StackRadar

CVE-2026-49265

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
524
of 17,957 indexed, latest versions
Container images
471
deployed by those charts
Fix available
1 of 1
affected package

Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)

Carried by container images the latest versions of 524 of 17,957 indexed charts deploy, on 471 images.

Affected packageAffected versionsFixed inImages
oauthlibpypi3.0.1, 3.0.2, 3.1.0, 3.1.1+4 more4.0.0471
OSV records
GHSA-xpv3-w29h-x7cv
Trending
Rank 25 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

524 by stars
ChartLatestAffected imagesRadar Score
truefoundry-monitoringtruefoundryVerified publisher0.1.61 of 8See more

truefoundry-monitoring truefoundry 0.1.6

1 of the 8 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
oauthlib@3.3.1
4.0.0

Open the chart page →

4,732
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
oauthlib@3.2.0
4.0.0

Open the chart page →

9,013
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
oauthlib@3.2.2
4.0.0

Open the chart page →

46,735
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
oauthlib@3.2.2
4.0.0

Open the chart page →

5,256
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
oauthlib@3.2.2
4.0.0

Open the chart page →

4,954
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
oauthlib@3.2.0
4.0.0

Open the chart page →

74,963
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
oauthlib@3.3.1
4.0.0

Open the chart page →

8,381
waldur-site-agentwaldur-site-agentVerified publisher1.0.71 of 1See more

waldur-site-agent waldur-site-agent 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
opennode/waldur-site-agent:1.0.76d2e3b97c8d2
oauthlib@3.3.1
4.0.0

Open the chart page →

591
wasabi-s3-operatorwasabi-s3-operatorVerified publisher0.2.71 of 1See more

wasabi-s3-operator wasabi-s3-operator 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
oauthlib@3.3.1
4.0.0

Open the chart page →

689
ambassadorwener6.9.51 of 2See more

ambassador wener 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
oauthlib@3.1.0
4.0.0

Open the chart page →

4,185
juicefs-csi-driverwener0.33.01 of 5See more

juicefs-csi-driver wener 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
oauthlib@3.2.2
4.0.0

Open the chart page →

9,591
kube-prometheus-stackwener91.8.21 of 6See more

kube-prometheus-stack wener 91.8.2

1 of the 6 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

357
victoria-metrics-k8s-stackwener0.95.01 of 7See more

victoria-metrics-k8s-stack wener 0.95.0

1 of the 7 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

788
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
oauthlib@3.1.0
4.0.0

Open the chart page →

4,185
juicefs-csi-driverwenerme0.33.01 of 5See more

juicefs-csi-driver wenerme 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
oauthlib@3.2.2
4.0.0

Open the chart page →

9,591
victoria-metrics-k8s-stackwenerme0.95.01 of 7See more

victoria-metrics-k8s-stack wenerme 0.95.0

1 of the 7 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

788
ceph-csi-cephfswikimedia0.2.01 of 5See more

ceph-csi-cephfs wikimedia 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.14.2dc4bbac6efe1
oauthlib@3.1.1
4.0.0

Open the chart page →

4,205
ceph-csi-rbdwikimedia0.2.01 of 6See more

ceph-csi-rbd wikimedia 0.2.0

1 of the 6 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.14.2dc4bbac6efe1
oauthlib@3.1.1
4.0.0

Open the chart page →

4,782
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
oauthlib@3.2.2
4.0.0

Open the chart page →

14,050
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kadalu/kadalu-operator:1.2.03726d7a805f2
oauthlib@3.2.2
4.0.0

Open the chart page →

4,991
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
oauthlib@3.2.2
4.0.0

Open the chart page →

2,242
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
oauthlib@3.3.1
4.0.0

Open the chart page →

2,916
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
oauthlib@3.2.2
4.0.0

Open the chart page →

597
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
oauthlib@3.3.1
4.0.0

Open the chart page →

8,586

Container images carrying it

471 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
oauthlib@3.3.1
4.0.0
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
oauthlib@3.2.2
4.0.0
1
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
oauthlib@3.2.2
4.0.0
1
ghcr.io/mshade/kronic:v0.1.466e3043851cd
oauthlib@3.2.2
4.0.0
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
oauthlib@3.2.2
4.0.0
1
ghcr.io/netbox-community/netbox:v4.7.159e3e5954d02
oauthlib@3.3.1
4.0.0
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
oauthlib@3.3.1
4.0.0
1
ghcr.io/olivetin/olivetin:2025.2.19a89958921526
oauthlib@3.2.2
4.0.0
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
oauthlib@3.3.1
4.0.0
1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
oauthlib@3.2.2
4.0.0
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
oauthlib@3.2.2
4.0.0
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
oauthlib@3.2.2
4.0.0
1
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
oauthlib@3.2.2
4.0.0
1
ghcr.io/open-webui/terminals-operator:latest5e1ceb6b3b26
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
oauthlib@3.2.2
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
oauthlib@3.2.2
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
oauthlib@3.3.1
4.0.0
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
oauthlib@3.3.1
4.0.0
1
ghcr.io/quenchworks/images/pgadmina989540d10b6
oauthlib@3.3.1
4.0.0
1
ghcr.io/reezogit/aws-secrets-synchronizer:0.2.1111ed7cf7b39
oauthlib@3.2.2
4.0.0
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
oauthlib@3.3.1
4.0.0
1
ghcr.io/sooperset/mcp-atlassian:0.11.927c8e5b890e1
oauthlib@3.3.1
4.0.0
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
oauthlib@3.2.2
4.0.0
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
oauthlib@3.2.2
4.0.0
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
oauthlib@3.2.2
4.0.0
1
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
oauthlib@3.3.1
4.0.0
1
ghcr.io/texano00/urunner:0.6.07c8be1dae3cd
oauthlib@3.2.2
4.0.0
1
ghcr.io/wittdennis/calibre-web:1.1.2953aa0935251
oauthlib@3.3.1
4.0.0
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
oauthlib@3.3.1
4.0.0
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
oauthlib@3.2.2
4.0.0
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
oauthlib@3.2.2
4.0.0
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
oauthlib@3.2.2
4.0.0
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
oauthlib@3.2.2
4.0.0
1
quay.io/ceph/ceph:v21.1.05ff3692d2f3f
oauthlib@3.2.2
4.0.0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
oauthlib@3.2.0
4.0.0
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
oauthlib@3.2.2
4.0.0
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
oauthlib@3.2.2
4.0.0
1
quay.io/evl.ms/argocd-exporter:0.0.136ea8f34aa6b
oauthlib@3.1.1
4.0.0
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
oauthlib@3.3.1
4.0.0
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
oauthlib@3.2.2
4.0.0
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
oauthlib@3.2.0
4.0.0
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
oauthlib@3.3.1
4.0.0
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
oauthlib@3.3.1
4.0.0
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
oauthlib@3.2.2
4.0.0
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
oauthlib@3.3.1
4.0.0
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
oauthlib@3.3.1
4.0.0
1
quay.io/k3rnel-pan1c/uptime-kuma:1.19.3f975fde9329b
oauthlib@3.1.0
4.0.0
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.