StackRadar

CVE-2026-49265

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
524
of 17,957 indexed, latest versions
Container images
471
deployed by those charts
Fix available
1 of 1
affected package

Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)

Carried by container images the latest versions of 524 of 17,957 indexed charts deploy, on 471 images.

Affected packageAffected versionsFixed inImages
oauthlibpypi3.0.1, 3.0.2, 3.1.0, 3.1.1+4 more4.0.0471
OSV records
GHSA-xpv3-w29h-x7cv
Trending
Rank 25 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

524 by stars
ChartLatestAffected imagesRadar Score
kube-prometheus-stackprometheus-communityOfficialVerified publisher91.8.21 of 6See more

kube-prometheus-stack prometheus-community 91.8.2

1 of the 6 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

357
lokigrafana7.3.01 of 6See more

loki grafana 7.3.0

1 of the 6 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
oauthlib@3.3.1
4.0.0

Open the chart page →

4,112
jenkinsjenkinsciOfficialVerified publisher5.9.641 of 2See more

jenkins jenkinsci 5.9.64

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

2,821
pgadmin4runixVerified publisher1.70.41 of 1See more

pgadmin4 runix 1.70.4

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.18c332c5f6dfba
oauthlib@3.3.1
4.0.0

Open the chart page →

17
authentikgoauthentikOfficialVerified publisher2026.8.31 of 1See more

authentik goauthentik 2026.8.3

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.8.3ab9b4e8cc4ab
oauthlib@3.3.1
4.0.0

Open the chart page →

1,214
jupyterhubjupyterhubOfficialVerified publisher4.4.22 of 7See more

jupyterhub jupyterhub 4.4.2

2 of the 7 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
oauthlib@3.3.1
4.0.0
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
oauthlib@3.3.1
4.0.0

Open the chart page →

8,785
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
oauthlib@3.2.2
4.0.0

Open the chart page →

32,872
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
oauthlib@3.2.2
4.0.0

Open the chart page →

11,951
rook-cephrookOfficialVerified publisher1.20.81 of 2See more

rook-ceph rook 1.20.8

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
rook/ceph:v1.20.8d47a748c058a
oauthlib@3.1.1
4.0.0

Open the chart page →

1,501
victoria-metrics-k8s-stackvictoriametricsVerified publisher0.95.01 of 7See more

victoria-metrics-k8s-stack victoriametrics 0.95.0

1 of the 7 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

788
home-assistanthelm-hassVerified publisher0.3.831 of 1See more

home-assistant helm-hass 0.3.83

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.43e6710a7ab2a
oauthlib@3.3.1
4.0.0

Open the chart page →

2,478
openebsopenebsOfficialVerified publisher4.6.11 of 35See more

openebs openebs 4.6.1

1 of the 35 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.30.2cdb361e67b1b
oauthlib@3.2.2
4.0.0

Open the chart page →

22,298
dagsterdagsterVerified publisher1.13.242 of 5See more

dagster dagster 1.13.24

2 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
dagster/dagster-celery-k8s:1.13.2494e5e5dd6da0
oauthlib@3.3.1
4.0.0
dagster/user-code-example:1.13.24206c454797f7
oauthlib@3.3.1
4.0.0

Open the chart page →

3,251
netboxnetboxOfficialVerified publisher8.3.891 of 5See more

netbox netbox 8.3.89

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/netbox-community/netbox:v4.7.159e3e5954d02
oauthlib@3.3.1
4.0.0

Open the chart page →

1,179
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
oauthlib@3.2.0
4.0.0

Open the chart page →

9,606
weblateweblateOfficialVerified publisher0.5.381 of 3See more

weblate weblate 0.5.38

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
weblate/weblate:2026.9.1.2f0be5b122b38
oauthlib@3.3.1
4.0.0

Open the chart page →

7,119
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.21 of 2See more

stackgres-operator stackgres-charts 1.19.2

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/stackgres/operator:1.19.282f33ab3fb1e
oauthlib@3.3.1
4.0.0

Open the chart page →

2,310
pulsarapache4.7.01 of 10See more

pulsar apache 4.7.0

1 of the 10 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
oauthlib@3.3.1
4.0.0

Open the chart page →

10,165
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
langgenius/dify-api:1.16.1dcefa5f7c47c
oauthlib@3.3.1
4.0.0

Open the chart page →

71,885
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
oauthlib@3.1.0
4.0.0

Open the chart page →

4,185
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
grafana/oncall:v1.16.5499851658393
oauthlib@3.2.2
4.0.0

Open the chart page →

16,723
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
oauthlib@3.1.0
4.0.0

Open the chart page →

5,020
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
oauthlib@3.2.0
4.0.0

Open the chart page →

7,970
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
oauthlib@3.2.2
4.0.0

Open the chart page →

6,478
litellm-helmlitellm1.103.11 of 2See more

litellm-helm litellm 1.103.1

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm:1.103.1df15400b5b80
oauthlib@3.3.1
4.0.0

Open the chart page →

5,387
localstacklocalstack0.7.11 of 1See more

localstack localstack 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
localstack/localstack:latest4abc29e923e5
oauthlib@3.3.1
4.0.0

Open the chart page →

2,438
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
oauthlib@3.2.2
4.0.0

Open the chart page →

6,304
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
oauthlib@3.1.0
4.0.0

Open the chart page →

5,278
kube-prometheus-stackkube-prometheus-stack-oci91.8.21 of 6See more

kube-prometheus-stack kube-prometheus-stack-oci 91.8.2

1 of the 6 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

357
prefect-serverprefectVerified publisher2026.9.262342031 of 2See more

prefect-server prefect 2026.9.26234203

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
prefecthq/prefect:3.8.7-python3.11b3cdfebebff0
oauthlib@3.3.1
4.0.0

Open the chart page →

5,959
kube-prometheuschoerodon9.3.11 of 7See more

kube-prometheus choerodon 9.3.1

1 of the 7 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
oauthlib@3.1.0
4.0.0

Open the chart page →

12,275
paperless-ngxfmjstudios0.2.81 of 5See more

paperless-ngx fmjstudios 0.2.8

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
oauthlib@3.2.2
4.0.0

Open the chart page →

32,695
openclawopenclawVerified publisher1.94.01 of 2See more

openclaw openclaw 1.94.0

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
oauthlib@3.2.2
4.0.0

Open the chart page →

3,842
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
oauthlib@3.2.2
4.0.0

Open the chart page →

41,587
ilumilumOfficialVerified publisher6.7.31 of 19See more

ilum ilum 6.7.3

1 of the 19 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
oauthlib@3.3.1
4.0.0

Open the chart page →

23,726
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
oauthlib@3.3.1
4.0.0

Open the chart page →

4,957
paperless-ngxpaperless-ngxVerified publisher0.3.231 of 3See more

paperless-ngx paperless-ngx 0.3.23

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.2.15fa76604a81d
oauthlib@3.3.1
4.0.0

Open the chart page →

8,353
home-assistantalekcVerified publisher2.11.41 of 1See more

home-assistant alekc 2.11.4

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.43e6710a7ab2a
oauthlib@3.3.1
4.0.0

Open the chart page →

2,478
home-assistantandrenarchyVerified publisher14.104.01 of 1See more

home-assistant andrenarchy 14.104.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
oauthlib@3.3.1
4.0.0

Open the chart page →

2,478
awx-operatorawx-operator-helm3.2.11 of 2See more

awx-operator awx-operator-helm 3.2.1

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
oauthlib@3.2.2
4.0.0

Open the chart page →

10,026
cluster-secretclutersecretVerified publisher0.7.01 of 1See more

cluster-secret clutersecret 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
oauthlib@3.2.2
4.0.0

Open the chart page →

3,283
gluugluuOfficialVerified publisher1.8.521 of 5See more

gluu gluu 1.8.52

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
gluufederation/cloudtools:4.5.17-1fe944d2e5d0f
oauthlib@3.3.1
4.0.0

Open the chart page →

323
janssenjanssen-auth-serverOfficialVerified publisher0.0.0-nightly8 of 8See more

janssen janssen-auth-server 0.0.0-nightly

8 of the 8 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/janssenproject/jans/auth-server:0.0.0-nightly5d6d9a2a1d96
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/casa:0.0.0-nightlye55838190832
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/cloudtools:0.0.0-nightly7b97fe25f964
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/config-api:0.0.0-nightly613eae7771a8
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/configurator:0.0.0-nightly990cbab56331
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/fido2:0.0.0-nightly1c63019e8ef6
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/persistence-loader:0.0.0-nightlyc6e314e9467d
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/scim:0.0.0-nightlyea680fe73dc9
oauthlib@3.3.1
4.0.0

Open the chart page →

1,687
abcdesktopabcdesktopOfficialVerified publisher4.4.131 of 9See more

abcdesktop abcdesktop 4.4.13

1 of the 9 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/abcdesktopio/pyos:4.4.alpine_latest5c43e3d66d2e
oauthlib@3.3.1
4.0.0

Open the chart page →

970
baserowbaserow-chartVerified publisher1.0.561 of 6See more

baserow baserow-chart 1.0.56

1 of the 6 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
baserow/backend:2.3.37c00549b3a6f
oauthlib@3.3.1
4.0.0

Open the chart page →

18,749
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
oauthlib@3.1.0
4.0.0
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
oauthlib@3.0.1
4.0.0

Open the chart page →

137,043
pgadmincetic0.1.121 of 1See more

pgadmin cetic 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
dpage/pgadmin4:latestc332c5f6dfba
oauthlib@3.3.1
4.0.0

Open the chart page →

17
dagster-user-deploymentsdagsterVerified publisher1.13.241 of 1See more

dagster-user-deployments dagster 1.13.24

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
dagster/user-code-example:1.13.24206c454797f7
oauthlib@3.3.1
4.0.0

Open the chart page →

824
daskhubdask2024.1.12 of 9See more

daskhub dask 2024.1.1

2 of the 9 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
pangeo/base-notebook:2024.01.155fbe688a4f80
oauthlib@3.2.2
4.0.0
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
oauthlib@3.2.2
4.0.0

Open the chart page →

14,861
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
oauthlib@3.3.1
4.0.0

Open the chart page →

83,881

Container images carrying it

471 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
taigaio/taiga-back:6.4.29f97323cc150
oauthlib@3.1.1
4.0.0
1
teknas09/bird-pod:latest12a1fa85c4aa
oauthlib@3.2.2
4.0.0
1
timescale/timescaledb-ha:pg164f288c0a5213
oauthlib@3.2.0
4.0.0
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
oauthlib@3.2.0
4.0.0
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
oauthlib@3.2.0
4.0.0
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
oauthlib@3.2.0
4.0.0
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
oauthlib@3.2.0
4.0.0
1
toniblyx/prowler:stablecf1ee9fc5b67
oauthlib@3.3.1
4.0.0
1
truebyteinnovationllp/jupyterhub-k8s:5.5.06bf978b96279
oauthlib@3.3.1
4.0.0
1
trueosiris/vrising:latest9356f98ad561
oauthlib@3.2.0
4.0.0
1
tussanakorndev/kube-pod-alerts:1.0.5216fdadadf9a
oauthlib@3.3.1
4.0.0
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
oauthlib@3.2.0
4.0.0
1
vabene1111/recipes:2.3.50f8d061895e9
oauthlib@3.3.1
4.0.0
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
oauthlib@3.1.1
4.0.0
1
voltha/voltha-tester:1.7.0655c3048a602
oauthlib@3.0.1
4.0.0
1
weblate/weblate:3.11.3-182848df56ecd
oauthlib@3.1.0
4.0.0
1
weblate/weblate:2026.9.1.2f0be5b122b38
oauthlib@3.3.1
4.0.0
1
wger/server:2.71c5789b93bfe
oauthlib@3.3.1
4.0.0
1
ybucci/traefik-external-dns-controller:2.2.08d27ad8b5f73
oauthlib@3.3.1
4.0.0
1
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
oauthlib@3.2.2
4.0.0
1
yetiplatform/yeti:2.9.09bcbe2650a14
oauthlib@3.2.2
4.0.0
1
yetiplatform/yeti:latest9c3006cedcca
oauthlib@3.2.2
4.0.0
1
zenmldocker/zenml-server:0.97.0aaa74934d606
oauthlib@3.3.1
4.0.0
1
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
oauthlib@3.3.1
4.0.0
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
oauthlib@3.2.2
4.0.0
1
gcr.io/ml-pipeline/metadata-writer:2.0.0-alpha.5ec3ae9f6df47
oauthlib@3.1.1
4.0.0
1
ghcr.io/abcdesktopio/pyos:4.4.alpine_latest5c43e3d66d2e
oauthlib@3.3.1
4.0.0
1
ghcr.io/afairgiant/medikeep:v0.71.0086579173033
oauthlib@3.3.1
4.0.0
1
ghcr.io/alexanderwanyoike/the0/runtime:1.14.9e301fbb8fae0
oauthlib@3.2.2
4.0.0
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
oauthlib@3.2.2
4.0.0
1
ghcr.io/argonix-io/argonix-api:0.5.5aa0e3efe5840
oauthlib@3.3.1
4.0.0
1
ghcr.io/axoflow/axosyslog:4.28.03785379a20f8
oauthlib@3.3.1
4.0.0
1
ghcr.io/axoflow/axosyslog:4.5.0aa7831e207cd
oauthlib@3.2.2
4.0.0
1
ghcr.io/bensoer/external-secrets-reloader:v0.1.38e31b5a81853
oauthlib@3.3.1
4.0.0
1
ghcr.io/bensoer/sibyl:v0.2.06dca4455fde3
oauthlib@3.3.1
4.0.0
1
ghcr.io/berriai/litellm:1.102.0:main-stable32cfd7a427f6
oauthlib@3.3.1
4.0.0
1
ghcr.io/berriai/litellm:1.103.1df15400b5b80
oauthlib@3.3.1
4.0.0
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
oauthlib@3.3.1
4.0.0
1
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
oauthlib@3.2.2
4.0.0
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
oauthlib@3.2.2
4.0.0
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
oauthlib@3.2.2
4.0.0
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
oauthlib@3.2.2
4.0.0
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
oauthlib@3.2.2
4.0.0
1
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
oauthlib@3.3.1
4.0.0
1
ghcr.io/cleanuparr/cleanuparr:2.10.8ec444338a67e
oauthlib@3.3.1
4.0.0
1
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
oauthlib@3.2.2
4.0.0
1
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
oauthlib@3.2.2
4.0.0
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
oauthlib@3.2.2
4.0.0
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
oauthlib@3.3.1
4.0.0
1
ghcr.io/developmentseed/titiler:latestfe8f2224e674
oauthlib@3.3.1
4.0.0
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.