StackRadar

CVE-2026-49264

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
549
of 17,957 indexed, latest versions
Container images
492
deployed by those charts
Fix available
1 of 1
affected package

Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation

Carried by container images the latest versions of 549 of 17,957 indexed charts deploy, on 492 images.

Affected packageAffected versionsFixed inImages
oauthlibpypi2.0.1, 2.0.7, 2.1.0, 3.0.1+7 more4.0.0492
OSV records
GHSA-hj66-6f7g-4r5v
Trending
Rank 28 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

549 by stars
ChartLatestAffected imagesRadar Score
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
oauthlib@3.0.1
4.0.0

Open the chart page →

85,362
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
oauthlib@3.0.1
4.0.0

Open the chart page →

85,362
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
oauthlib@3.0.1
4.0.0

Open the chart page →

86,389
tracing-stacksnubisks0.1.01 of 8See more

tracing-stack snubisks 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.7.15bc0c5634d4a
oauthlib@3.3.1
4.0.0

Open the chart page →

5,819
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/kiwigrid/k8s-sidecar:1.29.142002d66ddb3
oauthlib@3.2.2
4.0.0

Open the chart page →

8,290
kube-prometheus-stacksoftonic81.5.11 of 6See more

kube-prometheus-stack softonic 81.5.1

1 of the 6 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
oauthlib@3.3.1
4.0.0

Open the chart page →

5,129
servicexssl-hep1.8.62 of 16See more

servicex ssl-hep 1.8.6

2 of the 16 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
sslhep/servicex_app:v1.8.6c935e123030d
oauthlib@3.3.1
4.0.0
sslhep/x509-secrets:v1.8.634e1c87cea8a
oauthlib@3.2.2
4.0.0

Open the chart page →

57,809
open-appsec-injectorstartechnicaVerified publisher1.1.21 of 3See more

open-appsec-injector startechnica 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
oauthlib@3.3.1
4.0.0

Open the chart page →

4,562
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.12.089739be9ff38
oauthlib@3.1.0
4.0.0

Open the chart page →

16,586
prometheus-operatorstatcan0.2.21 of 7See more

prometheus-operator statcan 0.2.2

1 of the 7 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
oauthlib@3.1.0
4.0.0

Open the chart page →

12,275
storageclass-routerstorageclass-routerVerified publisher0.4.11 of 1See more

storageclass-router storageclass-router 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/maxiv/storageclass-router:0.4.160725dab588c
oauthlib@3.2.2
4.0.0

Open the chart page →

1,081
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
oauthlib@3.2.2
4.0.0

Open the chart page →

4,782
uptime-kumasupporttools2.6.01 of 3See more

uptime-kuma supporttools 2.6.0

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
supporttools/uptime-kuma:v2.6f8a49ed65809
oauthlib@2.1.0
4.0.0

Open the chart page →

4,465
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
oauthlib@3.3.1
4.0.0

Open the chart page →

3,446
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
opea/chatqna:1.038c51b791efa
oauthlib@3.2.2
4.0.0

Open the chart page →

41,947
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
opea/codegen:1.058f91683892d
oauthlib@3.2.2
4.0.0

Open the chart page →

30,663
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
opea/codetrans:1.0e2436483b73d
oauthlib@3.2.2
4.0.0

Open the chart page →

30,231
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
opea/docsum:1.03eaa91849512
oauthlib@3.2.2
4.0.0

Open the chart page →

30,712
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
oauthlib@3.2.2
4.0.0

Open the chart page →

5,774
the0the0Verified publisher0.9.101 of 9See more

the0 the0 0.9.10

1 of the 9 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.9e301fbb8fae0
oauthlib@3.2.2
4.0.0

Open the chart page →

5,769
monitoringthl-chartsVerified publisher0.1.11 of 10See more

monitoring thl-charts 0.1.1

1 of the 10 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.15.61f025ae37b7b
oauthlib@3.2.0
4.0.0

Open the chart page →

18,985
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.193170069ff0976
oauthlib@3.1.0
4.0.0

Open the chart page →

4,738
traefik-external-dns-controllertraefik-external-dns-operator2.2.01 of 1See more

traefik-external-dns-controller traefik-external-dns-operator 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-controller:2.2.08d27ad8b5f73
oauthlib@3.3.1
4.0.0

Open the chart page →

1,676
traefik-external-dns-operatortraefik-external-dns-operator1.0.11 of 1See more

traefik-external-dns-operator traefik-external-dns-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
oauthlib@3.2.2
4.0.0

Open the chart page →

1,317
tfy-grafanatruefoundryVerified publisher0.1.211 of 3See more

tfy-grafana truefoundry 0.1.21

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
oauthlib@3.3.1
4.0.0

Open the chart page →

1,151
truefoundry-monitoringtruefoundryVerified publisher0.1.61 of 8See more

truefoundry-monitoring truefoundry 0.1.6

1 of the 8 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
oauthlib@3.3.1
4.0.0

Open the chart page →

4,732
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
oauthlib@3.2.0
4.0.0

Open the chart page →

9,013
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
oauthlib@3.2.2
4.0.0

Open the chart page →

46,735
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
oauthlib@3.2.2
4.0.0

Open the chart page →

5,256
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
oauthlib@3.2.2
4.0.0

Open the chart page →

4,954
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
oauthlib@3.2.0
4.0.0

Open the chart page →

74,963
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
oauthlib@3.3.1
4.0.0

Open the chart page →

8,381
waldur-site-agentwaldur-site-agentVerified publisher1.0.71 of 1See more

waldur-site-agent waldur-site-agent 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
opennode/waldur-site-agent:1.0.76d2e3b97c8d2
oauthlib@3.3.1
4.0.0

Open the chart page →

591
wasabi-s3-operatorwasabi-s3-operatorVerified publisher0.2.71 of 1See more

wasabi-s3-operator wasabi-s3-operator 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
oauthlib@3.3.1
4.0.0

Open the chart page →

689
ambassadorwener6.9.51 of 2See more

ambassador wener 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
oauthlib@3.1.0
4.0.0

Open the chart page →

4,185
juicefs-csi-driverwener0.33.01 of 5See more

juicefs-csi-driver wener 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
oauthlib@3.2.2
4.0.0

Open the chart page →

9,591
kube-prometheus-stackwener91.8.21 of 6See more

kube-prometheus-stack wener 91.8.2

1 of the 6 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

357
victoria-metrics-k8s-stackwener0.95.01 of 7See more

victoria-metrics-k8s-stack wener 0.95.0

1 of the 7 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

788
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
oauthlib@3.1.0
4.0.0

Open the chart page →

4,185
juicefs-csi-driverwenerme0.33.01 of 5See more

juicefs-csi-driver wenerme 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
oauthlib@3.2.2
4.0.0

Open the chart page →

9,591
victoria-metrics-k8s-stackwenerme0.95.01 of 7See more

victoria-metrics-k8s-stack wenerme 0.95.0

1 of the 7 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

788
ceph-csi-cephfswikimedia0.2.01 of 5See more

ceph-csi-cephfs wikimedia 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.14.2dc4bbac6efe1
oauthlib@3.1.1
4.0.0

Open the chart page →

4,205
ceph-csi-rbdwikimedia0.2.01 of 6See more

ceph-csi-rbd wikimedia 0.2.0

1 of the 6 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.14.2dc4bbac6efe1
oauthlib@3.1.1
4.0.0

Open the chart page →

4,782
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
oauthlib@3.2.2
4.0.0

Open the chart page →

14,050
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
kadalu/kadalu-operator:1.2.03726d7a805f2
oauthlib@3.2.2
4.0.0

Open the chart page →

4,991
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
oauthlib@3.2.2
4.0.0

Open the chart page →

2,242
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
oauthlib@3.3.1
4.0.0

Open the chart page →

2,916
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
oauthlib@3.2.2
4.0.0

Open the chart page →

597
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
oauthlib@3.3.1
4.0.0

Open the chart page →

8,586

Container images carrying it

492 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
seafileltd/seafile-mc:10.0.170628f29c663
oauthlib@3.2.2
4.0.0
1
seafileltd/seafile-mc:9.0.97ac833196f60
oauthlib@3.2.1
4.0.0
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
oauthlib@3.1.1
4.0.0
1
shadowrhyder/gke-volume-autoscaler:3.0.24aae9270356a
oauthlib@3.3.1
4.0.0
1
signalen/backend:2.50.1826bb090bc4e4
oauthlib@3.3.1
4.0.0
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
oauthlib@3.2.2
4.0.0
1
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
oauthlib@3.2.2
4.0.0
1
socialmediamacroscope/screen_name_prompt:0.1.2724f3f5702e0
oauthlib@3.2.2
4.0.0
1
sokushinbutsu/devnopes:latest0bbd90448671
oauthlib@3.3.1
4.0.0
1
sslhep/servicex_app:v1.8.6c935e123030d
oauthlib@3.3.1
4.0.0
1
sslhep/x509-secrets:v1.8.634e1c87cea8a
oauthlib@3.2.2
4.0.0
1
supporttools/uptime-kuma:v2.6f8a49ed65809
oauthlib@2.1.0
4.0.0
1
surayya25/diabetes-app:new042c31d5a979
oauthlib@3.1.0
4.0.0
1
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
oauthlib@3.2.2
4.0.0
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
oauthlib@3.2.2
4.0.0
1
taigaio/taiga-back:6.4.29f97323cc150
oauthlib@3.1.1
4.0.0
1
teknas09/bird-pod:latest12a1fa85c4aa
oauthlib@3.2.2
4.0.0
1
timescale/timescaledb-ha:pg164f288c0a5213
oauthlib@3.2.0
4.0.0
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
oauthlib@3.2.0
4.0.0
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
oauthlib@3.2.0
4.0.0
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
oauthlib@3.2.0
4.0.0
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
oauthlib@3.2.0
4.0.0
1
toniblyx/prowler:stablecf1ee9fc5b67
oauthlib@3.3.1
4.0.0
1
truebyteinnovationllp/jupyterhub-k8s:5.5.06bf978b96279
oauthlib@3.3.1
4.0.0
1
trueosiris/vrising:latest9356f98ad561
oauthlib@3.2.0
4.0.0
1
tussanakorndev/kube-pod-alerts:1.0.5216fdadadf9a
oauthlib@3.3.1
4.0.0
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
oauthlib@3.2.0
4.0.0
1
vabene1111/recipes:2.3.50f8d061895e9
oauthlib@3.3.1
4.0.0
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
oauthlib@3.1.1
4.0.0
1
voltha/voltha-cli:1.6.0c4e41e92f046
oauthlib@2.1.0
4.0.0
1
voltha/voltha-netconf:1.6.037f80524c207
oauthlib@2.1.0
4.0.0
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
oauthlib@2.1.0
4.0.0
1
voltha/voltha-tester:1.7.0655c3048a602
oauthlib@3.0.1
4.0.0
1
voltha/voltha-voltha:1.6.0ff596b62de59
oauthlib@2.1.0
4.0.0
1
weblate/weblate:3.11.3-182848df56ecd
oauthlib@3.1.0
4.0.0
1
weblate/weblate:2026.9.1.2f0be5b122b38
oauthlib@3.3.1
4.0.0
1
wger/server:2.71c5789b93bfe
oauthlib@3.3.1
4.0.0
1
ybucci/traefik-external-dns-controller:2.2.08d27ad8b5f73
oauthlib@3.3.1
4.0.0
1
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
oauthlib@3.2.2
4.0.0
1
yetiplatform/yeti:2.9.09bcbe2650a14
oauthlib@3.2.2
4.0.0
1
yetiplatform/yeti:latest9c3006cedcca
oauthlib@3.2.2
4.0.0
1
zenmldocker/zenml-server:0.97.0aaa74934d606
oauthlib@3.3.1
4.0.0
1
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
oauthlib@3.3.1
4.0.0
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
oauthlib@3.2.2
4.0.0
1
gcr.io/ml-pipeline/metadata-writer:2.0.0-alpha.5ec3ae9f6df47
oauthlib@3.1.1
4.0.0
1
ghcr.io/abcdesktopio/pyos:4.4.alpine_latest5c43e3d66d2e
oauthlib@3.3.1
4.0.0
1
ghcr.io/afairgiant/medikeep:v0.71.0086579173033
oauthlib@3.3.1
4.0.0
1
ghcr.io/alexanderwanyoike/the0/runtime:1.14.9e301fbb8fae0
oauthlib@3.2.2
4.0.0
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
oauthlib@3.2.2
4.0.0
1
ghcr.io/argonix-io/argonix-api:0.5.5aa0e3efe5840
oauthlib@3.3.1
4.0.0
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.