StackRadar

CVE-2026-44432

High

Advisory

Published 11 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.9
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
330
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
2 of 3
affected packages

urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API

Carried by container images the latest versions of 330 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
py3-pipapk25.0.1-r0, 25.2-r0, 26.0.1-r126.1.2-r13
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+22 moreno fix listed107
urllib3pypi2.6.0, 2.6.1, 2.6.2, 2.6.32.7.099
OSV records
CGA-63m6-2q77-9p47CGA-7w5f-j6gp-9573GHSA-mf9v-mfxr-j63jUBUNTU-CVE-2026-44432
Also known as
CGA-9f85-qpfh-pwpj, CGA-g9cf-jc7j-hpwm, PYSEC-2026-142

Charts affected

330 by stars
ChartLatestAffected imagesRadar Score
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
smtpsmtpVerified publisher1.3.31 of 1See more

smtp smtp 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
urllib3@2.6.2
2.7.0

Open the chart page →

1,437
kube-prometheus-stacksoftonic81.5.11 of 6See more

kube-prometheus-stack softonic 81.5.1

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
urllib3@2.6.3
2.7.0

Open the chart page →

4,974
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
python-pip@20.0.2-5ubuntu1.6
no fix listed

Open the chart page →

30,687
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

11,888
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
open-appsec-injectorstartechnicaVerified publisher1.1.21 of 3See more

open-appsec-injector startechnica 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
urllib3@2.6.3
2.7.0

Open the chart page →

4,303
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python-pip@20.0.2-5ubuntu1.10
no fix listed

Open the chart page →

10,134
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
urllib3@2.6.3
2.7.0

Open the chart page →

2,396
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
urllib3@2.6.3
2.7.0

Open the chart page →

1,556
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
python-pip@22.0.2+dfsg-1
no fix listed

Open the chart page →

17,461
pagestest43221.0.01 of 3See more

pages test4322 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

5,704
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

6,973
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

9,347
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

4,305
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
python-pip@24.0+dfsg-1ubuntu1.2
no fix listed

Open the chart page →

7,628
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
wallarm/node-helpers:6.10.1aecd88b24c51
urllib3@2.6.3
2.7.0

Open the chart page →

2,824
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
wasabi-s3-operatorwasabi-s3-operatorVerified publisher0.2.71 of 1See more

wasabi-s3-operator wasabi-s3-operator 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
urllib3@2.6.3
2.7.0

Open the chart page →

628
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
urllib3@2.6.3
2.7.0

Open the chart page →

5,484

Container images carrying it

206 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
urllib3@2.6.3
2.7.0
1
opencsghq/label-studio:v2.5.047e22aa71870
urllib3@2.6.0
2.7.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
urllib3@2.6.0
2.7.0
1
opendatacube/pipelines:wofs-1.225d810e8504b8
python-pip@9.0.1-2.3~ubuntu1
no fix listed
1
opendatacube/restcube:latest91870111837c
python-pip@9.0.1-2.3~ubuntu1
no fix listed
1
opendatacube/wms:latest1b90cdf68831
python-pip@9.0.1-2.3~ubuntu1
no fix listed
1
openelevation/open-elevation:latest82fb21612e86
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
openmined/syft-backend:0.9.5b72f74a68b32
py3-pip@25.0.1-r0
26.1.2-r1
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
python-pip@9.0.1-2.3~ubuntu1.18.04.4
no fix listed
1
prompve/prometheus-pve-exporter:3.8.2e3d501a82df5
urllib3@2.6.3
2.7.0
1
redash/redash:26.3.0c5c9148f5c38
urllib3@2.6.3
2.7.0
1
reportportal/service-auto-analyzer:5.15.5c449b93629a5
urllib3@2.6.3
2.7.0
1
rezachalak/bzen-mongo:1.0.034f694325191
python-pip@20.0.2-5ubuntu1.9
no fix listed
1
scrapinghub/splash:3.4.1a5f89bc84606
python-pip@9.0.1-2.3~ubuntu1.18.04.1
no fix listed
1
seafileltd/seafile-mc:9.0.106693911bcc40
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
seafileltd/seafile-mc:10.0.170628f29c663
python-pip@20.0.2-5ubuntu1.9
no fix listed
1
seafileltd/seafile-mc:9.0.97ac833196f60
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
seldonio/locust-core:0.81d0da98a2d76
python-pip@8.1.1-2ubuntu0.4
no fix listed
1
shaowenchen/ops-controller-manager:latest26da43bb5b66
python-pip@22.0.2+dfsg-1ubuntu0.7
no fix listed
1
shaowenchen/ops-server:latest315444f703f4
python-pip@22.0.2+dfsg-1ubuntu0.6
no fix listed
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
python-pip@20.0.2-5ubuntu1.9
no fix listed
1
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
python-pip@9.0.1-2.3~ubuntu1.18.04.8
no fix listed
1
socialmediamacroscope/image_crawler:0.1.2f508216be63c
python-pip@9.0.1-2.3~ubuntu1.18.04.8
no fix listed
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
stashapp/stash:v0.31.1df744af5a0c9
urllib3@2.6.3
2.7.0
1
statcan/ckan:2.93921305425b8
python-pip@20.0.2-5ubuntu1.5
no fix listed
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
python-pip@20.0.2-5ubuntu1.5
no fix listed
1
timescale/timescaledb-ha:pg16d7db8f1085a3
python-pip@22.0.2+dfsg-1ubuntu0.7
no fix listed
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
python-pip@22.0.2+dfsg-1ubuntu0.5
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
python-pip@8.1.1-2ubuntu0.4
no fix listed
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
urllib3@2.6.3
2.7.0
1
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
urllib3@2.6.3
2.7.0
1
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
urllib3@2.6.3
2.7.0
1
tomsquest/docker-radicale:3.6.1.0a594c624c5a6
urllib3@2.6.3
2.7.0
1
tussanakorndev/kube-pod-alerts:1.0.5216fdadadf9a
urllib3@2.6.3
2.7.0
1
voltha/voltha-cli:1.6.0c4e41e92f046
python-pip@8.1.1-2ubuntu0.4
no fix listed
1
voltha/voltha-netconf:1.6.037f80524c207
python-pip@8.1.1-2ubuntu0.4
no fix listed
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
python-pip@8.1.1-2ubuntu0.4
no fix listed
1
voltha/voltha-tester:1.7.0655c3048a602
python-pip@8.1.1-2ubuntu0.4
no fix listed
1
voltha/voltha-voltha:1.6.0ff596b62de59
python-pip@8.1.1-2ubuntu0.4
no fix listed
1
wallarm/node-helpers:6.10.1aecd88b24c51
urllib3@2.6.3
2.7.0
1
wazuh/wazuh-manager:4.14.45a065930682d
urllib3@2.6.3
2.7.0
1
wazuh/wazuh-manager:4.14.3f09282d281f6
urllib3@2.6.3
2.7.0
1
xeladock/mysql_dns:latest4baf531453f1
python-pip@22.0.2+dfsg-1
no fix listed
1
ghcr.io/abcdesktopio/route:4.449c972229c6b
urllib3@2.6.3
2.7.0
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
py3-pip@25.2-r0
26.1.2-r1
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.