StackRadar

CVE-2026-45409

Medium

Advisory

Published 19 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
910
of 17,787 indexed, latest versions
Container images
969
deployed by those charts
Fix available
4 of 5
affected packages

Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix

Carried by container images the latest versions of 910 of 17,787 indexed charts deploy, on 969 images.

Affected packageAffected versionsFixed inImages
idnapypi2.4, 2.5, 2.6, 2.7+15 more3.15934
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+22 moreno fix listed106
python-idnadeb2.6-1, 2.8-1, 2.8-1ubuntu0.1, 3.3-1+3 more3.3-1ubuntu0.2, 3.6-2ubuntu0.269
python-idnarpm2.5-5.el8, 2.5-7.el8_10, 2.10-7.el9, 2.10-7.el9_4.1+1 more0:2.5-8.el8_10, 0:2.10-8.el9_8, 0:3.7-6.el10_264
py3-pipapk25.0.1-r0, 25.2-r0, 26.0.1-r126.1.2-r13
OSV records
CGA-9qj9-xwv6-6g35CGA-jxvh-c6v2-m7x3DEBIAN-CVE-2026-45409GHSA-65pc-fj4g-8rjxRHSA-2026:54290RHSA-2026:54481RHSA-2026:54484RLSA-2026:54481UBUNTU-CVE-2026-45409
Also known as
CGA-gpf6-q7mq-4ppj, CGA-qfx6-f9w7-v6f4, PYSEC-2026-215, USN-8549-1

Charts affected

910 by stars
ChartLatestAffected imagesRadar Score
gtmetrix-bqt3n1.0.01 of 1See more

gtmetrix-bq t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
t3nde/gtmetrix-bq:0.2.0d2939e9a719b
idna@2.9
3.15

Open the chart page →

1,287
take-the-helmtake-the-helm0.1.01 of 1See more

take-the-helm take-the-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
cadmusthefounder/lnd:take-the-helm-0.1.0e596c5fbf80f
idna@3.3
3.15

Open the chart page →

805
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
idna@3.11
3.15

Open the chart page →

1,556
democharttech-challenge0.1.01 of 4See more

demochart tech-challenge 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
alexvm6/generator:latestfb99ee4f760a
idna@3.4
3.15

Open the chart page →

3,632
rundeck-exportertechpreta0.1.91 of 1See more

rundeck-exporter techpreta 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
phsmith/rundeck-exporter:2.6.10265a7616ae8
idna@3.4
3.15

Open the chart page →

1,105
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
python-pip@22.0.2+dfsg-1
no fix listed

Open the chart page →

17,461
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
idna@3.10
3.15

Open the chart page →

5,704
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
idna@3.10
3.15

Open the chart page →

4,393
chatqnatest-opea1.0.05 of 11See more

chatqna test-opea 1.0.0

5 of the 11 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
opea/chatqna:1.038c51b791efa
idna@3.10
3.15
opea/embedding-tei:1.05c9639de61c1
idna@3.10
3.15
opea/llm-tgi:1.00c25aab3f106
idna@3.10
3.15
opea/reranking-tei:1.0e48613afb191
idna@3.10
3.15
opea/retriever-redis:1.0eb746b263705
idna@3.10
3.15

Open the chart page →

39,090
codegentest-opea1.0.02 of 5See more

codegen test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
opea/codegen:1.058f91683892d
idna@3.10
3.15
opea/llm-tgi:1.00c25aab3f106
idna@3.10
3.15

Open the chart page →

28,814
codetranstest-opea1.0.02 of 5See more

codetrans test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
opea/codetrans:1.0e2436483b73d
idna@3.10
3.15
opea/llm-tgi:1.00c25aab3f106
idna@3.10
3.15

Open the chart page →

28,385
docsumtest-opea1.0.02 of 5See more

docsum test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
opea/docsum:1.03eaa91849512
idna@3.10
3.15
opea/llm-docsum-tgi:1.002f9e8fa5d71
idna@3.10
3.15

Open the chart page →

28,858
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
idna@3.10
3.15

Open the chart page →

5,185
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
idna@3.10
3.15

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
idna@3.10
3.15

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
idna@3.10
3.15

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
idna@3.10
3.15

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
idna@3.10
3.15

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
idna@3.10
3.15

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
idna@3.10
3.15

Open the chart page →

5,350
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
idna@3.3
3.15

Open the chart page →

5,321
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
idna@2.10
3.15

Open the chart page →

2,408
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
idna@3.7
3.15

Open the chart page →

1,515
monitoringthl-chartsVerified publisher0.1.11 of 10See more

monitoring thl-charts 0.1.1

1 of the 10 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.15.61f025ae37b7b
idna@3.3
3.15

Open the chart page →

18,908
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.193170069ff0976
idna@2.8
3.15

Open the chart page →

4,423
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
idna@3.10
3.15

Open the chart page →

6,973
traefik-external-dns-operatortraefik-external-dns-operator1.0.11 of 1See more

traefik-external-dns-operator traefik-external-dns-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
idna@3.10
3.15

Open the chart page →

1,083
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
idna@3.4
3.15

Open the chart page →

3,164
tfy-grafanatruefoundryVerified publisher0.1.211 of 3See more

tfy-grafana truefoundry 0.1.21

1 of the 3 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
idna@3.11
3.15

Open the chart page →

1,062
truefoundry-monitoringtruefoundryVerified publisher0.1.61 of 8See more

truefoundry-monitoring truefoundry 0.1.6

1 of the 8 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
idna@3.11
3.15

Open the chart page →

4,526
zookeepertwomartensVerified publisher0.2.21 of 1See more

zookeeper twomartens 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
idna@3.10
3.15

Open the chart page →

1,733
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
idna@3.3
3.15

Open the chart page →

8,607
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
idna@3.10
3.15

Open the chart page →

4,768
devportalveecode-platform-nextVerified publisher0.1.221See more

devportal veecode-platform-next 0.1.22

1 container image this version deploys carries CVE-2026-45409.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
idna@3.7
3.15

Open the chart page →

velero-clientvelero-clientVerified publisher1.4.21 of 1See more

velero-client velero-client 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/velero-client/velero-client:1.4.203015f863a3e
idna@3.7
python-idna@3.7-4.el10
3.15
0:3.7-6.el10_2

Open the chart page →

513
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
idna@3.6
python-pip@22.0.2+dfsg-1ubuntu0.4
3.15
no fix listed

Open the chart page →

9,347
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

4,305
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
idna@3.3
python-idna@3.3-1
3.15
3.3-1ubuntu0.2

Open the chart page →

13,459
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
idna@3.10
python-pip@24.0+dfsg-1ubuntu1.2
3.15
no fix listed

Open the chart page →

7,628
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
wallarm/ingress-python:4.6.0-15cb2ae08b40f
idna@2.6
3.15

Open the chart page →

11,405
wallarm-node-nextwallarmVerified publisher0.5.31 of 2See more

wallarm-node-next wallarm 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
wallarm/node-helpers:5.0.2-1097cadc42336
idna@3.7
3.15

Open the chart page →

2,408
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
wallarm/node-helpers:6.10.1aecd88b24c51
idna@3.7
3.15

Open the chart page →

2,824
wasabi-s3-operatorwasabi-s3-operatorVerified publisher0.2.71 of 1See more

wasabi-s3-operator wasabi-s3-operator 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
idna@3.11
3.15

Open the chart page →

628
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
idna@3.7
3.15

Open the chart page →

5,484
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
idna@2.9
3.15

Open the chart page →

11,119
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
idna@3.2
3.15

Open the chart page →

7,085
weather-chartweather-web-app0.1.01 of 1See more

weather-chart weather-web-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
zohardocker12/weather_app_flask:latestb86d60dbb68d
idna@3.3
3.15

Open the chart page →

2,670
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
idna@2.7
3.15

Open the chart page →

4,086
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
datawire/emissary:3.12.21f67a1292d2a
idna@3.7
3.15

Open the chart page →

10,843
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-45409.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
idna@3.3
python-idna@3.3-1+deb12u1
3.15
no fix listed

Open the chart page →

9,117

Container images carrying it

969 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
idna@3.11
3.15
13
oomk8s/readiness-check:2.0.2875814cc853d
idna@2.8
python-pip@8.1.1-2ubuntu0.4
3.15
no fix listed
11
quay.io/openshift/origin-cli:latest605eaa5d469c
idna@3.7
3.15
7
oomk8s/readiness-check:2.0.07daa08b81954
idna@2.6
python-pip@8.1.1-2ubuntu0.4
3.15
no fix listed
6
opea/llm-tgi:1.00c25aab3f106
idna@3.10
3.15
4
shashkist/flask-contacts-app:latest581de1fd6084
idna@3.10
3.15
4
apache/superset:6.1.0:latest16b50bbef664
idna@3.10
3.15
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
idna@3.3
python-pip@20.0.2-5ubuntu1.6
3.15
no fix listed
3
dpage/pgadmin4:6.12781369df9994
idna@2.10
3.15
3
kiwigrid/k8s-sidecar:0.1.193170069ff0976
idna@2.8
3.15
3
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
idna@3.10
3.15
3
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
idna@2.8
3.15
3
kiwigrid/k8s-sidecar:1.30.2cdb361e67b1b
idna@3.10
3.15
3
quay.io/devtron/ai-agent:0.0.16545dac92173
idna@3.10
3.15
3
quay.io/kiwigrid/k8s-sidecar:1.14.235654389f8a9
idna@2.10
3.15
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
idna@2.5
python-idna@2.5-5.el8
3.15
0:2.5-8.el8_10
3
amancevice/superset:0.35.212a0a9e66550
idna@2.8
3.15
2
aquasec/kube-hunter:0.6.8e64fe49f059f
idna@3.3
3.15
2
blakeblackshear/frigate:0.11.18330b0a265b8
idna@3.4
3.15
2
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
idna@3.4
3.15
2
confluentinc/cp-zookeeper:latest7610a50b13e7
idna@3.10
3.15
2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
idna@3.4
3.15
2
cs3org/wopiserver:v9.4.202a9e78757b4
idna@3.4
3.15
2
datawire/aes:1.14.48588eafe6862
idna@2.7
3.15
2
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
idna@3.4
3.15
2
hjacobs/kube-ops-view:20.4.058221b57d4d2
idna@2.9
3.15
2
homebridge/homebridge:latest77c685a40911
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
2
istio/examples-bookinfo-productpage-v1:1.15.00a5eb4795952
idna@2.8
3.15
2
istio/examples-bookinfo-productpage-v1:1.14.022a0410f35a8
idna@2.8
3.15
2
kiwigrid/k8s-sidecar:1.24.44138bea678f0
idna@3.4
3.15
2
kiwigrid/k8s-sidecar:1.24.35af76eebbba7
idna@3.4
3.15
2
kiwigrid/k8s-sidecar:1.30.98c06e1ba643a
idna@3.10
3.15
2
langgenius/dify-sandbox:0.2.009b7e8705673
idna@3.7
3.15
2
larribas/mlflow:1.9.105ccb0b46bfb
idna@2.10
3.15
2
lncm/specter-desktop:v1.10.536eaa06f99f4
idna@2.10
3.15
2
locustio/locust:2.32.2a0d4b88e42c1
idna@3.10
3.15
2
louislam/uptime-kuma:2.5.4917318f9d7be
idna@3.3
python-idna@3.3-1+deb12u1
3.15
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
idna@3.3
python-idna@3.3-1+deb12u1
3.15
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
idna@3.3
python-idna@3.3-1+deb12u1
3.15
no fix listed
2
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
idna@3.3
3.15
2
neuvector/manager:3.2.1f1b7d666eae0
idna@2.8
3.15
2
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
idna@2.10
3.15
2
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
idna@2.8
3.15
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
idna@2.6
python-pip@8.1.1-2ubuntu0.4
3.15
no fix listed
2
opea/embedding-tei:1.05c9639de61c1
idna@3.10
3.15
2
opea/reranking-tei:1.0e48613afb191
idna@3.10
3.15
2
opea/retriever-redis:1.0eb746b263705
idna@3.10
3.15
2
opendatacube/ows:latest668cbb41473c
idna@3.10
3.15
2
sealife/fritzbox-exporter:1.0f5cc2f0f4c9b
idna@2.10
3.15
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
python-pip@20.0.2-5ubuntu1.6
no fix listed
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.