StackRadar

CVE-2026-49265

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
524
of 17,957 indexed, latest versions
Container images
471
deployed by those charts
Fix available
1 of 1
affected package

Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)

Carried by container images the latest versions of 524 of 17,957 indexed charts deploy, on 471 images.

Affected packageAffected versionsFixed inImages
oauthlibpypi3.0.1, 3.0.2, 3.1.0, 3.1.1+4 more4.0.0471
OSV records
GHSA-xpv3-w29h-x7cv
Trending
Rank 25 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

524 by stars
ChartLatestAffected imagesRadar Score
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
oauthlib@3.2.2
4.0.0

Open the chart page →

32,941
runwhen-localrunwhen-contribVerified publisher0.7.01 of 3See more

runwhen-local runwhen-contrib 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
oauthlib@3.3.1
4.0.0

Open the chart page →

3,580
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
oauthlib@3.2.0
4.0.0

Open the chart page →

8,074
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
oauthlib@3.2.2
4.0.0

Open the chart page →

10,785
pgadminsb-helm-charts0.3.01 of 1See more

pgadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.13561c1f8f99f2
oauthlib@3.2.2
4.0.0

Open the chart page →

1,857
photonschichtelVerified publisher0.2.01 of 1See more

photon schichtel 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
rtuszik/photon-docker:2.4.021549c60f9e6
oauthlib@3.3.1
4.0.0

Open the chart page →

3,153
seafileschmitzis13.0.131 of 4See more

seafile schmitzis 13.0.13

1 of the 4 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
schmitzis/monorepo:seafile-13.0-latestf7e51ba2fb07
oauthlib@3.2.2
4.0.0

Open the chart page →

43,887
uptime-kumaschoenwald1.0.101 of 1See more

uptime-kuma schoenwald 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
oauthlib@3.2.2
4.0.0

Open the chart page →

32,738
seafileseafileVerified publisher0.12.11 of 1See more

seafile seafile 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
oauthlib@3.2.0
4.0.0

Open the chart page →

78,638
seldon-core-analyticsseldon1.17.11 of 8See more

seldon-core-analytics seldon 1.17.1

1 of the 8 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
oauthlib@3.1.0
4.0.0

Open the chart page →

10,778
ccx-monitoringseveralnines0.6.211 of 7See more

ccx-monitoring severalnines 0.6.21

1 of the 7 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
oauthlib@3.3.1
4.0.0

Open the chart page →

7,887
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
oauthlib@3.3.1
4.0.0

Open the chart page →

5,657
sibylsibyl0.2.01 of 1See more

sibyl sibyl 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/bensoer/sibyl:v0.2.06dca4455fde3
oauthlib@3.3.1
4.0.0

Open the chart page →

1,082
backendsignalen4.25.01 of 4See more

backend signalen 4.25.0

1 of the 4 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
signalen/backend:2.50.1826bb090bc4e4
oauthlib@3.3.1
4.0.0

Open the chart page →

11,542
pgadminsikalabs0.1.01 of 2See more

pgadmin sikalabs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
dpage/pgadmin4:latestc332c5f6dfba
oauthlib@3.3.1
4.0.0

Open the chart page →

17
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
oauthlib@3.1.0
4.0.0

Open the chart page →

9,210
home-assistantsmall-hack2.1.01 of 1See more

home-assistant small-hack 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.3.10e091dfce306
oauthlib@3.3.1
4.0.0

Open the chart page →

4,396
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
oauthlib@3.2.2
4.0.0

Open the chart page →

5,888
aafsmo-helm-chart6.0.01 of 14See more

aaf smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
oauthlib@3.0.1
4.0.0

Open the chart page →

86,389
aaismo-helm-chart6.0.01 of 14See more

aai smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
oauthlib@3.0.1
4.0.0

Open the chart page →

86,389
dmaap-listenersmo-helm-chart6.0.01 of 3See more

dmaap-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
oauthlib@3.0.1
4.0.0

Open the chart page →

86,389
elasticsearchsmo-helm-chart6.0.01 of 5See more

elasticsearch smo-helm-chart 6.0.0

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
oauthlib@3.0.1
4.0.0

Open the chart page →

85,362
mariadb-initsmo-helm-chart6.0.01 of 2See more

mariadb-init smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
oauthlib@3.0.1
4.0.0

Open the chart page →

85,362
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
oauthlib@3.0.1
4.0.0

Open the chart page →

86,389
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
oauthlib@3.0.1
4.0.0

Open the chart page →

86,389
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
oauthlib@3.0.1
4.0.0

Open the chart page →

86,389
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
oauthlib@3.0.1
4.0.0

Open the chart page →

85,362
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
oauthlib@3.0.1
4.0.0

Open the chart page →

85,362
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
oauthlib@3.0.1
4.0.0

Open the chart page →

86,389
tracing-stacksnubisks0.1.01 of 8See more

tracing-stack snubisks 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.7.15bc0c5634d4a
oauthlib@3.3.1
4.0.0

Open the chart page →

5,819
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/kiwigrid/k8s-sidecar:1.29.142002d66ddb3
oauthlib@3.2.2
4.0.0

Open the chart page →

8,290
kube-prometheus-stacksoftonic81.5.11 of 6See more

kube-prometheus-stack softonic 81.5.1

1 of the 6 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
oauthlib@3.3.1
4.0.0

Open the chart page →

5,129
servicexssl-hep1.8.62 of 16See more

servicex ssl-hep 1.8.6

2 of the 16 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
sslhep/servicex_app:v1.8.6c935e123030d
oauthlib@3.3.1
4.0.0
sslhep/x509-secrets:v1.8.634e1c87cea8a
oauthlib@3.2.2
4.0.0

Open the chart page →

57,809
open-appsec-injectorstartechnicaVerified publisher1.1.21 of 3See more

open-appsec-injector startechnica 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
oauthlib@3.3.1
4.0.0

Open the chart page →

4,562
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.12.089739be9ff38
oauthlib@3.1.0
4.0.0

Open the chart page →

16,586
prometheus-operatorstatcan0.2.21 of 7See more

prometheus-operator statcan 0.2.2

1 of the 7 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
oauthlib@3.1.0
4.0.0

Open the chart page →

12,275
storageclass-routerstorageclass-routerVerified publisher0.4.11 of 1See more

storageclass-router storageclass-router 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/maxiv/storageclass-router:0.4.160725dab588c
oauthlib@3.2.2
4.0.0

Open the chart page →

1,081
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
oauthlib@3.2.2
4.0.0

Open the chart page →

4,782
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
oauthlib@3.3.1
4.0.0

Open the chart page →

3,446
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
opea/chatqna:1.038c51b791efa
oauthlib@3.2.2
4.0.0

Open the chart page →

41,947
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
opea/codegen:1.058f91683892d
oauthlib@3.2.2
4.0.0

Open the chart page →

30,663
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
opea/codetrans:1.0e2436483b73d
oauthlib@3.2.2
4.0.0

Open the chart page →

30,231
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
opea/docsum:1.03eaa91849512
oauthlib@3.2.2
4.0.0

Open the chart page →

30,712
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
oauthlib@3.2.2
4.0.0

Open the chart page →

5,774
the0the0Verified publisher0.9.101 of 9See more

the0 the0 0.9.10

1 of the 9 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.9e301fbb8fae0
oauthlib@3.2.2
4.0.0

Open the chart page →

5,769
monitoringthl-chartsVerified publisher0.1.11 of 10See more

monitoring thl-charts 0.1.1

1 of the 10 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.15.61f025ae37b7b
oauthlib@3.2.0
4.0.0

Open the chart page →

18,985
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.193170069ff0976
oauthlib@3.1.0
4.0.0

Open the chart page →

4,738
traefik-external-dns-controllertraefik-external-dns-operator2.2.01 of 1See more

traefik-external-dns-controller traefik-external-dns-operator 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-controller:2.2.08d27ad8b5f73
oauthlib@3.3.1
4.0.0

Open the chart page →

1,676
traefik-external-dns-operatortraefik-external-dns-operator1.0.11 of 1See more

traefik-external-dns-operator traefik-external-dns-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
oauthlib@3.2.2
4.0.0

Open the chart page →

1,317
tfy-grafanatruefoundryVerified publisher0.1.211 of 3See more

tfy-grafana truefoundry 0.1.21

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
oauthlib@3.3.1
4.0.0

Open the chart page →

1,151

Container images carrying it

471 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
buntha/mlflow:2.1.1154542cc3083
oauthlib@3.2.2
4.0.0
1
byjg/easy-haproxy:6.1.1230fdb7b00ae
oauthlib@3.3.1
4.0.0
1
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
oauthlib@3.2.2
4.0.0
1
caronc/apprise:latestcc5ef662ad2a
oauthlib@3.3.1
4.0.0
1
castai/hibernate:v0.14da62858c8381
oauthlib@3.3.1
4.0.0
1
cccs/assemblyline-core:4.7.4.stable2125fdf4aa72ab
oauthlib@3.3.1
4.0.0
1
cccs/assemblyline-socketio:4.7.4.stable21ba390e87f340
oauthlib@3.3.1
4.0.0
1
cccs/assemblyline-ui:4.7.4.stable210623c3fd039e
oauthlib@3.3.1
4.0.0
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
oauthlib@3.3.1
4.0.0
1
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
oauthlib@3.3.1
4.0.0
1
codecov/self-hosted-api:24.4.10475cb1c3136
oauthlib@3.1.0
4.0.0
1
codecov/self-hosted-worker:24.4.1837f546b479b
oauthlib@3.1.0
4.0.0
1
crocodilestick/calibre-web-automated:v4.0.6c31a738b6d5e
oauthlib@3.3.1
4.0.0
1
dagster/dagster-celery-k8s:1.13.2494e5e5dd6da0
oauthlib@3.3.1
4.0.0
1
dagster/dagster-cloud-agent:1.13.24e29285673c2c
oauthlib@3.3.1
4.0.0
1
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
oauthlib@3.3.1
4.0.0
1
datadog/agent:7.22.08f20e56b5311
oauthlib@3.1.0
4.0.0
1
datadog/agent:6aad9994de6a7
oauthlib@3.1.0
4.0.0
1
datagrok/grok_spawner:latest8c2d48c1545c
oauthlib@3.3.1
4.0.0
1
datamate/seafile-professional:11.0.202dd66b722464
oauthlib@3.3.1
4.0.0
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
oauthlib@3.1.0
4.0.0
1
datawire/aes:1.13.62beb65062c8b
oauthlib@3.1.0
4.0.0
1
datawire/emissary:2.0.2-ea9716efbdd24b
oauthlib@3.1.0
4.0.0
1
devopsgoofy/k8s-platform:latestad865312099f
oauthlib@3.2.2
4.0.0
1
devopstales/kubedash:3.1.08bb837da5aec
oauthlib@3.2.2
4.0.0
1
devopstales/kube-openid-connector:1.042c40a0e9f1b
oauthlib@3.2.0
4.0.0
1
devopstales/trivy-operator:2.575136aa7a26e
oauthlib@3.2.2
4.0.0
1
djjudas21/autonodelabel:0.0.6f17233350c4f
oauthlib@3.2.2
4.0.0
1
dockerid31415926/pod-pvc-mapping:v0.1.3354309669f16
oauthlib@3.1.1
4.0.0
1
dockerid31415926/pvc-exporter:v0.1.35a1dd17e0e07
oauthlib@3.1.1
4.0.0
1
dpage/pgadmin4:8.418cd5711fc9a
oauthlib@3.2.2
4.0.0
1
dpage/pgadmin4:7.537946e4f3e7b
oauthlib@3.2.2
4.0.0
1
dpage/pgadmin4:9.11.050700ac17936
oauthlib@3.3.1
4.0.0
1
dpage/pgadmin4:9.252cb72a9e3da
oauthlib@3.2.2
4.0.0
1
dpage/pgadmin4:8.13561c1f8f99f2
oauthlib@3.2.2
4.0.0
1
dserio83/velero-api:0.3.16b3d9115fee2
oauthlib@3.2.2
4.0.0
1
dserio83/velero-watchdog:0.1.8d5deae589229
oauthlib@3.2.2
4.0.0
1
eclipseaerios/aerios-k8s-shim:v1.0.0d4ed3d8e5db4
oauthlib@3.2.2
4.0.0
1
elautoestopista/raponchi:0.3.0b6f74db9fc81
oauthlib@3.2.2
4.0.0
1
elyra/kernel-image-puller:3.2.2c922f1f1646a
oauthlib@3.2.2
4.0.0
1
evgkrsk/postgres-controller:0.6.237f0e1f435c3
oauthlib@3.2.2
4.0.0
1
evk02/mlflow:2.2.1ef6ff257ef35
oauthlib@3.2.2
4.0.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
oauthlib@3.1.0
4.0.0
1
flag5/clustersecret:0.0.94ad5748bfcc6
oauthlib@3.1.1
4.0.0
1
flanksource/batch-runner:v1.0.44689687a7cf95
oauthlib@3.2.2
4.0.0
1
galaxy/cloudman-server:lateste5c265fe9fcd
oauthlib@3.2.1
4.0.0
1
gethue/hue:latest7d5c1b9f8a79
oauthlib@3.3.1
4.0.0
1
getsentry/sentry-kubernetes:latest6ac37974fd2a
oauthlib@3.0.1
4.0.0
1
gluufederation/cloudtools:4.5.17-1fe944d2e5d0f
oauthlib@3.3.1
4.0.0
1
gluufederation/opendj:4.3.0_011a1128b28b95
oauthlib@3.1.1
4.0.0
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.