StackRadar

CVE-2026-44432

High

Advisory

Published 11 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.9
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
330
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
2 of 3
affected packages

urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API

Carried by container images the latest versions of 330 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
py3-pipapk25.0.1-r0, 25.2-r0, 26.0.1-r126.1.2-r13
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+22 moreno fix listed107
urllib3pypi2.6.0, 2.6.1, 2.6.2, 2.6.32.7.099
OSV records
CGA-63m6-2q77-9p47CGA-7w5f-j6gp-9573GHSA-mf9v-mfxr-j63jUBUNTU-CVE-2026-44432
Also known as
CGA-9f85-qpfh-pwpj, CGA-g9cf-jc7j-hpwm, PYSEC-2026-142

Charts affected

330 by stars
ChartLatestAffected imagesRadar Score
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
smtpsmtpVerified publisher1.3.31 of 1See more

smtp smtp 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
urllib3@2.6.2
2.7.0

Open the chart page →

1,437
kube-prometheus-stacksoftonic81.5.11 of 6See more

kube-prometheus-stack softonic 81.5.1

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
urllib3@2.6.3
2.7.0

Open the chart page →

4,974
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
python-pip@20.0.2-5ubuntu1.6
no fix listed

Open the chart page →

30,687
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

11,888
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
open-appsec-injectorstartechnicaVerified publisher1.1.21 of 3See more

open-appsec-injector startechnica 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
urllib3@2.6.3
2.7.0

Open the chart page →

4,303
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python-pip@20.0.2-5ubuntu1.10
no fix listed

Open the chart page →

10,134
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
urllib3@2.6.3
2.7.0

Open the chart page →

2,396
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
urllib3@2.6.3
2.7.0

Open the chart page →

1,556
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
python-pip@22.0.2+dfsg-1
no fix listed

Open the chart page →

17,461
pagestest43221.0.01 of 3See more

pages test4322 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

5,704
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

6,973
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

9,347
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

4,305
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
python-pip@24.0+dfsg-1ubuntu1.2
no fix listed

Open the chart page →

7,628
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
wallarm/node-helpers:6.10.1aecd88b24c51
urllib3@2.6.3
2.7.0

Open the chart page →

2,824
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
wasabi-s3-operatorwasabi-s3-operatorVerified publisher0.2.71 of 1See more

wasabi-s3-operator wasabi-s3-operator 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
urllib3@2.6.3
2.7.0

Open the chart page →

628
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
urllib3@2.6.3
2.7.0

Open the chart page →

5,484

Container images carrying it

206 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/caas-team/py-kube-downscaler:26.4.0af05a098b0d2
urllib3@2.6.3
2.7.0
1
ghcr.io/cleanuparr/cleanuparr:2.10.5c7cd53ad559a
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/cloudscript-technology/dumpscript:v0.0.42-alpine-edgefce5b6fd161c
urllib3@2.6.3
2.7.0
1
ghcr.io/ctfd/ctfd:3.8.2870e396fddf8
urllib3@2.6.0
2.7.0
1
ghcr.io/dask/dask-gateway-server:2026.3.0afa5a729114e
urllib3@2.6.3
2.7.0
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
urllib3@2.6.3
2.7.0
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
python-pip@24.0+dfsg-1ubuntu1.1
no fix listed
1
ghcr.io/eslupmi/impulse:v3.7.03ded1b7ebca0
urllib3@2.6.3
2.7.0
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
urllib3@2.6.3
2.7.0
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
urllib3@2.6.3
2.7.0
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
urllib3@2.6.3
2.7.0
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
urllib3@2.6.2
2.7.0
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
urllib3@2.6.3
2.7.0
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
urllib3@2.6.3
2.7.0
1
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
urllib3@2.6.2
2.7.0
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
python-pip@20.0.2-5ubuntu1.11
no fix listed
1
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
urllib3@2.6.3
2.7.0
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
urllib3@2.6.3
2.7.0
1
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
urllib3@2.6.3
2.7.0
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
urllib3@2.6.3
2.7.0
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
urllib3@2.6.3
2.7.0
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
urllib3@2.6.3
2.7.0
1
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
urllib3@2.6.3
2.7.0
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
urllib3@2.6.2
2.7.0
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
urllib3@2.6.3
2.7.0
1
ghcr.io/vinny1892/octantis:latest45459c0910fc
urllib3@2.6.3
2.7.0
1
ghcr.io/zazukoians/qlever-server:v0.10.0f10fd24b2290
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
urllib3@2.6.3
2.7.0
1
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
urllib3@2.6.3
2.7.0
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
urllib3@2.6.3
2.7.0
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
urllib3@2.6.3
2.7.0
1
quay.io/kiwigrid/k8s-sidecar:2.6.0a6c101156d42
urllib3@2.6.3
2.7.0
1
quay.io/maxiv/pieeat:0.9.3099715479210
urllib3@2.6.3
2.7.0
1
quay.io/netscaler/netscaler-k8s-ingress-controller:4.2.26a68453858339
urllib3@2.6.3
2.7.0
1
quay.io/opstree/k8s-sidecar:2.7.126aa9bb3386b
urllib3@2.6.3
2.7.0
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
urllib3@2.6.2
2.7.0
1
quay.io/ortelius/ms-dep-pkg-cud:main-v10.0.1670-g9abe110c0c881b509a
urllib3@2.6.2
2.7.0
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
urllib3@2.6.2
2.7.0
1
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
urllib3@2.6.2
2.7.0
1
quay.io/ortelius/ms-scorecard:main-v10.0.1276-g966a8a43337e52fdd4
urllib3@2.6.2
2.7.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.