CVE-2026-3644
HighAdvisory
Published 16 Mar 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.005
- 40th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 618
- of 17,781 indexed, latest versions
- Container images
- 596
- deployed by those charts
- Fix available
- 13 of 14
- affected packages
CVE-2026-3644 affecting package python3 for versions less than 3.12.9-14
Carried by container images the latest versions of 618 of 17,781 indexed charts deploy, on 596 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| python3.11deb | 3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more | 3.11.0~rc1-1~22.04.1+esm2 | 181 |
| python3.8deb | 3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more | 3.8.10-0ubuntu1~20.04.18+esm7 | 100 |
| python3.10deb | 3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more | 3.10.12-1~22.04.16 | 71 |
| python3apk | 3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+5 more | 3.12.14-r0, 3.14.5-r0 | 66 |
| python3.12deb | 3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+8 more | 3.12.3-1ubuntu0.15 | 48 |
| python3.6deb | 3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more | 3.6.9-1~18.04ubuntu1.13+esm10 | 44 |
| python2.7deb | 2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+9 more | 2.7.6-8ubuntu0.6+esm30, 2.7.12-1ubuntu0~16.04.18+esm22, 2.7.17-1~18.04ubuntu1.13+esm15, 2.7.18-13ubuntu1.5+esm9 | 43 |
| python3.5deb | 3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9 | 3.5.2-2ubuntu0~16.04.13+esm25 | 25 |
| python3.13deb | 3.13.5-2, 3.13.5-2+e30, 3.13.7-1ubuntu0.1 | 3.13.5-2+deb13u2, 3.13.5-2+e36 | 23 |
| python3.4deb | 3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7 | 3.4.3-1ubuntu1~14.04.7+esm21 | 7 |
| python-3.12apk | 3.12.0-r1, 3.12.9-r1, 3.12.14-r2, 3.12.14-r6 | no fix listed | 8 |
| python-3.14apk | 3.14.2-r2 | 3.14.3-r6 | 4 |
| python-3.13apk | 3.13.7-r0, 3.13.10-r0, 3.13.12-r2 | 3.13.12-r7 | 3 |
| python3rpm | 3.12.9-13.azl3 | 3.12.9-14 | 1 |
- OSV records
- ALPINE-CVE-2026-3644DEBIAN-CVE-2026-3644UBUNTU-CVE-2026-3644CGA-3rjg-h44j-w26vCGA-6q68-qxxc-rv68CGA-9vxg-2373-8rm4AZL-80055ECHO-6a47-d40a-2c76
- Also known as
- CGA-975c-63xh-w2w9, CGA-977h-c34r-5v9j, CGA-vr9r-627r-wx6c, USN-8509-1, USN-8744-1
Charts affected
618 by stars
Container images carrying it
596 by charts deploying them
A fixed version is listed for 13 of the 14 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| instill/ | c4a393e601ed | python3.13 | 3.13.5-2+deb13u2 | 1 |
| instill/ | ebe12f77a3f9 | python3.13 | 3.13.5-2+deb13u2 | 1 |
| instill/ | e980125e5ba5 | python3.13 | 3.13.5-2+deb13u2 | 1 |
| intel/ | aa8f5483a2ef | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm7 | 1 |
| intel/ | 1a89327e499b | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm7 | 1 |
| intelowlproject/ | 0b22e547ea6b | python3.11 | no fix listed | 1 |
| iofog/ | 7260cf861479 | python2.7 | 2.7.17-1~18.04ubuntu1.13+esm15 | 1 |
| iomesh/ | 1a151f602451 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| iomesh/ | 5d3f9bf9240b | python3.10 | 3.10.12-1~22.04.16 | 1 |
| iosifache/ | 85df3f04b5da | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm7 | 1 |
| ispras/ | 42aa9fa9f189 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| istio/ | 2232f365aed6 | python3.6 | 3.6.9-1~18.04ubuntu1.13+esm10 | 1 |
| istio/ | 268ab879ea51 | python3.5 | 3.5.2-2ubuntu0~16.04.13+esm25 | 1 |
| istio/ | 655eefa11c84 | python3.6 | 3.6.9-1~18.04ubuntu1.13+esm10 | 1 |
| istio/ | 294ca55bd1cc | python3.6 | 3.6.9-1~18.04ubuntu1.13+esm10 | 1 |
| istio/ | c09319753454 | python3.5 | 3.5.2-2ubuntu0~16.04.13+esm25 | 1 |
| istio/ | e7e110a421c2 | python3.6 | 3.6.9-1~18.04ubuntu1.13+esm10 | 1 |
| istio/ | 0c78be035e98 | python3.5 | 3.5.2-2ubuntu0~16.04.13+esm25 | 1 |
| istio/ | 87a9db561d2e | python3.6 | 3.6.9-1~18.04ubuntu1.13+esm10 | 1 |
| istio/ | 88c6c693e67a | python3.6 | 3.6.9-1~18.04ubuntu1.13+esm10 | 1 |
| jaedb/ | 048cfbf58d57 | python3.11 | no fix listed | 1 |
| jakowenko/ | b858bac9e32a | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm7 | 1 |
| jeboehm/ | 9da13edf5aa8 | python3 | 3.12.14-r0 | 1 |
| jedi132000/ | dc2a81e92f23 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm7 | 1 |
| jmferrer/ | 030f68ec6998 | python3.5 | 3.5.2-2ubuntu0~16.04.13+esm25 | 1 |
| jordan/ | f75025fe8ea8 | python3.11 | no fix listed | 1 |
| josh5/ | 4d49c4816260 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| juicedata/ | 95008ba63318 | python3.11 | no fix listed | 1 |
| jupyterhub/ | 3974ba945e65 | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| jupyterhub/ | b6b4a1a34bf0 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm7 | 1 |
| jupyterhub/ | e4770285aaf7 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm7 | 1 |
| kenchrcum/ | c326e28a8f5f | python3 | 3.12.14-r0 | 1 |
| kenchrcum/ | 5310497aea3f | python3 | 3.12.14-r0 | 1 |
| kennethreitz/ | 599fe5e50731 | python3.6 | 3.6.9-1~18.04ubuntu1.13+esm10 | 1 |
| kfirfer/ | 2efb4a5d74a3 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm7 | 1 |
| kinseii/ | 7160eb143728 | python3.11 | no fix listed | 1 |
| knspar/ | 09499d2dc91a | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| knspar/ | 0c4f0543ee58 | python3.11 | no fix listed | 1 |
| kong/ | a6ac46531193 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| kubearmor/ | a08141311045 | python3 | 3.12.14-r0 | 1 |
| kubearmor/ | 236ade6e67b1 | python3 | 3.12.14-r0 | 1 |
| kubeoperator/ | be8f0d624640 | python3.6 | 3.6.9-1~18.04ubuntu1.13+esm10 | 1 |
| kubeovn/ | 6722b54eb5c0 | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| kusionstack/ | 126c8f0b0976 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| laly9999/ | dd0e503913e1 | python3.11 | no fix listed | 1 |
| langgenius/ | dcefa5f7c47c | python3.11 | no fix listed | 1 |
| langgenius/ | 3c694329357b | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| langgenius/ | 8269050f192e | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| library/ | 093ee8ee5eb2 | python3.11 | no fix listed | 1 |
| library/ | 588609d76b21 | python3.11 | no fix listed | 1 |