StackRadar

CVE-2026-4360

Medium

Advisory

Published 30 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
20th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
553
of 17,787 indexed, latest versions
Container images
531
deployed by those charts
Fix available
15 of 16
affected packages

Tarfile.extract() doesn't fully respect filter parameter

Carried by container images the latest versions of 553 of 17,787 indexed charts deploy, on 531 images.

Affected packageAffected versionsFixed inImages
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more3.8.10-0ubuntu1~20.04.18+esm7100
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3+11 more3.12.3-1ubuntu0.1786
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+16 more3.10.12-1~22.04.1880
python3apk3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+7 more3.12.14-r0, 3.14.7-r075
python3.13deb3.13.5-2, 3.13.5-2+deb13u2, 3.13.5-2+deb13u4, 3.13.7-1ubuntu0.13.13.5-2+deb13u575
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more3.6.9-1~18.04ubuntu1.13+esm1044
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+9 more2.7.6-8ubuntu0.6+esm30, 2.7.12-1ubuntu0~16.04.18+esm22, 2.7.17-1~18.04ubuntu1.13+esm15, 2.7.18-13ubuntu1.5+esm943
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.93.5.2-2ubuntu0~16.04.13+esm2525
python3.14deb3.14.4-1, 3.14.4-1ubuntu0.13.14.4-1ubuntu0.28
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.73.4.3-1ubuntu1~14.04.7+esm217
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-1no fix listed3
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.13.11.0~rc1-1~22.04.1+esm22
python3rpm3.12.9-13.azl33.12.9-141
python-3.14apk3.14.2-r2, 3.14.4-r2, 3.14.6-r03.14.6-r36
python-3.13apk3.13.7-r0, 3.13.10-r0, 3.13.12-r23.13.14-r23
python-3.12apk3.12.0-r1, 3.12.9-r13.12.13-r102
OSV records
ALPINE-CVE-2026-4360BIT-python-2026-4360DEBIAN-CVE-2026-4360UBUNTU-CVE-2026-4360CGA-3j98-689h-m79jCGA-8qxw-mxj5-qqfvCGA-jr9q-86mm-jvfcAZL-91749
Also known as
BIT-libpython-2026-4360, BIT-python-min-2026-4360, CGA-fj7c-qx2m-pqr4, CGA-v6c3-6q52-4qfj, CGA-x27p-jmrc-jcmr, PSF-2026-32, USN-8744-1

Charts affected

553 by stars
ChartLatestAffected imagesRadar Score
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-4360.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.18

Open the chart page →

9,296
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-4360.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.18

Open the chart page →

14,172
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-4360.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
python3.10@3.10.12-1~22.04.16
3.10.12-1~22.04.18

Open the chart page →

7,916

Container images carrying it

531 by charts deploying them

A fixed version is listed for 15 of the 16 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
python3.8@3.8.10-0ubuntu1~20.04.13
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
python3.12@3.12.3-1ubuntu0.13
3.12.3-1ubuntu0.17
1
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
python3.13@3.13.5-2+deb13u4
3.13.5-2+deb13u5
1
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
python-3.14@3.14.4-r2
3.14.6-r3
1
ghcr.io/thoroslives/zilean:v3.10.1bce6aca0f6ca
python3@3.11.12-r1
3.12.14-r0
1
ghcr.io/topolvm/pie:0.18.0aa467443e407
python3.10@3.10.12-1~22.04.17
3.10.12-1~22.04.18
1
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
python3.10@3.10.12-1~22.04.17
3.10.12-1~22.04.18
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
python3.10@3.10.12-1~22.04.6
3.10.12-1~22.04.18
1
ghcr.io/wittdennis/homeassistant-otbr:4.2.31b53b0b3488e
python3.13@3.13.5-2+deb13u4
3.13.5-2+deb13u5
1
ghcr.io/zazukoians/qlever-server:v0.10.0f10fd24b2290
python3.12@3.12.3-1ubuntu0.15
3.12.3-1ubuntu0.17
1
mcr.microsoft.com/acstor/local-csi-driver:v0.3.0f9af53a79fd1
python3@3.12.9-13.azl3
3.12.9-14
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
python2.7@2.7.17-1~18.04ubuntu1.11
python3.6@3.6.9-1~18.04ubuntu1.12
2.7.17-1~18.04ubuntu1.13+esm15
3.6.9-1~18.04ubuntu1.13+esm10
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm7
1
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
python3.12@3.12.3-1ubuntu0.15
3.12.3-1ubuntu0.17
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
python3.10@3.10.12-1~22.04.16
3.10.12-1~22.04.18
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
python3.12@3.12.3-1ubuntu0.13
3.12.3-1ubuntu0.17
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
python2.7@2.7.17-1~18.04ubuntu1.11
python3.6@3.6.9-1~18.04ubuntu1.12
2.7.17-1~18.04ubuntu1.13+esm15
3.6.9-1~18.04ubuntu1.13+esm10
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
python3@3.12.13-r0
3.12.14-r0
1
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
python3@3.12.12-r0
3.12.14-r0
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
python3.8@3.8.5-1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7
1
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
python3@3.12.13-r0
3.12.14-r0
1
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
python3.13@3.13.5-2+deb13u4
3.13.5-2+deb13u5
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
python3.6@3.6.9-1~18.04ubuntu1.8
3.6.9-1~18.04ubuntu1.13+esm10
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
python3.12@3.12.3-1ubuntu0.9
3.12.3-1ubuntu0.17
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
python-3.14@3.14.2-r2
3.14.6-r3
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
python-3.14@3.14.2-r2
3.14.6-r3
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
python-3.14@3.14.2-r2
3.14.6-r3
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
python-3.14@3.14.2-r2
3.14.6-r3
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
python3.12@3.12.3-1ubuntu0.15
3.12.3-1ubuntu0.17
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
python3.8@3.8.5-1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
python3@3.12.13-r0
3.12.14-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.