StackRadar

CVE-2026-44432

High

Advisory

Published 11 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.9
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
330
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
2 of 3
affected packages

urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API

Carried by container images the latest versions of 330 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
py3-pipapk25.0.1-r0, 25.2-r0, 26.0.1-r126.1.2-r13
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+22 moreno fix listed107
urllib3pypi2.6.0, 2.6.1, 2.6.2, 2.6.32.7.099
OSV records
CGA-63m6-2q77-9p47CGA-7w5f-j6gp-9573GHSA-mf9v-mfxr-j63jUBUNTU-CVE-2026-44432
Also known as
CGA-9f85-qpfh-pwpj, CGA-g9cf-jc7j-hpwm, PYSEC-2026-142

Charts affected

330 by stars
ChartLatestAffected imagesRadar Score
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
urllib3@2.6.2
2.7.0

Open the chart page →

5,366
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
python-pip@24.0+dfsg-1ubuntu1.3
urllib3@2.6.1
no fix listed
2.7.0

Open the chart page →

19,391
pulsarapache4.7.02 of 10See more

pulsar apache 4.7.0

2 of the 10 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
urllib3@2.6.3
2.7.0
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
urllib3@2.6.3
2.7.0

Open the chart page →

9,864
difydify-helmVerified publisher0.38.02 of 11See more

dify dify-helm 0.38.0

2 of the 11 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
langgenius/dify-sandbox:0.2.15750e1111426e
urllib3@2.6.3
2.7.0

Open the chart page →

22,002
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
urllib3@2.6.3
2.7.0

Open the chart page →

11,384
milvusmilvus-helm5.0.271 of 4See more

milvus milvus-helm 5.0.27

1 of the 4 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

10,670
memgraphmemgraphVerified publisher1.0.61 of 2See more

memgraph memgraph 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
memgraph/memgraph:3.13.0a1dc375774ed
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

1,373
openclawopenclawVerified publisher1.91.31 of 2See more

openclaw openclaw 1.91.3

1 of the 2 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

2,977
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
urllib3@2.6.3
2.7.0

Open the chart page →

4,332
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
openmined/syft-backend:0.9.5b72f74a68b32
py3-pip@25.0.1-r0
26.1.2-r1

Open the chart page →

17,245
wordpresshelmforgeVerified publisher3.0.61 of 3See more

wordpress helmforge 3.0.6

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:9.7.2257388edf9c8
urllib3@2.6.3
2.7.0

Open the chart page →

4,148
lightrun-helm-chartlightrun-helm-chartOfficialVerified publisher3.51.01 of 9See more

lightrun-helm-chart lightrun-helm-chart 3.51.0

1 of the 9 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.4.108dbcf531a03a
urllib3@2.6.3
2.7.0

Open the chart page →

463
jellyfinloeken-at-homeVerified publisher10.11.81 of 1See more

jellyfin loeken-at-home 10.11.8

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
loeken/jellyfin:10.11.87efbc24e47b0
urllib3@2.6.3
2.7.0

Open the chart page →

883
py-kube-downscalerpy-kube-downscalerVerified publisher0.3.121 of 1See more

py-kube-downscaler py-kube-downscaler 0.3.12

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/caas-team/py-kube-downscaler:26.4.0af05a098b0d2
urllib3@2.6.3
2.7.0

Open the chart page →

731
abcdesktopabcdesktopOfficialVerified publisher4.4.121 of 9See more

abcdesktop abcdesktop 4.4.12

1 of the 9 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/abcdesktopio/route:4.449c972229c6b
urllib3@2.6.3
2.7.0

Open the chart page →

768
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
python-pip@20.0.2-5ubuntu1.1
no fix listed

Open the chart page →

52,919
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
python-pip@22.0.2+dfsg-1ubuntu0.6
no fix listed

Open the chart page →

27,267
geonode-k8sgeonode-k8sVerified publisher2.0.02 of 10See more

geonode-k8s geonode-k8s 2.0.0

2 of the 10 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
python-pip@22.0.2+dfsg-1ubuntu0.7
no fix listed
geopython/pycsw:3.0.0-beta284662ea6b78b
urllib3@2.6.2
2.7.0

Open the chart page →

13,953
dolibarrhelmforgeVerified publisher1.2.181 of 3See more

dolibarr helmforge 1.2.18

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:9.7.2257388edf9c8
urllib3@2.6.3
2.7.0

Open the chart page →

4,109
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

9,460
netscaler-ingress-controllernetscalerOfficialVerified publisher4.2.261 of 1See more

netscaler-ingress-controller netscaler 4.2.26

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
quay.io/netscaler/netscaler-k8s-ingress-controller:4.2.26a68453858339
urllib3@2.6.3
2.7.0

Open the chart page →

142
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
python-pip@20.0.2-5ubuntu1.9
no fix listed

Open the chart page →

7,960
dumpscriptcloudscriptVerified publisher1.8.31 of 1See more

dumpscript cloudscript 1.8.3

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/dumpscript:v0.0.42-alpine-edgefce5b6fd161c
urllib3@2.6.3
2.7.0

Open the chart page →

2,125
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
urllib3@2.6.3
2.7.0

Open the chart page →

9,316
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
python-pip@24.0+dfsg-1ubuntu1.1
no fix listed

Open the chart page →

4,147
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
python-pip@20.0.2-5ubuntu1.6
no fix listed

Open the chart page →

10,598
ghost-on-kubernetesghost-on-kubernetes-helmVerified publisher1.1.21 of 3See more

ghost-on-kubernetes ghost-on-kubernetes-helm 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.4b3b90af2a655
urllib3@2.6.3
2.7.0

Open the chart page →

1,447
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

4,477
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
urllib3@2.6.3
2.7.0

Open the chart page →

4,634
klancesklances0.1.41 of 1See more

klances klances 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
urllib3@2.6.3
2.7.0

Open the chart page →

1,693
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
python-pip@20.0.2-5ubuntu1.11
no fix listed

Open the chart page →

11,582
bitwarden-crd-operatorlerentisVerified publisher0.18.01 of 1See more

bitwarden-crd-operator lerentis 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
urllib3@2.6.3
2.7.0

Open the chart page →

2,003
memgraph-high-availabilitymemgraphVerified publisher1.4.01 of 2See more

memgraph-high-availability memgraph 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
memgraph/memgraph:3.13.0a1dc375774ed
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

1,373
nominatimrobjuz6.4.11 of 4See more

nominatim robjuz 6.4.1

1 of the 4 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
mediagis/nominatim:5.3.27923a8e67197
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

8,690
sn-platformstreamnative1.11.441 of 9See more

sn-platform streamnative 1.11.44

1 of the 9 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python-pip@20.0.2-5ubuntu1.10
no fix listed

Open the chart page →

15,477
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
python-pip@9.0.1-2.3~ubuntu1.18.04.5
no fix listed

Open the chart page →

12,046
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
python-pip@22.0.2+dfsg-1ubuntu0.6
no fix listed

Open the chart page →

7,740
open-elevationbeeinventor0.1.01 of 2See more

open-elevation beeinventor 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
openelevation/open-elevation:latest82fb21612e86
python-pip@20.0.2-5ubuntu1.6
no fix listed

Open the chart page →

13,145
cloudflared-ingress-operatorcloudflared-ingress-operatorVerified publisher0.3.21 of 1See more

cloudflared-ingress-operator cloudflared-ingress-operator 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
urllib3@2.6.3
2.7.0

Open the chart page →

1,724
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

10,858
craftycontrollerdrewburr-labs-helm-chartsVerified publisher0.3.01 of 1See more

craftycontroller drewburr-labs-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

3,671
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
python-pip@20.0.2-5ubuntu1.6
no fix listed

Open the chart page →

15,653
IMgrycapOfficialVerified publisher1.8.01 of 3See more

IM grycap 1.8.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.4b3b90af2a655
urllib3@2.6.3
2.7.0

Open the chart page →

4,132
matomohelmforgeVerified publisher2.3.01 of 3See more

matomo helmforge 2.3.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:9.7.2b2cf29815e62
urllib3@2.6.3
2.7.0

Open the chart page →

2,680
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
python-pip@22.0.2+dfsg-1ubuntu0.6
urllib3@2.6.3
no fix listed
2.7.0

Open the chart page →

12,397
jupyterhub-outpostjupyter-jscVerified publisher2.4.11 of 1See more

jupyterhub-outpost jupyter-jsc 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
jupyterjsc/jupyterhub-outpost:2.3.1aea53b13f235
urllib3@2.6.3
2.7.0

Open the chart page →

1,678
k8s-grafana-stackk8s-grafana-stackVerified publisher0.2.321 of 17See more

k8s-grafana-stack k8s-grafana-stack 0.2.32

1 of the 17 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
urllib3@2.6.3
2.7.0

Open the chart page →

15,418
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
urllib3@2.6.3
2.7.0

Open the chart page →

7,710
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
py3-pip@25.2-r0
26.1.2-r1

Open the chart page →

4,292
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
urllib3@2.6.3
2.7.0

Open the chart page →

7,201

Container images carrying it

206 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
galaxy/galaxy-init:v18.010267bad550e6
python-pip@1.5.4-1ubuntu4
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
python-pip@1.5.4-1ubuntu4
no fix listed
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
python-pip@22.0.2+dfsg-1ubuntu0.7
no fix listed
1
geopython/pycsw:3.0.0-beta284662ea6b78b
urllib3@2.6.2
2.7.0
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
python-pip@9.0.1-2.3~ubuntu1.18.04.2
no fix listed
1
gethue/hue:4.11.011b649636e68
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
gethue/hue:4.10.05702b2c37ff9
python-pip@9.0.1-2.3~ubuntu1.18.04.5
no fix listed
1
gethue/hue:latest7d5c1b9f8a79
python-pip@22.0.2+dfsg-1ubuntu0.6
urllib3@2.6.3
no fix listed
2.7.0
1
heartexlabs/label-studio:latestaa461572e8f9
urllib3@2.6.3
2.7.0
1
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
python-pip@20.0.2-5ubuntu1.11
no fix listed
1
helmforge/fastmcp-server:0.2.061f759a1421f
urllib3@2.6.3
2.7.0
1
helmforge/fastmcp-server:0.11.2fcb7017327d6
urllib3@2.6.3
2.7.0
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
urllib3@2.6.3
2.7.0
1
jonasal/devpi-server:6.17.0-alpineec1eee99a18d
urllib3@2.6.2
2.7.0
1
josh5/unmanic:0.2.64d49c4816260
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
python-pip@20.0.2-5ubuntu1.1
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
jupyterjsc/jupyterhub-outpost:2.3.1aea53b13f235
urllib3@2.6.3
2.7.0
1
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
urllib3@2.6.3
2.7.0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
urllib3@2.6.3
2.7.0
1
kenchrcum/grafana-dashboard-converter:0.3.105310497aea3f
urllib3@2.6.3
2.7.0
1
kenchrcum/hetzner-s3-operator:0.1.384dae7aeea5b
urllib3@2.6.3
2.7.0
1
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
urllib3@2.6.3
2.7.0
1
kennethreitz/httpbin:latest599fe5e50731
python-pip@9.0.1-2.3~ubuntu1
no fix listed
1
knspar/phronetis:0.1.4609499d2dc91a
python-pip@24.0+dfsg-1ubuntu1.1
no fix listed
1
kong/httpbin:latesta6ac46531193
python-pip@22.0.2+dfsg-1ubuntu0.5
no fix listed
1
kusionstack/kusion:v0.14.0126c8f0b0976
python-pip@22.0.2+dfsg-1ubuntu0.5
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
python-pip@24.0+dfsg-1ubuntu1.3
urllib3@2.6.1
no fix listed
2.7.0
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
langgenius/dify-sandbox:0.2.15750e1111426e
urllib3@2.6.3
2.7.0
1
library/mysql:8.4.113466ba4a4828
urllib3@2.6.3
2.7.0
1
library/mysql:885b9bf2e29cf
urllib3@2.6.3
2.7.0
1
library/mysql:8.4.108dbcf531a03a
urllib3@2.6.3
2.7.0
1
linuxserver/calibre-web:0.6.24241009026e6f
python-pip@24.0+dfsg-1ubuntu1.2
no fix listed
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
py3-pip@26.0.1-r1
urllib3@2.6.3
26.1.2-r1
2.7.0
1
loeken/jellyfin:10.11.87efbc24e47b0
urllib3@2.6.3
2.7.0
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
marcoimme/oidcmock:latestb6035c0721a8
urllib3@2.6.3
2.7.0
1
mawad98/backstage-pyactions:demo99422c56a274
urllib3@2.6.3
2.7.0
1
mediagis/nominatim:5.3.27923a8e67197
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
mediagis/nominatim:3.7c15e941485ef
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed
1
mindsdb/mindsdb:latest163011c09299
urllib3@2.6.3
2.7.0
1
mshanley80/httpbin2022:latest5b189a70c0fb
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
urllib3@2.6.3
2.7.0
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
python-pip@9.0.1-2.3~ubuntu1.18.04.1
no fix listed
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
python-pip@8.1.1-2ubuntu0.4
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.