CVE-2026-41205
HighAdvisory
Published 16 Apr 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.004
- 29th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 107
- of 17,781 indexed, latest versions
- Container images
- 108
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Mako: Path traversal via double-slash URI prefix in TemplateLookup
Carried by container images the latest versions of 107 of 17,781 indexed charts deploy, on 108 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| makopypi | 0.8.1, 1.0.2, 1.0.6.dev0, 1.0.7+24 more | 1.3.11 | 108 |
| makodeb | 1.0.7+ds1-1, 1.2.4+ds-1, 1.3.2-1 | 1.0.7+ds1-1ubuntu0.2+esm1, 1.3.2-1ubuntu0.1 | 4 |
- OSV records
- DEBIAN-CVE-2026-41205GHSA-v92g-xgxw-vvmmUBUNTU-CVE-2026-41205
- Also known as
- PYSEC-2026-88, USN-8234-1
Charts affected
107 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| studygovernorstudy-governorVerified publisher | 0.1.38 | 1 of 3See more | 1,447 |
| jupyterhubuninettsigma2 | 1.6.0 | 1 of 5See more | 8,607 |
| simple-prima-notavcnngrVerified publisher | 0.5.3 | 1 of 4See more | 4,768 |
| supersetwbstack | 0.1.0 | 1 of 1See more | 7,085 |
| ceph-csi-cephfswikimedia | 0.1.8 | 1 of 5See more | 10,285 |
| ceph-csi-rbdwikimedia | 0.1.13 | 1 of 6See more | 11,784 |
| powerdnsadminwitcom-gmbh | 0.3.4 | 1 of 1See more | 2,643 |
Container images carrying it
108 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.