StackRadar

CVE-2026-48523

Medium

Advisory

Published 28 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.4
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
115
of 17,781 indexed, latest versions
Container images
117
deployed by those charts
Fix available
1 of 2
affected packages

PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys

Carried by container images the latest versions of 115 of 17,781 indexed charts deploy, on 117 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi2.9.0, 2.10.1, 2.11.0, 2.12.0+1 more2.13.091
pyjwtdeb1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+3 moreno fix listed28
OSV records
GHSA-jq35-7prp-9v3fUBUNTU-CVE-2026-48523
Also known as
PYSEC-2026-176

Charts affected

115 by stars
ChartLatestAffected imagesRadar Score
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
pyjwt@2.10.1
2.13.0

Open the chart page →

5,366
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.11 of 2See more

stackgres-operator stackgres-charts 1.19.1

1 of the 2 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
quay.io/stackgres/operator:1.19.1f241b0b20326
pyjwt@2.9.0
2.13.0

Open the chart page →

2,119
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
grafana/oncall:v1.16.5499851658393
pyjwt@2.10.1
2.13.0

Open the chart page →

16,251
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
pyjwt@2.10.1
2.13.0

Open the chart page →

11,384
openclawopenclawVerified publisher1.91.31 of 2See more

openclaw openclaw 1.91.3

1 of the 2 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
pyjwt@2.7.0-1ubuntu0.1
no fix listed

Open the chart page →

2,977
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
pyjwt@2.7.0-1ubuntu0.1
no fix listed

Open the chart page →

4,556
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
pyjwt@2.12.1
2.13.0

Open the chart page →

4,332
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
openmined/syft-backend:0.9.5b72f74a68b32
pyjwt@2.10.1
2.13.0

Open the chart page →

17,245
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
pyjwt@2.3.0-1ubuntu0.2
no fix listed

Open the chart page →

27,267
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
pyjwt@2.7.0-1ubuntu0.1
no fix listed

Open the chart page →

9,460
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
pyjwt@2.7.0-1
no fix listed
apache/hertzbeat-collector:1.8.0a2bab1be574c
pyjwt@2.7.0-1
no fix listed

Open the chart page →

14,000
alerta-webalerta-webVerified publisher0.1.121 of 2See more

alerta-web alerta-web 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
hayk96/alerta-web:9.0.486377705e9e3
pyjwt@2.10.1
2.13.0

Open the chart page →

3,569
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
pyjwt@2.10.1
2.13.0

Open the chart page →

4,634
mealieth-chartsVerified publisher0.5.11 of 1See more

mealie th-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
pyjwt@2.10.1
2.13.0

Open the chart page →

3,804
akeyless-api-gatewayakeyless-services-helmVerified publisher1.62.221 of 1See more

akeyless-api-gateway akeyless-services-helm 1.62.22

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
akeyless/base:latest759e4289fae8
pyjwt@2.12.0
2.13.0

Open the chart page →

2,358
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.01 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
pyjwt@2.10.1
2.13.0

Open the chart page →

12,037
anteonanteonVerified publisher2.6.41 of 13See more

anteon anteon 2.6.4

1 of the 13 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
pyjwt@2.9.0
2.13.0

Open the chart page →

22,202
tikaapache-tika3.2.21 of 1See more

tika apache-tika 3.2.2

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
apache/tika:3.2.2.0-fullffab324253ed
pyjwt@2.10.1
2.13.0

Open the chart page →

437
squestchristianhuthVerified publisher6.6.71 of 4See more

squest christianhuth 6.6.7

1 of the 4 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
pyjwt@2.10.1
2.13.0

Open the chart page →

9,971
syncstorage-rschristianhuthVerified publisher6.1.11 of 2See more

syncstorage-rs christianhuth 6.1.1

1 of the 2 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/porelli/firefox-sync:syncstorage-rs-mysql-0.18.27d244e514216
pyjwt@2.10.1
2.13.0

Open the chart page →

693
paperless-ngxcrystalnetVerified publisher0.2.221 of 3See more

paperless-ngx crystalnet 0.2.22

1 of the 3 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
pyjwt@2.9.0
2.13.0

Open the chart page →

13,761
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
pyjwt@2.3.0-1ubuntu0.2
no fix listed

Open the chart page →

10,858
taigafermosit0.0.111 of 7See more

taiga fermosit 0.0.11

1 of the 7 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
pyjwt@2.10.1
2.13.0

Open the chart page →

8,496
obicogabe565Verified publisher0.6.01 of 3See more

obico gabe565 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/gabe565/obico/web:latesta5c1daef46c0
pyjwt@2.10.1
2.13.0

Open the chart page →

1,965
IMgrycapOfficialVerified publisher1.8.01 of 3See more

IM grycap 1.8.0

1 of the 3 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/grycap/im:latest06a16d4f279f
pyjwt@2.10.1
2.13.0

Open the chart page →

4,132
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
pyjwt@2.9.0
2.13.0

Open the chart page →

4,292
medusamedusaVerified publisher1.3.81 of 1See more

medusa medusa 1.3.8

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
linuxserver/medusa:v1.0.26-ls2884477fb1ce3ca
pyjwt@2.10.1
2.13.0

Open the chart page →

977
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
gpappsoft/privacyidea-docker:3.12.2af7841adad26
pyjwt@2.10.1
2.13.0

Open the chart page →

5,440
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
pyjwt@2.7.0-1ubuntu0.1
no fix listed

Open the chart page →

23,964
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg16d7db8f1085a3
pyjwt@2.3.0-1ubuntu0.3
no fix listed

Open the chart page →

12,930
mealiertomik-helm-chartsVerified publisher0.0.21 of 1See more

mealie rtomik-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
pyjwt@2.10.1
2.13.0

Open the chart page →

3,929
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
pyjwt@2.10.1
2.13.0

Open the chart page →

2,928
taigaunxwaresVerified publisher2026.3.81 of 6See more

taiga unxwares 2026.3.8

1 of the 6 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
pyjwt@2.10.1
2.13.0

Open the chart page →

9,148
airbyteairbyte-v2Verified publisher2.2.01 of 10See more

airbyte airbyte-v2 2.2.0

1 of the 10 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
airbyte/manifest-server:7.23.73b3a670af168
pyjwt@2.10.1
2.13.0

Open the chart page →

12,473
browserlessalekcVerified publisher1.2.71 of 1See more

browserless alekc 1.2.7

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
pyjwt@2.7.0-1ubuntu0.1
no fix listed

Open the chart page →

2,078
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
pyjwt@2.11.0
2.13.0

Open the chart page →

5,558
pgadminappscodeVerified publisher2026.3.301 of 1See more

pgadmin appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.11.050700ac17936
pyjwt@2.10.1
2.13.0

Open the chart page →

1,565
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
pyjwt@2.3.0-1ubuntu0.2
no fix listed

Open the chart page →

32,501
backstage-pyactionsbackstage-pyactionsVerified publisher0.1.01 of 1See more

backstage-pyactions backstage-pyactions 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
mawad98/backstage-pyactions:demo99422c56a274
pyjwt@2.12.1
2.13.0

Open the chart page →

2,738
opencvecfi20170.1.21 of 7See more

opencve cfi2017 0.1.2

1 of the 7 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
pyjwt@2.10.1
2.13.0

Open the chart page →

15,371
kitchenowlchart-kitchenowl0.1.121 of 2See more

kitchenowl chart-kitchenowl 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
pyjwt@2.9.0
2.13.0

Open the chart page →

4,803
timetaggerchristianhuthVerified publisher2.2.01 of 1See more

timetagger christianhuth 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
pyjwt@2.11.0
2.13.0

Open the chart page →

1,958
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pyjwt@2.3.0-1ubuntu0.2
no fix listed

Open the chart page →

20,900
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pyjwt@2.12.1
2.13.0

Open the chart page →

4,601
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pyjwt@2.10.1
2.13.0

Open the chart page →

6,162
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
pyjwt@2.9.0
2.13.0

Open the chart page →

8,009
opencloudcommunity-opencloud3.0.01 of 11See more

opencloud community-opencloud 3.0.0

1 of the 11 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
apache/tika:latest-full80072bb73dd3
pyjwt@2.10.1-4ubuntu1
pyjwt@2.10.1
no fix listed
2.13.0

Open the chart page →

3,773
csghubcsghubVerified publisher2.4.33 of 34See more

csghub csghub 2.4.3

3 of the 34 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pyjwt@2.10.1
2.13.0
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pyjwt@2.10.1
2.13.0
opencsghq/label-studio:v2.4.0b4e849fcf94a
pyjwt@2.10.1
2.13.0

Open the chart page →

58,897
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
pyjwt@2.10.1
2.13.0

Open the chart page →

6,632
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
pyjwt@2.10.1
2.13.0

Open the chart page →

2,305

Container images carrying it

117 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apache/superset:6.1.0:latest16b50bbef664
pyjwt@2.10.1
2.13.0
3
apache/tika:2.9.2.1-fullae0b86d3c4d0
pyjwt@2.7.0-1
no fix listed
2
taigaio/taiga-back:latest4beed8f62c9f
pyjwt@2.10.1
2.13.0
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
pyjwt@2.7.0-1ubuntu0.1
no fix listed
2
airbyte/manifest-server:7.23.73b3a670af168
pyjwt@2.10.1
2.13.0
1
akeyless/base:latest759e4289fae8
pyjwt@2.12.0
2.13.0
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
pyjwt@2.7.0-1ubuntu0.1
no fix listed
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
pyjwt@2.9.0
2.13.0
1
apache/hertzbeat:1.8.075d48a62748f
pyjwt@2.7.0-1
no fix listed
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
pyjwt@2.7.0-1
no fix listed
1
apache/tika:latest-full80072bb73dd3
pyjwt@2.10.1-4ubuntu1
pyjwt@2.10.1
no fix listed
2.13.0
1
apache/tika:3.2.2.0-fullffab324253ed
pyjwt@2.10.1
2.13.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pyjwt@2.10.1
2.13.0
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pyjwt@2.10.1
2.13.0
1
bmeares/meerschaum:2.8.48e9c5bacaa82
pyjwt@2.10.1
2.13.0
1
boky/postfix:5.1.0aafc77238423
pyjwt@2.10.1
2.13.0
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
pyjwt@2.10.1
2.13.0
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
pyjwt@2.11.0
2.13.0
1
datamate/seafile-professional:11.0.202dd66b722464
pyjwt@2.3.0-1ubuntu0.2
no fix listed
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
pyjwt@2.9.0
2.13.0
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
pyjwt@2.10.1
2.13.0
1
dpage/pgadmin4:9.11.050700ac17936
pyjwt@2.10.1
2.13.0
1
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
2.13.0
1
dpage/pgadmin4:8.13561c1f8f99f2
pyjwt@2.9.0
2.13.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
pyjwt@1.7.1-2ubuntu2.1
pyjwt@2.9.0
no fix listed
2.13.0
1
flanksource/batch-runner:v1.0.44689687a7cf95
pyjwt@2.10.1
2.13.0
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pyjwt@2.10.1
2.13.0
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
pyjwt@2.10.1
2.13.0
1
grafana/oncall:v1.16.5499851658393
pyjwt@2.10.1
2.13.0
1
hayk96/alerta-web:9.0.486377705e9e3
pyjwt@2.10.1
2.13.0
1
heartexlabs/label-studio:latestaa461572e8f9
pyjwt@2.10.1
2.13.0
1
helmforge/fastmcp-server:0.2.061f759a1421f
pyjwt@2.12.1
2.13.0
1
helmforge/fastmcp-server:0.11.2fcb7017327d6
pyjwt@2.12.1
2.13.0
1
homeassistant/home-assistant:2026.75a531753cea9
pyjwt@2.12.1
2.13.0
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
pyjwt@2.12.1
2.13.0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
pyjwt@2.12.1
2.13.0
1
linuxserver/medusa:v1.0.26-ls2884477fb1ce3ca
pyjwt@2.10.1
2.13.0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pyjwt@2.12.0
2.13.0
1
mawad98/backstage-pyactions:demo99422c56a274
pyjwt@2.12.1
2.13.0
1
memgraph/mcp-memgraph:0.1.13ecdf7faea3f7
pyjwt@2.12.1
2.13.0
1
mindsdb/mindsdb:latest163011c09299
pyjwt@2.12.0
2.13.0
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
pyjwt@2.10.1
2.13.0
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
pyjwt@2.12.1
2.13.0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
pyjwt@2.12.1
2.13.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pyjwt@2.10.1
2.13.0
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pyjwt@2.10.1
2.13.0
1
opencsghq/label-studio:v2.5.047e22aa71870
pyjwt@2.10.1
2.13.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
pyjwt@2.10.1
2.13.0
1
openmined/syft-backend:0.9.5b72f74a68b32
pyjwt@2.10.1
2.13.0
1
qonstrukt/php:8.4-v8-apache089af7925aa1
pyjwt@2.7.0-1ubuntu0.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.