StackRadar

CVE-2026-48526

High

Advisory

Published 28 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
262
of 17,781 indexed, latest versions
Container images
255
deployed by those charts
Fix available
1 of 2
affected packages

PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed

Carried by container images the latest versions of 262 of 17,781 indexed charts deploy, on 255 images.

Affected packageAffected versionsFixed inImages
pyjwtpypi1.4.2, 1.5.3, 1.6.1, 1.6.4+16 more2.13.0254
pyjwtdeb1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+5 moreno fix listed37
OSV records
DEBIAN-CVE-2026-48526GHSA-xgmm-8j9v-c9wxUBUNTU-CVE-2026-48526
Also known as
PYSEC-2026-179

Charts affected

262 by stars
ChartLatestAffected imagesRadar Score
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.13.0

Open the chart page →

7,248
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
pyjwt@2.4.0
2.13.0

Open the chart page →

8,607
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0

Open the chart page →

45,239
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pyjwt@2.10.1
2.13.0

Open the chart page →

4,768
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0

Open the chart page →

4,305
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pyjwt@2.3.0-1ubuntu0.2
pyjwt@2.3.0
no fix listed
2.13.0

Open the chart page →

13,459
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
pyjwt@2.10.1
2.13.0

Open the chart page →

5,484
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pyjwt@2.4.0
2.13.0

Open the chart page →

7,085
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
2.13.0

Open the chart page →

9,117
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyjwt@1.6.1
2.13.0

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyjwt@1.6.1
2.13.0

Open the chart page →

11,784
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-48526.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
pyjwt@2.3.0-1ubuntu0.3
no fix listed

Open the chart page →

7,849

Container images carrying it

255 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.13.0
11
apache/superset:6.1.0:latest16b50bbef664
pyjwt@2.10.1
2.13.0
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
pyjwt@2.3.0
2.13.0
3
dpage/pgadmin4:6.12781369df9994
pyjwt@2.4.0
2.13.0
3
amancevice/superset:0.35.212a0a9e66550
pyjwt@1.7.1
2.13.0
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0
2
cs3org/wopiserver:v9.4.202a9e78757b4
pyjwt@2.6.0
2.13.0
2
larribas/mlflow:1.9.105ccb0b46bfb
pyjwt@1.7.1
2.13.0
2
louislam/uptime-kuma:2.5.4917318f9d7be
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
2.13.0
2
louislam/uptime-kuma:2.3.29aeb4e51d038
pyjwt@2.6.0-1
pyjwt@2.6.0
no fix listed
2.13.0
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
pyjwt@2.6.0-1+deb12u1
pyjwt@2.6.0
no fix listed
2.13.0
2
taigaio/taiga-back:latest4beed8f62c9f
pyjwt@2.10.1
2.13.0
2
weblate/weblate:4.2.2-169c160d37a3c
pyjwt@1.7.1
2.13.0
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.13.0
2
ghcr.io/games-on-whales/xorg:1.0.0305b3327ebba
pyjwt@1.7.1
2.13.0
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyjwt@1.6.1
2.13.0
2
airbyte/manifest-server:7.23.73b3a670af168
pyjwt@2.10.1
2.13.0
1
akeyless/base:latest759e4289fae8
pyjwt@2.12.0
2.13.0
1
akeyless/base-rhel:0.0.14ba8900a0061
pyjwt@2.6.0
2.13.0
1
alerta/alerta-web:8.5.04786b9eaa606
pyjwt@2.1.0
2.13.0
1
allegroai/clearml:2.0.0-613713ae38f7daf
pyjwt@2.8.0
2.13.0
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
pyjwt@2.0.1
2.13.0
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
pyjwt@2.4.0
2.13.0
1
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
pyjwt@2.4.0
2.13.0
1
amancevice/superset:0.28.1c8c04bfe3d66
pyjwt@1.7.1
2.13.0
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
pyjwt@1.7.1
2.13.0
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
pyjwt@2.7.0-1ubuntu0.1
pyjwt@2.7.0
no fix listed
2.13.0
1
apache/airflow:2.8.4-python3.964e58748b6b9
pyjwt@2.8.0
2.13.0
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
pyjwt@2.9.0
2.13.0
1
apache/airflow:2.8.1e5560ad0b86e
pyjwt@2.8.0
2.13.0
1
apache/hertzbeat:1.8.075d48a62748f
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
pyjwt@2.7.0-1
pyjwt@2.7.0
no fix listed
2.13.0
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
pyjwt@2.2.0
2.13.0
1
apache/superset:4.0.1ab9467fd712c
pyjwt@2.4.0
2.13.0
1
apache/tika:latest-full80072bb73dd3
pyjwt@2.10.1-4ubuntu1
pyjwt@2.10.1
no fix listed
2.13.0
1
apache/tika:3.2.2.0-fullffab324253ed
pyjwt@2.10.1
2.13.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pyjwt@2.10.1
2.13.0
1
aristidetm/k8s-hub:3.3.7ccb516cb8474
pyjwt@2.8.0
2.13.0
1
baserow/backend:1.31.1e0b3c8130b91
pyjwt@2.8.0
2.13.0
1
baserow/baserow:1.30.1df0c42eb67e8
pyjwt@2.8.0
2.13.0
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pyjwt@2.10.1
2.13.0
1
bmeares/meerschaum:2.8.48e9c5bacaa82
pyjwt@2.10.1
2.13.0
1
boky/postfix:5.1.0aafc77238423
pyjwt@2.10.1
2.13.0
1
buntha/mlflow:2.1.1154542cc3083
pyjwt@2.6.0
2.13.0
1
cdignam/kodiak:v0.54.05a6a55b39cee
pyjwt@1.7.1
2.13.0
1
ceph/daemon:latest-nautilus90f30824a96e
pyjwt@1.5.3
2.13.0
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
pyjwt@2.10.1
2.13.0
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
pyjwt@2.11.0
2.13.0
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
pyjwt@2.6.0
2.13.0
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
pyjwt@2.6.0
2.13.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.