CVE-2026-4786
HighAdvisory
Published 13 Apr 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.1
- base score, highest
- EPSS
- 0.003
- 21st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 432
- of 17,787 indexed, latest versions
- Container images
- 409
- deployed by those charts
- Fix available
- 10 of 17
- affected packages
Red Hat Security Advisory: python security update
Carried by container images the latest versions of 432 of 17,787 indexed charts deploy, on 409 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| python3.8deb | 3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more | no fix listed | 100 |
| python3.10deb | 3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more | 3.10.12-1~22.04.16 | 71 |
| python2.7deb | 2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 more | no fix listed | 54 |
| python3.12deb | 3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+8 more | 3.12.3-1ubuntu0.15 | 48 |
| python3.6deb | 3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more | no fix listed | 44 |
| python3.5deb | 3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9 | no fix listed | 25 |
| pythonrpm | 2.7.5-77.el7_6, 2.7.5-86.el7, 2.7.5-89.el7, 2.7.5-90.el7+1 more | 0:2.7.5-94.el7_9.5 | 12 |
| python3.4deb | 3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7 | no fix listed | 7 |
| python3.11deb | 3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1 | no fix listed | 2 |
| python3.14deb | 3.14.4-1 | 3.14.4-1ubuntu0.1 | 2 |
| python3.13deb | 3.13.7-1ubuntu0.1 | no fix listed | 1 |
| python3apk | 3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+4 more | 3.12.14-r0 | 63 |
| python-3.14apk | 3.14.2-r2, 3.14.4-r2 | 3.14.4-r3 | 5 |
| pythonbitnami | 3.11.11-0, 3.12.8-0, 3.13.5-1 | 3.10.21 | 3 |
| python-3.13apk | 3.13.7-r0, 3.13.10-r0, 3.13.12-r2 | 3.13.13-r2 | 3 |
| python-3.12apk | 3.12.0-r1, 3.12.9-r1 | 3.12.14-r2 | 2 |
| python3rpm | 3.12.9-13.azl3 | 3.12.9-14 | 1 |
- OSV records
- ALPINE-CVE-2026-4786BIT-python-2026-4786CGA-53c8-jf7x-64gmCGA-5cv4-jxr8-9chvCGA-7vp4-6c8x-mjv8RHSA-2026:19589UBUNTU-CVE-2026-4786AZL-83054
- Also known as
- BIT-libpython-2026-4786, BIT-python-min-2026-4786, CGA-6pqf-5rmg-x54j, CGA-97m2-fx86-4q55, CGA-xqw6-5r86-7mxx, PSF-0000-CVE-2026-4786, PSF-2026-17, USN-8509-1
Charts affected
432 by stars
Container images carrying it
409 by charts deploying them
A fixed version is listed for 10 of the 17 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 3c56f354fac5 | python3 | 3.12.14-r0 | 1 |
| quay.io/ | a2d3a4c67b0f | python3.6 | no fix listed | 1 |
| quay.io/ | 3408107e5cc4 | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| quay.io/ | 97b7f49eec76 | python-3.14 | 3.14.4-r3 | 1 |
| quay.io/ | 8a4150e94a45 | python-3.14 | 3.14.4-r3 | 1 |
| quay.io/ | f5c4c8adfc82 | python-3.14 | 3.14.4-r3 | 1 |
| quay.io/ | b5054bd4e97a | python-3.14 | 3.14.4-r3 | 1 |
| registry.gitlab.com/ | f6385712935f | python3.8 | no fix listed | 1 |
| registry.gitlab.com/ | 7eea4f0883dd | python3 | 3.12.14-r0 | 1 |