StackRadar

CVE-2026-52726

High

Advisory

Published 10 Jun 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
8
of 17,781 indexed, latest versions
Container images
17
deployed by those charts
Fix available
1 of 2
affected packages

Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload

Carried by container images the latest versions of 8 of 17,781 indexed charts deploy, on 17 images.

Affected packageAffected versionsFixed inImages
dulwichpypi0.24.10, 0.25.2, 1.1.01.2.59
dulwichdeb0.21.6-1build2, 0.22.7-1no fix listed8
OSV records
DEBIAN-CVE-2026-52726GHSA-gfhv-vqv2-4544UBUNTU-CVE-2026-52726
Also known as
PYSEC-2026-2465

Charts affected

8 by stars
ChartLatestAffected imagesRadar Score
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-52726.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
dulwich@0.21.6-1build2
no fix listed

Open the chart page →

4,556
py-kube-downscalerpy-kube-downscalerVerified publisher0.3.121 of 1See more

py-kube-downscaler py-kube-downscaler 0.3.12

1 of the 1 container images this version deploys carry CVE-2026-52726.

Container imageDigestPackageFixed in
ghcr.io/caas-team/py-kube-downscaler:26.4.0af05a098b0d2
dulwich@1.1.0
1.2.5

Open the chart page →

731
redminemt1905027.3.41 of 3See more

redmine mt190502 7.3.4

1 of the 3 container images this version deploys carry CVE-2026-52726.

Container imageDigestPackageFixed in
library/redmine:6.1.204ac44a2595b
dulwich@0.22.7-1
no fix listed

Open the chart page →

7,527
redmineredmine-helm-chartVerified publisher0.2.61 of 1See more

redmine redmine-helm-chart 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-52726.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
dulwich@0.22.7-1
no fix listed

Open the chart page →

4,240
deployhubdeployhubVerified publisher10.0.4157 of 11See more

deployhub deployhub 10.0.415

7 of the 11 container images this version deploys carry CVE-2026-52726.

Container imageDigestPackageFixed in
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
dulwich@0.24.10
1.2.5
quay.io/ortelius/ms-dep-pkg-cud:main-v10.0.1670-g9abe110c0c881b509a
dulwich@0.24.10
1.2.5
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
dulwich@0.24.10
1.2.5
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
dulwich@0.24.10
1.2.5
quay.io/ortelius/ms-scorecard:main-v10.0.1276-g966a8a43337e52fdd4
dulwich@0.24.10
1.2.5
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
dulwich@0.24.10
1.2.5
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
dulwich@0.24.10
1.2.5

Open the chart page →

11,160
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.05 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

5 of the 40 container images this version deploys carry CVE-2026-52726.

Container imageDigestPackageFixed in
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
dulwich@0.21.6-1build2
no fix listed
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
dulwich@0.21.6-1build2
no fix listed
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
dulwich@0.21.6-1build2
no fix listed
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
dulwich@0.21.6-1build2
no fix listed
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
dulwich@0.21.6-1build2
no fix listed

Open the chart page →

71,208
redminerestic-pvc-backupVerified publisher0.2.61 of 1See more

redmine restic-pvc-backup 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-52726.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
dulwich@0.22.7-1
no fix listed

Open the chart page →

4,240
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2026-52726.

Container imageDigestPackageFixed in
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
dulwich@0.25.2
1.2.5

Open the chart page →

66,266

Container images carrying it

17 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/redmine:6.1.3-trixief474a901faec
dulwich@0.22.7-1
no fix listed
2
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
dulwich@0.21.6-1build2
no fix listed
1
library/redmine:6.1.204ac44a2595b
dulwich@0.22.7-1
no fix listed
1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
dulwich@0.25.2
1.2.5
1
ghcr.io/caas-team/py-kube-downscaler:26.4.0af05a098b0d2
dulwich@1.1.0
1.2.5
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
dulwich@0.21.6-1build2
no fix listed
1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
dulwich@0.21.6-1build2
no fix listed
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
dulwich@0.21.6-1build2
no fix listed
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
dulwich@0.21.6-1build2
no fix listed
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
dulwich@0.21.6-1build2
no fix listed
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
dulwich@0.24.10
1.2.5
1
quay.io/ortelius/ms-dep-pkg-cud:main-v10.0.1670-g9abe110c0c881b509a
dulwich@0.24.10
1.2.5
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
dulwich@0.24.10
1.2.5
1
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
dulwich@0.24.10
1.2.5
1
quay.io/ortelius/ms-scorecard:main-v10.0.1276-g966a8a43337e52fdd4
dulwich@0.24.10
1.2.5
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
dulwich@0.24.10
1.2.5
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
dulwich@0.24.10
1.2.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.