StackRadar

CVE-2026-54274

High

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.003
23rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
158
of 17,781 indexed, latest versions
Container images
159
deployed by those charts
Fix available
1 of 2
affected packages

aiohttp: Incomplete websocket frame payloads bypass memory limits

Carried by container images the latest versions of 158 of 17,781 indexed charts deploy, on 159 images.

Affected packageAffected versionsFixed inImages
aiohttppypi3.4.4, 3.5.4, 3.6.2, 3.7.1+33 more3.14.1159
python-aiohttpdeb3.8.4-1, 3.11.16-1+deb13u1no fix listed2
OSV records
DEBIAN-CVE-2026-54274GHSA-xcgm-r5h9-7989
Also known as
PYSEC-2026-2108

Charts affected

158 by stars
ChartLatestAffected imagesRadar Score
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54274.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
aiohttp@3.9.5
3.14.1

Open the chart page →

1,515
traefik-external-dns-operatortraefik-external-dns-operator1.0.11 of 1See more

traefik-external-dns-operator traefik-external-dns-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-54274.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
aiohttp@3.11.14
3.14.1

Open the chart page →

1,083
orchestratremolo3.1.551 of 5See more

orchestra tremolo 3.1.55

1 of the 5 container images this version deploys carry CVE-2026-54274.

Container imageDigestPackageFixed in
ghcr.io/tremolosecurity/python-slim-nonroot/python3:1.0.079bb14620fe9
aiohttp@3.14.0
3.14.1

Open the chart page →

7,637
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-54274.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
aiohttp@3.8.1
3.14.1

Open the chart page →

8,607
wasabi-s3-operatorwasabi-s3-operatorVerified publisher0.2.71 of 1See more

wasabi-s3-operator wasabi-s3-operator 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-54274.

Container imageDigestPackageFixed in
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
aiohttp@3.13.5
3.14.1

Open the chart page →

628
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-54274.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
aiohttp@3.7.4
3.14.1

Open the chart page →

11,119
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-54274.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.14.1

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-54274.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.14.1

Open the chart page →

1,636

Container images carrying it

159 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
intelowlproject/intelowl:v6.6.10b22e547ea6b
aiohttp@3.13.5
3.14.1
1
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
aiohttp@3.7.4
3.14.1
1
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
aiohttp@3.8.5
3.14.1
1
jupyterjsc/jupyterhub-outpost:2.3.1aea53b13f235
aiohttp@3.13.5
3.14.1
1
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
aiohttp@3.13.5
3.14.1
1
kenchrcum/hetzner-s3-operator:0.1.384dae7aeea5b
aiohttp@3.13.5
3.14.1
1
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
aiohttp@3.13.5
3.14.1
1
knspar/phronetis-operator:0.1.60c4f0543ee58
aiohttp@3.12.13
3.14.1
1
langgenius/dify-api:1.0.0066035f93856
aiohttp@3.11.12
3.14.1
1
langgenius/dify-api:0.6.11fca918260dd6
aiohttp@3.9.5
3.14.1
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
aiohttp@3.13.3
3.14.1
1
lsstsqre/kafkaaggregator:masterbe1b21060854
aiohttp@3.7.4
3.14.1
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
aiohttp@3.8.1
3.14.1
1
makersquad/harp-proxy:0.8.1a40dd258c527
aiohttp@3.11.18
3.14.1
1
milesmcc/shynet:v0.13.1ba54f7797a6b
aiohttp@3.8.1
3.14.1
1
milesmcc/shynet:v0.12.0e821e31140f7
aiohttp@3.8.1
3.14.1
1
mindsdb/mindsdb:latest163011c09299
aiohttp@3.13.5
3.14.1
1
opea/asr:1.025dd26d9cd09
aiohttp@3.10.5
3.14.1
1
opea/chatqna:1.038c51b791efa
aiohttp@3.10.5
3.14.1
1
opea/codegen:1.058f91683892d
aiohttp@3.10.5
3.14.1
1
opea/codetrans:1.0e2436483b73d
aiohttp@3.10.5
3.14.1
1
opea/docsum:1.03eaa91849512
aiohttp@3.10.5
3.14.1
1
opea/guardrails-tgi:1.0262c6048aab8
aiohttp@3.10.5
3.14.1
1
opea/guardrails-tgi:latestf68bec6a1271
aiohttp@3.11.11
3.14.1
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
aiohttp@3.10.5
3.14.1
1
opea/speecht5:1.0249afad3d268
aiohttp@3.10.5
3.14.1
1
opea/tts:1.0257ae94709e9
aiohttp@3.10.5
3.14.1
1
opea/web-retriever-chroma:1.0fe08165d7770
aiohttp@3.10.5
3.14.1
1
openbas/caldera-server:5.1.0a277796d9724
aiohttp@3.10.8
3.14.1
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
aiohttp@3.12.13
3.14.1
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
aiohttp@3.10.11
3.14.1
1
opencsghq/csgship-agentic:v0.4.02cd29671a03e
aiohttp@3.12.15
3.14.1
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
aiohttp@3.12.15
3.14.1
1
opendatacube/restcube:latest91870111837c
aiohttp@3.6.2
3.14.1
1
opendatacube/wms:latest1b90cdf68831
aiohttp@3.6.2
3.14.1
1
openmined/syft-backend:0.9.5b72f74a68b32
aiohttp@3.11.12
3.14.1
1
pangeo/base-notebook:2024.01.155fbe688a4f80
aiohttp@3.9.1
3.14.1
1
phntom/email-manager:0.1.22d8e2a9f2f085
aiohttp@3.8.4
3.14.1
1
prowlercloud/prowler-api:5.31.14f252d579be2
aiohttp@3.14.0
3.14.1
1
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
aiohttp@3.13.5
3.14.1
1
rommapp/romm:4.4.1b909e95d1aab
aiohttp@3.12.14
3.14.1
1
runx1/opta-agent:latest0ca3867d3200
aiohttp@3.8.1
3.14.1
1
saidsef/scapy-containerised:v2025.02f17f7c435891
aiohttp@3.11.12
3.14.1
1
salehmir/jesse:1.10.101afa95f979e9
aiohttp@3.12.12
3.14.1
1
semaphoreui/semaphore:v2.9.645b50bc11833f
aiohttp@3.8.5
3.14.1
1
skylenet/ethereum-genesis-generator:latest210353ce7c89
aiohttp@3.8.3
3.14.1
1
sruthitanneru/pi-sample:ui-lateste565ea454ffd
aiohttp@3.11.8
3.14.1
1
stratospire/activityrelay:0.2.3a4c34cb01117
aiohttp@3.8.3
3.14.1
1
substratusai/verba:v0.4.0-baseURL261695be635eb
aiohttp@3.9.5
3.14.1
1
thelande/kasa_exporter:v0.2.3a1fdb8baa152
aiohttp@3.9.5
3.14.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.