StackRadar

CVE-2026-44432

High

Advisory

Published 11 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.9
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
330
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
2 of 3
affected packages

urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API

Carried by container images the latest versions of 330 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
py3-pipapk25.0.1-r0, 25.2-r0, 26.0.1-r126.1.2-r13
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+22 moreno fix listed107
urllib3pypi2.6.0, 2.6.1, 2.6.2, 2.6.32.7.099
OSV records
CGA-63m6-2q77-9p47CGA-7w5f-j6gp-9573GHSA-mf9v-mfxr-j63jUBUNTU-CVE-2026-44432
Also known as
CGA-9f85-qpfh-pwpj, CGA-g9cf-jc7j-hpwm, PYSEC-2026-142

Charts affected

330 by stars
ChartLatestAffected imagesRadar Score
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
smtpsmtpVerified publisher1.3.31 of 1See more

smtp smtp 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
urllib3@2.6.2
2.7.0

Open the chart page →

1,437
kube-prometheus-stacksoftonic81.5.11 of 6See more

kube-prometheus-stack softonic 81.5.1

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
urllib3@2.6.3
2.7.0

Open the chart page →

4,974
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
python-pip@20.0.2-5ubuntu1.6
no fix listed

Open the chart page →

30,687
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

11,888
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
open-appsec-injectorstartechnicaVerified publisher1.1.21 of 3See more

open-appsec-injector startechnica 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
urllib3@2.6.3
2.7.0

Open the chart page →

4,303
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python-pip@20.0.2-5ubuntu1.10
no fix listed

Open the chart page →

10,134
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
urllib3@2.6.3
2.7.0

Open the chart page →

2,396
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
urllib3@2.6.3
2.7.0

Open the chart page →

1,556
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
python-pip@22.0.2+dfsg-1
no fix listed

Open the chart page →

17,461
pagestest43221.0.01 of 3See more

pages test4322 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

5,704
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

6,973
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

9,347
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

4,305
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
python-pip@24.0+dfsg-1ubuntu1.2
no fix listed

Open the chart page →

7,628
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
wallarm/node-helpers:6.10.1aecd88b24c51
urllib3@2.6.3
2.7.0

Open the chart page →

2,824
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
wasabi-s3-operatorwasabi-s3-operatorVerified publisher0.2.71 of 1See more

wasabi-s3-operator wasabi-s3-operator 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
urllib3@2.6.3
2.7.0

Open the chart page →

628
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
urllib3@2.6.3
2.7.0

Open the chart page →

5,484

Container images carrying it

206 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
galaxy/galaxy-init:v18.010267bad550e6
python-pip@1.5.4-1ubuntu4
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
python-pip@1.5.4-1ubuntu4
no fix listed
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
python-pip@22.0.2+dfsg-1ubuntu0.7
no fix listed
1
geopython/pycsw:3.0.0-beta284662ea6b78b
urllib3@2.6.2
2.7.0
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
python-pip@9.0.1-2.3~ubuntu1.18.04.2
no fix listed
1
gethue/hue:4.11.011b649636e68
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
gethue/hue:4.10.05702b2c37ff9
python-pip@9.0.1-2.3~ubuntu1.18.04.5
no fix listed
1
gethue/hue:latest7d5c1b9f8a79
python-pip@22.0.2+dfsg-1ubuntu0.6
urllib3@2.6.3
no fix listed
2.7.0
1
heartexlabs/label-studio:latestaa461572e8f9
urllib3@2.6.3
2.7.0
1
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
python-pip@20.0.2-5ubuntu1.11
no fix listed
1
helmforge/fastmcp-server:0.2.061f759a1421f
urllib3@2.6.3
2.7.0
1
helmforge/fastmcp-server:0.11.2fcb7017327d6
urllib3@2.6.3
2.7.0
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
urllib3@2.6.3
2.7.0
1
jonasal/devpi-server:6.17.0-alpineec1eee99a18d
urllib3@2.6.2
2.7.0
1
josh5/unmanic:0.2.64d49c4816260
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
python-pip@20.0.2-5ubuntu1.1
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
jupyterjsc/jupyterhub-outpost:2.3.1aea53b13f235
urllib3@2.6.3
2.7.0
1
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
urllib3@2.6.3
2.7.0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
urllib3@2.6.3
2.7.0
1
kenchrcum/grafana-dashboard-converter:0.3.105310497aea3f
urllib3@2.6.3
2.7.0
1
kenchrcum/hetzner-s3-operator:0.1.384dae7aeea5b
urllib3@2.6.3
2.7.0
1
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
urllib3@2.6.3
2.7.0
1
kennethreitz/httpbin:latest599fe5e50731
python-pip@9.0.1-2.3~ubuntu1
no fix listed
1
knspar/phronetis:0.1.4609499d2dc91a
python-pip@24.0+dfsg-1ubuntu1.1
no fix listed
1
kong/httpbin:latesta6ac46531193
python-pip@22.0.2+dfsg-1ubuntu0.5
no fix listed
1
kusionstack/kusion:v0.14.0126c8f0b0976
python-pip@22.0.2+dfsg-1ubuntu0.5
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
python-pip@24.0+dfsg-1ubuntu1.3
urllib3@2.6.1
no fix listed
2.7.0
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
langgenius/dify-sandbox:0.2.15750e1111426e
urllib3@2.6.3
2.7.0
1
library/mysql:8.4.113466ba4a4828
urllib3@2.6.3
2.7.0
1
library/mysql:885b9bf2e29cf
urllib3@2.6.3
2.7.0
1
library/mysql:8.4.108dbcf531a03a
urllib3@2.6.3
2.7.0
1
linuxserver/calibre-web:0.6.24241009026e6f
python-pip@24.0+dfsg-1ubuntu1.2
no fix listed
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
py3-pip@26.0.1-r1
urllib3@2.6.3
26.1.2-r1
2.7.0
1
loeken/jellyfin:10.11.87efbc24e47b0
urllib3@2.6.3
2.7.0
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
marcoimme/oidcmock:latestb6035c0721a8
urllib3@2.6.3
2.7.0
1
mawad98/backstage-pyactions:demo99422c56a274
urllib3@2.6.3
2.7.0
1
mediagis/nominatim:5.3.27923a8e67197
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
mediagis/nominatim:3.7c15e941485ef
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed
1
mindsdb/mindsdb:latest163011c09299
urllib3@2.6.3
2.7.0
1
mshanley80/httpbin2022:latest5b189a70c0fb
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
urllib3@2.6.3
2.7.0
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
python-pip@9.0.1-2.3~ubuntu1.18.04.1
no fix listed
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
python-pip@8.1.1-2ubuntu0.4
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.