StackRadar

CVE-2026-4360

Medium

Advisory

Published 30 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
20th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
554
of 17,781 indexed, latest versions
Container images
531
deployed by those charts
Fix available
15 of 16
affected packages

Tarfile.extract() doesn't fully respect filter parameter

Carried by container images the latest versions of 554 of 17,781 indexed charts deploy, on 531 images.

Affected packageAffected versionsFixed inImages
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more3.8.10-0ubuntu1~20.04.18+esm7100
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+10 more3.12.3-1ubuntu0.1787
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+16 more3.10.12-1~22.04.1880
python3apk3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+7 more3.12.14-r0, 3.14.7-r075
python3.13deb3.13.5-2, 3.13.5-2+deb13u2, 3.13.5-2+deb13u4, 3.13.7-1ubuntu0.13.13.5-2+deb13u574
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more3.6.9-1~18.04ubuntu1.13+esm1044
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+9 more2.7.6-8ubuntu0.6+esm30, 2.7.12-1ubuntu0~16.04.18+esm22, 2.7.17-1~18.04ubuntu1.13+esm15, 2.7.18-13ubuntu1.5+esm943
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.93.5.2-2ubuntu0~16.04.13+esm2525
python3.14deb3.14.4-1, 3.14.4-1ubuntu0.13.14.4-1ubuntu0.28
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.73.4.3-1ubuntu1~14.04.7+esm217
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-1no fix listed3
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.13.11.0~rc1-1~22.04.1+esm22
python3rpm3.12.9-13.azl33.12.9-141
python-3.14apk3.14.2-r2, 3.14.4-r2, 3.14.6-r03.14.6-r36
python-3.13apk3.13.7-r0, 3.13.10-r0, 3.13.12-r23.13.14-r23
python-3.12apk3.12.0-r1, 3.12.9-r13.12.13-r102
OSV records
ALPINE-CVE-2026-4360BIT-python-2026-4360DEBIAN-CVE-2026-4360UBUNTU-CVE-2026-4360CGA-3j98-689h-m79jCGA-8qxw-mxj5-qqfvCGA-jr9q-86mm-jvfcAZL-91749
Also known as
BIT-libpython-2026-4360, BIT-python-min-2026-4360, CGA-fj7c-qx2m-pqr4, CGA-v6c3-6q52-4qfj, CGA-x27p-jmrc-jcmr, PSF-2026-32, USN-8744-1

Charts affected

554 by stars
ChartLatestAffected imagesRadar Score
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-4360.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
python3@3.12.11-r0
3.12.14-r0

Open the chart page →

14,983
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-4360.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.18

Open the chart page →

9,248
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-4360.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.18

Open the chart page →

14,100
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-4360.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
python3.10@3.10.12-1~22.04.16
3.10.12-1~22.04.18

Open the chart page →

7,849

Container images carrying it

531 by charts deploying them

A fixed version is listed for 15 of the 16 affected packages.

Container imageDigestPackageFixed inUsed by
atlassian/jira-software:11.3.11e5548cd4eea8
python3.12@3.12.3-1ubuntu0.16
3.12.3-1ubuntu0.17
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7
1
beanbag/reviewboard:latest6b840f546e1c
python3.10@3.10.12-1~22.04.17
python3.11@3.11.0~rc1-1~22.04.1
3.10.12-1~22.04.18
3.11.0~rc1-1~22.04.1+esm2
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
python3.8@3.8.10-0ubuntu1~20.04.6
3.8.10-0ubuntu1~20.04.18+esm7
1
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
python@3.11.11-0
no fix listed
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7
1
boky/postfix:5.1.0aafc77238423
python3.13@3.13.5-2
3.13.5-2+deb13u5
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm7
1
byjg/easy-haproxy:6.1.1230fdb7b00ae
python3@3.14.5-r0
3.14.7-r0
1
camptocamp/mapserver:latestbf2e8e118c9b
python3.12@3.12.3-1ubuntu0.16
3.12.3-1ubuntu0.17
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
python3.10@3.10.12-1~22.04.15
3.10.12-1~22.04.18
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
python3.4@3.4.3-1ubuntu1~14.04.7
3.4.3-1ubuntu1~14.04.7+esm21
1
chetangautamm/repo:sipp.v3e7f7049e1544
python3.8@3.8.5-1~20.04
3.8.10-0ubuntu1~20.04.18+esm7
1
cheyang/distributed-tf:1.6.046cc34755493
python2.7@2.7.12-1ubuntu0~16.04.3
python3.5@3.5.2-2ubuntu0~16.04.4
2.7.12-1ubuntu0~16.04.18+esm22
3.5.2-2ubuntu0~16.04.13+esm25
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
python3.13@3.13.5-2
3.13.5-2+deb13u5
1
chocobozzz/peertube:v8.1.5052712130691
python3.13@3.13.5-2+deb13u2
3.13.5-2+deb13u5
1
chriseaton/adventureworks:latest54c3384ce701
python3.10@3.10.12-1~22.04.9
3.10.12-1~22.04.18
1
citizenstig/httpbin:latestb81c818ccb86
python3.5@3.5.2-2ubuntu0~16.04.1
3.5.2-2ubuntu0~16.04.13+esm25
1
cloudve/janis-terminal:latestaf56e77ca587
python3.6@3.6.9-1~18.04ubuntu1
3.6.9-1~18.04ubuntu1.13+esm10
1
cloudve/ttyd:latestd79c1c5881c0
python3.6@3.6.9-1~18.04ubuntu1
3.6.9-1~18.04ubuntu1.13+esm10
1
copyparty/ac:1.19.200a0a8605062c
python3@3.12.12-r0
3.12.14-r0
1
countly/countly-server:25.05.4e3c238248f99
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
python3.13@3.13.5-2+deb13u2
3.13.5-2+deb13u5
1
cznic/knot-resolver:v6.4.2fe71c5214fdc
python3.13@3.13.5-2+deb13u4
3.13.5-2+deb13u5
1
dariomader/twampy:v0.0.2d2f4a8c5e690
python-3.12@3.12.0-r1
3.12.13-r10
1
daskdev/dask-notebook:1.1.0052630f5ca04
python3.6@3.6.7-1~18.04
3.6.9-1~18.04ubuntu1.13+esm10
1
datamate/seafile-professional:11.0.202dd66b722464
python3.10@3.10.12-1~22.04.11
3.10.12-1~22.04.18
1
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
python3.13@3.13.5-2
3.13.5-2+deb13u5
1
digitalist/matomo:5.12.0bc4aeeaea769
python3@3.14.5-r0
3.14.7-r0
1
docuseal/docuseal:2.4.17493fd7f6728
python3@3.12.12-r0
3.12.14-r0
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
python3.8@3.8.10-0ubuntu1~20.04.18
3.8.10-0ubuntu1~20.04.18+esm7
1
dpage/pgadmin4:9.252cb72a9e3da
python3@3.12.9-r0
3.12.14-r0
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
python3.13@3.13.5-2
3.13.5-2+deb13u5
1
eftechcombr/glpi:php-fpm-12.0.0-rc1f3d0ed01709e
python3@3.12.12-r0
3.12.14-r0
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
python3.6@3.6.9-1~18.04ubuntu1.4
3.6.9-1~18.04ubuntu1.13+esm10
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
python3.6@3.6.9-1~18.04ubuntu1.4
3.6.9-1~18.04ubuntu1.13+esm10
1
elautoestopista/aeneabot:4.2.1125ba620d528
python3@3.12.12-r0
3.12.14-r0
1
electriccoinco/lightwalletd:v0.5.42ae3a551e111
python3.13@3.13.5-2+deb13u4
3.13.5-2+deb13u5
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
python2.7@2.7.12-1ubuntu0~16.04.2
2.7.12-1ubuntu0~16.04.18+esm22
1
ethpandaops/assertoor:latest1efa2fba6711
python3.13@3.13.5-2+deb13u2
3.13.5-2+deb13u5
1
extrim/perlite:1.5.99cb7eb5598b6
python3@3.12.9-r0
3.12.14-r0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
python3.8@3.8.10-0ubuntu1~20.04.18
3.8.10-0ubuntu1~20.04.18+esm7
1
flanksource/batch-runner:v1.0.44689687a7cf95
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.17
1
flashcatcloud/categraf:latest42e6ab16472e
python3.12@3.12.3-1ubuntu0.12
3.12.3-1ubuntu0.17
1
flyway/flyway:9.1545b5d7cdc75a
python3.8@3.8.10-0ubuntu1~20.04.6
3.8.10-0ubuntu1~20.04.18+esm7
1
fosrl/pangolin:1.13.0c32ad797ab96
python3@3.12.12-r0
3.12.14-r0
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
python3.6@3.6.9-1~18.04ubuntu1.9
3.6.9-1~18.04ubuntu1.13+esm10
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
python3.6@3.6.9-1~18.04ubuntu1.8
3.6.9-1~18.04ubuntu1.13+esm10
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
python2.7@2.7.18-13ubuntu1.5
python3.10@3.10.12-1~22.04.10
2.7.18-13ubuntu1.5+esm9
3.10.12-1~22.04.18
1
galaxy/cloudman-server:lateste5c265fe9fcd
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.