StackRadar

CVE-2026-39892

Critical

Advisory

Published 8 Apr 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.007
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
171
of 17,781 indexed, latest versions
Container images
68
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 171 of 17,781 indexed charts deploy, on 68 images.

Affected packageAffected versionsFixed inImages
cryptographypypi45.0.2, 45.0.3, 45.0.4, 45.0.5+9 more46.0.768
py3-cryptographyapk46.0.5-r046.0.7-r01
OSV records
ALPINE-CVE-2026-39892PYSEC-2026-36
Also known as
GHSA-p423-j2cm-9vmq

Charts affected

171 by stars
ChartLatestAffected imagesRadar Score
pagesronan-pages1.0.01 of 3See more

pages ronan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
cryptography@45.0.5
46.0.7

Open the chart page →

4,499
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
cryptography@46.0.6
46.0.7

Open the chart page →

6,207
pagessamanvithkaranth1.0.01 of 3See more

pages samanvithkaranth 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
pagessarubits-pages1.0.01 of 3See more

pages sarubits-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
pagessekharpkube1.0.01 of 3See more

pages sekharpkube 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
cryptography@46.0.5
46.0.7

Open the chart page →

5,201
pagesshrutiujlan-pages1.0.01 of 3See more

pages shrutiujlan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
smtpsmtpVerified publisher1.3.31 of 1See more

smtp smtp 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
cryptography@46.0.3
46.0.7

Open the chart page →

1,437
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

11,888
srebotsrebot0.14.01 of 2See more

srebot srebot 0.14.0

1 of the 2 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
cryptography@46.0.5
46.0.7

Open the chart page →

1,542
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
pagestest43221.0.01 of 3See more

pages test4322 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

5,704
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

6,973
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-39892.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7

Open the chart page →

20,190

Container images carrying it

68 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
46.0.7
89
library/mysql:8:8.4:8.4.11b3b90af2a655
cryptography@46.0.5
46.0.7
16
library/mysql:9.7.2257388edf9c8
cryptography@46.0.5
46.0.7
6
apache/superset:6.1.0:latest16b50bbef664
cryptography@46.0.5
46.0.7
3
library/mysql:9.7.2b2cf29815e62
cryptography@46.0.5
46.0.7
2
taigaio/taiga-back:latest4beed8f62c9f
cryptography@46.0.3
46.0.7
2
apache/tika:latest-full80072bb73dd3
cryptography@46.0.5
46.0.7
1
appwrite/appwrite:1.9.01aaa70127114
cryptography@46.0.5
py3-cryptography@46.0.5-r0
46.0.7
46.0.7-r0
1
boky/postfix:5.1.0aafc77238423
cryptography@46.0.3
46.0.7
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
cryptography@46.0.5
46.0.7
1
datamate/seafile-professional:11.0.202dd66b722464
cryptography@45.0.6
46.0.7
1
dpage/pgadmin4:9.11.050700ac17936
cryptography@46.0.3
46.0.7
1
freedom98/flask:k3.0d7ce1533f297
cryptography@45.0.4
46.0.7
1
heartexlabs/label-studio:latestaa461572e8f9
cryptography@46.0.5
46.0.7
1
helmforge/fastmcp-server:0.2.061f759a1421f
cryptography@46.0.6
46.0.7
1
knspar/phronetis:0.1.4609499d2dc91a
cryptography@45.0.4
46.0.7
1
kyovint/kyoimgtransactions:1.0.048c19e3ae9a3
cryptography@45.0.7
46.0.7
1
kyovint/kyoimgusers:1.0.080084149156e
cryptography@45.0.7
46.0.7
1
library/mysql:8.4.113466ba4a4828
cryptography@46.0.5
46.0.7
1
library/mysql:885b9bf2e29cf
cryptography@46.0.5
46.0.7
1
library/mysql:8.4.108dbcf531a03a
cryptography@46.0.5
46.0.7
1
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
cryptography@45.0.3
46.0.7
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
cryptography@46.0.5
46.0.7
1
mawad98/backstage-pyactions:demo99422c56a274
cryptography@46.0.6
46.0.7
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
cryptography@46.0.3
46.0.7
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
cryptography@45.0.6
46.0.7
1
opendatacube/wps:latest80df355a660b
cryptography@45.0.4
46.0.7
1
openvpn/openvpn-as:latest2253c10ec652
cryptography@46.0.6
46.0.7
1
prompve/prometheus-pve-exporter:3.8.2e3d501a82df5
cryptography@46.0.5
46.0.7
1
redash/redash:25.8.000d813437db5
cryptography@45.0.5
46.0.7
1
redash/redash:26.3.0c5c9148f5c38
cryptography@46.0.5
46.0.7
1
rommapp/romm:4.4.1b909e95d1aab
cryptography@45.0.5
46.0.7
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
cryptography@46.0.5
46.0.7
1
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
cryptography@46.0.4
46.0.7
1
tussanakorndev/kube-pod-alerts:1.0.5216fdadadf9a
cryptography@46.0.5
46.0.7
1
vabene1111/recipes:2.3.50f8d061895e9
cryptography@45.0.5
46.0.7
1
zepai/knowledge-graph-mcp:v0.2.16ab0ee79926b
cryptography@45.0.4
46.0.7
1
ghcr.io/ctfd/ctfd:3.8.2870e396fddf8
cryptography@45.0.6
46.0.7
1
ghcr.io/dask/dask-gateway-server:2026.3.0afa5a729114e
cryptography@46.0.6
46.0.7
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
cryptography@46.0.5
46.0.7
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
cryptography@46.0.3
46.0.7
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
cryptography@46.0.5
46.0.7
1
ghcr.io/grycap/im:latest06a16d4f279f
cryptography@46.0.1
46.0.7
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
cryptography@46.0.2
46.0.7
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
cryptography@46.0.5
46.0.7
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
cryptography@46.0.5
46.0.7
1
ghcr.io/iisas/domino-rest:latest3009350bfc11
cryptography@45.0.7
46.0.7
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
cryptography@46.0.3
46.0.7
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
cryptography@46.0.3
46.0.7
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
cryptography@46.0.6
46.0.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.