StackRadar

CVE-2026-44432

High

Advisory

Published 11 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.9
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
330
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
2 of 3
affected packages

urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API

Carried by container images the latest versions of 330 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
py3-pipapk25.0.1-r0, 25.2-r0, 26.0.1-r126.1.2-r13
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+22 moreno fix listed107
urllib3pypi2.6.0, 2.6.1, 2.6.2, 2.6.32.7.099
OSV records
CGA-63m6-2q77-9p47CGA-7w5f-j6gp-9573GHSA-mf9v-mfxr-j63jUBUNTU-CVE-2026-44432
Also known as
CGA-9f85-qpfh-pwpj, CGA-g9cf-jc7j-hpwm, PYSEC-2026-142

Charts affected

330 by stars
ChartLatestAffected imagesRadar Score
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
smtpsmtpVerified publisher1.3.31 of 1See more

smtp smtp 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
urllib3@2.6.2
2.7.0

Open the chart page →

1,437
kube-prometheus-stacksoftonic81.5.11 of 6See more

kube-prometheus-stack softonic 81.5.1

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
urllib3@2.6.3
2.7.0

Open the chart page →

4,974
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
python-pip@20.0.2-5ubuntu1.6
no fix listed

Open the chart page →

30,687
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

11,888
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
open-appsec-injectorstartechnicaVerified publisher1.1.21 of 3See more

open-appsec-injector startechnica 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
urllib3@2.6.3
2.7.0

Open the chart page →

4,303
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python-pip@20.0.2-5ubuntu1.10
no fix listed

Open the chart page →

10,134
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
urllib3@2.6.3
2.7.0

Open the chart page →

2,396
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
urllib3@2.6.3
2.7.0

Open the chart page →

1,556
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
python-pip@22.0.2+dfsg-1
no fix listed

Open the chart page →

17,461
pagestest43221.0.01 of 3See more

pages test4322 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

5,704
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

6,973
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

9,347
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

4,305
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
python-pip@24.0+dfsg-1ubuntu1.2
no fix listed

Open the chart page →

7,628
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
wallarm/node-helpers:6.10.1aecd88b24c51
urllib3@2.6.3
2.7.0

Open the chart page →

2,824
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0

Open the chart page →

20,190
wasabi-s3-operatorwasabi-s3-operatorVerified publisher0.2.71 of 1See more

wasabi-s3-operator wasabi-s3-operator 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
urllib3@2.6.3
2.7.0

Open the chart page →

628
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-44432.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
urllib3@2.6.3
2.7.0

Open the chart page →

5,484

Container images carrying it

206 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.7.0
89
library/mysql:8:8.4:8.4.11b3b90af2a655
urllib3@2.6.3
2.7.0
16
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
urllib3@2.6.3
2.7.0
13
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed
11
library/mysql:9.7.2257388edf9c8
urllib3@2.6.3
2.7.0
6
oomk8s/readiness-check:2.0.07daa08b81954
python-pip@8.1.1-2ubuntu0.4
no fix listed
6
apache/superset:6.1.0:latest16b50bbef664
urllib3@2.6.3
2.7.0
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
python-pip@20.0.2-5ubuntu1.6
no fix listed
3
alpine/k8s:1.32.12048f8d9c8cc7
urllib3@2.6.3
2.7.0
2
homebridge/homebridge:latest77c685a40911
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
2
library/mysql:9.7.2b2cf29815e62
urllib3@2.6.3
2.7.0
2
memgraph/memgraph:3.13.0a1dc375774ed
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
python-pip@8.1.1-2ubuntu0.4
no fix listed
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
python-pip@20.0.2-5ubuntu1.6
no fix listed
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python-pip@20.0.2-5ubuntu1.10
no fix listed
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
python-pip@22.0.2+dfsg-1ubuntu0.2
no fix listed
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
2
ghcr.io/xeor/karb:1.0.6:main647a3c938d31
urllib3@2.6.3
2.7.0
2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
urllib3@2.6.3
2.7.0
2
a10networks/acos-prometheus-exporter:latest8dc58d434d71
python-pip@9.0.1-2.3~ubuntu1.18.04.1
no fix listed
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
python-pip@9.0.1-2.3~ubuntu1.18.04.5
no fix listed
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
python-pip@22.0.2+dfsg-1ubuntu0.3
no fix listed
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
python-pip@22.0.2+dfsg-1ubuntu0.3
no fix listed
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
apachepulsar/pulsar:3.0.79c9947de139d
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed
1
apache/ranger:2.7.076c176e8a0e4
python-pip@22.0.2+dfsg-1ubuntu0.6
no fix listed
1
appwrite/appwrite:1.9.01aaa70127114
urllib3@2.6.3
2.7.0
1
appwrite/appwrite:1.9.6adc7d0e7ec23
urllib3@2.6.3
2.7.0
1
archivebox/archivebox:0.7.41a5a37331091
urllib3@2.6.3
2.7.0
1
arunvelsriram/utils:latest655ad18fd8d6
python-pip@24.0+dfsg-1ubuntu1.2
no fix listed
1
assistiot/open_api_backend:1.1.230812ba93555
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
python-pip@20.0.2-5ubuntu1.8
no fix listed
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
boky/postfix:5.1.0aafc77238423
urllib3@2.6.2
2.7.0
1
castai/hibernate:v0.14da62858c8381
urllib3@2.6.3
2.7.0
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
urllib3@2.6.3
2.7.0
1
citizenstig/httpbin:latestb81c818ccb86
python-pip@8.1.1-2ubuntu0.4
no fix listed
1
cloudve/janis-terminal:latestaf56e77ca587
python-pip@9.0.1-2.3~ubuntu1.18.04.1
no fix listed
1
datamate/seafile-professional:11.0.202dd66b722464
python-pip@22.0.2+dfsg-1ubuntu0.6
no fix listed
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
python-pip@20.0.2-5ubuntu1.11
no fix listed
1
dpage/pgadmin4:9.11.050700ac17936
urllib3@2.6.1
2.7.0
1
eclipseaerios/trust-manager:1.0.0f55442e2c0ed
urllib3@2.6.3
2.7.0
1
elautoestopista/aeneabot:4.2.1125ba620d528
urllib3@2.6.3
2.7.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
python-pip@20.0.2-5ubuntu1.11
no fix listed
1
flashcatcloud/nightingale:8.5.1421acb36181b
urllib3@2.6.3
2.7.0
1
flyway/flyway:9.1545b5d7cdc75a
python-pip@20.0.2-5ubuntu1.8
no fix listed
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
python-pip@9.0.1-2.3~ubuntu1.18.04.6
no fix listed
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
python-pip@9.0.1-2.3~ubuntu1.18.04.5
no fix listed
1
galaxy/cloudman-server:lateste5c265fe9fcd
python-pip@20.0.2-5ubuntu1.6
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.