StackRadar

CVE-2026-44307

High

Advisory

Published 6 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
110
of 17,781 indexed, latest versions
Container images
111
deployed by those charts
Fix available
1 of 1
affected package

Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup

Carried by container images the latest versions of 110 of 17,781 indexed charts deploy, on 111 images.

Affected packageAffected versionsFixed inImages
makopypi0.8.1, 1.0.2, 1.0.6.dev0, 1.0.7+25 more1.3.12111
OSV records
GHSA-2h4p-vjrc-8xpq
Also known as
PYSEC-2026-2617

Charts affected

110 by stars
ChartLatestAffected imagesRadar Score
pev2schichtelVerified publisher0.3.01 of 1See more

pev2 schichtel 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
dalibo/explain.dalibo.com:2.20.12a0b749c2f7f
mako@1.3.10
1.3.12

Open the chart page →

1,178
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
mako@1.2.4
1.3.12

Open the chart page →

5,565
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
mako@1.0.8
1.3.12

Open the chart page →

2,060
studygovernorstudy-governorVerified publisher0.1.381 of 3See more

studygovernor study-governor 0.1.38

1 of the 3 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
mako@1.3.0
1.3.12

Open the chart page →

1,447
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
mako@1.2.2
1.3.12

Open the chart page →

8,607
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
mako@1.3.9
1.3.12

Open the chart page →

4,768
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
mako@1.2.4
1.3.12

Open the chart page →

7,085
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
mako@1.0.6.dev0
1.3.12

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
mako@1.0.6.dev0
1.3.12

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-44307.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
mako@1.1.5
1.3.12

Open the chart page →

2,643

Container images carrying it

111 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/superset:6.1.0:latest16b50bbef664
mako@1.3.10
1.3.12
3
dpage/pgadmin4:6.12781369df9994
mako@1.2.1
1.3.12
3
amancevice/superset:0.35.212a0a9e66550
mako@1.0.14
1.3.12
2
larribas/mlflow:1.9.105ccb0b46bfb
mako@1.1.3
1.3.12
2
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
mako@1.1.5
1.3.12
2
opendatacube/ows:latest668cbb41473c
mako@1.3.8
1.3.12
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
mako@1.0.6.dev0
1.3.12
2
amancevice/superset:0.28.1c8c04bfe3d66
mako@1.0.7
1.3.12
1
apache/airflow:2.8.4-python3.964e58748b6b9
mako@1.3.2
1.3.12
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
mako@1.3.5
1.3.12
1
apache/airflow:2.8.1e5560ad0b86e
mako@1.3.0
1.3.12
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
mako@1.1.4
1.3.12
1
apache/superset:4.0.1ab9467fd712c
mako@1.2.4
1.3.12
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
mako@1.3.10
1.3.12
1
archish27/python-fastapi-postgres:latest6610071a2101
mako@1.2.1
1.3.12
1
aristidetm/basic-notebook:3.6.5469dbc951224
mako@1.3.5
1.3.12
1
aristidetm/k8s-hub:3.3.7ccb516cb8474
mako@1.3.2
1.3.12
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
mako@1.3.10
1.3.12
1
buntha/mlflow:2.1.1154542cc3083
mako@1.2.4
1.3.12
1
ceph/daemon:latest-nautilus90f30824a96e
mako@0.8.1
1.3.12
1
chorss/docker-pgadmin4:4.115c549cacb8ab
mako@1.1.0
1.3.12
1
cleveritcz/opencve:1.5.0c75c1636e0b7
mako@1.3.3
1.3.12
1
dalibo/explain.dalibo.com:2.20.12a0b749c2f7f
mako@1.3.10
1.3.12
1
daskdev/dask-notebook:1.1.0052630f5ca04
mako@1.0.7
1.3.12
1
devopstales/kubedash:3.1.08bb837da5aec
mako@1.3.10
1.3.12
1
dpage/pgadmin4:8.418cd5711fc9a
mako@1.3.2
1.3.12
1
dpage/pgadmin4:7.537946e4f3e7b
mako@1.2.4
1.3.12
1
dpage/pgadmin4:9.11.050700ac17936
mako@1.3.10
1.3.12
1
dpage/pgadmin4:9.252cb72a9e3da
mako@1.3.9
1.3.12
1
dpage/pgadmin4:8.13561c1f8f99f2
mako@1.3.6
1.3.12
1
dpage/pgadmin4:4.5a5a656e1d5fd
mako@1.0.8
1.3.12
1
dpage/pgadmin4:4.22b1f00b8163cf
mako@1.1.2
1.3.12
1
elastichq/elasticsearch-hq:latestbb3bd22c2b87
mako@1.1.0
1.3.12
1
evk02/mlflow:2.2.1ef6ff257ef35
mako@1.2.4
1.3.12
1
freedom98/flask:k3.0d7ce1533f297
mako@1.3.10
1.3.12
1
galaxy/galaxy-init:v18.010267bad550e6
mako@1.0.2
1.3.12
1
gethue/hue:4.11.011b649636e68
mako@1.2.3
1.3.12
1
gethue/hue:4.10.05702b2c37ff9
mako@1.1.4
1.3.12
1
gethue/hue:latest7d5c1b9f8a79
mako@1.2.3
1.3.12
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
mako@1.3.9
1.3.12
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
mako@1.2.0
1.3.12
1
ihatemoney/ihatemoney:5.2.0457fda1feb32
mako@1.2.0
1.3.12
1
jaedb/iris:latest048cfbf58d57
mako@1.2.4.dev0
1.3.12
1
jakuboskera/guestbook:v0.3.04989afa06e74
mako@1.1.6
1.3.12
1
jakuboskera/todo:v0.2.3714b1adbbc2d
mako@1.3.10
1.3.12
1
john19968010/fastapi-template:latest31a90f6bd69c
mako@1.2.4
1.3.12
1
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
mako@1.2.4
1.3.12
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
mako@1.1.3
1.3.12
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
mako@1.1.4
1.3.12
1
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
mako@1.2.4
1.3.12
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.