StackRadar

CVE-2026-49264

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
549
of 17,957 indexed, latest versions
Container images
492
deployed by those charts
Fix available
1 of 1
affected package

Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation

Carried by container images the latest versions of 549 of 17,957 indexed charts deploy, on 492 images.

Affected packageAffected versionsFixed inImages
oauthlibpypi2.0.1, 2.0.7, 2.1.0, 3.0.1+7 more4.0.0492
OSV records
GHSA-hj66-6f7g-4r5v
Trending
Rank 28 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

549 by stars
ChartLatestAffected imagesRadar Score
uptime-kumafmjstudios0.2.21 of 1See more

uptime-kuma fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
oauthlib@2.1.0
4.0.0

Open the chart page →

4,465
uptime-kumafossa1.0.11 of 1See more

uptime-kuma fossa 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/k3rnel-pan1c/uptime-kuma:1.19.3f975fde9329b
oauthlib@3.1.0
4.0.0

Open the chart page →

5,413
frinx-machinefrinx-helm-charts11.0.01 of 26See more

frinx-machine frinx-helm-charts 11.0.0

1 of the 26 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.26.1b8d5067137fe
oauthlib@3.2.2
4.0.0

Open the chart page →

44,552
frinx-machine-monitoringfrinx-helm-charts0.1.21 of 8See more

frinx-machine-monitoring frinx-helm-charts 0.1.2

1 of the 8 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.26.1b8d5067137fe
oauthlib@3.2.2
4.0.0

Open the chart page →

10,752
borgmaticgabe565Verified publisher0.10.11 of 1See more

borgmatic gabe565 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
oauthlib@3.2.2
4.0.0

Open the chart page →

2,651
changedetection-iogabe565Verified publisher0.12.01 of 2See more

changedetection-io gabe565 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:latest096dae27b5d6
oauthlib@3.3.1
4.0.0

Open the chart page →

2,916
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
oauthlib@3.2.2
4.0.0

Open the chart page →

2,344
beetsgeek-cookbookVerified publisher1.4.21 of 1See more

beets geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
linuxserver/beets:1.5.0e36d16f7341c
oauthlib@3.1.1
4.0.0

Open the chart page →

1,212
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
oauthlib@3.1.1
4.0.0

Open the chart page →

16,770
changedetection-iogeek-cookbookVerified publisher1.5.21 of 1See more

changedetection-io geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
oauthlib@3.1.1
4.0.0

Open the chart page →

2,635
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
oauthlib@3.2.0
4.0.0

Open the chart page →

12,632
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
oauthlib@3.1.1
4.0.0

Open the chart page →

104,662
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
oauthlib@3.3.1
4.0.0

Open the chart page →

9,690
geomapfishgeomapfish0.8.01 of 3See more

geomapfish geomapfish 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
oauthlib@3.2.2
4.0.0

Open the chart page →

6,992
volume-autoscalergke-volume-autoscaler3.0.21 of 1See more

volume-autoscaler gke-volume-autoscaler 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
shadowrhyder/gke-volume-autoscaler:3.0.24aae9270356a
oauthlib@3.3.1
4.0.0

Open the chart page →

926
ldap-backupgluuVerified publisher1.6.111 of 1See more

ldap-backup gluu 1.6.11

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
gluufederation/opendj:4.3.0_011a1128b28b95
oauthlib@3.1.1
4.0.0

Open the chart page →

3,174
docker-registry-gcgmelilloVerified publisher0.1.91 of 1See more

docker-registry-gc gmelillo 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
gmelillo/registry:0.1.8c599d608a2f7
oauthlib@3.3.1
4.0.0

Open the chart page →

1,006
gnp-stackgnp-stack0.0.51 of 14See more

gnp-stack gnp-stack 0.0.5

1 of the 14 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.30.10835d79d8fbae
oauthlib@3.3.1
4.0.0

Open the chart page →

13,674
platformgoofy-chart0.1.01 of 1See more

platform goofy-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
devopsgoofy/k8s-platform:latestad865312099f
oauthlib@3.2.2
4.0.0

Open the chart page →

3,003
kube-prometheus-stackgpg-dev84.0.01 of 6See more

kube-prometheus-stack gpg-dev 84.0.0

1 of the 6 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.6.0a6c101156d42
oauthlib@3.3.1
4.0.0

Open the chart page →

4,432
grafana-dashboard-convertergrafana-dashboard-converterVerified publisher0.3.101 of 1See more

grafana-dashboard-converter grafana-dashboard-converter 0.3.10

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
kenchrcum/grafana-dashboard-converter:0.3.105310497aea3f
oauthlib@3.3.1
4.0.0

Open the chart page →

983
helixhelix1.4.31 of 2See more

helix helix 1.4.3

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
oauthlib@3.3.1
4.0.0

Open the chart page →

6,131
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
oauthlib@3.2.2
4.0.0

Open the chart page →

5,113
mlflowhelm-charts-nr1.0.101 of 1See more

mlflow helm-charts-nr 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
oauthlib@3.1.0
4.0.0

Open the chart page →

4,535
newrelic-controllerhelm-charts-nr1.2.01 of 1See more

newrelic-controller helm-charts-nr 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
maxrocketinternet/newrelic-controller:0.8ff66958597f0
oauthlib@3.1.0
4.0.0

Open the chart page →

919
postgres-controllerhelm-charts-nr1.4.01 of 1See more

postgres-controller helm-charts-nr 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
maxrocketinternet/postgres-controller:0.572ac4d33b99d
oauthlib@3.1.0
4.0.0

Open the chart page →

946
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
oauthlib@3.1.0
4.0.0

Open the chart page →

8,477
chiefonboardinghelmforgeVerified publisher1.1.151 of 3See more

chiefonboarding helmforge 1.1.15

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
oauthlib@3.3.1
4.0.0

Open the chart page →

8,083
hermes-agenthelmforgeVerified publisher1.0.11 of 1See more

hermes-agent helmforge 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.9.24fca358f12efd
oauthlib@3.3.1
4.0.0

Open the chart page →

6,076
jupyterhubhelmforgeVerified publisher1.0.61 of 3See more

jupyterhub helmforge 1.0.6

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
oauthlib@3.3.1
4.0.0

Open the chart page →

5,903
langflowhelmforgeVerified publisher2.0.21 of 1See more

langflow helmforge 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
langflowai/langflow:1.12.334055a07d446
oauthlib@3.3.1
4.0.0

Open the chart page →

244
medikeephelmforgeVerified publisher2.0.21 of 3See more

medikeep helmforge 2.0.2

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/afairgiant/medikeep:v0.71.0086579173033
oauthlib@3.3.1
4.0.0

Open the chart page →

5,407
netboxhelmforgeVerified publisher2.0.21 of 4See more

netbox helmforge 2.0.2

1 of the 4 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
oauthlib@3.3.1
4.0.0

Open the chart page →

4,094
olivetinhelmforgeVerified publisher1.2.21 of 2See more

olivetin helmforge 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
jamesread/olivetin:3000.20.0f3066e207efd
oauthlib@3.3.1
4.0.0

Open the chart page →

298
hetzner-s3-operatorhetzner-s3-operatorVerified publisher0.1.31 of 1See more

hetzner-s3-operator hetzner-s3-operator 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
kenchrcum/hetzner-s3-operator:0.1.384dae7aeea5b
oauthlib@3.3.1
4.0.0

Open the chart page →

689
changedetectionhomeenterpriseinc0.2.01 of 2See more

changedetection homeenterpriseinc 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.44534b9bc5c46e
oauthlib@3.2.2
4.0.0

Open the chart page →

1,974
homeassistanthomeenterpriseinc0.3.01 of 1See more

homeassistant homeenterpriseinc 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2022.3.5565751f33794
oauthlib@3.2.0
4.0.0

Open the chart page →

7,947
paperlesshpVerified publisher0.1.21 of 5See more

paperless hp 0.1.2

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
oauthlib@3.3.1
4.0.0

Open the chart page →

29,775
browserlessicoretechVerified publisher0.16.61 of 1See more

browserless icoretech 0.16.6

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
oauthlib@3.2.2
4.0.0

Open the chart page →

2,479
monitoring-stackict-platformVerified publisher0.4.01 of 13See more

monitoring-stack ict-platform 0.4.0

1 of the 13 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
oauthlib@3.3.1
4.0.0

Open the chart page →

9,937
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:1.2.0e4770285aaf7
oauthlib@3.1.1
4.0.0

Open the chart page →

117,870
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
oauthlib@3.3.1
4.0.0

Open the chart page →

2,502
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
oauthlib@3.1.1
4.0.0

Open the chart page →

7,041
healthchecksimprowisedVerified publisher1.1.11 of 2See more

healthchecks improwised 1.1.1

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
linuxserver/healthchecks:2.7.2023033194696dab3c50
oauthlib@3.2.2
4.0.0

Open the chart page →

2,653
pgadmininseefrlab3.2.01 of 1See more

pgadmin inseefrlab 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
dpage/pgadmin4:latestc332c5f6dfba
oauthlib@3.3.1
4.0.0

Open the chart page →

17
redashinseefrlab2.1.01 of 3See more

redash inseefrlab 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
redash/redash:10.0.0.b503639392753c0376
oauthlib@2.1.0
4.0.0

Open the chart page →

3,644
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
oauthlib@3.3.1
4.0.0

Open the chart page →

19,668
inventreeinventreeOfficialVerified publisher0.4.301 of 2See more

inventree inventree 0.4.30

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
inventree/inventree:1.5.6b61e6a7534bf
oauthlib@3.3.1
4.0.0

Open the chart page →

5,613
kubernetes-pythonjacobcolvinVerified publisher0.1.11 of 1See more

kubernetes-python jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/macropower/kubernetes-python:1.0a887b5cae4af
oauthlib@3.3.1
4.0.0

Open the chart page →

74
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
oauthlib@3.2.2
4.0.0

Open the chart page →

46,735

Container images carrying it

492 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
maponyacharles/sceptreai:api-0.1.127b37b092130a
oauthlib@3.3.1
4.0.0
1
mathesar/mathesar:0.12.0091757cb01fe
oauthlib@3.3.1
4.0.0
1
microslac/auth:latest5c1eb1f5c64d
oauthlib@3.2.2
4.0.0
1
milesmcc/shynet:v0.13.1ba54f7797a6b
oauthlib@3.2.1
4.0.0
1
milesmcc/shynet:v0.12.0e821e31140f7
oauthlib@3.1.1
4.0.0
1
mindsdb/mindsdb:latest163011c09299
oauthlib@3.3.1
4.0.0
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
oauthlib@3.2.2
4.0.0
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
oauthlib@3.2.2
4.0.0
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
oauthlib@3.1.0
4.0.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
oauthlib@3.2.0
4.0.0
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
oauthlib@3.3.1
4.0.0
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
oauthlib@3.2.2
4.0.0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
oauthlib@3.3.1
4.0.0
1
nlmacamp/check_mk:latest5dbb8589f824
oauthlib@2.1.0
4.0.0
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
oauthlib@3.3.1
4.0.0
1
onyxdotapp/onyx-backend:latest60e83a098ae4
oauthlib@3.2.2
4.0.0
1
opea/chatqna:1.038c51b791efa
oauthlib@3.2.2
4.0.0
1
opea/codegen:1.058f91683892d
oauthlib@3.2.2
4.0.0
1
opea/codetrans:1.0e2436483b73d
oauthlib@3.2.2
4.0.0
1
opea/docsum:1.03eaa91849512
oauthlib@3.2.2
4.0.0
1
opea/web-retriever-chroma:1.0fe08165d7770
oauthlib@3.2.2
4.0.0
1
opencsghq/agenticflow:ee-v0.6.5-241cba9c366f1
oauthlib@3.3.1
4.0.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
oauthlib@3.2.2
4.0.0
1
openebs/rawfile-localpv:v0.15.396fd7987ea79
oauthlib@3.3.1
4.0.0
1
opennode/waldur-mastermind:8.1.24c82b15d9042
oauthlib@3.3.1
4.0.0
1
opennode/waldur-site-agent:1.0.76d2e3b97c8d2
oauthlib@3.3.1
4.0.0
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
oauthlib@3.1.0
4.0.0
1
opsmxdev/ubi8-autopilot:v2.9.10-202006181240c7e4ea797f11
oauthlib@3.1.0
4.0.0
1
pangeo/base-notebook:2024.01.155fbe688a4f80
oauthlib@3.2.2
4.0.0
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
oauthlib@3.1.0
4.0.0
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
oauthlib@3.2.2
4.0.0
1
polyaxon/polyaxon-api:2.17.0163707082036
oauthlib@3.3.1
4.0.0
1
polyaxon/polyaxon-streams:2.17.0a5fec70e757b
oauthlib@3.3.1
4.0.0
1
praecoapp/elastalert-server:202302195a0d8715e8b1
oauthlib@3.2.2
4.0.0
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
oauthlib@3.2.2
4.0.0
1
prefecthq/prefect:3.8.7-python3.11b3cdfebebff0
oauthlib@3.3.1
4.0.0
1
prefecthq/prometheus-prefect-exporter:4.1.06e0e79cabdc2
oauthlib@3.3.1
4.0.0
1
pretix/standalone:2026.7.05df3b7aa852e
oauthlib@3.3.1
4.0.0
1
prowlercloud/prowler-api:5.31.14f252d579be2
oauthlib@3.3.1
4.0.0
1
psono/psono-server:5.0.03b974b43ea03
oauthlib@3.1.0
4.0.0
1
qonstrukt/php:8.4-v8-apache089af7925aa1
oauthlib@3.2.2
4.0.0
1
redash/redash:25.8.000d813437db5
oauthlib@3.2.2
4.0.0
1
redash/redash:10.0.0.b503639392753c0376
oauthlib@2.1.0
4.0.0
1
redash/redash:26.3.0c5c9148f5c38
oauthlib@3.2.2
4.0.0
1
robustadev/krr:v1.30.0b8d782e568c7
oauthlib@3.2.2
4.0.0
1
rook/ceph:v1.19.2944a1dd70496
oauthlib@3.1.1
4.0.0
1
rook/ceph:v1.20.8d47a748c058a
oauthlib@3.1.1
4.0.0
1
rtuszik/photon-docker:2.4.021549c60f9e6
oauthlib@3.3.1
4.0.0
1
schmitzis/monorepo:seafile-13.0-latestf7e51ba2fb07
oauthlib@3.2.2
4.0.0
1
seafileltd/seafile-mc:9.0.106693911bcc40
oauthlib@3.2.2
4.0.0
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.