StackRadar

CVE-2026-44432

High

Advisory

Published 11 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.9
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
330
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
2 of 3
affected packages

urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API

Carried by container images the latest versions of 330 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
py3-pipapk25.0.1-r0, 25.2-r0, 26.0.1-r126.1.2-r13
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+22 moreno fix listed107
urllib3pypi2.6.0, 2.6.1, 2.6.2, 2.6.32.7.099
OSV records
CGA-63m6-2q77-9p47CGA-7w5f-j6gp-9573GHSA-mf9v-mfxr-j63jUBUNTU-CVE-2026-44432
Also known as
CGA-9f85-qpfh-pwpj, CGA-g9cf-jc7j-hpwm, PYSEC-2026-142

Charts affected

330 by stars
ChartLatestAffected imagesRadar Score
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
smtpsmtpVerified publisher1.3.31 of 1See more

smtp smtp 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
urllib3@2.6.2
2.7.0

Open the chart page →

1,437
kube-prometheus-stacksoftonic81.5.11 of 6See more

kube-prometheus-stack softonic 81.5.1

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
urllib3@2.6.3
2.7.0

Open the chart page →

4,974
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
python-pip@20.0.2-5ubuntu1.6
no fix listed

Open the chart page →

30,687
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

11,888
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
open-appsec-injectorstartechnicaVerified publisher1.1.21 of 3See more

open-appsec-injector startechnica 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
urllib3@2.6.3
2.7.0

Open the chart page →

4,303
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python-pip@20.0.2-5ubuntu1.10
no fix listed

Open the chart page →

10,134
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
urllib3@2.6.3
2.7.0

Open the chart page →

2,396
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
urllib3@2.6.3
2.7.0

Open the chart page →

1,556
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
python-pip@22.0.2+dfsg-1
no fix listed

Open the chart page →

17,461
pagestest43221.0.01 of 3See more

pages test4322 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

5,704
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

6,973
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

9,347
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

4,305
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
python-pip@24.0+dfsg-1ubuntu1.2
no fix listed

Open the chart page →

7,628
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
wallarm/node-helpers:6.10.1aecd88b24c51
urllib3@2.6.3
2.7.0

Open the chart page →

2,824
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
wasabi-s3-operatorwasabi-s3-operatorVerified publisher0.2.71 of 1See more

wasabi-s3-operator wasabi-s3-operator 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
urllib3@2.6.3
2.7.0

Open the chart page →

628
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
urllib3@2.6.3
2.7.0

Open the chart page →

5,484

Container images carrying it

206 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
urllib3@2.6.2
2.7.0
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
urllib3@2.6.2
2.7.0
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
urllib3@2.6.3
2.7.0
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
python-pip@20.0.2-5ubuntu1.1
no fix listed
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
urllib3@2.6.2
2.7.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.