StackRadar

CVE-2026-44307

High

Advisory

Published 6 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
110
of 17,781 indexed, latest versions
Container images
111
deployed by those charts
Fix available
1 of 1
affected package

Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup

Carried by container images the latest versions of 110 of 17,781 indexed charts deploy, on 111 images.

Affected packageAffected versionsFixed inImages
makopypi0.8.1, 1.0.2, 1.0.6.dev0, 1.0.7+25 more1.3.12111
OSV records
GHSA-2h4p-vjrc-8xpq
Also known as
PYSEC-2026-2617

Charts affected

110 by stars
ChartLatestAffected imagesRadar Score
pev2schichtelVerified publisher0.3.01 of 1See more

pev2 schichtel 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
dalibo/explain.dalibo.com:2.20.12a0b749c2f7f
mako@1.3.10
1.3.12

Open the chart page →

1,178
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
mako@1.2.4
1.3.12

Open the chart page →

5,565
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
mako@1.0.8
1.3.12

Open the chart page →

2,060
studygovernorstudy-governorVerified publisher0.1.381 of 3See more

studygovernor study-governor 0.1.38

1 of the 3 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
mako@1.3.0
1.3.12

Open the chart page →

1,447
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
mako@1.2.2
1.3.12

Open the chart page →

8,607
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
mako@1.3.9
1.3.12

Open the chart page →

4,768
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
mako@1.2.4
1.3.12

Open the chart page →

7,085
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
mako@1.0.6.dev0
1.3.12

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
mako@1.0.6.dev0
1.3.12

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
mako@1.1.5
1.3.12

Open the chart page →

2,643

Container images carrying it

111 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
mako@1.2.4
1.3.12
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
mako@1.2.4
1.3.12
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
mako@1.3.10
1.3.12
1
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
mako@1.2.4
1.3.12
1
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
mako@1.3.10
1.3.12
1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
mako@1.3.2
1.3.12
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
mako@1.3.0
1.3.12
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
mako@1.2.2
1.3.12
1
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
mako@1.1.5
1.3.12
1
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
mako@1.1.5
1.3.12
1
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
mako@1.3.0
1.3.12
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.