StackRadar

CVE-2026-48522

Medium

Advisory

Published 28 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.2
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
262
of 17,781 indexed, latest versions
Container images
255
deployed by those charts
Fix available
1 of 2
affected packages

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

Carried by container images the latest versions of 262 of 17,781 indexed charts deploy, on 255 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi1.4.2, 1.5.3, 1.6.1, 1.6.4+16 more2.13.0254
pyjwtdeb1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+5 moreno fix listed37
OSV records
DEBIAN-CVE-2026-48522GHSA-993g-76c3-p5m4PYSEC-2026-175UBUNTU-CVE-2026-48522

Charts affected

262 by stars
ChartLatestAffected imagesRadar Score
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.13.0

Open the chart page →

7,248
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
pyjwt@2.4.0
2.13.0

Open the chart page →

8,607
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0

Open the chart page →

45,239
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
2.13.0

Open the chart page →

4,768
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0

Open the chart page →

4,305
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
no fix listed
2.13.0

Open the chart page →

13,459
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
pyjwt@2.10.1
2.13.0

Open the chart page →

5,484
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pyjwt@2.4.0
2.13.0

Open the chart page →

7,085
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
2.13.0

Open the chart page →

9,117
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyjwt@1.6.1
2.13.0

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyjwt@1.6.1
2.13.0

Open the chart page →

11,784
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pyjwt@2.3.0-1ubuntu0.3
no fix listed

Open the chart page →

7,849

Container images carrying it

255 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
pangeo/base-notebook:2024.01.155fbe688a4f80
pyjwt@2.8.0
2.13.0
1
qonstrukt/php:8.4-v8-apache089af7925aa1
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.13.0
1
redash/redash:25.8.000d813437db5
pyjwt@2.4.0
2.13.0
1
redash/redash:10.0.0.b503639392753c0376
pyjwt@1.7.1
2.13.0
1
redash/redash:26.3.0c5c9148f5c38
pyjwt@2.4.0
2.13.0
1
salehmir/jesse:1.10.101afa95f979e9
pyjwt@2.8.0
2.13.0
1
seafileltd/seafile-mc:9.0.106693911bcc40
pyjwt@2.1.0
2.13.0
1
seafileltd/seafile-mc:10.0.170628f29c663
pyjwt@2.6.0
2.13.0
1
seafileltd/seafile-mc:9.0.97ac833196f60
pyjwt@2.5.0
2.13.0
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.6.0
no fix listed
2.13.0
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
pyjwt@2.1.0
2.13.0
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
pyjwt@2.8.0
2.13.0
1
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
pyjwt@2.8.0
2.13.0
1
statcan/ckan:2.93921305425b8
pyjwt@1.7.1
2.13.0
1
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
pyjwt@2.6.0
2.13.0
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
pyjwt@2.6.0
2.13.0
1
taigaio/taiga-back:6.4.29f97323cc150
pyjwt@2.1.0
2.13.0
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
no fix listed
2.13.0
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
no fix listed
2.13.0
1
timescale/timescaledb-ha:pg16d7db8f1085a3
pyjwt@2.3.0-1ubuntu0.3
pyjwt@2.3.0
no fix listed
2.13.0
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
no fix listed
2.13.0
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
pyjwt@2.3.0-1
pyjwt@2.3.0
no fix listed
2.13.0
1
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
pyjwt@2.9.0
2.13.0
1
trueosiris/vrising:latest9356f98ad561
pyjwt@2.3.0-1ubuntu0.3
pyjwt@2.3.0
no fix listed
2.13.0
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
no fix listed
2.13.0
1
vabene1111/recipes:2.3.50f8d061895e9
pyjwt@2.10.1
2.13.0
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
pyjwt@2.3.0
2.13.0
1
wazuh/wazuh-manager:4.11.11da5c38c6a78
pyjwt@2.8.0
2.13.0
1
wazuh/wazuh-manager:4.14.45a065930682d
pyjwt@2.10.1
2.13.0
1
wazuh/wazuh-manager:4.14.3f09282d281f6
pyjwt@2.10.1
2.13.0
1
weblate/weblate:3.11.3-182848df56ecd
pyjwt@1.7.1
2.13.0
1
yetiplatform/yeti:2.9.09bcbe2650a14
pyjwt@2.10.1
2.13.0
1
yetiplatform/yeti:latest9c3006cedcca
pyjwt@2.10.1
2.13.0
1
zepai/knowledge-graph-mcp:v0.2.16ab0ee79926b
pyjwt@2.10.1
2.13.0
1
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pyjwt@2.3.0-1ubuntu0.3
no fix listed
1
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
pyjwt@2.10.1
2.13.0
1
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.13.0
1
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
pyjwt@2.11.0
2.13.0
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
pyjwt@2.9.0
2.13.0
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.13.0
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.13.0
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
pyjwt@2.10.1
2.13.0
1
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
pyjwt@2.6.0
2.13.0
1
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
pyjwt@2.10.1
2.13.0
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
pyjwt@2.8.0
2.13.0
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
pyjwt@2.4.0
2.13.0
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
pyjwt@2.4.0
2.13.0
1
ghcr.io/dodevops/azure-app-exporter/azure-app-exporter:0.1.38b472877847f5
pyjwt@2.8.0
2.13.0
1
ghcr.io/eslupmi/impulse:v3.7.03ded1b7ebca0
pyjwt@2.10.1
2.13.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.