StackRadar

CVE-2026-49477

High

Advisory

Published 9 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
79
of 17,781 indexed, latest versions
Container images
88
deployed by those charts
Fix available
1 of 2
affected packages

Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser

Carried by container images the latest versions of 79 of 17,781 indexed charts deploy, on 88 images.

Affected packageAffected versionsFixed inImages
soupsievepypi1.9.5, 1.9.6, 2.2, 2.2.1+10 more2.8.488
soupsievedeb2.5-1no fix listed1
OSV records
GHSA-836r-79rf-4m37UBUNTU-CVE-2026-49477
Also known as
PYSEC-2026-3072

Charts affected

79 by stars
ChartLatestAffected imagesRadar Score
bazarrk8s-home-lab-repo11.3.21 of 1See more

bazarr k8s-home-lab-repo 11.3.2

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
ghcr.io/home-operations/bazarr:1.5.680cb090162b4
soupsieve@2.3.2.post1
2.8.4

Open the chart page →

1,794
beetsk8s-home-lab-repo3.1.11 of 1See more

beets k8s-home-lab-repo 3.1.1

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
soupsieve@2.7
2.8.4

Open the chart page →

2,733
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
soupsieve@2.8.3
2.8.4

Open the chart page →

7,081
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
soupsieve@2.5
2.8.4

Open the chart page →

6,447
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
soupsieve@2.8.3
2.8.4

Open the chart page →

9,620
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
soupsieve@2.6
2.8.4

Open the chart page →

8,405
jupyterhubkubeblocksVerified publisher0.1.01 of 7See more

jupyterhub kubeblocks 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
soupsieve@2.4.1
2.8.4

Open the chart page →

7,356
kyso-nbdimekyso1.0.01 of 1See more

kyso-nbdime kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
kyso/kyso-nbdime:latest4aa9d38ee81d
soupsieve@2.3.2.post1
2.8.4

Open the chart page →

2,765
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
soupsieve@2.6
2.8.4

Open the chart page →

37,942
errbotmidokura-communityVerified publisher0.0.51 of 1See more

errbot midokura-community 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
errbotio/errbot:6.1.900ee4e0953ab
soupsieve@2.3.2.post1
2.8.4

Open the chart page →

2,233
fossologymidokura-communityVerified publisher0.2.21 of 2See more

fossology midokura-community 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
fossology/fossology:4.2.18bd1f22ba7bb
soupsieve@2.3.2.post1
2.8.4

Open the chart page →

3,294
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
yetiplatform/yeti:2.9.09bcbe2650a14
soupsieve@2.6
2.8.4

Open the chart page →

71,208
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
soupsieve@2.6
2.8.4

Open the chart page →

6,583
devpiowan-charts0.1.01 of 1See more

devpi owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
owanio1992/devpi:6.16.04ade8e1e4d7e
soupsieve@2.7
2.8.4

Open the chart page →

510
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
soupsieve@2.8.1
2.8.4

Open the chart page →

4,749
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
soupsieve@2.8.1
2.8.4

Open the chart page →

3,854
email-managerphntom0.1.221 of 2See more

email-manager phntom 0.1.22

1 of the 2 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
phntom/email-manager:0.1.22d8e2a9f2f085
soupsieve@2.4
2.8.4

Open the chart page →

2,565
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
soupsieve@2.6
2.8.4

Open the chart page →

21,211
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
soupsieve@2.6
2.8.4

Open the chart page →

15,591
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
soupsieve@2.6
2.8.4

Open the chart page →

9,607
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
soupsieve@2.6
2.8.4

Open the chart page →

3,512
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
soupsieve@2.6
2.8.4

Open the chart page →

4,718
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
soupsieve@2.8
2.8.4

Open the chart page →

4,499
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
soupsieve@2.5
2.8.4

Open the chart page →

10,209
syncstorageschichtelVerified publisher0.1.11 of 1See more

syncstorage schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
mozilla/syncstorage-rs:0.15.893752877dced
soupsieve@2.5
2.8.4

Open the chart page →

1,318
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
soupsieve@2.3.2.post1
2.8.4

Open the chart page →

5,565
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
soupsieve@2.8.3
2.8.4

Open the chart page →

2,396
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
soupsieve@2.6
2.8.4

Open the chart page →

5,350
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-49477.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
soupsieve@2.7
2.8.4

Open the chart page →

7,628

Container images carrying it

88 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/ai-agent:0.0.16545dac92173
soupsieve@2.6
2.8.4
3
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
soupsieve@2.6
2.8.4
2
apache/airflow:2.8.4-python3.964e58748b6b9
soupsieve@2.5
2.8.4
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
soupsieve@2.6
2.8.4
1
apache/airflow:2.8.1e5560ad0b86e
soupsieve@2.5
2.8.4
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
soupsieve@2.6
2.8.4
1
aristidetm/basic-notebook:3.6.5469dbc951224
soupsieve@2.5
2.8.4
1
assistiot/fl_training_collector:latest792715dd3084
soupsieve@2.2.1
2.8.4
1
benbusby/whoogle-search:0.5.4f77f7e6e4ad2
soupsieve@1.9.5
2.8.4
1
bnjbvr/kresus:0.22.137e216b182c8
soupsieve@2.6
2.8.4
1
datadog/agent:6aad9994de6a7
soupsieve@1.9.6
2.8.4
1
errbotio/errbot:6.1.900ee4e0953ab
soupsieve@2.3.2.post1
2.8.4
1
fossology/fossology:4.2.18bd1f22ba7bb
soupsieve@2.3.2.post1
2.8.4
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
soupsieve@2.6
2.8.4
1
grafana/oncall:v1.16.5499851658393
soupsieve@2.7
2.8.4
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
soupsieve@2.3.2.post1
2.8.4
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
soupsieve@2.5
2.8.4
1
homeassistant/home-assistant:2023.12.48d000332b09b
soupsieve@2.5
2.8.4
1
improwised/erpnext-worker:v13.4.197280b55cbd4
soupsieve@2.2.1
2.8.4
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
soupsieve@2.8.3
2.8.4
1
jaedb/iris:latest048cfbf58d57
soupsieve@2.7
2.8.4
1
jonasal/devpi-server:6.17.0-alpineec1eee99a18d
soupsieve@2.8.1
2.8.4
1
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
soupsieve@2.4.1
2.8.4
1
jupyterjsc/jupyterhub-outpost:2.3.1aea53b13f235
soupsieve@2.8.3
2.8.4
1
kyso/kyso-nbdime:latest4aa9d38ee81d
soupsieve@2.3.2.post1
2.8.4
1
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
soupsieve@2.8.3
2.8.4
1
langgenius/dify-api:1.0.0066035f93856
soupsieve@2.6
2.8.4
1
langgenius/dify-api:0.6.11fca918260dd6
soupsieve@2.5
2.8.4
1
linuxserver/beets:1.5.0e36d16f7341c
soupsieve@2.3.1
2.8.4
1
linuxserver/calibre-web:0.6.24241009026e6f
soupsieve@2.7
2.8.4
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
soupsieve@1.9.6
2.8.4
1
mindsdb/mindsdb:latest163011c09299
soupsieve@2.8.3
2.8.4
1
mozilla/syncserver:latest016162bf39d8
soupsieve@1.9.5
2.8.4
1
mozilla/syncstorage-rs:0.15.893752877dced
soupsieve@2.5
2.8.4
1
opea/web-retriever-chroma:1.0fe08165d7770
soupsieve@2.6
2.8.4
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
soupsieve@2.7
2.8.4
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
soupsieve@2.8.3
2.8.4
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
soupsieve@2.7
2.8.4
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
soupsieve@2.2
2.8.4
1
openvpn/openvpn-as:latest2253c10ec652
soupsieve@2.5-1
soupsieve@2.5
no fix listed
2.8.4
1
owanio1992/devpi:6.16.04ade8e1e4d7e
soupsieve@2.7
2.8.4
1
pangeo/base-notebook:2024.01.155fbe688a4f80
soupsieve@2.5
2.8.4
1
phntom/email-manager:0.1.22d8e2a9f2f085
soupsieve@2.4
2.8.4
1
sissbruecker/linkding:1.35.00c5dddf0b37c
soupsieve@2.6
2.8.4
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
soupsieve@2.6
2.8.4
1
stackstorm/st2actionrunner:3.888235ba70cad
soupsieve@2.5
2.8.4
1
stackstorm/st2api:3.86f56d239d280
soupsieve@2.5
2.8.4
1
stackstorm/st2auth:3.833ecfda16608
soupsieve@2.5
2.8.4
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
soupsieve@2.5
2.8.4
1
stackstorm/st2notifier:3.8f190a6212195
soupsieve@2.5
2.8.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.