StackRadar

CVE-2026-48522

Medium

Advisory

Published 28 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.2
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
262
of 17,781 indexed, latest versions
Container images
255
deployed by those charts
Fix available
1 of 2
affected packages

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

Carried by container images the latest versions of 262 of 17,781 indexed charts deploy, on 255 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi1.4.2, 1.5.3, 1.6.1, 1.6.4+16 more2.13.0254
pyjwtdeb1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+5 moreno fix listed37
OSV records
DEBIAN-CVE-2026-48522GHSA-993g-76c3-p5m4PYSEC-2026-175UBUNTU-CVE-2026-48522

Charts affected

262 by stars
ChartLatestAffected imagesRadar Score
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.13.0

Open the chart page →

7,248
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
pyjwt@2.4.0
2.13.0

Open the chart page →

8,607
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0

Open the chart page →

45,239
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
2.13.0

Open the chart page →

4,768
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0

Open the chart page →

4,305
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
no fix listed
2.13.0

Open the chart page →

13,459
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
pyjwt@2.10.1
2.13.0

Open the chart page →

5,484
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pyjwt@2.4.0
2.13.0

Open the chart page →

7,085
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
2.13.0

Open the chart page →

9,117
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyjwt@1.6.1
2.13.0

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyjwt@1.6.1
2.13.0

Open the chart page →

11,784
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pyjwt@2.3.0-1ubuntu0.3
no fix listed

Open the chart page →

7,849

Container images carrying it

255 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kelvinsp/mlflow:1.26.1cd33e6db2a59
pyjwt@2.4.0
2.13.0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
pyjwt@2.12.1
2.13.0
1
kiwigrid/k8s-sidecar:0.0.186eb52513d59e
pyjwt@1.7.1
2.13.0
1
kiwigrid/k8s-sidecar:0.0.16899ccd0b1f54
pyjwt@1.7.1
2.13.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
pyjwt@2.3.0
2.13.0
1
langgenius/dify-api:1.0.0066035f93856
pyjwt@2.8.0
2.13.0
1
langgenius/dify-api:0.6.11fca918260dd6
pyjwt@2.8.0
2.13.0
1
linuxserver/medusa:v1.0.26-ls2884477fb1ce3ca
pyjwt@2.10.1
2.13.0
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
pyjwt@1.7.1
2.13.0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pyjwt@2.12.0
2.13.0
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
pyjwt@2.6.0-1
pyjwt@2.6.0
no fix listed
2.13.0
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
pyjwt@1.7.0
2.13.0
1
louislam/uptime-kuma:13d632903e6af
pyjwt@1.7.0
2.13.0
1
louislam/uptime-kuma:2.5.33e24e96c89ef
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
2.13.0
1
louislam/uptime-kuma:2.0.24c364ef96aad
pyjwt@2.6.0-1
pyjwt@2.6.0
no fix listed
2.13.0
1
louislam/uptime-kuma:2.4.091e963bfda56
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
2.13.0
1
louislam/uptime-kuma:1.23.1396510915e6be
pyjwt@1.7.0
2.13.0
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
pyjwt@2.6.0-1
pyjwt@2.6.0
no fix listed
2.13.0
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
pyjwt@1.7.0
2.13.0
1
louislam/uptime-kuma:1.18.5a84767d7934f
pyjwt@1.7.0
2.13.0
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
pyjwt@1.7.0
2.13.0
1
lsstsqre/prepuller:latest19c2dfc4e4ff
pyjwt@2.1.0
2.13.0
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
pyjwt@2.0.1
2.13.0
1
lsstsqre/squash-api:0.5.34879415ec6ac
pyjwt@1.4.2
2.13.0
1
lsstsqre/wfdispatcher:lateste9feb99f524d
pyjwt@2.0.1
2.13.0
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
pyjwt@2.3.0
2.13.0
1
mawad98/backstage-pyactions:demo99422c56a274
pyjwt@2.12.1
2.13.0
1
memgraph/mcp-memgraph:0.1.13ecdf7faea3f7
pyjwt@2.12.1
2.13.0
1
milesmcc/shynet:v0.13.1ba54f7797a6b
pyjwt@2.4.0
2.13.0
1
milesmcc/shynet:v0.12.0e821e31140f7
pyjwt@2.3.0
2.13.0
1
mindsdb/mindsdb:latest163011c09299
pyjwt@2.12.0
2.13.0
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
pyjwt@2.10.1
2.13.0
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
pyjwt@2.6.0
2.13.0
1
mozilla/syncserver:latest016162bf39d8
pyjwt@1.7.1
2.13.0
1
mozilla/syncstorage-rs:0.15.893752877dced
pyjwt@2.8.0
2.13.0
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
pyjwt@1.7.1
2.13.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
pyjwt@2.4.0
2.13.0
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
pyjwt@2.12.1
2.13.0
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
pyjwt@2.8.0
2.13.0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
pyjwt@2.12.1
2.13.0
1
nlmacamp/check_mk:latest5dbb8589f824
pyjwt@1.6.4
2.13.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pyjwt@2.10.1
2.13.0
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pyjwt@2.10.1
2.13.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pyjwt@2.8.0
2.13.0
1
opencsghq/label-studio:v2.5.047e22aa71870
pyjwt@2.10.1
2.13.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
pyjwt@2.10.1
2.13.0
1
openmined/syft-backend:0.9.5b72f74a68b32
pyjwt@2.10.1
2.13.0
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
pyjwt@2.0.1
2.13.0
1
openzaak/open-notificaties:1.3.02e65313b9b10
pyjwt@2.3.0
2.13.0
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
pyjwt@2.3.0
2.13.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.