StackRadar

CVE-2026-49265

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
524
of 17,957 indexed, latest versions
Container images
471
deployed by those charts
Fix available
1 of 1
affected package

Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)

Carried by container images the latest versions of 524 of 17,957 indexed charts deploy, on 471 images.

Affected packageAffected versionsFixed inImages
oauthlibpypi3.0.1, 3.0.2, 3.1.0, 3.1.1+4 more4.0.0471
OSV records
GHSA-xpv3-w29h-x7cv
Trending
Rank 25 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

524 by stars
ChartLatestAffected imagesRadar Score
geomapfishgeomapfish0.8.01 of 3See more

geomapfish geomapfish 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
oauthlib@3.2.2
4.0.0

Open the chart page →

6,992
volume-autoscalergke-volume-autoscaler3.0.21 of 1See more

volume-autoscaler gke-volume-autoscaler 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
shadowrhyder/gke-volume-autoscaler:3.0.24aae9270356a
oauthlib@3.3.1
4.0.0

Open the chart page →

926
ldap-backupgluuVerified publisher1.6.111 of 1See more

ldap-backup gluu 1.6.11

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
gluufederation/opendj:4.3.0_011a1128b28b95
oauthlib@3.1.1
4.0.0

Open the chart page →

3,174
docker-registry-gcgmelilloVerified publisher0.1.91 of 1See more

docker-registry-gc gmelillo 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
gmelillo/registry:0.1.8c599d608a2f7
oauthlib@3.3.1
4.0.0

Open the chart page →

1,006
gnp-stackgnp-stack0.0.51 of 14See more

gnp-stack gnp-stack 0.0.5

1 of the 14 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.30.10835d79d8fbae
oauthlib@3.3.1
4.0.0

Open the chart page →

13,674
platformgoofy-chart0.1.01 of 1See more

platform goofy-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
devopsgoofy/k8s-platform:latestad865312099f
oauthlib@3.2.2
4.0.0

Open the chart page →

3,003
kube-prometheus-stackgpg-dev84.0.01 of 6See more

kube-prometheus-stack gpg-dev 84.0.0

1 of the 6 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.6.0a6c101156d42
oauthlib@3.3.1
4.0.0

Open the chart page →

4,432
grafana-dashboard-convertergrafana-dashboard-converterVerified publisher0.3.101 of 1See more

grafana-dashboard-converter grafana-dashboard-converter 0.3.10

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kenchrcum/grafana-dashboard-converter:0.3.105310497aea3f
oauthlib@3.3.1
4.0.0

Open the chart page →

983
helixhelix1.4.31 of 2See more

helix helix 1.4.3

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
oauthlib@3.3.1
4.0.0

Open the chart page →

6,131
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
oauthlib@3.2.2
4.0.0

Open the chart page →

5,113
mlflowhelm-charts-nr1.0.101 of 1See more

mlflow helm-charts-nr 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
oauthlib@3.1.0
4.0.0

Open the chart page →

4,535
newrelic-controllerhelm-charts-nr1.2.01 of 1See more

newrelic-controller helm-charts-nr 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
maxrocketinternet/newrelic-controller:0.8ff66958597f0
oauthlib@3.1.0
4.0.0

Open the chart page →

919
postgres-controllerhelm-charts-nr1.4.01 of 1See more

postgres-controller helm-charts-nr 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
maxrocketinternet/postgres-controller:0.572ac4d33b99d
oauthlib@3.1.0
4.0.0

Open the chart page →

946
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
oauthlib@3.1.0
4.0.0

Open the chart page →

8,477
chiefonboardinghelmforgeVerified publisher1.1.151 of 3See more

chiefonboarding helmforge 1.1.15

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
oauthlib@3.3.1
4.0.0

Open the chart page →

8,083
hermes-agenthelmforgeVerified publisher1.0.11 of 1See more

hermes-agent helmforge 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.9.24fca358f12efd
oauthlib@3.3.1
4.0.0

Open the chart page →

6,076
jupyterhubhelmforgeVerified publisher1.0.61 of 3See more

jupyterhub helmforge 1.0.6

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
oauthlib@3.3.1
4.0.0

Open the chart page →

5,903
langflowhelmforgeVerified publisher2.0.21 of 1See more

langflow helmforge 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
langflowai/langflow:1.12.334055a07d446
oauthlib@3.3.1
4.0.0

Open the chart page →

244
medikeephelmforgeVerified publisher2.0.21 of 3See more

medikeep helmforge 2.0.2

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/afairgiant/medikeep:v0.71.0086579173033
oauthlib@3.3.1
4.0.0

Open the chart page →

5,407
netboxhelmforgeVerified publisher2.0.21 of 4See more

netbox helmforge 2.0.2

1 of the 4 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
oauthlib@3.3.1
4.0.0

Open the chart page →

4,094
olivetinhelmforgeVerified publisher1.2.21 of 2See more

olivetin helmforge 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
jamesread/olivetin:3000.20.0f3066e207efd
oauthlib@3.3.1
4.0.0

Open the chart page →

298
hetzner-s3-operatorhetzner-s3-operatorVerified publisher0.1.31 of 1See more

hetzner-s3-operator hetzner-s3-operator 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kenchrcum/hetzner-s3-operator:0.1.384dae7aeea5b
oauthlib@3.3.1
4.0.0

Open the chart page →

689
changedetectionhomeenterpriseinc0.2.01 of 2See more

changedetection homeenterpriseinc 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.44534b9bc5c46e
oauthlib@3.2.2
4.0.0

Open the chart page →

1,974
homeassistanthomeenterpriseinc0.3.01 of 1See more

homeassistant homeenterpriseinc 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2022.3.5565751f33794
oauthlib@3.2.0
4.0.0

Open the chart page →

7,947
paperlesshpVerified publisher0.1.21 of 5See more

paperless hp 0.1.2

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
oauthlib@3.3.1
4.0.0

Open the chart page →

29,775
browserlessicoretechVerified publisher0.16.61 of 1See more

browserless icoretech 0.16.6

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
oauthlib@3.2.2
4.0.0

Open the chart page →

2,479
monitoring-stackict-platformVerified publisher0.4.01 of 13See more

monitoring-stack ict-platform 0.4.0

1 of the 13 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
oauthlib@3.3.1
4.0.0

Open the chart page →

9,937
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:1.2.0e4770285aaf7
oauthlib@3.1.1
4.0.0

Open the chart page →

117,870
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
oauthlib@3.3.1
4.0.0

Open the chart page →

2,502
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
oauthlib@3.1.1
4.0.0

Open the chart page →

7,041
healthchecksimprowisedVerified publisher1.1.11 of 2See more

healthchecks improwised 1.1.1

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
linuxserver/healthchecks:2.7.2023033194696dab3c50
oauthlib@3.2.2
4.0.0

Open the chart page →

2,653
pgadmininseefrlab3.2.01 of 1See more

pgadmin inseefrlab 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
dpage/pgadmin4:latestc332c5f6dfba
oauthlib@3.3.1
4.0.0

Open the chart page →

17
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
oauthlib@3.3.1
4.0.0

Open the chart page →

19,668
inventreeinventreeOfficialVerified publisher0.4.301 of 2See more

inventree inventree 0.4.30

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
inventree/inventree:1.5.6b61e6a7534bf
oauthlib@3.3.1
4.0.0

Open the chart page →

5,613
kubernetes-pythonjacobcolvinVerified publisher0.1.11 of 1See more

kubernetes-python jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/macropower/kubernetes-python:1.0a887b5cae4af
oauthlib@3.3.1
4.0.0

Open the chart page →

74
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
oauthlib@3.2.2
4.0.0

Open the chart page →

46,735
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
oauthlib@3.1.0
4.0.0

Open the chart page →

4,313
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
oauthlib@3.2.2
4.0.0

Open the chart page →

7,268
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
oauthlib@3.2.2
4.0.0

Open the chart page →

7,250
beetsjmmaloney40.9.61 of 1See more

beets jmmaloney4 0.9.6

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/beets:1.4.9-ls94826263aebec3
oauthlib@3.1.0
4.0.0

Open the chart page →

1,231
shynetjuniorjpdj0.1.321 of 1See more

shynet juniorjpdj 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.13.1ba54f7797a6b
oauthlib@3.2.1
4.0.0

Open the chart page →

2,730
bazarrk8s-home-lab-repo11.3.21 of 1See more

bazarr k8s-home-lab-repo 11.3.2

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/home-operations/bazarr:1.5.680cb090162b4
oauthlib@3.2.2
4.0.0

Open the chart page →

1,900
beetsk8s-home-lab-repo3.1.11 of 1See more

beets k8s-home-lab-repo 3.1.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
oauthlib@3.2.2
4.0.0

Open the chart page →

2,957
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
oauthlib@3.3.1
4.0.0

Open the chart page →

10,059
jupyterhub-chartk8s-jupyterhub0.1.01 of 1See more

jupyterhub-chart k8s-jupyterhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
truebyteinnovationllp/jupyterhub-k8s:5.5.06bf978b96279
oauthlib@3.3.1
4.0.0

Open the chart page →

1,656
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
oauthlib@3.3.1
4.0.0

Open the chart page →

5,011
karbkarbVerified publisher1.0.31 of 1See more

karb karb 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/xeor/karb:main647a3c938d31
oauthlib@3.3.1
4.0.0

Open the chart page →

700
karb-chartkarbVerified publisher1.0.61 of 1See more

karb-chart karb 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/xeor/karb:1.0.6647a3c938d31
oauthlib@3.3.1
4.0.0

Open the chart page →

700
mlflowkelvins0.4.01 of 3See more

mlflow kelvins 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kelvinsp/mlflow:1.26.1cd33e6db2a59
oauthlib@3.2.0
4.0.0

Open the chart page →

4,517
elastalert2kfirfer2.2.51 of 1See more

elastalert2 kfirfer 2.2.5

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
jertel/elastalert2:2.2.34dcc0ef93efc
oauthlib@3.1.1
4.0.0

Open the chart page →

1,652

Container images carrying it

471 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/janssenproject/jans/cloudtools:0.0.0-nightly7b97fe25f964
oauthlib@3.3.1
4.0.0
2
ghcr.io/janssenproject/jans/config-api:0.0.0-nightly613eae7771a8
oauthlib@3.3.1
4.0.0
2
ghcr.io/janssenproject/jans/configurator:0.0.0-nightly990cbab56331
oauthlib@3.3.1
4.0.0
2
ghcr.io/janssenproject/jans/fido2:0.0.0-nightly1c63019e8ef6
oauthlib@3.3.1
4.0.0
2
ghcr.io/janssenproject/jans/scim:0.0.0-nightlyea680fe73dc9
oauthlib@3.3.1
4.0.0
2
ghcr.io/kiwigrid/k8s-sidecar:1.29.142002d66ddb3
oauthlib@3.2.2
4.0.0
2
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
oauthlib@3.2.2
4.0.0
2
ghcr.io/xeor/karb:1.0.6:main647a3c938d31
oauthlib@3.3.1
4.0.0
2
quay.io/cephcsi/cephcsi:v3.14.2dc4bbac6efe1
oauthlib@3.1.1
4.0.0
2
quay.io/kiwigrid/k8s-sidecar:1.19.26a8671702d6f
oauthlib@3.2.0
4.0.0
2
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
oauthlib@3.3.1
4.0.0
2
quay.io/kiwigrid/k8s-sidecar:2.8.1abb55b2165c6
oauthlib@3.3.1
4.0.0
2
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
oauthlib@3.2.2
4.0.0
2
acockburn/appdaemon:4.0.83a93281d7e94
oauthlib@3.1.0
4.0.0
1
afrank/mozalert-controller:latestd463c37b08d7
oauthlib@3.1.0
4.0.0
1
aibrix/metadata-service:v0.7.063fb81a64377
oauthlib@3.3.1
4.0.0
1
akeyless/base:latest759e4289fae8
oauthlib@3.2.2
4.0.0
1
akeyless/base-rhel:0.0.14ba8900a0061
oauthlib@3.2.2
4.0.0
1
akeyless/gateway:5.4.0d4768a9b089c
oauthlib@3.2.2
4.0.0
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
oauthlib@3.1.0
4.0.0
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
oauthlib@3.2.2
4.0.0
1
andreymileshin/kube-info:v0.1.0f7b300bc9e66
oauthlib@3.2.2
4.0.0
1
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
oauthlib@3.2.2
4.0.0
1
apache/airflow:2.8.4-python3.964e58748b6b9
oauthlib@3.2.2
4.0.0
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
oauthlib@3.2.2
4.0.0
1
apache/airflow:2.8.1e5560ad0b86e
oauthlib@3.2.2
4.0.0
1
apache/hertzbeat:1.8.075d48a62748f
oauthlib@3.2.2
4.0.0
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
oauthlib@3.2.2
4.0.0
1
apache/tika:latest-full80072bb73dd3
oauthlib@3.3.1
4.0.0
1
apache/tika:3.2.2.0-fullffab324253ed
oauthlib@3.2.2
4.0.0
1
aristidetm/basic-notebook:3.6.5469dbc951224
oauthlib@3.2.2
4.0.0
1
aristidetm/k8s-hub:3.3.7ccb516cb8474
oauthlib@3.2.2
4.0.0
1
assistiot/fl_local_operations_inference:latest0518b63a2e69
oauthlib@3.2.2
4.0.0
1
assistiot/resource-provisioning_api:1.0.044a37b00d4f8
oauthlib@3.2.2
4.0.0
1
assistiot/resource-provisioning_im:1.0.0a942dc14030a
oauthlib@3.2.2
4.0.0
1
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
oauthlib@3.2.2
4.0.0
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
oauthlib@3.2.2
4.0.0
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
oauthlib@3.2.2
4.0.0
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
oauthlib@3.2.2
4.0.0
1
assistiot/traffic-classification_api:2.0.0e32b87786142
oauthlib@3.2.2
4.0.0
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
oauthlib@3.2.2
4.0.0
1
balihb/pod-pvc-mapping:0.2.4ee48e79f5d76
oauthlib@3.1.1
4.0.0
1
baserow/backend:2.3.37c00549b3a6f
oauthlib@3.3.1
4.0.0
1
baserow/backend:1.31.1e0b3c8130b91
oauthlib@3.2.2
4.0.0
1
baserow/baserow:1.30.1df0c42eb67e8
oauthlib@3.2.2
4.0.0
1
bbilly1/tubearchivist:v0.5.9b827a713f55b
oauthlib@3.3.1
4.0.0
1
beanbag/reviewboard:latest6b840f546e1c
oauthlib@3.3.1
4.0.0
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
oauthlib@3.3.1
4.0.0
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
oauthlib@3.3.1
4.0.0
1
blackducksoftware/bdba-frontend:2026.9.10afa8763ccb8
oauthlib@3.3.1
4.0.0
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.