open the chart page →

19,224
autonodelabeldjjudas21Verified publisher0.0.101 of 1See more

autonodelabel djjudas21 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
djjudas21/autonodelabel:0.0.6f17233350c4f
poetry@1.5.1
2.3.3

Open the chart page →

1,304
kube-downscalerhelm-charts-nr0.7.61 of 1See more

kube-downscaler helm-charts-nr 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
poetry@1.5.1
2.3.3

Open the chart page →

4,293
lnbitskronkltdVerified publisher0.1.01 of 1See more

lnbits kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
lnbitsdocker/lnbits-legend:latest26fae6327477
poetry@1.7.1
2.3.3

Open the chart page →

1,444
kube-janitorkube-janitor0.3.31 of 1See more

kube-janitor kube-janitor 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
hjacobs/kube-janitor:23.7.0fbb303ed463c
poetry@1.5.1
2.3.3

Open the chart page →

4,293
lnbitslnbits0.2.11 of 1See more

lnbits lnbits 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
poetry@1.4.2
2.3.3

Open the chart page →

1,949
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.05 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

5 of the 40 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
poetry@1.8.2+dfsg-1ubuntu2
poetry@1.8.2
no fix listed
2.3.3
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
poetry@1.8.2+dfsg-1ubuntu2
poetry@1.8.2
no fix listed
2.3.3
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
poetry@1.8.2+dfsg-1ubuntu2
poetry@1.8.2
no fix listed
2.3.3
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
poetry@1.8.2+dfsg-1ubuntu2
poetry@1.8.2
no fix listed
2.3.3
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
poetry@1.8.2+dfsg-1ubuntu2
poetry@1.8.2
no fix listed
2.3.3

Open the chart page →

71,208
phronetisphronetis0.1.271 of 2See more

phronetis phronetis 0.1.27

1 of the 2 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
knspar/phronetis:0.1.4609499d2dc91a
poetry@2.1.3
2.3.3

Open the chart page →

16,196
kubecostradar-baseVerified publisher1.0.01 of 7See more

kubecost radar-base 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
poetry@2.0.1
2.3.3

Open the chart page →

9,355
kube-web-viewrlex0.5.01 of 1See more

kube-web-view rlex 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:23.8.0431f1bf013d0
poetry@1.6.1
2.3.3

Open the chart page →

4,908
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
poetry@1.8.4
2.3.3

Open the chart page →

9,607
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
poetry@2.1.1
2.3.3

Open the chart page →

3,512
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
poetry@2.1.1
2.3.3

Open the chart page →

4,718
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
poetry@2.1.1
2.3.3

Open the chart page →

7,901
servicexssl-hep1.8.511 of 16See more

servicex ssl-hep 1.8.5

11 of the 16 container images this version deploys carry CVE-2026-34591.

Container imageDigestPackageFixed in
sslhep/servicex_app:v1.8.51d12f943cec5
poetry@2.1.1
2.3.3
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
poetry@2.1.1
2.3.3
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
poetry@2.1.1
2.3.3
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
poetry@2.1.1
2.3.3
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
poetry@2.1.1
2.3.3
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
poetry@2.1.1
2.3.3
sslhep/servicex-did-finder:v1.8.5ab0090083567
poetry@2.1.1
2.3.3
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
poetry@2.3.0
2.3.3
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
poetry@2.1.1
2.3.3
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
poetry@2.1.1
2.3.3
sslhep/x509-secrets:v1.8.5d9e9ecb12d59
poetry@2.1.1
2.3.3

Open the chart page →

66,266

Container images carrying it

44 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/ai-agent:0.0.16545dac92173
poetry@1.8.4
2.3.3
3
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
poetry@1.5.1
2.3.3
2
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
poetry@2.1.1
2.3.3
2
airbyte/manifest-server:7.23.73b3a670af168
poetry@2.0.1
2.3.3
1
camerahub/camerahub:0.36.23a5af37dd6e1b
poetry@1.4.2
2.3.3
1
djjudas21/autonodelabel:0.0.6f17233350c4f
poetry@1.5.1
2.3.3
1
hansehe/locust:1.1.0bc8e45262bc4
poetry@1.7.1
2.3.3
1
hjacobs/kube-janitor:23.7.0fbb303ed463c
poetry@1.5.1
2.3.3
1
hjacobs/kube-ops-view:23.5.0a4fae38f93d7
poetry@1.4.2
2.3.3
1
hjacobs/kube-web-view:23.8.0431f1bf013d0
poetry@1.6.1
2.3.3
1
knspar/phronetis:0.1.4609499d2dc91a
poetry@2.1.3
2.3.3
1
langgenius/dify-api:1.0.0066035f93856
poetry@2.0.1
2.3.3
1
lnbitsdocker/lnbits-legend:latest26fae6327477
poetry@1.7.1
2.3.3
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
poetry@1.4.2
2.3.3
1
redash/redash:25.8.000d813437db5
poetry@1.8.3
2.3.3
1
redash/redash:26.3.0c5c9148f5c38
poetry@2.1.4
2.3.3
1
sslhep/servicex_app:v1.8.51d12f943cec5
poetry@2.1.1
2.3.3
1
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
poetry@2.1.1
2.3.3
1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
poetry@2.1.1
2.3.3
1
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
poetry@2.1.1
2.3.3
1
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
poetry@2.1.1
2.3.3
1
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
poetry@2.1.1
2.3.3
1
sslhep/servicex-did-finder:v1.8.5ab0090083567
poetry@2.1.1
2.3.3
1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
poetry@2.3.0
2.3.3
1
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
poetry@2.1.1
2.3.3
1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
poetry@2.1.1
2.3.3
1
sslhep/x509-secrets:v1.8.5d9e9ecb12d59
poetry@2.1.1
2.3.3
1
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
poetry@2.1.1
2.3.3
1
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
poetry@2.0.1
2.3.3
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
poetry@1.8.2+dfsg-1ubuntu2
poetry@1.8.2
no fix listed
2.3.3
1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
poetry@1.8.2+dfsg-1ubuntu2
poetry@1.8.2
no fix listed
2.3.3
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
poetry@1.8.2+dfsg-1ubuntu2
poetry@1.8.2
no fix listed
2.3.3
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
poetry@1.8.2+dfsg-1ubuntu2
poetry@1.8.2
no fix listed
2.3.3
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
poetry@1.8.2+dfsg-1ubuntu2
poetry@1.8.2
no fix listed
2.3.3
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
poetry@2.0.1
2.3.3
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
poetry@1.8.0
2.3.3
1
quay.io/hpestorage/filex-csi-driver:2.6.4b7f960bbf472
poetry@1.8.3
2.3.3
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
poetry@2.2.1
2.3.3
1
quay.io/ortelius/ms-dep-pkg-cud:main-v10.0.1670-g9abe110c0c881b509a
poetry@2.2.1
2.3.3
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
poetry@2.2.1
2.3.3
1
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
poetry@2.2.1
2.3.3
1
quay.io/ortelius/ms-scorecard:main-v10.0.1276-g966a8a43337e52fdd4
poetry@2.2.1
2.3.3
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
poetry@2.2.1
2.3.3
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
poetry@2.2.1
2.3.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.