CVE-2026-45409
MediumAdvisory
Published 19 May 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.004
- 34th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 913
- of 17,787 indexed, latest versions
- Container images
- 972
- deployed by those charts
- Fix available
- 4 of 5
- affected packages
Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
Carried by container images the latest versions of 913 of 17,787 indexed charts deploy, on 972 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| idnapypi | 2.4, 2.5, 2.6, 2.7+15 more | 3.15 | 937 |
| python-pipdeb | 1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+22 more | no fix listed | 106 |
| python-idnadeb | 2.6-1, 2.8-1, 2.8-1ubuntu0.1, 3.3-1+3 more | 3.3-1ubuntu0.2, 3.6-2ubuntu0.2 | 69 |
| python-idnarpm | 2.5-5.el8, 2.5-7.el8_10, 2.10-7.el9, 2.10-7.el9_4.1+1 more | 0:2.5-8.el8_10, 0:2.10-8.el9_8, 0:3.7-6.el10_2 | 64 |
| py3-pipapk | 25.0.1-r0, 25.2-r0, 26.0.1-r1 | 26.1.2-r1 | 3 |
- OSV records
- CGA-9qj9-xwv6-6g35CGA-jxvh-c6v2-m7x3DEBIAN-CVE-2026-45409GHSA-65pc-fj4g-8rjxRHSA-2026:54290RHSA-2026:54481RHSA-2026:54484RLSA-2026:54481UBUNTU-CVE-2026-45409
- Also known as
- CGA-gpf6-q7mq-4ppj, CGA-qfx6-f9w7-v6f4, PYSEC-2026-215, USN-8549-1
Charts affected
913 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| ambassadorwenerme | 6.9.5 | 1 of 2See more | 4,086 |
| emissary-ingresswenerme | 8.12.2 | 1 of 2See more | 10,843 |
| juicefs-csi-driverwenerme | 0.32.5 | 1 of 5See more | 9,117 |
| ceph-csi-cephfswikimedia | 0.1.8 | 1 of 5See more | 10,285 |
| ceph-csi-rbdwikimedia | 0.1.13 | 1 of 6See more | 11,784 |
| docker-hub-rate-limit-exporterwiremindVerified publisher | 0.3.0 | 1 of 1See more | 1,843 |
| marge-botwiremindVerified publisher | 1.4.4 | 1 of 1See more | 5,542 |
| powerdnsadminwitcom-gmbh | 0.3.4 | 1 of 1See more | 2,643 |
| xkopsxkops | 0.1.0 | 2 of 5See more | 13,677 |
| enterprise-gatewayzeet | 3.2.2 | 1 of 2See more | 1,838 |
| zerossl-cert-managerzerossl-cert-manager | 0.1.0 | 1 of 2See more | 570 |
| alertmanager-matrix-forwarderzloi-space | 1.0.1 | 1 of 2See more | 3,118 |
| grafana-matrix-forwarderzloi-space | 1.0.0 | 1 of 2See more | 1,636 |
Container images carrying it
972 by charts deploying them
A fixed version is listed for 4 of the 5 affected packages.