StackRadar

CVE-2026-54280

High

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
158
of 17,781 indexed, latest versions
Container images
159
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 158 of 17,781 indexed charts deploy, on 159 images.

Affected packageAffected versionsFixed inImages
aiohttppypi3.4.4, 3.5.4, 3.6.2, 3.7.1+33 more3.14.1159
python-aiohttpdeb3.8.4-1, 3.11.16-1+deb13u1no fix listed2
OSV records
DEBIAN-CVE-2026-54280PYSEC-2026-2113
Also known as
GHSA-9x8q-7h8h-wcw9

Charts affected

158 by stars
ChartLatestAffected imagesRadar Score
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54280.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
aiohttp@3.9.5
3.14.1

Open the chart page →

1,515
traefik-external-dns-operatortraefik-external-dns-operator1.0.11 of 1See more

traefik-external-dns-operator traefik-external-dns-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-54280.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
aiohttp@3.11.14
3.14.1

Open the chart page →

1,083
orchestratremolo3.1.551 of 5See more

orchestra tremolo 3.1.55

1 of the 5 container images this version deploys carry CVE-2026-54280.

Container imageDigestPackageFixed in
ghcr.io/tremolosecurity/python-slim-nonroot/python3:1.0.079bb14620fe9
aiohttp@3.14.0
3.14.1

Open the chart page →

7,637
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-54280.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
aiohttp@3.8.1
3.14.1

Open the chart page →

8,607
wasabi-s3-operatorwasabi-s3-operatorVerified publisher0.2.71 of 1See more

wasabi-s3-operator wasabi-s3-operator 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-54280.

Container imageDigestPackageFixed in
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
aiohttp@3.13.5
3.14.1

Open the chart page →

628
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-54280.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
aiohttp@3.7.4
3.14.1

Open the chart page →

11,119
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-54280.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.14.1

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-54280.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.14.1

Open the chart page →

1,636

Container images carrying it

159 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
aiohttp@3.11.11
3.14.1
1
quay.io/evl.ms/argocd-exporter:0.0.136ea8f34aa6b
aiohttp@3.7.4.post0
3.14.1
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
aiohttp@3.13.5
3.14.1
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
aiohttp@3.13.5
3.14.1
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
aiohttp@3.9.1
3.14.1
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
aiohttp@3.13.5
3.14.1
1
quay.io/maxiv/pieeat:0.9.3099715479210
aiohttp@3.13.5
3.14.1
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
aiohttp@3.8.1
3.14.1
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
aiohttp@3.9.5
3.14.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.