StackRadar

CVE-2026-48525

Medium

Advisory

Published 28 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
153
of 17,781 indexed, latest versions
Container images
157
deployed by those charts
Fix available
1 of 2
affected packages

PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS

Carried by container images the latest versions of 153 of 17,781 indexed charts deploy, on 157 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi2.8.0, 2.9.0, 2.10.1, 2.11.0+2 more2.13.0122
pyjwtdeb1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+5 moreno fix listed37
OSV records
DEBIAN-CVE-2026-48525GHSA-w7vc-732c-9m39UBUNTU-CVE-2026-48525
Also known as
PYSEC-2026-178

Charts affected

153 by stars
ChartLatestAffected imagesRadar Score
airbyteairbyte-v2Verified publisher2.2.01 of 10See more

airbyte airbyte-v2 2.2.0

1 of the 10 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
airbyte/manifest-server:7.23.73b3a670af168
pyjwt@2.10.1
2.13.0

Open the chart page →

12,473
browserlessalekcVerified publisher1.2.71 of 1See more

browserless alekc 1.2.7

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
pyjwt@2.7.0-1ubuntu0.1
no fix listed

Open the chart page →

2,078
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
pyjwt@2.11.0
2.13.0

Open the chart page →

5,558
ddosifyanteonVerified publisher1.7.52 of 13See more

ddosify anteon 1.7.5

2 of the 13 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
pyjwt@2.8.0
2.13.0
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
pyjwt@2.8.0
2.13.0

Open the chart page →

25,669
pgadminappscodeVerified publisher2026.3.301 of 1See more

pgadmin appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.11.050700ac17936
pyjwt@2.10.1
2.13.0

Open the chart page →

1,565
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
pyjwt@2.3.0-1ubuntu0.2
no fix listed

Open the chart page →

32,501
azure-app-exporterazure-app-exporterVerified publisher0.4.21 of 2See more

azure-app-exporter azure-app-exporter 0.4.2

1 of the 2 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
ghcr.io/dodevops/azure-app-exporter/azure-app-exporter:0.1.38b472877847f5
pyjwt@2.8.0
2.13.0

Open the chart page →

1,790
backstage-pyactionsbackstage-pyactionsVerified publisher0.1.01 of 1See more

backstage-pyactions backstage-pyactions 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
mawad98/backstage-pyactions:demo99422c56a274
pyjwt@2.12.1
2.13.0

Open the chart page →

2,738
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
pyjwt@2.8.0
2.13.0

Open the chart page →

10,145
opencvecfi20170.1.21 of 7See more

opencve cfi2017 0.1.2

1 of the 7 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
pyjwt@2.10.1
2.13.0

Open the chart page →

15,371
kitchenowlchart-kitchenowl0.1.121 of 2See more

kitchenowl chart-kitchenowl 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
pyjwt@2.9.0
2.13.0

Open the chart page →

4,803
timetaggerchristianhuthVerified publisher2.2.01 of 1See more

timetagger christianhuth 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
pyjwt@2.11.0
2.13.0

Open the chart page →

1,958
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pyjwt@2.3.0-1ubuntu0.2
no fix listed

Open the chart page →

20,900
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pyjwt@2.12.1
2.13.0

Open the chart page →

4,601
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pyjwt@2.10.1
2.13.0

Open the chart page →

6,162
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
pyjwt@2.9.0
2.13.0

Open the chart page →

8,009
opencloudcommunity-opencloud3.0.01 of 11See more

opencloud community-opencloud 3.0.0

1 of the 11 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
apache/tika:latest-full80072bb73dd3
pyjwt@2.10.1-4ubuntu1
pyjwt@2.10.1
no fix listed
2.13.0

Open the chart page →

3,773
csghubcsghubVerified publisher2.4.33 of 34See more

csghub csghub 2.4.3

3 of the 34 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pyjwt@2.10.1
2.13.0
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pyjwt@2.10.1
2.13.0
opencsghq/label-studio:v2.4.0b4e849fcf94a
pyjwt@2.10.1
2.13.0

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pyjwt@2.8.0
2.13.0

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
pyjwt@2.10.1
2.13.0

Open the chart page →

6,632
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
aristidetm/k8s-hub:3.3.7ccb516cb8474
pyjwt@2.8.0
2.13.0

Open the chart page →

16,604
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
pyjwt@2.8.0
2.13.0

Open the chart page →

6,179
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
pyjwt@2.10.1
2.13.0

Open the chart page →

2,305
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
pyjwt@2.10.1
2.13.0

Open the chart page →

11,160
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
pyjwt@2.8.0
2.13.0

Open the chart page →

19,224
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
pyjwt@2.8.0
2.13.0

Open the chart page →

14,627
dominodomino-iisasVerified publisher0.3.11 of 3See more

domino domino-iisas 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
ghcr.io/iisas/domino-rest:latest3009350bfc11
pyjwt@2.10.1
2.13.0

Open the chart page →

10,270
codecovdoubanVerified publisher0.2.42 of 8See more

codecov douban 0.2.4

2 of the 8 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
codecov/self-hosted-api:24.4.10475cb1c3136
pyjwt@2.8.0
2.13.0
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
pyjwt@2.3.0-1ubuntu0.2
no fix listed

Open the chart page →

24,917
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
pyjwt@2.3.0-1
no fix listed

Open the chart page →

30,699
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
pyjwt@2.6.0-1+deb12u1
no fix listed

Open the chart page →

30,159
datadog-apmfairwinds-incubator2.0.01 of 1See more

datadog-apm fairwinds-incubator 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
pyjwt@2.10.1
2.13.0

Open the chart page →

2,785
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.418cd5711fc9a
pyjwt@2.8.0
2.13.0

Open the chart page →

12,454
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
pyjwt@1.7.1-2ubuntu2.1
pyjwt@2.9.0
no fix listed
2.13.0

Open the chart page →

64,489
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
pyjwt@2.10.1
2.13.0

Open the chart page →

5,292
fluxcd-helm-upgraderfluxcd-helm-upgraderVerified publisher0.7.71 of 1See more

fluxcd-helm-upgrader fluxcd-helm-upgrader 0.7.7

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
pyjwt@2.12.1
2.13.0

Open the chart page →

2,420
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
pyjwt@2.10.1
2.13.0

Open the chart page →

2,183
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pyjwt@2.10.1
2.13.0

Open the chart page →

8,923
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
pyjwt@2.9.0
2.13.0

Open the chart page →

49,025
helixhelix1.4.31 of 2See more

helix helix 1.4.3

1 of the 2 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
pyjwt@2.12.1
2.13.0

Open the chart page →

5,568
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
pyjwt@2.10.1
2.13.0

Open the chart page →

4,647
supersethelm-charts-nr1.1.31 of 1See more

superset helm-charts-nr 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
pyjwt@2.10.1
2.13.0

Open the chart page →

2,305
chiefonboardinghelmforgeVerified publisher1.1.141 of 3See more

chiefonboarding helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
pyjwt@2.11.0
2.13.0

Open the chart page →

10,849
fastmcp-serverhelmforgeVerified publisher1.7.41 of 1See more

fastmcp-server helmforge 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.11.2fcb7017327d6
pyjwt@2.12.1
2.13.0

Open the chart page →

3,281
jupyterhubhelmforgeVerified publisher1.0.61 of 3See more

jupyterhub helmforge 1.0.6

1 of the 3 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
pyjwt@2.12.1
2.13.0

Open the chart page →

5,341
mcp-serverhelmforgeVerified publisher1.0.01 of 1See more

mcp-server helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.2.061f759a1421f
pyjwt@2.12.1
2.13.0

Open the chart page →

3,430
netboxhelmforgeVerified publisher2.0.11 of 4See more

netbox helmforge 2.0.1

1 of the 4 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
pyjwt@2.12.1
2.13.0

Open the chart page →

4,243
supersethelmforgeVerified publisher1.3.61 of 5See more

superset helmforge 1.3.6

1 of the 5 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
apache/superset:6.1.016b50bbef664
pyjwt@2.10.1
2.13.0

Open the chart page →

5,714
uptime-kumahelmforgeVerified publisher1.5.121 of 1See more

uptime-kuma helmforge 1.5.12

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.33e24e96c89ef
pyjwt@2.6.0-1+deb12u1
no fix listed

Open the chart page →

30,099
browserlessicoretechVerified publisher0.16.61 of 1See more

browserless icoretech 0.16.6

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
pyjwt@2.7.0-1ubuntu0.1
no fix listed

Open the chart page →

1,948
impulseimpulse1.0.161 of 1See more

impulse impulse 1.0.16

1 of the 1 container images this version deploys carry CVE-2026-48525.

Container imageDigestPackageFixed in
ghcr.io/eslupmi/impulse:v3.7.03ded1b7ebca0
pyjwt@2.10.1
2.13.0

Open the chart page →

1,348

Container images carrying it

157 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
pyjwt@2.12.1
2.13.0
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
pyjwt@2.8.0
2.13.0
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
pyjwt@2.12.1
2.13.0
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
pyjwt@2.10.1
2.13.0
1
quay.io/stackgres/operator:1.19.1f241b0b20326
pyjwt@2.9.0
2.13.0
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
pyjwt@2.8.0
2.13.0
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
pyjwt@2.10.1
2.13.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.