StackRadar

CVE-2026-39892

Critical

Advisory

Published 8 Apr 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.007
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
171
of 17,781 indexed, latest versions
Container images
68
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 171 of 17,781 indexed charts deploy, on 68 images.

Affected packageAffected versionsFixed inImages
cryptographypypi45.0.2, 45.0.3, 45.0.4, 45.0.5+9 more46.0.768
py3-cryptographyapk46.0.5-r046.0.7-r01
OSV records
ALPINE-CVE-2026-39892PYSEC-2026-36
Also known as
GHSA-p423-j2cm-9vmq

Charts affected

171 by stars
ChartLatestAffected imagesRadar Score
pagesronan-pages1.0.01 of 3See more

pages ronan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
cryptography@45.0.5
46.0.7

Open the chart page →

4,499
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
cryptography@46.0.6
46.0.7

Open the chart page →

6,207
pagessamanvithkaranth1.0.01 of 3See more

pages samanvithkaranth 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
pagessarubits-pages1.0.01 of 3See more

pages sarubits-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
pagessekharpkube1.0.01 of 3See more

pages sekharpkube 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
cryptography@46.0.5
46.0.7

Open the chart page →

5,201
pagesshrutiujlan-pages1.0.01 of 3See more

pages shrutiujlan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
smtpsmtpVerified publisher1.3.31 of 1See more

smtp smtp 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
cryptography@46.0.3
46.0.7

Open the chart page →

1,437
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

11,888
srebotsrebot0.14.01 of 2See more

srebot srebot 0.14.0

1 of the 2 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
cryptography@46.0.5
46.0.7

Open the chart page →

1,542
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
pagestest43221.0.01 of 3See more

pages test4322 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

5,704
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

6,973
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190

Container images carrying it

68 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
cryptography@46.0.5
46.0.7
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
cryptography@46.0.0
46.0.7
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
cryptography@46.0.5
46.0.7
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
cryptography@46.0.3
46.0.7
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
cryptography@46.0.6
46.0.7
1
ghcr.io/vinny1892/octantis:latest45459c0910fc
cryptography@46.0.6
46.0.7
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
cryptography@45.0.6
46.0.7
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
cryptography@45.0.2
46.0.7
1
quay.io/hpestorage/filex-csi-driver:2.6.4b7f960bbf472
cryptography@46.0.3
46.0.7
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
cryptography@46.0.3
46.0.7
1
quay.io/ortelius/ms-dep-pkg-cud:main-v10.0.1670-g9abe110c0c881b509a
cryptography@46.0.3
46.0.7
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
cryptography@46.0.3
46.0.7
1
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
cryptography@46.0.3
46.0.7
1
quay.io/ortelius/ms-scorecard:main-v10.0.1276-g966a8a43337e52fdd4
cryptography@46.0.3
46.0.7
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
cryptography@46.0.3
46.0.7
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
cryptography@46.0.3
46.0.7
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
cryptography@46.0.5
46.0.7
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
cryptography@46.0.3
46.0.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.