StackRadar

CVE-2026-41205

High

Advisory

Published 16 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
107
of 17,781 indexed, latest versions
Container images
108
deployed by those charts
Fix available
2 of 2
affected packages

Mako: Path traversal via double-slash URI prefix in TemplateLookup

Carried by container images the latest versions of 107 of 17,781 indexed charts deploy, on 108 images.

Affected packageAffected versionsFixed inImages
makopypi0.8.1, 1.0.2, 1.0.6.dev0, 1.0.7+24 more1.3.11108
makodeb1.0.7+ds1-1, 1.2.4+ds-1, 1.3.2-11.0.7+ds1-1ubuntu0.2+esm1, 1.3.2-1ubuntu0.14
OSV records
DEBIAN-CVE-2026-41205GHSA-v92g-xgxw-vvmmUBUNTU-CVE-2026-41205
Also known as
PYSEC-2026-88, USN-8234-1

Charts affected

107 by stars
ChartLatestAffected imagesRadar Score
studygovernorstudy-governorVerified publisher0.1.381 of 3See more

studygovernor study-governor 0.1.38

1 of the 3 container images this version deploys carry CVE-2026-41205.

Container imageDigestPackageFixed in
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
mako@1.3.0
1.3.11

Open the chart page →

1,447
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-41205.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
mako@1.2.2
1.3.11

Open the chart page →

8,607
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-41205.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
mako@1.3.9
1.3.11

Open the chart page →

4,768
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41205.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
mako@1.2.4
1.3.11

Open the chart page →

7,085
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-41205.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
mako@1.0.6.dev0
1.3.11

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-41205.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
mako@1.0.6.dev0
1.3.11

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-41205.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
mako@1.1.5
1.3.11

Open the chart page →

2,643

Container images carrying it

108 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.