StackRadar

CVE-2026-48526

High

Advisory

Published 28 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
262
of 17,781 indexed, latest versions
Container images
255
deployed by those charts
Fix available
1 of 2
affected packages

PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed

Carried by container images the latest versions of 262 of 17,781 indexed charts deploy, on 255 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi1.4.2, 1.5.3, 1.6.1, 1.6.4+16 more2.13.0254
pyjwtdeb1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+5 moreno fix listed37
OSV records
DEBIAN-CVE-2026-48526GHSA-xgmm-8j9v-c9wxUBUNTU-CVE-2026-48526
Also known as
PYSEC-2026-179

Charts affected

262 by stars
ChartLatestAffected imagesRadar Score
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.13.0

Open the chart page →

7,248
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
pyjwt@2.4.0
2.13.0

Open the chart page →

8,607
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0

Open the chart page →

45,239
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
2.13.0

Open the chart page →

4,768
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0

Open the chart page →

4,305
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
no fix listed
2.13.0

Open the chart page →

13,459
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
pyjwt@2.10.1
2.13.0

Open the chart page →

5,484
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pyjwt@2.4.0
2.13.0

Open the chart page →

7,085
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
2.13.0

Open the chart page →

9,117
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyjwt@1.6.1
2.13.0

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyjwt@1.6.1
2.13.0

Open the chart page →

11,784
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pyjwt@2.3.0-1ubuntu0.3
no fix listed

Open the chart page →

7,849

Container images carrying it

255 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
pyjwt@2.6.0
2.13.0
1
codecov/self-hosted-api:24.4.10475cb1c3136
pyjwt@2.8.0
2.13.0
1
codecov/self-hosted-worker:24.4.1837f546b479b
pyjwt@2.4.0
2.13.0
1
datadog/agent:7.22.08f20e56b5311
pyjwt@1.7.1
2.13.0
1
datadog/agent:6aad9994de6a7
pyjwt@1.7.1
2.13.0
1
datamate/seafile-professional:11.0.202dd66b722464
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.6.0
no fix listed
2.13.0
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
pyjwt@2.8.0
2.13.0
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
pyjwt@2.9.0
2.13.0
1
ddosify/selfhosted_backend:3.2.93c11e3182652
pyjwt@2.8.0
2.13.0
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
pyjwt@2.8.0
2.13.0
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
pyjwt@2.10.1
2.13.0
1
dpage/pgadmin4:8.418cd5711fc9a
pyjwt@2.8.0
2.13.0
1
dpage/pgadmin4:7.537946e4f3e7b
pyjwt@2.7.0
2.13.0
1
dpage/pgadmin4:9.11.050700ac17936
pyjwt@2.10.1
2.13.0
1
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
2.13.0
1
dpage/pgadmin4:8.13561c1f8f99f2
pyjwt@2.9.0
2.13.0
1
evk02/mlflow:2.2.1ef6ff257ef35
pyjwt@2.6.0
2.13.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
pyjwt@1.7.1-2ubuntu2.1
pyjwt@2.9.0
no fix listed
2.13.0
1
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
pyjwt@2.4.0
2.13.0
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
pyjwt@1.7.1
2.13.0
1
flanksource/batch-runner:v1.0.44689687a7cf95
pyjwt@2.10.1
2.13.0
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
pyjwt@1.7.1
2.13.0
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
pyjwt@1.7.1
2.13.0
1
galaxy/cloudman-server:lateste5c265fe9fcd
pyjwt@2.4.0
2.13.0
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pyjwt@2.10.1
2.13.0
1
gethue/hue:4.11.011b649636e68
pyjwt@2.4.0
2.13.0
1
gethue/hue:4.10.05702b2c37ff9
pyjwt@1.7.1
2.13.0
1
gethue/hue:latest7d5c1b9f8a79
pyjwt@2.4.0
2.13.0
1
getsentry/sentry-kubernetes:latest6ac37974fd2a
pyjwt@1.7.1
2.13.0
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
pyjwt@2.10.1
2.13.0
1
grafana/oncall:v1.16.5499851658393
pyjwt@2.10.1
2.13.0
1
hayk96/alerta-web:9.0.486377705e9e3
pyjwt@2.10.1
2.13.0
1
heartexlabs/label-studio:latestaa461572e8f9
pyjwt@2.10.1
2.13.0
1
helmforge/fastmcp-server:0.2.061f759a1421f
pyjwt@2.12.1
2.13.0
1
helmforge/fastmcp-server:0.11.2fcb7017327d6
pyjwt@2.12.1
2.13.0
1
hhyo/archery:v1.9.11aa41843419e
pyjwt@2.5.0
2.13.0
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
pyjwt@2.8.0
2.13.0
1
homeassistant/home-assistant:2026.75a531753cea9
pyjwt@2.12.1
2.13.0
1
homeassistant/home-assistant:2023.12.48d000332b09b
pyjwt@2.8.0
2.13.0
1
i4trust/activation-service:2.2.09f3719176893
pyjwt@2.7.0
2.13.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
pyjwt@1.7.1
2.13.0
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
pyjwt@2.12.1
2.13.0
1
jertel/elastalert2:2.2.34dcc0ef93efc
pyjwt@1.7.1
2.13.0
1
jmferrer/azure-devops-agent:latest030f68ec6998
pyjwt@1.7.1
2.13.0
1
john19968010/fastapi-template:latest31a90f6bd69c
pyjwt@2.6.0
2.13.0
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
2.13.0
1
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
pyjwt@2.8.0
2.13.0
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
pyjwt@1.7.1
2.13.0
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
pyjwt@1.7.1
2.13.0
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
pyjwt@1.7.1
2.13.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.