StackRadar

CVE-2026-44405

Low

Advisory

Published 6 May 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.4
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
256
of 17,781 indexed, latest versions
Container images
134
deployed by those charts
Fix available
None
affected packages

Paramiko rsakey.py allows the SHA-1 algorithm

Carried by container images the latest versions of 256 of 17,781 indexed charts deploy, on 134 images.

Affected packageAffected versionsFixed inImages
paramikopypi1.10.1, 2.1.2, 2.4.2, 2.6.0+17 moreno fix listed134
paramikodeb1.10.1-1git1ubuntu0.1no fix listed2
OSV records
GHSA-r374-rxx8-8654UBUNTU-CVE-2026-44405
Also known as
PYSEC-2026-2858

Charts affected

256 by stars
ChartLatestAffected imagesRadar Score
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-44405.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
paramiko@4.0.0
no fix listed

Open the chart page →

6,973
phonebook-chartusuladams2Verified publisher0.2.11 of 3See more

phonebook-chart usuladams2 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-44405.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
paramiko@2.11.0
no fix listed

Open the chart page →

3,176
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-44405.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
paramiko@3.5.1
no fix listed

Open the chart page →

4,768
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44405.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
paramiko@4.0.0
no fix listed

Open the chart page →

20,190
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44405.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
paramiko@4.0.0
no fix listed

Open the chart page →

20,190
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-44405.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
paramiko@3.4.0
no fix listed

Open the chart page →

7,085

Container images carrying it

134 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
paramiko@2.11.0
no fix listed
1
stackstorm/st2notifier:3.8f190a6212195
paramiko@2.11.0
no fix listed
1
stackstorm/st2rulesengine:3.8259503496ff9
paramiko@2.11.0
no fix listed
1
stackstorm/st2scheduler:3.8b1de2055c362
paramiko@2.11.0
no fix listed
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
paramiko@2.11.0
no fix listed
1
stackstorm/st2stream:3.81c8904a3bf67
paramiko@2.11.0
no fix listed
1
stackstorm/st2timersengine:3.81bf35bfaf00c
paramiko@2.11.0
no fix listed
1
stackstorm/st2workflowengine:3.819fdfffdbba8
paramiko@2.11.0
no fix listed
1
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
paramiko@3.4.0
no fix listed
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
paramiko@2.11.0
no fix listed
1
voltha/voltha-cli:1.6.0c4e41e92f046
paramiko@2.4.2
no fix listed
1
voltha/voltha-netconf:1.6.037f80524c207
paramiko@2.4.2
no fix listed
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
paramiko@2.4.2
no fix listed
1
voltha/voltha-tester:1.7.0655c3048a602
paramiko@2.6.0
no fix listed
1
voltha/voltha-voltha:1.6.0ff596b62de59
paramiko@2.4.2
no fix listed
1
wallabag/wallabag:2.4.25e4c26a7fb4a
paramiko@2.7.1
no fix listed
1
ygqygq2/mysql-exec-sql:latest54f30def1558
paramiko@2.11.0
no fix listed
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
paramiko@3.4.0
no fix listed
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
paramiko@2.10.1
no fix listed
1
ghcr.io/ducksify/pgdump-to-s3:latestc42c0946bd0f
paramiko@2.11.0
no fix listed
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
paramiko@4.0.0
no fix listed
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
paramiko@4.0.0
no fix listed
1
ghcr.io/grycap/im:latest06a16d4f279f
paramiko@4.0.0
no fix listed
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
paramiko@3.5.0
no fix listed
1
ghcr.io/home-assistant/home-assistant:2026.9.0372d991e5888
paramiko@3.5.0
no fix listed
1
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
paramiko@3.5.0
no fix listed
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
paramiko@3.5.0
no fix listed
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
paramiko@2.10.4
no fix listed
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
paramiko@3.3.1
no fix listed
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
paramiko@3.5.0
no fix listed
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
paramiko@3.4.0
no fix listed
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
paramiko@3.5.1
no fix listed
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
paramiko@2.11.0
no fix listed
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
paramiko@2.10.3
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.