StackRadar

CVE-2026-44546

Medium

Advisory

Published 3 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
13
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 13 images.

Affected packageAffected versionsFixed inImages
daphnepypi3.0.2, 4.1.0, 4.1.2, 4.2.14.2.213
OSV records
PYSEC-2026-214
Also known as
GHSA-xh68-hfp5-5x5m

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-44546.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
daphne@4.1.2
4.2.2

Open the chart page →

17,404
psonoankra-chartsVerified publisher1.2.01 of 2See more

psono ankra-charts 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-44546.

Container imageDigestPackageFixed in
psono/psono-server:5.0.03b974b43ea03
daphne@4.1.2
4.2.2

Open the chart page →

2,388
anteonanteonVerified publisher2.6.42 of 13See more

anteon anteon 2.6.4

2 of the 13 container images this version deploys carry CVE-2026-44546.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
daphne@4.1.0
4.2.2
ddosify/selfhosted_backend:3.2.93c11e3182652
daphne@4.1.0
4.2.2

Open the chart page →

22,202
obicogabe565Verified publisher0.6.01 of 3See more

obico gabe565 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-44546.

Container imageDigestPackageFixed in
ghcr.io/gabe565/obico/web:latesta5c1daef46c0
daphne@4.1.2
4.2.2

Open the chart page →

1,965
paperlessgeek-cookbookVerified publisher9.2.01 of 1See more

paperless geek-cookbook 9.2.0

1 of the 1 container images this version deploys carry CVE-2026-44546.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
daphne@3.0.2
4.2.2

Open the chart page →

3,924
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-44546.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
daphne@3.0.2
4.2.2

Open the chart page →

12,397
ddosifyanteonVerified publisher1.7.52 of 13See more

ddosify anteon 1.7.5

2 of the 13 container images this version deploys carry CVE-2026-44546.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
daphne@4.1.0
4.2.2
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
daphne@4.1.0
4.2.2

Open the chart page →

25,669
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-44546.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
daphne@3.0.2
4.2.2

Open the chart page →

22,891
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-44546.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
daphne@4.1.2
4.2.2

Open the chart page →

10,145
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-44546.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
daphne@4.2.1
4.2.2

Open the chart page →

17,852
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-44546.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
daphne@3.0.2
4.2.2

Open the chart page →

16,417

Container images carrying it

13 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
baserow/backend:1.31.1e0b3c8130b91
daphne@4.1.2
4.2.2
1
baserow/baserow:1.30.1df0c42eb67e8
daphne@4.1.2
4.2.2
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
daphne@4.1.0
4.2.2
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
daphne@4.1.0
4.2.2
1
ddosify/selfhosted_backend:3.2.93c11e3182652
daphne@4.1.0
4.2.2
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
daphne@4.1.0
4.2.2
1
gethue/hue:4.11.011b649636e68
daphne@3.0.2
4.2.2
1
gethue/hue:4.10.05702b2c37ff9
daphne@3.0.2
4.2.2
1
gethue/hue:latest7d5c1b9f8a79
daphne@3.0.2
4.2.2
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
daphne@4.2.1
4.2.2
1
psono/psono-server:5.0.03b974b43ea03
daphne@4.1.2
4.2.2
1
ghcr.io/gabe565/obico/web:latesta5c1daef46c0
daphne@4.1.2
4.2.2
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
daphne@3.0.2
4.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.