StackRadar

CVE-2026-54273

High

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.003
20th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
158
of 17,781 indexed, latest versions
Container images
159
deployed by those charts
Fix available
1 of 2
affected packages

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

Carried by container images the latest versions of 158 of 17,781 indexed charts deploy, on 159 images.

Affected packageAffected versionsFixed inImages
aiohttppypi3.4.4, 3.5.4, 3.6.2, 3.7.1+33 more3.14.1159
python-aiohttpdeb3.8.4-1, 3.11.16-1+deb13u1no fix listed2
OSV records
DEBIAN-CVE-2026-54273GHSA-4fvr-rgm6-gqmc
Also known as
PYSEC-2026-2107

Charts affected

158 by stars
ChartLatestAffected imagesRadar Score
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54273.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
aiohttp@3.9.5
3.14.1

Open the chart page →

1,515
traefik-external-dns-operatortraefik-external-dns-operator1.0.11 of 1See more

traefik-external-dns-operator traefik-external-dns-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-54273.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
aiohttp@3.11.14
3.14.1

Open the chart page →

1,083
orchestratremolo3.1.551 of 5See more

orchestra tremolo 3.1.55

1 of the 5 container images this version deploys carry CVE-2026-54273.

Container imageDigestPackageFixed in
ghcr.io/tremolosecurity/python-slim-nonroot/python3:1.0.079bb14620fe9
aiohttp@3.14.0
3.14.1

Open the chart page →

7,637
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-54273.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
aiohttp@3.8.1
3.14.1

Open the chart page →

8,607
wasabi-s3-operatorwasabi-s3-operatorVerified publisher0.2.71 of 1See more

wasabi-s3-operator wasabi-s3-operator 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-54273.

Container imageDigestPackageFixed in
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
aiohttp@3.13.5
3.14.1

Open the chart page →

628
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-54273.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
aiohttp@3.7.4
3.14.1

Open the chart page →

11,119
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-54273.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.14.1

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-54273.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.14.1

Open the chart page →

1,636

Container images carrying it

159 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opea/llm-tgi:1.00c25aab3f106
aiohttp@3.10.5
3.14.1
4
quay.io/devtron/ai-agent:0.0.16545dac92173
aiohttp@3.10.10
3.14.1
3
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.14.1
2
opea/embedding-tei:1.05c9639de61c1
aiohttp@3.10.5
3.14.1
2
opea/reranking-tei:1.0e48613afb191
aiohttp@3.10.5
3.14.1
2
opea/retriever-redis:1.0eb746b263705
aiohttp@3.10.5
3.14.1
2
safeglobal/safe-config-service:latest09a5e495c219
aiohttp@3.13.5
3.14.1
2
vdiogov/glpi-conteiner:latest6945f84f0058
aiohttp@3.8.4
python-aiohttp@3.8.4-1
3.14.1
no fix listed
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
aiohttp@3.13.5
3.14.1
2
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
aiohttp@3.11.13
3.14.1
2
ghcr.io/xeor/karb:1.0.6:main647a3c938d31
aiohttp@3.13.3
3.14.1
2
acockburn/appdaemon:4.0.83a93281d7e94
aiohttp@3.7.4
3.14.1
1
alerta/alerta-web:8.5.04786b9eaa606
aiohttp@3.8.0
3.14.1
1
apache/airflow:2.8.4-python3.964e58748b6b9
aiohttp@3.9.3
3.14.1
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
aiohttp@3.10.5
3.14.1
1
apache/airflow:2.8.1e5560ad0b86e
aiohttp@3.9.1
3.14.1
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
aiohttp@3.7.4
3.14.1
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
aiohttp@3.11.16
3.14.1
1
aristidetm/basic-notebook:3.6.5469dbc951224
aiohttp@3.9.5
3.14.1
1
aristidetm/k8s-hub:3.3.7ccb516cb8474
aiohttp@3.9.3
3.14.1
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
aiohttp@3.7.4
3.14.1
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
aiohttp@3.9.3
3.14.1
1
baserow/backend:1.31.1e0b3c8130b91
aiohttp@3.9.5
3.14.1
1
baserow/baserow:1.30.1df0c42eb67e8
aiohttp@3.9.5
3.14.1
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
aiohttp@3.13.2
3.14.1
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
aiohttp@3.13.5
3.14.1
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
aiohttp@3.13.3
3.14.1
1
ciuse99/suggestarr:v1.0.20d72768245ef5
aiohttp@3.11.12
3.14.1
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
aiohttp@3.11.10
3.14.1
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
aiohttp@3.11.10
3.14.1
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
aiohttp@3.11.10
3.14.1
1
codaprotocol/buildkite-exporter:0.2.137c68e67a401
aiohttp@3.7.3
3.14.1
1
cznic/knot-resolver:v6.4.2fe71c5214fdc
aiohttp@3.11.16
python-aiohttp@3.11.16-1+deb13u1
3.14.1
no fix listed
1
datamate/seafile-professional:11.0.202dd66b722464
aiohttp@3.12.15
3.14.1
1
deepflowce/deepflow-app:v6.2.6.5a1888d35e787
aiohttp@3.4.4
3.14.1
1
devopstales/trivy-operator:2.575136aa7a26e
aiohttp@3.8.3
3.14.1
1
dserio83/velero-api:0.3.16b3d9115fee2
aiohttp@3.12.12
3.14.1
1
evk02/mlflow:2.2.1ef6ff257ef35
aiohttp@3.8.4
3.14.1
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
aiohttp@3.8.3
3.14.1
1
flag5/clustersecret:0.0.94ad5748bfcc6
aiohttp@3.8.1
3.14.1
1
galaxy/cloudman-server:lateste5c265fe9fcd
aiohttp@3.8.1
3.14.1
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
aiohttp@3.11.18
3.14.1
1
guillh/web3-prometheus-exporter:0.3.04fb99dbc32b2
aiohttp@3.10.3
3.14.1
1
halkeye/slack-resurrect:v0.1.477b05e95fdb5
aiohttp@3.5.4
3.14.1
1
hayk96/alerta-web:9.0.486377705e9e3
aiohttp@3.10.5
3.14.1
1
hhyo/archery:v1.9.11aa41843419e
aiohttp@3.8.3
3.14.1
1
hjacobs/kube-web-view:23.8.0431f1bf013d0
aiohttp@3.8.4
3.14.1
1
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
aiohttp@3.6.2
3.14.1
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
aiohttp@3.8.5
3.14.1
1
homeassistant/home-assistant:2023.12.48d000332b09b
aiohttp@3.9.1
3.14.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.