StackRadar

CVE-2026-49265

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
524
of 17,957 indexed, latest versions
Container images
471
deployed by those charts
Fix available
1 of 1
affected package

Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)

Carried by container images the latest versions of 524 of 17,957 indexed charts deploy, on 471 images.

Affected packageAffected versionsFixed inImages
oauthlibpypi3.0.1, 3.0.2, 3.1.0, 3.1.1+4 more4.0.0471
OSV records
GHSA-xpv3-w29h-x7cv
Trending
Rank 25 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

524 by stars
ChartLatestAffected imagesRadar Score
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
oauthlib@3.1.0
4.0.0

Open the chart page →

4,623
mealiedeimosfr-charts1.0.161 of 1See more

mealie deimosfr-charts 1.0.16

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.28.08b02290f4d18
oauthlib@3.3.1
4.0.0

Open the chart page →

3,293
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
oauthlib@3.1.0
4.0.0

Open the chart page →

8,477
kubedashdevopstalesOfficialVerified publisher4.0.01 of 8See more

kubedash devopstales 4.0.0

1 of the 8 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
devopstales/kubedash:3.1.08bb837da5aec
oauthlib@3.2.2
4.0.0

Open the chart page →

10,013
trivy-operatordevopstalesVerified publisher2.5.01 of 1See more

trivy-operator devopstales 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
devopstales/trivy-operator:2.575136aa7a26e
oauthlib@3.2.2
4.0.0

Open the chart page →

5,691
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
oauthlib@3.2.0
4.0.0

Open the chart page →

78,638
dyff-orchestratordyff-orchestratorVerified publisher0.22.191 of 1See more

dyff-orchestrator dyff-orchestrator 0.22.19

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
oauthlib@3.3.1
4.0.0

Open the chart page →

1,524
jenkinsedu2.7.11 of 2See more

jenkins edu 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.193170069ff0976
oauthlib@3.1.0
4.0.0

Open the chart page →

4,738
elastalert2elastalert22.31.01 of 1See more

elastalert2 elastalert2 2.31.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
jertel/elastalert2:2.31.03cbf63f9b7dc
oauthlib@3.3.1
4.0.0

Open the chart page →

2,086
taigafermosit0.0.111 of 7See more

taiga fermosit 0.0.11

1 of the 7 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
oauthlib@3.3.1
4.0.0

Open the chart page →

9,119
home-assistantgabe565Verified publisher0.17.01 of 1See more

home-assistant gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:latestd89226851697
oauthlib@3.3.1
4.0.0

Open the chart page →

2,478
obicogabe565Verified publisher0.6.01 of 3See more

obico gabe565 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/gabe565/obico/web:latest122456be28c9
oauthlib@3.2.2
4.0.0

Open the chart page →

2,143
appdaemongeek-cookbookVerified publisher8.4.21 of 1See more

appdaemon geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
acockburn/appdaemon:4.0.83a93281d7e94
oauthlib@3.1.0
4.0.0

Open the chart page →

3,568
games-on-whalesgeek-cookbookVerified publisher1.8.21 of 7See more

games-on-whales geek-cookbook 1.8.2

1 of the 7 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/xorg:1.0.0305b3327ebba
oauthlib@3.1.0
4.0.0

Open the chart page →

116,072
kube-ops-viewgeek-cookbookVerified publisher1.2.21 of 1See more

kube-ops-view geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:20.4.058221b57d4d2
oauthlib@3.1.0
4.0.0

Open the chart page →

1,872
lazylibrariangeek-cookbookVerified publisher7.4.21 of 1See more

lazylibrarian geek-cookbook 7.4.2

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
linuxserver/lazylibrarian:version-1152df82f93d2560e233
oauthlib@3.1.1
4.0.0

Open the chart page →

11,999
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
oauthlib@3.1.1
4.0.0

Open the chart page →

8,062
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
oauthlib@3.1.1
4.0.0

Open the chart page →

10,542
gluugluu-flexOfficialVerified publisher0.0.0-nightly9 of 9See more

gluu gluu-flex 0.0.0-nightly

9 of the 9 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/gluufederation/flex/admin-ui:0.0.0-nightly60587399f746
oauthlib@3.3.1
4.0.0
ghcr.io/gluufederation/flex/persistence-loader:0.0.0-nightlycd60a0ae161c
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/auth-server:0.0.0-nightly5d6d9a2a1d96
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/casa:0.0.0-nightlye55838190832
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/cloudtools:0.0.0-nightly7b97fe25f964
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/config-api:0.0.0-nightly613eae7771a8
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/configurator:0.0.0-nightly990cbab56331
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/fido2:0.0.0-nightly1c63019e8ef6
oauthlib@3.3.1
4.0.0
ghcr.io/janssenproject/jans/scim:0.0.0-nightlyea680fe73dc9
oauthlib@3.3.1
4.0.0

Open the chart page →

1,714
IMgrycapOfficialVerified publisher1.8.01 of 3See more

IM grycap 1.8.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/grycap/im:latest06a16d4f279f
oauthlib@3.3.1
4.0.0

Open the chart page →

4,580
bazarrhalkeye0.2.01 of 1See more

bazarr halkeye 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
linuxserver/bazarr:latestd24bd0048c75
oauthlib@3.3.1
4.0.0

Open the chart page →

127
uptime-kumahelmforgeVerified publisher1.5.151 of 1See more

uptime-kuma helmforge 1.5.15

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.5c74379ac4509
oauthlib@3.2.2
4.0.0

Open the chart page →

32,727
helmuphelmupVerified publisher0.1.02 of 3See more

helmup helmup 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
oauthlib@3.2.2
4.0.0
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
oauthlib@3.2.2
4.0.0

Open the chart page →

17,633
mongo-pod-labelerhmdmph1.0.21 of 1See more

mongo-pod-labeler hmdmph 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
hmdmph/mongo-pod-labeler:1.0.1-alpine79e4a170f3dc
oauthlib@3.1.0
4.0.0

Open the chart page →

1,229
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
oauthlib@3.3.1
4.0.0

Open the chart page →

69,182
iris-webappiris-webapp0.2.41 of 2See more

iris-webapp iris-webapp 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
oauthlib@3.3.1
4.0.0

Open the chart page →

12,876
jenkinsjkimVerified publisher5.5.141 of 2See more

jenkins jkim 5.5.14

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.27.6db85bd553253
oauthlib@3.2.2
4.0.0

Open the chart page →

7,713
git-configmap-syncjulb-meVerified publisher1.0.11 of 2See more

git-configmap-sync julb-me 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
julb/kubernetes-configmap-sync:1.1.0d7d8836366ad
oauthlib@3.1.0
4.0.0

Open the chart page →

2,255
jupyterhub-outpostjupyter-jscVerified publisher2.4.11 of 1See more

jupyterhub-outpost jupyter-jsc 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
jupyterjsc/jupyterhub-outpost:2.3.1aea53b13f235
oauthlib@3.3.1
4.0.0

Open the chart page →

1,840
k8s-grafana-stackk8s-grafana-stackVerified publisher0.2.321 of 17See more

k8s-grafana-stack k8s-grafana-stack 0.2.32

1 of the 17 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
oauthlib@3.3.1
4.0.0

Open the chart page →

13,502
kronickronic0.1.71 of 1See more

kronic kronic 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/mshade/kronic:v0.1.466e3043851cd
oauthlib@3.2.2
4.0.0

Open the chart page →

1,087
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
oauthlib@3.2.2
4.0.0

Open the chart page →

21,611
kubeseal-webguikubeseal-webgui6.0.41 of 2See more

kubeseal-webgui kubeseal-webgui 6.0.4

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/jaydee94/kubeseal-webgui/api:4.5.33cceb9462ae1
oauthlib@3.2.2
4.0.0

Open the chart page →

4,510
traefik-whitelist-ddnskubitodevVerified publisher1.0.51 of 1See more

traefik-whitelist-ddns kubitodev 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kubitodev/traefik-ip-whitelist-sync:1.0.2aa24869319bf
oauthlib@3.2.0
4.0.0

Open the chart page →

961
kuma-ingress-watcherkuma-ingress-watcherVerified publisher1.4.01 of 1See more

kuma-ingress-watcher kuma-ingress-watcher 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
oauthlib@3.2.2
4.0.0

Open the chart page →

2,887
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
langflowai/langflow:latest79c02794adeb
oauthlib@3.3.1
4.0.0

Open the chart page →

4,468
langflow-runtimelangflow0.1.11 of 1See more

langflow-runtime langflow 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
langflowai/langflow:latest79c02794adeb
oauthlib@3.3.1
4.0.0

Open the chart page →

325
bitwarden-crd-operatorlerentisVerified publisher0.19.01 of 1See more

bitwarden-crd-operator lerentis 0.19.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/lerentis/bitwarden-crd-operator:0.18.0912b19a7f09a
oauthlib@3.3.1
4.0.0

Open the chart page →

621
lgtmlgtmVerified publisher0.28.01 of 9See more

lgtm lgtm 0.28.0

1 of the 9 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

959
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
oauthlib@3.3.1
4.0.0

Open the chart page →

4,820
home-assistantloeken-at-homeVerified publisher2026.5.11 of 1See more

home-assistant loeken-at-home 2026.5.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
loeken/home-assistant:2026.5.14ce6abc553b3
oauthlib@3.3.1
4.0.0

Open the chart page →

3,447
plane-enterprisemakeplaneOfficialVerified publisher3.10.11 of 13See more

plane-enterprise makeplane 3.10.1

1 of the 13 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
makeplane/backend-commercial:v3.3.0f587597c46b5
oauthlib@3.3.1
4.0.0

Open the chart page →

4,114
medusamedusaVerified publisher1.3.101 of 1See more

medusa medusa 1.3.10

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
linuxserver/medusa:v1.0.26-ls29002137158996f
oauthlib@3.3.1
4.0.0

Open the chart page →

374
mlflow-controllermlflow-deployment-controller0.1.82 of 2See more

mlflow-controller mlflow-deployment-controller 0.1.8

2 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
oauthlib@3.2.2
4.0.0
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
oauthlib@3.2.2
4.0.0

Open the chart page →

9,262
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
buntha/mlflow:2.1.1154542cc3083
oauthlib@3.2.2
4.0.0

Open the chart page →

6,353
helm-taigamvitale1989-helm-taigaVerified publisher0.2.51 of 2See more

helm-taiga mvitale1989-helm-taiga 0.2.5

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
oauthlib@3.1.0
4.0.0

Open the chart page →

5,418
papermergenicholaswildeVerified publisher1.0.21 of 1See more

papermerge nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/papermerge:version-v2.0.198ba2dd3f0bd
oauthlib@3.2.0
4.0.0

Open the chart page →

20,868
opentelemetry-demoopentelemetry-helmOfficialVerified publisher0.42.11 of 34See more

opentelemetry-demo opentelemetry-helm 0.42.1

1 of the 34 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
oauthlib@3.3.1
4.0.0

Open the chart page →

22,392
paperless-ngxpaperlessVerified publisher0.4.01 of 3See more

paperless-ngx paperless 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngxdigest-pinnedaa810a36942c
oauthlib@3.3.1
4.0.0

Open the chart page →

9,596
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
oauthlib@3.2.2
4.0.0

Open the chart page →

7,533

Container images carrying it

471 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
oauthlib@3.3.1
4.0.0
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
oauthlib@3.2.2
4.0.0
1
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
oauthlib@3.2.2
4.0.0
1
ghcr.io/mshade/kronic:v0.1.466e3043851cd
oauthlib@3.2.2
4.0.0
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
oauthlib@3.2.2
4.0.0
1
ghcr.io/netbox-community/netbox:v4.7.159e3e5954d02
oauthlib@3.3.1
4.0.0
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
oauthlib@3.3.1
4.0.0
1
ghcr.io/olivetin/olivetin:2025.2.19a89958921526
oauthlib@3.2.2
4.0.0
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
oauthlib@3.3.1
4.0.0
1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
oauthlib@3.2.2
4.0.0
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
oauthlib@3.2.2
4.0.0
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
oauthlib@3.2.2
4.0.0
1
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
oauthlib@3.2.2
4.0.0
1
ghcr.io/open-webui/terminals-operator:latest5e1ceb6b3b26
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
oauthlib@3.2.2
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
oauthlib@3.3.1
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
oauthlib@3.2.2
4.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
oauthlib@3.3.1
4.0.0
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
oauthlib@3.3.1
4.0.0
1
ghcr.io/quenchworks/images/pgadmina989540d10b6
oauthlib@3.3.1
4.0.0
1
ghcr.io/reezogit/aws-secrets-synchronizer:0.2.1111ed7cf7b39
oauthlib@3.2.2
4.0.0
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
oauthlib@3.3.1
4.0.0
1
ghcr.io/sooperset/mcp-atlassian:0.11.927c8e5b890e1
oauthlib@3.3.1
4.0.0
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
oauthlib@3.2.2
4.0.0
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
oauthlib@3.2.2
4.0.0
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
oauthlib@3.2.2
4.0.0
1
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
oauthlib@3.3.1
4.0.0
1
ghcr.io/texano00/urunner:0.6.07c8be1dae3cd
oauthlib@3.2.2
4.0.0
1
ghcr.io/wittdennis/calibre-web:1.1.2953aa0935251
oauthlib@3.3.1
4.0.0
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
oauthlib@3.3.1
4.0.0
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
oauthlib@3.2.2
4.0.0
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
oauthlib@3.2.2
4.0.0
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
oauthlib@3.2.2
4.0.0
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
oauthlib@3.2.2
4.0.0
1
quay.io/ceph/ceph:v21.1.05ff3692d2f3f
oauthlib@3.2.2
4.0.0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
oauthlib@3.2.0
4.0.0
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
oauthlib@3.2.2
4.0.0
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
oauthlib@3.2.2
4.0.0
1
quay.io/evl.ms/argocd-exporter:0.0.136ea8f34aa6b
oauthlib@3.1.1
4.0.0
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
oauthlib@3.3.1
4.0.0
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
oauthlib@3.2.2
4.0.0
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
oauthlib@3.2.0
4.0.0
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
oauthlib@3.3.1
4.0.0
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
oauthlib@3.3.1
4.0.0
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
oauthlib@3.2.2
4.0.0
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
oauthlib@3.3.1
4.0.0
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
oauthlib@3.3.1
4.0.0
1
quay.io/k3rnel-pan1c/uptime-kuma:1.19.3f975fde9329b
oauthlib@3.1.0
4.0.0
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.