StackRadar

CVE-2026-49264

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
549
of 17,957 indexed, latest versions
Container images
492
deployed by those charts
Fix available
1 of 1
affected package

Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation

Carried by container images the latest versions of 549 of 17,957 indexed charts deploy, on 492 images.

Affected packageAffected versionsFixed inImages
oauthlibpypi2.0.1, 2.0.7, 2.1.0, 3.0.1+7 more4.0.0492
OSV records
GHSA-hj66-6f7g-4r5v
Trending
Rank 28 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

549 by stars
ChartLatestAffected imagesRadar Score
uptime-kumafmjstudios0.2.21 of 1See more

uptime-kuma fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
oauthlib@2.1.0
4.0.0

Open the chart page →

4,465
uptime-kumafossa1.0.11 of 1See more

uptime-kuma fossa 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/k3rnel-pan1c/uptime-kuma:1.19.3f975fde9329b
oauthlib@3.1.0
4.0.0

Open the chart page →

5,413
frinx-machinefrinx-helm-charts11.0.01 of 26See more

frinx-machine frinx-helm-charts 11.0.0

1 of the 26 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.26.1b8d5067137fe
oauthlib@3.2.2
4.0.0

Open the chart page →

44,552
frinx-machine-monitoringfrinx-helm-charts0.1.21 of 8See more

frinx-machine-monitoring frinx-helm-charts 0.1.2

1 of the 8 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.26.1b8d5067137fe
oauthlib@3.2.2
4.0.0

Open the chart page →

10,752
borgmaticgabe565Verified publisher0.10.11 of 1See more

borgmatic gabe565 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
oauthlib@3.2.2
4.0.0

Open the chart page →

2,651
changedetection-iogabe565Verified publisher0.12.01 of 2See more

changedetection-io gabe565 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:latest096dae27b5d6
oauthlib@3.3.1
4.0.0

Open the chart page →

2,916
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
oauthlib@3.2.2
4.0.0

Open the chart page →

2,344
beetsgeek-cookbookVerified publisher1.4.21 of 1See more

beets geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
linuxserver/beets:1.5.0e36d16f7341c
oauthlib@3.1.1
4.0.0

Open the chart page →

1,212
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
oauthlib@3.1.1
4.0.0

Open the chart page →

16,770
changedetection-iogeek-cookbookVerified publisher1.5.21 of 1See more

changedetection-io geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
oauthlib@3.1.1
4.0.0

Open the chart page →

2,635
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
oauthlib@3.2.0
4.0.0

Open the chart page →

12,632
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
oauthlib@3.1.1
4.0.0

Open the chart page →

104,662
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
oauthlib@3.3.1
4.0.0

Open the chart page →

9,690
geomapfishgeomapfish0.8.01 of 3See more

geomapfish geomapfish 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
oauthlib@3.2.2
4.0.0

Open the chart page →

6,992
volume-autoscalergke-volume-autoscaler3.0.21 of 1See more

volume-autoscaler gke-volume-autoscaler 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
shadowrhyder/gke-volume-autoscaler:3.0.24aae9270356a
oauthlib@3.3.1
4.0.0

Open the chart page →

926
ldap-backupgluuVerified publisher1.6.111 of 1See more

ldap-backup gluu 1.6.11

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
gluufederation/opendj:4.3.0_011a1128b28b95
oauthlib@3.1.1
4.0.0

Open the chart page →

3,174
docker-registry-gcgmelilloVerified publisher0.1.91 of 1See more

docker-registry-gc gmelillo 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
gmelillo/registry:0.1.8c599d608a2f7
oauthlib@3.3.1
4.0.0

Open the chart page →

1,006
gnp-stackgnp-stack0.0.51 of 14See more

gnp-stack gnp-stack 0.0.5

1 of the 14 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.30.10835d79d8fbae
oauthlib@3.3.1
4.0.0

Open the chart page →

13,674
platformgoofy-chart0.1.01 of 1See more

platform goofy-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
devopsgoofy/k8s-platform:latestad865312099f
oauthlib@3.2.2
4.0.0

Open the chart page →

3,003
kube-prometheus-stackgpg-dev84.0.01 of 6See more

kube-prometheus-stack gpg-dev 84.0.0

1 of the 6 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.6.0a6c101156d42
oauthlib@3.3.1
4.0.0

Open the chart page →

4,432
grafana-dashboard-convertergrafana-dashboard-converterVerified publisher0.3.101 of 1See more

grafana-dashboard-converter grafana-dashboard-converter 0.3.10

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
kenchrcum/grafana-dashboard-converter:0.3.105310497aea3f
oauthlib@3.3.1
4.0.0

Open the chart page →

983
helixhelix1.4.31 of 2See more

helix helix 1.4.3

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
oauthlib@3.3.1
4.0.0

Open the chart page →

6,131
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
oauthlib@3.2.2
4.0.0

Open the chart page →

5,113
mlflowhelm-charts-nr1.0.101 of 1See more

mlflow helm-charts-nr 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
oauthlib@3.1.0
4.0.0

Open the chart page →

4,535
newrelic-controllerhelm-charts-nr1.2.01 of 1See more

newrelic-controller helm-charts-nr 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
maxrocketinternet/newrelic-controller:0.8ff66958597f0
oauthlib@3.1.0
4.0.0

Open the chart page →

919
postgres-controllerhelm-charts-nr1.4.01 of 1See more

postgres-controller helm-charts-nr 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
maxrocketinternet/postgres-controller:0.572ac4d33b99d
oauthlib@3.1.0
4.0.0

Open the chart page →

946
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
oauthlib@3.1.0
4.0.0

Open the chart page →

8,477
chiefonboardinghelmforgeVerified publisher1.1.151 of 3See more

chiefonboarding helmforge 1.1.15

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
oauthlib@3.3.1
4.0.0

Open the chart page →

8,083
hermes-agenthelmforgeVerified publisher1.0.11 of 1See more

hermes-agent helmforge 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.9.24fca358f12efd
oauthlib@3.3.1
4.0.0

Open the chart page →

6,076
jupyterhubhelmforgeVerified publisher1.0.61 of 3See more

jupyterhub helmforge 1.0.6

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
oauthlib@3.3.1
4.0.0

Open the chart page →

5,903
langflowhelmforgeVerified publisher2.0.21 of 1See more

langflow helmforge 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
langflowai/langflow:1.12.334055a07d446
oauthlib@3.3.1
4.0.0

Open the chart page →

244
medikeephelmforgeVerified publisher2.0.21 of 3See more

medikeep helmforge 2.0.2

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/afairgiant/medikeep:v0.71.0086579173033
oauthlib@3.3.1
4.0.0

Open the chart page →

5,407
netboxhelmforgeVerified publisher2.0.21 of 4See more

netbox helmforge 2.0.2

1 of the 4 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
oauthlib@3.3.1
4.0.0

Open the chart page →

4,094
olivetinhelmforgeVerified publisher1.2.21 of 2See more

olivetin helmforge 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
jamesread/olivetin:3000.20.0f3066e207efd
oauthlib@3.3.1
4.0.0

Open the chart page →

298
hetzner-s3-operatorhetzner-s3-operatorVerified publisher0.1.31 of 1See more

hetzner-s3-operator hetzner-s3-operator 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
kenchrcum/hetzner-s3-operator:0.1.384dae7aeea5b
oauthlib@3.3.1
4.0.0

Open the chart page →

689
changedetectionhomeenterpriseinc0.2.01 of 2See more

changedetection homeenterpriseinc 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.44534b9bc5c46e
oauthlib@3.2.2
4.0.0

Open the chart page →

1,974
homeassistanthomeenterpriseinc0.3.01 of 1See more

homeassistant homeenterpriseinc 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2022.3.5565751f33794
oauthlib@3.2.0
4.0.0

Open the chart page →

7,947
paperlesshpVerified publisher0.1.21 of 5See more

paperless hp 0.1.2

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
oauthlib@3.3.1
4.0.0

Open the chart page →

29,775
browserlessicoretechVerified publisher0.16.61 of 1See more

browserless icoretech 0.16.6

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
oauthlib@3.2.2
4.0.0

Open the chart page →

2,479
monitoring-stackict-platformVerified publisher0.4.01 of 13See more

monitoring-stack ict-platform 0.4.0

1 of the 13 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
oauthlib@3.3.1
4.0.0

Open the chart page →

9,937
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:1.2.0e4770285aaf7
oauthlib@3.1.1
4.0.0

Open the chart page →

117,870
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
oauthlib@3.3.1
4.0.0

Open the chart page →

2,502
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
oauthlib@3.1.1
4.0.0

Open the chart page →

7,041
healthchecksimprowisedVerified publisher1.1.11 of 2See more

healthchecks improwised 1.1.1

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
linuxserver/healthchecks:2.7.2023033194696dab3c50
oauthlib@3.2.2
4.0.0

Open the chart page →

2,653
pgadmininseefrlab3.2.01 of 1See more

pgadmin inseefrlab 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
dpage/pgadmin4:latestc332c5f6dfba
oauthlib@3.3.1
4.0.0

Open the chart page →

17
redashinseefrlab2.1.01 of 3See more

redash inseefrlab 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
redash/redash:10.0.0.b503639392753c0376
oauthlib@2.1.0
4.0.0

Open the chart page →

3,644
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
oauthlib@3.3.1
4.0.0

Open the chart page →

19,668
inventreeinventreeOfficialVerified publisher0.4.301 of 2See more

inventree inventree 0.4.30

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
inventree/inventree:1.5.6b61e6a7534bf
oauthlib@3.3.1
4.0.0

Open the chart page →

5,613
kubernetes-pythonjacobcolvinVerified publisher0.1.11 of 1See more

kubernetes-python jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/macropower/kubernetes-python:1.0a887b5cae4af
oauthlib@3.3.1
4.0.0

Open the chart page →

74
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
oauthlib@3.2.2
4.0.0

Open the chart page →

46,735

Container images carrying it

492 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bbilly1/tubearchivist:v0.5.9b827a713f55b
oauthlib@3.3.1
4.0.0
1
beanbag/reviewboard:latest6b840f546e1c
oauthlib@3.3.1
4.0.0
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
oauthlib@3.3.1
4.0.0
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
oauthlib@3.3.1
4.0.0
1
blackducksoftware/bdba-frontend:2026.9.10afa8763ccb8
oauthlib@3.3.1
4.0.0
1
buntha/mlflow:2.1.1154542cc3083
oauthlib@3.2.2
4.0.0
1
byjg/easy-haproxy:6.1.1230fdb7b00ae
oauthlib@3.3.1
4.0.0
1
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
oauthlib@3.2.2
4.0.0
1
caronc/apprise:latestcc5ef662ad2a
oauthlib@3.3.1
4.0.0
1
castai/hibernate:v0.14da62858c8381
oauthlib@3.3.1
4.0.0
1
cccs/assemblyline-core:4.7.4.stable2125fdf4aa72ab
oauthlib@3.3.1
4.0.0
1
cccs/assemblyline-socketio:4.7.4.stable21ba390e87f340
oauthlib@3.3.1
4.0.0
1
cccs/assemblyline-ui:4.7.4.stable210623c3fd039e
oauthlib@3.3.1
4.0.0
1
ceph/daemon:latest-nautilus90f30824a96e
oauthlib@2.0.1
4.0.0
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
oauthlib@3.3.1
4.0.0
1
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
oauthlib@3.3.1
4.0.0
1
codecov/self-hosted-api:24.4.10475cb1c3136
oauthlib@3.1.0
4.0.0
1
codecov/self-hosted-worker:24.4.1837f546b479b
oauthlib@3.1.0
4.0.0
1
crocodilestick/calibre-web-automated:v4.0.6c31a738b6d5e
oauthlib@3.3.1
4.0.0
1
dagster/dagster-celery-k8s:1.13.2494e5e5dd6da0
oauthlib@3.3.1
4.0.0
1
dagster/dagster-cloud-agent:1.13.24e29285673c2c
oauthlib@3.3.1
4.0.0
1
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
oauthlib@3.3.1
4.0.0
1
datadog/agent:7.22.08f20e56b5311
oauthlib@3.1.0
4.0.0
1
datadog/agent:6aad9994de6a7
oauthlib@3.1.0
4.0.0
1
datagrok/grok_spawner:latest8c2d48c1545c
oauthlib@3.3.1
4.0.0
1
datamate/seafile-professional:11.0.202dd66b722464
oauthlib@3.3.1
4.0.0
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
oauthlib@3.1.0
4.0.0
1
datawire/aes:1.13.62beb65062c8b
oauthlib@3.1.0
4.0.0
1
datawire/emissary:2.0.2-ea9716efbdd24b
oauthlib@3.1.0
4.0.0
1
devopsgoofy/k8s-platform:latestad865312099f
oauthlib@3.2.2
4.0.0
1
devopstales/kubedash:3.1.08bb837da5aec
oauthlib@3.2.2
4.0.0
1
devopstales/kube-openid-connector:1.042c40a0e9f1b
oauthlib@3.2.0
4.0.0
1
devopstales/trivy-operator:2.575136aa7a26e
oauthlib@3.2.2
4.0.0
1
djjudas21/autonodelabel:0.0.6f17233350c4f
oauthlib@3.2.2
4.0.0
1
dockerid31415926/pod-pvc-mapping:v0.1.3354309669f16
oauthlib@3.1.1
4.0.0
1
dockerid31415926/pvc-exporter:v0.1.35a1dd17e0e07
oauthlib@3.1.1
4.0.0
1
dpage/pgadmin4:8.418cd5711fc9a
oauthlib@3.2.2
4.0.0
1
dpage/pgadmin4:7.537946e4f3e7b
oauthlib@3.2.2
4.0.0
1
dpage/pgadmin4:9.11.050700ac17936
oauthlib@3.3.1
4.0.0
1
dpage/pgadmin4:9.252cb72a9e3da
oauthlib@3.2.2
4.0.0
1
dpage/pgadmin4:8.13561c1f8f99f2
oauthlib@3.2.2
4.0.0
1
dserio83/velero-api:0.3.16b3d9115fee2
oauthlib@3.2.2
4.0.0
1
dserio83/velero-watchdog:0.1.8d5deae589229
oauthlib@3.2.2
4.0.0
1
eclipseaerios/aerios-k8s-shim:v1.0.0d4ed3d8e5db4
oauthlib@3.2.2
4.0.0
1
elautoestopista/raponchi:0.3.0b6f74db9fc81
oauthlib@3.2.2
4.0.0
1
elyra/kernel-image-puller:3.2.2c922f1f1646a
oauthlib@3.2.2
4.0.0
1
evgkrsk/postgres-controller:0.6.237f0e1f435c3
oauthlib@3.2.2
4.0.0
1
evk02/mlflow:2.2.1ef6ff257ef35
oauthlib@3.2.2
4.0.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
oauthlib@3.1.0
4.0.0
1
flag5/clustersecret:0.0.94ad5748bfcc6
oauthlib@3.1.1
4.0.0
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.