StackRadar

CVE-2026-49264

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
549
of 17,957 indexed, latest versions
Container images
492
deployed by those charts
Fix available
1 of 1
affected package

Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation

Carried by container images the latest versions of 549 of 17,957 indexed charts deploy, on 492 images.

Affected packageAffected versionsFixed inImages
oauthlibpypi2.0.1, 2.0.7, 2.1.0, 3.0.1+7 more4.0.0492
OSV records
GHSA-hj66-6f7g-4r5v
Trending
Rank 28 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

549 by stars
ChartLatestAffected imagesRadar Score
kube-prometheus-stackprometheus-communityOfficialVerified publisher91.8.21 of 6See more

kube-prometheus-stack prometheus-community 91.8.2

1 of the 6 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

357
lokigrafana7.3.01 of 6See more

loki grafana 7.3.0

1 of the 6 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
oauthlib@3.3.1
4.0.0

Open the chart page →

4,112
jenkinsjenkinsciOfficialVerified publisher5.9.641 of 2See more

jenkins jenkinsci 5.9.64

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

2,821
pgadmin4runixVerified publisher1.70.41 of 1See more

pgadmin4 runix 1.70.4

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.18c332c5f6dfba
oauthlib@3.3.1
4.0.0

Open the chart page →

17
authentikgoauthentikOfficialVerified publisher2026.8.31 of 1See more

authentik goauthentik 2026.8.3

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.8.3ab9b4e8cc4ab
oauthlib@3.3.1
4.0.0

Open the chart page →

1,214
jupyterhubjupyterhubOfficialVerified publisher4.4.22 of 7See more

jupyterhub jupyterhub 4.4.2

2 of the 7 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
oauthlib@3.3.1
4.0.0
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
oauthlib@3.3.1
4.0.0

Open the chart page →

8,785
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
oauthlib@3.2.2
4.0.0

Open the chart page →

32,872
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
oauthlib@3.2.2
4.0.0

Open the chart page →

11,951
rook-cephrookOfficialVerified publisher1.20.81 of 2See more

rook-ceph rook 1.20.8

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
rook/ceph:v1.20.8d47a748c058a
oauthlib@3.1.1
4.0.0

Open the chart page →

1,501
victoria-metrics-k8s-stackvictoriametricsVerified publisher0.95.01 of 7See more

victoria-metrics-k8s-stack victoriametrics 0.95.0

1 of the 7 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

788
home-assistanthelm-hassVerified publisher0.3.831 of 1See more

home-assistant helm-hass 0.3.83

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.43e6710a7ab2a
oauthlib@3.3.1
4.0.0

Open the chart page →

2,478
openebsopenebsOfficialVerified publisher4.6.11 of 35See more

openebs openebs 4.6.1

1 of the 35 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.30.2cdb361e67b1b
oauthlib@3.2.2
4.0.0

Open the chart page →

22,298
dagsterdagsterVerified publisher1.13.242 of 5See more

dagster dagster 1.13.24

2 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
dagster/dagster-celery-k8s:1.13.2494e5e5dd6da0
oauthlib@3.3.1
4.0.0
dagster/user-code-example:1.13.24206c454797f7
oauthlib@3.3.1
4.0.0

Open the chart page →

3,251
netboxnetboxOfficialVerified publisher8.3.891 of 5See more

netbox netbox 8.3.89

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/netbox-community/netbox:v4.7.159e3e5954d02
oauthlib@3.3.1
4.0.0

Open the chart page →

1,179
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
oauthlib@3.2.0
4.0.0

Open the chart page →

9,606
weblateweblateOfficialVerified publisher0.5.381 of 3See more

weblate weblate 0.5.38

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
weblate/weblate:2026.9.1.2f0be5b122b38
oauthlib@3.3.1
4.0.0

Open the chart page →

7,119
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.21 of 2See more

stackgres-operator stackgres-charts 1.19.2

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/stackgres/operator:1.19.282f33ab3fb1e
oauthlib@3.3.1
4.0.0

Open the chart page →

2,310
pulsarapache4.7.01 of 10See more

pulsar apache 4.7.0

1 of the 10 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
oauthlib@3.3.1
4.0.0

Open the chart page →

10,165
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
langgenius/dify-api:1.16.1dcefa5f7c47c
oauthlib@3.3.1
4.0.0

Open the chart page →

71,885
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
oauthlib@3.1.0
4.0.0

Open the chart page →

4,185
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
grafana/oncall:v1.16.5499851658393
oauthlib@3.2.2
4.0.0

Open the chart page →

16,723
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
oauthlib@3.1.0
4.0.0

Open the chart page →

5,020
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
oauthlib@3.2.0
4.0.0

Open the chart page →

7,970
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
oauthlib@3.2.2
4.0.0

Open the chart page →

6,478
litellm-helmlitellm1.103.11 of 2See more

litellm-helm litellm 1.103.1

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm:1.103.1df15400b5b80
oauthlib@3.3.1
4.0.0

Open the chart page →

5,387
localstacklocalstack0.7.11 of 1See more

localstack localstack 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
localstack/localstack:latest4abc29e923e5
oauthlib@3.3.1
4.0.0

Open the chart page →

2,438
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
oauthlib@3.2.2
4.0.0

Open the chart page →

6,304
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
oauthlib@3.1.0
4.0.0

Open the chart page →

5,278
kube-prometheus-stackkube-prometheus-stack-oci91.8.21 of 6See more

kube-prometheus-stack kube-prometheus-stack-oci 91.8.2

1 of the 6 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

357
prefect-serverprefectVerified publisher2026.9.262342031 of 2See more

prefect-server prefect 2026.9.26234203

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
prefecthq/prefect:3.8.7-python3.11b3cdfebebff0
oauthlib@3.3.1
4.0.0

Open the chart page →

5,959
supersetcloudposse1.2.01 of 1See more

superset cloudposse 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
oauthlib@2.1.0
4.0.0

Open the chart page →

6,246
kube-prometheuschoerodon9.3.11 of 7See more

kube-prometheus choerodon 9.3.1

1 of the 7 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
oauthlib@3.1.0
4.0.0

Open the chart page →

12,275
paperless-ngxfmjstudios0.2.81 of 5See more

paperless-ngx fmjstudios 0.2.8

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
oauthlib@3.2.2
4.0.0

Open the chart page →

32,695
openclawopenclawVerified publisher1.94.01 of 2See more

openclaw openclaw 1.94.0

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
oauthlib@3.2.2
4.0.0

Open the chart page →

3,842
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
oauthlib@3.2.2
4.0.0

Open the chart page →

41,587
ilumilumOfficialVerified publisher6.7.31 of 19See more

ilum ilum 6.7.3

1 of the 19 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
oauthlib@3.3.1
4.0.0

Open the chart page →

23,726
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
oauthlib@3.3.1
4.0.0

Open the chart page →

4,957
paperless-ngxpaperless-ngxVerified publisher0.3.231 of 3See more

paperless-ngx paperless-ngx 0.3.23

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.2.15fa76604a81d
oauthlib@3.3.1
4.0.0

Open the chart page →

8,353
home-assistantalekcVerified publisher2.11.41 of 1See more

home-assistant alekc 2.11.4

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.43e6710a7ab2a
oauthlib@3.3.1
4.0.0

Open the chart page →

2,478
home-assistantandrenarchyVerified publisher14.104.01 of 1See more

home-assistant andrenarchy 14.104.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
oauthlib@3.3.1
4.0.0

Open the chart page →

2,478
awx-operatorawx-operator-helm3.2.11 of 2See more

awx-operator awx-operator-helm 3.2.1

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
oauthlib@3.2.2
4.0.0

Open the chart page →

10,026
cluster-secretclutersecretVerified publisher0.7.01 of 1See more

cluster-secret clutersecret 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
oauthlib@3.2.2
4.0.0

Open the chart page →

3,283
uptime-kumaduyet0.1.81 of 1See more

uptime-kuma duyet 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.18.5a84767d7934f
oauthlib@2.1.0
4.0.0

Open the chart page →

4,708
gluugluuOfficialVerified publisher1.8.521 of 5See more

gluu gluu 1.8.52

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
gluufederation/cloudtools:4.5.17-1fe944d2e5d0f
oauthlib@3.3.1
4.0.0

Open the chart page →

323
janssenjanssen-auth-serverOfficialVerified publisher0.0.0-nightly8 of 8See more

janssen janssen-auth-server 0.0.0-nightly

8 of the 8 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/janssenproject/jans/auth-server:0.0.0-nightly5d6d9a2a1d96
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/casa:0.0.0-nightlye55838190832
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/cloudtools:0.0.0-nightly7b97fe25f964
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/config-api:0.0.0-nightly613eae7771a8
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/configurator:0.0.0-nightly990cbab56331
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/fido2:0.0.0-nightly1c63019e8ef6
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/persistence-loader:0.0.0-nightlyc6e314e9467d
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/scim:0.0.0-nightlyea680fe73dc9
oauthlib@3.3.1
4.0.0

Open the chart page →

1,687
abcdesktopabcdesktopOfficialVerified publisher4.4.131 of 9See more

abcdesktop abcdesktop 4.4.13

1 of the 9 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/abcdesktopio/pyos:4.4.alpine_latest5c43e3d66d2e
oauthlib@3.3.1
4.0.0

Open the chart page →

970
baserowbaserow-chartVerified publisher1.0.561 of 6See more

baserow baserow-chart 1.0.56

1 of the 6 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
baserow/backend:2.3.37c00549b3a6f
oauthlib@3.3.1
4.0.0

Open the chart page →

18,749
fadicetic0.3.13 of 25See more

fadi cetic 0.3.1

3 of the 25 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
oauthlib@2.1.0
4.0.0
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
oauthlib@3.1.0
4.0.0
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
oauthlib@3.0.1
4.0.0

Open the chart page →

137,043
pgadmincetic0.1.121 of 1See more

pgadmin cetic 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
dpage/pgadmin4:latestc332c5f6dfba
oauthlib@3.3.1
4.0.0

Open the chart page →

17
dagster-user-deploymentsdagsterVerified publisher1.13.241 of 1See more

dagster-user-deployments dagster 1.13.24

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
dagster/user-code-example:1.13.24206c454797f7
oauthlib@3.3.1
4.0.0

Open the chart page →

824

Container images carrying it

492 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
oauthlib@3.2.0
4.0.0
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
oauthlib@3.1.1
4.0.0
1
ghcr.io/kubeshop/k8s-sidecar:ignore-initial-events7f583a36a764
oauthlib@3.2.1
4.0.0
1
ghcr.io/kubevoip/kubevoip:v0.6.841c603a93642
oauthlib@3.3.1
4.0.0
1
ghcr.io/lerentis/bitwarden-crd-operator:0.18.0912b19a7f09a
oauthlib@3.3.1
4.0.0
1
ghcr.io/linuxserver/beets:1.4.9-ls94826263aebec3
oauthlib@3.1.0
4.0.0
1
ghcr.io/linuxserver/calibre-web:latest0767226fcf20
oauthlib@3.3.1
4.0.0
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
oauthlib@3.3.1
4.0.0
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
oauthlib@3.2.2
4.0.0
1
ghcr.io/linuxserver/papermerge:version-v2.0.198ba2dd3f0bd
oauthlib@3.2.0
4.0.0
1
ghcr.io/linuxserver/sickchill:2021.5.10-1-ls63a607452a692a
oauthlib@3.1.0
4.0.0
1
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
oauthlib@3.3.1
4.0.0
1
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
oauthlib@3.2.0
4.0.0
1
ghcr.io/macropower/kubernetes-python:1.0a887b5cae4af
oauthlib@3.3.1
4.0.0
1
ghcr.io/mcp-hangar/mcp-hangar:2.23.0b731546941ce
oauthlib@3.3.1
4.0.0
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
oauthlib@3.2.2
4.0.0
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
oauthlib@3.3.1
4.0.0
1
ghcr.io/mealie-recipes/mealie:v3.28.08b02290f4d18
oauthlib@3.3.1
4.0.0
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
oauthlib@3.2.2
4.0.0
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
oauthlib@3.3.1
4.0.0
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
oauthlib@3.2.2
4.0.0
1
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
oauthlib@3.2.2
4.0.0
1
ghcr.io/mshade/kronic:v0.1.466e3043851cd
oauthlib@3.2.2
4.0.0
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
oauthlib@3.2.2
4.0.0
1
ghcr.io/netbox-community/netbox:v4.7.159e3e5954d02
oauthlib@3.3.1
4.0.0
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
oauthlib@3.3.1
4.0.0
1
ghcr.io/olivetin/olivetin:2025.2.19a89958921526
oauthlib@3.2.2
4.0.0
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
oauthlib@3.3.1
4.0.0
1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
oauthlib@3.2.2
4.0.0
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
oauthlib@3.2.2
4.0.0
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
oauthlib@3.2.2
4.0.0
1
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
oauthlib@3.2.2
4.0.0
1
ghcr.io/open-webui/terminals-operator:latest5e1ceb6b3b26
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
oauthlib@3.2.2
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
oauthlib@3.2.2
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
oauthlib@3.3.1
4.0.0
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
oauthlib@3.3.1
4.0.0
1
ghcr.io/quenchworks/images/pgadmina989540d10b6
oauthlib@3.3.1
4.0.0
1
ghcr.io/reezogit/aws-secrets-synchronizer:0.2.1111ed7cf7b39
oauthlib@3.2.2
4.0.0
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
oauthlib@3.3.1
4.0.0
1
ghcr.io/sooperset/mcp-atlassian:0.11.927c8e5b890e1
oauthlib@3.3.1
4.0.0
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
oauthlib@3.2.2
4.0.0
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
oauthlib@3.2.2
4.0.0
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
oauthlib@3.2.2
4.0.0
1
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
oauthlib@3.3.1
4.0.0
1
ghcr.io/texano00/urunner:0.6.07c8be1dae3cd
oauthlib@3.2.2
4.0.0
1
ghcr.io/wittdennis/calibre-web:1.1.2953aa0935251
oauthlib@3.3.1
4.0.0
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.