StackRadar

CVE-2026-48522

Medium

Advisory

Published 28 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.2
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
262
of 17,781 indexed, latest versions
Container images
255
deployed by those charts
Fix available
1 of 2
affected packages

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

Carried by container images the latest versions of 262 of 17,781 indexed charts deploy, on 255 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi1.4.2, 1.5.3, 1.6.1, 1.6.4+16 more2.13.0254
pyjwtdeb1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+5 moreno fix listed37
OSV records
DEBIAN-CVE-2026-48522GHSA-993g-76c3-p5m4PYSEC-2026-175UBUNTU-CVE-2026-48522

Charts affected

262 by stars
ChartLatestAffected imagesRadar Score
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.13.0

Open the chart page →

7,248
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
pyjwt@2.4.0
2.13.0

Open the chart page →

8,607
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0

Open the chart page →

45,239
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
2.13.0

Open the chart page →

4,768
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0

Open the chart page →

4,305
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
no fix listed
2.13.0

Open the chart page →

13,459
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
pyjwt@2.10.1
2.13.0

Open the chart page →

5,484
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pyjwt@2.4.0
2.13.0

Open the chart page →

7,085
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
2.13.0

Open the chart page →

9,117
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyjwt@1.6.1
2.13.0

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyjwt@1.6.1
2.13.0

Open the chart page →

11,784
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-48522.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pyjwt@2.3.0-1ubuntu0.3
no fix listed

Open the chart page →

7,849

Container images carrying it

255 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/gabe565/obico/web:latesta5c1daef46c0
pyjwt@2.10.1
2.13.0
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
pyjwt@2.11.0
2.13.0
1
ghcr.io/grycap/im:latest06a16d4f279f
pyjwt@2.10.1
2.13.0
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
pyjwt@2.10.1
2.13.0
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
pyjwt@2.10.1
2.13.0
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
pyjwt@2.3.0
2.13.0
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
pyjwt@2.8.0
2.13.0
1
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
pyjwt@2.10.1
2.13.0
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
pyjwt@2.10.1
2.13.0
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
pyjwt@2.11.0
2.13.0
1
ghcr.io/iisas/domino-rest:latest3009350bfc11
pyjwt@2.10.1
2.13.0
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pyjwt@2.6.0
2.13.0
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
pyjwt@2.10.1
2.13.0
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
pyjwt@2.10.1
2.13.0
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
pyjwt@2.8.0
2.13.0
1
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
pyjwt@2.7.0
2.13.0
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
pyjwt@2.12.1
2.13.0
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
pyjwt@2.10.1
2.13.0
1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.13.0
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.13.0
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.13.0
1
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.13.0
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
pyjwt@2.9.0
2.13.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
pyjwt@2.9.0
2.13.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
pyjwt@2.10.1
2.13.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
pyjwt@2.10.1
2.13.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
pyjwt@2.10.1
2.13.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
pyjwt@2.10.1
2.13.0
1
ghcr.io/porelli/firefox-sync:syncstorage-rs-mysql-0.18.27d244e514216
pyjwt@2.10.1
2.13.0
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
pyjwt@2.11.0
2.13.0
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
pyjwt@2.10.1
2.13.0
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
pyjwt@2.9.0
2.13.0
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
pyjwt@2.10.1
2.13.0
1
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
pyjwt@2.12.1
2.13.0
1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
pyjwt@2.4.0
2.13.0
1
ghcr.io/vinny1892/octantis:latest45459c0910fc
pyjwt@2.12.1
2.13.0
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
pyjwt@2.8.0
2.13.0
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
pyjwt@2.10.1
2.13.0
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
pyjwt@2.9.0
2.13.0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
pyjwt@2.4.0
2.13.0
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pyjwt@2.12.1
2.13.0
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
pyjwt@2.10.1
2.13.0
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
pyjwt@2.3.0
2.13.0
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
pyjwt@2.12.1
2.13.0
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
pyjwt@2.8.0
2.13.0
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
pyjwt@2.12.1
2.13.0
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
pyjwt@2.4.0
2.13.0
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
pyjwt@2.10.1
2.13.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.