StackRadar

CVE-2026-48523

Medium

Advisory

Published 28 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.4
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
115
of 17,781 indexed, latest versions
Container images
117
deployed by those charts
Fix available
1 of 2
affected packages

PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys

Carried by container images the latest versions of 115 of 17,781 indexed charts deploy, on 117 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi2.9.0, 2.10.1, 2.11.0, 2.12.0+1 more2.13.091
pyjwtdeb1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+3 moreno fix listed28
OSV records
GHSA-jq35-7prp-9v3fUBUNTU-CVE-2026-48523
Also known as
PYSEC-2026-176

Charts affected

115 by stars
ChartLatestAffected imagesRadar Score
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
pyjwt@2.3.0-1ubuntu0.3
no fix listed

Open the chart page →

7,295
pgadminsb-helm-charts0.3.01 of 1See more

pgadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.13561c1f8f99f2
pyjwt@2.9.0
2.13.0

Open the chart page →

1,713
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pyjwt@2.12.0
2.13.0

Open the chart page →

5,201
smtpsmtpVerified publisher1.3.31 of 1See more

smtp smtp 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
pyjwt@2.10.1
2.13.0

Open the chart page →

1,437
srebotsrebot0.14.01 of 2See more

srebot srebot 0.14.0

1 of the 2 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
pyjwt@2.11.0
2.13.0

Open the chart page →

1,542
artifactory-cleanupsubshellVerified publisher1.0.11 of 1See more

artifactory-cleanup subshell 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
devopshq/artifactory-cleanup:1.0.1830e093bffa91
pyjwt@2.10.1
2.13.0

Open the chart page →

2,534
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
pyjwt@2.9.0
2.13.0

Open the chart page →

4,731
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
pyjwt@2.12.1
2.13.0

Open the chart page →

1,556
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
pyjwt@2.7.0-1ubuntu0.1
no fix listed

Open the chart page →

7,248
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
pyjwt@2.7.0-1
no fix listed

Open the chart page →

45,239
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
2.13.0

Open the chart page →

4,768
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pyjwt@2.7.0-1
no fix listed

Open the chart page →

4,305
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pyjwt@2.3.0-1ubuntu0.2
no fix listed

Open the chart page →

13,459
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
pyjwt@2.10.1
2.13.0

Open the chart page →

5,484
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-48523.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pyjwt@2.3.0-1ubuntu0.3
no fix listed

Open the chart page →

7,849

Container images carrying it

117 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apache/superset:6.1.0:latest16b50bbef664
pyjwt@2.10.1
2.13.0
3
apache/tika:2.9.2.1-fullae0b86d3c4d0
pyjwt@2.7.0-1
no fix listed
2
taigaio/taiga-back:latest4beed8f62c9f
pyjwt@2.10.1
2.13.0
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
pyjwt@2.7.0-1ubuntu0.1
no fix listed
2
airbyte/manifest-server:7.23.73b3a670af168
pyjwt@2.10.1
2.13.0
1
akeyless/base:latest759e4289fae8
pyjwt@2.12.0
2.13.0
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
pyjwt@2.7.0-1ubuntu0.1
no fix listed
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
pyjwt@2.9.0
2.13.0
1
apache/hertzbeat:1.8.075d48a62748f
pyjwt@2.7.0-1
no fix listed
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
pyjwt@2.7.0-1
no fix listed
1
apache/tika:latest-full80072bb73dd3
pyjwt@2.10.1-4ubuntu1
pyjwt@2.10.1
no fix listed
2.13.0
1
apache/tika:3.2.2.0-fullffab324253ed
pyjwt@2.10.1
2.13.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pyjwt@2.10.1
2.13.0
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pyjwt@2.10.1
2.13.0
1
bmeares/meerschaum:2.8.48e9c5bacaa82
pyjwt@2.10.1
2.13.0
1
boky/postfix:5.1.0aafc77238423
pyjwt@2.10.1
2.13.0
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
pyjwt@2.10.1
2.13.0
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
pyjwt@2.11.0
2.13.0
1
datamate/seafile-professional:11.0.202dd66b722464
pyjwt@2.3.0-1ubuntu0.2
no fix listed
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
pyjwt@2.9.0
2.13.0
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
pyjwt@2.10.1
2.13.0
1
dpage/pgadmin4:9.11.050700ac17936
pyjwt@2.10.1
2.13.0
1
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
2.13.0
1
dpage/pgadmin4:8.13561c1f8f99f2
pyjwt@2.9.0
2.13.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
pyjwt@1.7.1-2ubuntu2.1
pyjwt@2.9.0
no fix listed
2.13.0
1
flanksource/batch-runner:v1.0.44689687a7cf95
pyjwt@2.10.1
2.13.0
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pyjwt@2.10.1
2.13.0
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
pyjwt@2.10.1
2.13.0
1
grafana/oncall:v1.16.5499851658393
pyjwt@2.10.1
2.13.0
1
hayk96/alerta-web:9.0.486377705e9e3
pyjwt@2.10.1
2.13.0
1
heartexlabs/label-studio:latestaa461572e8f9
pyjwt@2.10.1
2.13.0
1
helmforge/fastmcp-server:0.2.061f759a1421f
pyjwt@2.12.1
2.13.0
1
helmforge/fastmcp-server:0.11.2fcb7017327d6
pyjwt@2.12.1
2.13.0
1
homeassistant/home-assistant:2026.75a531753cea9
pyjwt@2.12.1
2.13.0
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
pyjwt@2.12.1
2.13.0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
pyjwt@2.12.1
2.13.0
1
linuxserver/medusa:v1.0.26-ls2884477fb1ce3ca
pyjwt@2.10.1
2.13.0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pyjwt@2.12.0
2.13.0
1
mawad98/backstage-pyactions:demo99422c56a274
pyjwt@2.12.1
2.13.0
1
memgraph/mcp-memgraph:0.1.13ecdf7faea3f7
pyjwt@2.12.1
2.13.0
1
mindsdb/mindsdb:latest163011c09299
pyjwt@2.12.0
2.13.0
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
pyjwt@2.10.1
2.13.0
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
pyjwt@2.12.1
2.13.0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
pyjwt@2.12.1
2.13.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pyjwt@2.10.1
2.13.0
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pyjwt@2.10.1
2.13.0
1
opencsghq/label-studio:v2.5.047e22aa71870
pyjwt@2.10.1
2.13.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
pyjwt@2.10.1
2.13.0
1
openmined/syft-backend:0.9.5b72f74a68b32
pyjwt@2.10.1
2.13.0
1
qonstrukt/php:8.4-v8-apache089af7925aa1
pyjwt@2.7.0-1ubuntu0.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.