StackRadar

CVE-2026-49264

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
549
of 17,957 indexed, latest versions
Container images
492
deployed by those charts
Fix available
1 of 1
affected package

Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation

Carried by container images the latest versions of 549 of 17,957 indexed charts deploy, on 492 images.

Affected packageAffected versionsFixed inImages
oauthlibpypi2.0.1, 2.0.7, 2.1.0, 3.0.1+7 more4.0.0492
OSV records
GHSA-hj66-6f7g-4r5v
Trending
Rank 28 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

549 by stars
ChartLatestAffected imagesRadar Score
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
kfserving/models-web-app:v0.6.1f322d6ffdfa3
oauthlib@3.1.1
4.0.0

Open the chart page →

3,864
csghubcsghubVerified publisher2.5.02 of 34See more

csghub csghub 2.5.0

2 of the 34 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.30.2cdb361e67b1b
oauthlib@3.2.2
4.0.0
opencsghq/agenticflow:ee-v0.6.5-241cba9c366f1
oauthlib@3.3.1
4.0.0

Open the chart page →

52,989
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
oauthlib@3.2.2
4.0.0

Open the chart page →

12,572
jupyterhubd4nVerified publisher3.3.72 of 7See more

jupyterhub d4n 3.3.7

2 of the 7 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
oauthlib@3.2.2
4.0.0
aristidetm/k8s-hub:3.3.7ccb516cb8474
oauthlib@3.2.2
4.0.0

Open the chart page →

17,520
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
oauthlib@3.2.2
4.0.0

Open the chart page →

6,443
dapr-agentsdapr-agents-devVerified publisher0.1.52 of 31See more

dapr-agents dapr-agents-dev 0.1.5

2 of the 31 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.30.98c06e1ba643a
oauthlib@3.3.1
4.0.0
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
oauthlib@3.3.1
4.0.0

Open the chart page →

23,432
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
oauthlib@3.2.2
4.0.0

Open the chart page →

5,533
datagrokdatagrok1.0.31 of 7See more

datagrok datagrok 1.0.3

1 of the 7 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
datagrok/grok_spawner:latest8c2d48c1545c
oauthlib@3.3.1
4.0.0

Open the chart page →

2,512
mlflowdeliveryheroVerified publisher1.0.101 of 1See more

mlflow deliveryhero 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
oauthlib@3.1.0
4.0.0

Open the chart page →

4,535
newrelic-controllerdeliveryheroVerified publisher1.2.01 of 1See more

newrelic-controller deliveryhero 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
maxrocketinternet/newrelic-controller:0.8ff66958597f0
oauthlib@3.1.0
4.0.0

Open the chart page →

919
postgres-controllerdeliveryheroVerified publisher1.4.01 of 1See more

postgres-controller deliveryhero 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
maxrocketinternet/postgres-controller:0.572ac4d33b99d
oauthlib@3.1.0
4.0.0

Open the chart page →

946
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
oauthlib@3.2.2
4.0.0

Open the chart page →

80,522
devnopesdevnopes0.1.81 of 1See more

devnopes devnopes 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
sokushinbutsu/devnopes:latest0bbd90448671
oauthlib@3.3.1
4.0.0

Open the chart page →

495
kube-openid-connectdevopstalesVerified publisher1.1.01 of 1See more

kube-openid-connect devopstales 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
devopstales/kube-openid-connector:1.042c40a0e9f1b
oauthlib@3.2.0
4.0.0

Open the chart page →

1,351
kube-prometheus-stackdevtron19.3.01 of 6See more

kube-prometheus-stack devtron 19.3.0

1 of the 6 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.14.235654389f8a9
oauthlib@3.1.1
4.0.0

Open the chart page →

8,697
kube-prometheus-stackdevtron-labs19.3.01 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

1 of the 6 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.14.235654389f8a9
oauthlib@3.1.1
4.0.0

Open the chart page →

8,697
dbappdiabetesappVerified publisher0.1.01 of 1See more

dbapp diabetesapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
surayya25/diabetes-app:new042c31d5a979
oauthlib@3.1.0
4.0.0

Open the chart page →

4,107
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
oauthlib@3.2.2
4.0.0

Open the chart page →

56,519
autonodelabeldjjudas21Verified publisher0.0.101 of 1See more

autonodelabel djjudas21 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
djjudas21/autonodelabel:0.0.6f17233350c4f
oauthlib@3.2.2
4.0.0

Open the chart page →

1,333
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
oauthlib@2.1.0
4.0.0

Open the chart page →

4,486
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
oauthlib@2.1.0
4.0.0

Open the chart page →

15,295
dnation-kubernetes-jsonnet-translatordnationcloud2.0.11 of 1See more

dnation-kubernetes-jsonnet-translator dnationcloud 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
oauthlib@3.3.1
4.0.0

Open the chart page →

4,038
dnation-kubernetes-monitoringdnationcloud3.0.21 of 1See more

dnation-kubernetes-monitoring dnationcloud 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
oauthlib@3.3.1
4.0.0

Open the chart page →

4,038
dnation-kubernetes-monitoring-stackdnationcloud5.0.03 of 18See more

dnation-kubernetes-monitoring-stack dnationcloud 5.0.0

3 of the 18 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
oauthlib@3.3.1
4.0.0
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
oauthlib@3.2.2
4.0.0
quay.io/kiwigrid/k8s-sidecar:2.8.1abb55b2165c6
oauthlib@3.3.1
4.0.0

Open the chart page →

23,915
codecovdoubanVerified publisher0.2.43 of 8See more

codecov douban 0.2.4

3 of the 8 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
codecov/self-hosted-api:24.4.10475cb1c3136
oauthlib@3.1.0
4.0.0
codecov/self-hosted-worker:24.4.1837f546b479b
oauthlib@3.1.0
4.0.0
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
oauthlib@3.2.0
4.0.0

Open the chart page →

25,854
healthchecksdoubanVerified publisher1.0.101 of 2See more

healthchecks douban 1.0.10

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
healthchecks/healthchecks:latestaa08a61b0dcf
oauthlib@3.3.1
4.0.0

Open the chart page →

2,000
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
oauthlib@3.2.0
4.0.0

Open the chart page →

31,633
drogue-cloud-metricsdrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-metrics drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.19.26a8671702d6f
oauthlib@3.2.0
4.0.0

Open the chart page →

13,665
rook-cephdtrdnk-helm-chartsVerified publisher0.0.11 of 2See more

rook-ceph dtrdnk-helm-charts 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
rook/ceph:v1.19.2944a1dd70496
oauthlib@3.1.1
4.0.0

Open the chart page →

2,048
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
oauthlib@3.1.0
4.0.0

Open the chart page →

11,353
grafana-dashboardsdysnixVerified publisher0.2.21 of 2See more

grafana-dashboards dysnix 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.10.718feb3906286
oauthlib@3.1.0
4.0.0

Open the chart page →

5,198
aerios-k8s-shimeclipse-aeriosVerified publisher1.0.01 of 1See more

aerios-k8s-shim eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
eclipseaerios/aerios-k8s-shim:v1.0.0d4ed3d8e5db4
oauthlib@3.2.2
4.0.0

Open the chart page →

1,687
home-assistantegebackVerified publisher2.0.351 of 1See more

home-assistant egeback 2.0.35

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
oauthlib@3.3.1
4.0.0

Open the chart page →

2,521
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
oauthlib@3.2.2
4.0.0

Open the chart page →

32,872
pgadmin4eks-storageclass0.1.01 of 2See more

pgadmin4 eks-storageclass 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
dpage/pgadmin4:latestc332c5f6dfba
oauthlib@3.3.1
4.0.0

Open the chart page →

17
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
oauthlib@3.2.2
4.0.0

Open the chart page →

95,989
upgrade-responderepinioVerified publisher0.2.01 of 5See more

upgrade-responder epinio 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.25.2cb4c638ffb1f
oauthlib@3.2.2
4.0.0

Open the chart page →

7,605
argocd-version-exporterevilmartians0.0.11 of 1See more

argocd-version-exporter evilmartians 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/evl.ms/argocd-exporter:0.0.136ea8f34aa6b
oauthlib@3.1.1
4.0.0

Open the chart page →

2,463
extended-ceph-exporterextended-ceph-exporterVerified publisher1.10.01 of 2See more

extended-ceph-exporter extended-ceph-exporter 1.10.0

1 of the 2 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/ceph/ceph:v21.1.05ff3692d2f3f
oauthlib@3.2.2
4.0.0

Open the chart page →

3,473
external-secrets-reloaderexternal-secrets-reloader0.1.01 of 1See more

external-secrets-reloader external-secrets-reloader 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/bensoer/external-secrets-reloader:v0.1.38e31b5a81853
oauthlib@3.3.1
4.0.0

Open the chart page →

1,093
datadog-apmfairwinds-incubator2.0.11 of 1See more

datadog-apm fairwinds-incubator 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
oauthlib@3.3.1
4.0.0

Open the chart page →

3,126
farm-observabilityfarm-observabilityOfficialVerified publisher0.27.22 of 18See more

farm-observability farm-observability 0.27.2

2 of the 18 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.7.3694950d736c8
oauthlib@3.3.1
4.0.0
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
oauthlib@3.3.1
4.0.0

Open the chart page →

14,098
fauxgpufauxgpuVerified publisher0.2.41 of 4See more

fauxgpu fauxgpu 0.2.4

1 of the 4 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
ghcr.io/devops-dojo7/fauxgpu/api:0.2.428f706597c2f
oauthlib@3.3.1
4.0.0

Open the chart page →

3,231
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
oauthlib@3.0.1
4.0.0

Open the chart page →

14,964
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.418cd5711fc9a
oauthlib@3.2.2
4.0.0

Open the chart page →

13,227
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
oauthlib@3.1.0
4.0.0

Open the chart page →

118,495
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
oauthlib@3.2.2
4.0.0

Open the chart page →

5,862
kube-ops-viewfluent-operatorVerified publisher0.1.21 of 1See more

kube-ops-view fluent-operator 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:20.4.058221b57d4d2
oauthlib@3.1.0
4.0.0

Open the chart page →

1,872
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
louislam/uptime-kuma:170233f4acb51
oauthlib@2.1.0
4.0.0

Open the chart page →

3,748
fluxcd-helm-upgraderfluxcd-helm-upgraderVerified publisher0.7.71 of 1See more

fluxcd-helm-upgrader fluxcd-helm-upgrader 0.7.7

1 of the 1 container images this version deploys carry CVE-2026-49264.

Container imageDigestPackageFixed in
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
oauthlib@3.3.1
4.0.0

Open the chart page →

2,575

Container images carrying it

492 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
oauthlib@3.2.0
4.0.0
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
oauthlib@3.1.1
4.0.0
1
ghcr.io/kubeshop/k8s-sidecar:ignore-initial-events7f583a36a764
oauthlib@3.2.1
4.0.0
1
ghcr.io/kubevoip/kubevoip:v0.6.841c603a93642
oauthlib@3.3.1
4.0.0
1
ghcr.io/lerentis/bitwarden-crd-operator:0.18.0912b19a7f09a
oauthlib@3.3.1
4.0.0
1
ghcr.io/linuxserver/beets:1.4.9-ls94826263aebec3
oauthlib@3.1.0
4.0.0
1
ghcr.io/linuxserver/calibre-web:latest0767226fcf20
oauthlib@3.3.1
4.0.0
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
oauthlib@3.3.1
4.0.0
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
oauthlib@3.2.2
4.0.0
1
ghcr.io/linuxserver/papermerge:version-v2.0.198ba2dd3f0bd
oauthlib@3.2.0
4.0.0
1
ghcr.io/linuxserver/sickchill:2021.5.10-1-ls63a607452a692a
oauthlib@3.1.0
4.0.0
1
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
oauthlib@3.3.1
4.0.0
1
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
oauthlib@3.2.0
4.0.0
1
ghcr.io/macropower/kubernetes-python:1.0a887b5cae4af
oauthlib@3.3.1
4.0.0
1
ghcr.io/mcp-hangar/mcp-hangar:2.23.0b731546941ce
oauthlib@3.3.1
4.0.0
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
oauthlib@3.2.2
4.0.0
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
oauthlib@3.3.1
4.0.0
1
ghcr.io/mealie-recipes/mealie:v3.28.08b02290f4d18
oauthlib@3.3.1
4.0.0
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
oauthlib@3.2.2
4.0.0
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
oauthlib@3.3.1
4.0.0
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
oauthlib@3.2.2
4.0.0
1
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
oauthlib@3.2.2
4.0.0
1
ghcr.io/mshade/kronic:v0.1.466e3043851cd
oauthlib@3.2.2
4.0.0
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
oauthlib@3.2.2
4.0.0
1
ghcr.io/netbox-community/netbox:v4.7.159e3e5954d02
oauthlib@3.3.1
4.0.0
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
oauthlib@3.3.1
4.0.0
1
ghcr.io/olivetin/olivetin:2025.2.19a89958921526
oauthlib@3.2.2
4.0.0
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
oauthlib@3.3.1
4.0.0
1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
oauthlib@3.2.2
4.0.0
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
oauthlib@3.2.2
4.0.0
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
oauthlib@3.2.2
4.0.0
1
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
oauthlib@3.2.2
4.0.0
1
ghcr.io/open-webui/terminals-operator:latest5e1ceb6b3b26
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
oauthlib@3.2.2
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
oauthlib@3.2.2
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
oauthlib@3.3.1
4.0.0
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
oauthlib@3.3.1
4.0.0
1
ghcr.io/quenchworks/images/pgadmina989540d10b6
oauthlib@3.3.1
4.0.0
1
ghcr.io/reezogit/aws-secrets-synchronizer:0.2.1111ed7cf7b39
oauthlib@3.2.2
4.0.0
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
oauthlib@3.3.1
4.0.0
1
ghcr.io/sooperset/mcp-atlassian:0.11.927c8e5b890e1
oauthlib@3.3.1
4.0.0
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
oauthlib@3.2.2
4.0.0
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
oauthlib@3.2.2
4.0.0
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
oauthlib@3.2.2
4.0.0
1
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
oauthlib@3.3.1
4.0.0
1
ghcr.io/texano00/urunner:0.6.07c8be1dae3cd
oauthlib@3.2.2
4.0.0
1
ghcr.io/wittdennis/calibre-web:1.1.2953aa0935251
oauthlib@3.3.1
4.0.0
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.