StackRadar

CVE-2026-48523

Medium

Advisory

Published 28 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.4
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
115
of 17,781 indexed, latest versions
Container images
117
deployed by those charts
Fix available
1 of 2
affected packages

PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys

Carried by container images the latest versions of 115 of 17,781 indexed charts deploy, on 117 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi2.9.0, 2.10.1, 2.11.0, 2.12.0+1 more2.13.091
pyjwtdeb1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+3 moreno fix listed28
OSV records
GHSA-jq35-7prp-9v3fUBUNTU-CVE-2026-48523
Also known as
PYSEC-2026-176

Charts affected

115 by stars
ChartLatestAffected imagesRadar Score
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
pyjwt@2.10.1
2.13.0

Open the chart page →

11,160
dominodomino-iisasVerified publisher0.3.11 of 3See more

domino domino-iisas 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/iisas/domino-rest:latest3009350bfc11
pyjwt@2.10.1
2.13.0

Open the chart page →

10,270
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
pyjwt@2.3.0-1ubuntu0.2
no fix listed

Open the chart page →

24,917
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
pyjwt@2.3.0-1
no fix listed

Open the chart page →

30,699
datadog-apmfairwinds-incubator2.0.01 of 1See more

datadog-apm fairwinds-incubator 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
pyjwt@2.10.1
2.13.0

Open the chart page →

2,785
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
pyjwt@1.7.1-2ubuntu2.1
pyjwt@2.9.0
no fix listed
2.13.0

Open the chart page →

64,489
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
pyjwt@2.10.1
2.13.0

Open the chart page →

5,292
fluxcd-helm-upgraderfluxcd-helm-upgraderVerified publisher0.7.71 of 1See more

fluxcd-helm-upgrader fluxcd-helm-upgrader 0.7.7

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
pyjwt@2.12.1
2.13.0

Open the chart page →

2,420
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
pyjwt@2.10.1
2.13.0

Open the chart page →

2,183
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pyjwt@2.10.1
2.13.0

Open the chart page →

8,923
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
pyjwt@2.9.0
2.13.0

Open the chart page →

49,025
helixhelix1.4.31 of 2See more

helix helix 1.4.3

1 of the 2 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
pyjwt@2.12.1
2.13.0

Open the chart page →

5,568
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
pyjwt@2.10.1
2.13.0

Open the chart page →

4,647
supersethelm-charts-nr1.1.31 of 1See more

superset helm-charts-nr 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
pyjwt@2.10.1
2.13.0

Open the chart page →

2,305
chiefonboardinghelmforgeVerified publisher1.1.141 of 3See more

chiefonboarding helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
pyjwt@2.11.0
2.13.0

Open the chart page →

10,849
fastmcp-serverhelmforgeVerified publisher1.7.41 of 1See more

fastmcp-server helmforge 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.11.2fcb7017327d6
pyjwt@2.12.1
2.13.0

Open the chart page →

3,281
jupyterhubhelmforgeVerified publisher1.0.61 of 3See more

jupyterhub helmforge 1.0.6

1 of the 3 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
pyjwt@2.12.1
2.13.0

Open the chart page →

5,341
mcp-serverhelmforgeVerified publisher1.0.01 of 1See more

mcp-server helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.2.061f759a1421f
pyjwt@2.12.1
2.13.0

Open the chart page →

3,430
netboxhelmforgeVerified publisher2.0.11 of 4See more

netbox helmforge 2.0.1

1 of the 4 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
pyjwt@2.12.1
2.13.0

Open the chart page →

4,243
supersethelmforgeVerified publisher1.3.61 of 5See more

superset helmforge 1.3.6

1 of the 5 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
apache/superset:6.1.016b50bbef664
pyjwt@2.10.1
2.13.0

Open the chart page →

5,714
browserlessicoretechVerified publisher0.16.61 of 1See more

browserless icoretech 0.16.6

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
pyjwt@2.7.0-1ubuntu0.1
no fix listed

Open the chart page →

1,948
impulseimpulse1.0.161 of 1See more

impulse impulse 1.0.16

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/eslupmi/impulse:v3.7.03ded1b7ebca0
pyjwt@2.10.1
2.13.0

Open the chart page →

1,348
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
pyjwt@2.10.1
2.13.0

Open the chart page →

3,157
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
pyjwt@2.12.1
2.13.0

Open the chart page →

17,852
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
pyjwt@2.7.0-1
no fix listed

Open the chart page →

45,239
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
pyjwt@2.7.0-1
no fix listed

Open the chart page →

6,586
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
pyjwt@2.7.0-1
no fix listed

Open the chart page →

6,568
beetsk8s-home-lab-repo3.1.11 of 1See more

beets k8s-home-lab-repo 3.1.1

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
pyjwt@2.10.1
2.13.0

Open the chart page →

2,733
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
pyjwt@2.10.1
2.13.0

Open the chart page →

9,103
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
pyjwt@2.11.0
2.13.0

Open the chart page →

4,568
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
pyjwt@2.12.1
2.13.0

Open the chart page →

7,081
graphiti-mcpkiberonlabs0.1.21 of 1See more

graphiti-mcp kiberonlabs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
zepai/knowledge-graph-mcp:v0.2.16ab0ee79926b
pyjwt@2.10.1
2.13.0

Open the chart page →

3,393
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
pyjwt@2.12.0
2.13.0

Open the chart page →

9,620
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pyjwt@2.10.1
2.13.0

Open the chart page →

8,405
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
pyjwt@2.12.1
2.13.0

Open the chart page →

2,444
meerschaummeerschaumVerified publisher0.2.01 of 1See more

meerschaum meerschaum 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
bmeares/meerschaum:2.8.48e9c5bacaa82
pyjwt@2.10.1
2.13.0

Open the chart page →

5,823
memgraph-mcpmemgraphVerified publisher1.0.01 of 1See more

memgraph-mcp memgraph 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
memgraph/mcp-memgraph:0.1.13ecdf7faea3f7
pyjwt@2.12.1
2.13.0

Open the chart page →

1,672
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
pyjwt@2.10.1
2.13.0

Open the chart page →

43,341
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
pyjwt@2.10.1
2.13.0

Open the chart page →

11,950
octantisoctantis0.1.01 of 1See more

octantis octantis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/vinny1892/octantis:latest45459c0910fc
pyjwt@2.12.1
2.13.0

Open the chart page →

2,555
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
pyjwt@2.10.1
2.13.0

Open the chart page →

10,978
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.05 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

5 of the 40 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
yetiplatform/yeti:2.9.09bcbe2650a14
pyjwt@2.10.1
2.13.0
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
pyjwt@2.7.0-1ubuntu0.1
no fix listed
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
pyjwt@2.7.0-1ubuntu0.1
no fix listed
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
pyjwt@2.7.0-1ubuntu0.1
no fix listed
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
pyjwt@2.7.0-1ubuntu0.1
no fix listed

Open the chart page →

71,208
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
pyjwt@2.10.1
2.13.0

Open the chart page →

6,583
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
pyjwt@2.10.1
2.13.0

Open the chart page →

4,749
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
pyjwt@2.10.1
2.13.0

Open the chart page →

3,854
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
pyjwt@2.9.0
2.13.0

Open the chart page →

21,211
imgtagrotationalVerified publisher0.2.01 of 1See more

imgtag rotational 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
pyjwt@2.10.1
2.13.0

Open the chart page →

3,312
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
pyjwt@2.10.1
2.13.0

Open the chart page →

7,436
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
pyjwt@2.10.1
2.13.0

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
pyjwt@2.10.1
2.13.0

Open the chart page →

4,499

Container images carrying it

117 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
pyjwt@2.10.1
2.13.0
1
ghcr.io/porelli/firefox-sync:syncstorage-rs-mysql-0.18.27d244e514216
pyjwt@2.10.1
2.13.0
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
pyjwt@2.11.0
2.13.0
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
pyjwt@2.10.1
2.13.0
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
pyjwt@2.9.0
2.13.0
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
pyjwt@2.10.1
2.13.0
1
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
pyjwt@2.12.1
2.13.0
1
ghcr.io/vinny1892/octantis:latest45459c0910fc
pyjwt@2.12.1
2.13.0
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
pyjwt@2.10.1
2.13.0
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
pyjwt@2.9.0
2.13.0
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pyjwt@2.12.1
2.13.0
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
pyjwt@2.10.1
2.13.0
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
pyjwt@2.12.1
2.13.0
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
pyjwt@2.12.1
2.13.0
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
pyjwt@2.10.1
2.13.0
1
quay.io/stackgres/operator:1.19.1f241b0b20326
pyjwt@2.9.0
2.13.0
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
pyjwt@2.10.1
2.13.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.