StackRadar

CVE-2026-54770

Medium

Advisory

Published 27 Aug 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.003
27th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
18
of 17,781 indexed, latest versions
Container images
28
deployed by those charts
Fix available
1 of 1
affected package

WebOb: Open redirect in Location header normalization via leading C0 control / space characters

Carried by container images the latest versions of 18 of 17,781 indexed charts deploy, on 28 images.

Affected packageAffected versionsFixed inImages
webobpypi1.2.3, 1.4.1, 1.8.2, 1.8.5+2 more1.8.1128
OSV records
GHSA-6hx8-3wjj-gr8g
Also known as
PYSEC-2026-3943

Charts affected

18 by stars
ChartLatestAffected imagesRadar Score
stackstorm-hastackstormVerified publisher1.1.011 of 17See more

stackstorm-ha stackstorm 1.1.0

11 of the 17 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
webob@1.8.7
1.8.11
stackstorm/st2api:3.86f56d239d280
webob@1.8.7
1.8.11
stackstorm/st2auth:3.833ecfda16608
webob@1.8.7
1.8.11
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
webob@1.8.7
1.8.11
stackstorm/st2notifier:3.8f190a6212195
webob@1.8.7
1.8.11
stackstorm/st2rulesengine:3.8259503496ff9
webob@1.8.7
1.8.11
stackstorm/st2scheduler:3.8b1de2055c362
webob@1.8.7
1.8.11
stackstorm/st2sensorcontainer:3.8b1a338f64773
webob@1.8.7
1.8.11
stackstorm/st2stream:3.81c8904a3bf67
webob@1.8.7
1.8.11
stackstorm/st2timersengine:3.81bf35bfaf00c
webob@1.8.7
1.8.11
stackstorm/st2workflowengine:3.819fdfffdbba8
webob@1.8.7
1.8.11

Open the chart page →

96,419
syncstorage-rschristianhuthVerified publisher6.1.11 of 2See more

syncstorage-rs christianhuth 6.1.1

1 of the 2 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
ghcr.io/porelli/firefox-sync:syncstorage-rs-mysql-0.18.27d244e514216
webob@1.8.9
1.8.11

Open the chart page →

693
devpisb-helm-charts0.3.01 of 1See more

devpi sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
jonasal/devpi-server:6.17.0-alpineec1eee99a18d
webob@1.8.9
1.8.11

Open the chart page →

920
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
webob@1.8.5
1.8.11

Open the chart page →

24,930
radosgwananace-chartsVerified publisher0.3.41 of 1See more

radosgw ananace-charts 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
ceph/daemon:latest-nautilus90f30824a96e
webob@1.2.3
1.8.11

Open the chart page →

1,650
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
webob@1.8.7
1.8.11
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
webob@1.8.7
1.8.11

Open the chart page →

22,568
syncserverchristianhuthVerified publisher1.3.01 of 1See more

syncserver christianhuth 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
mozilla/syncserver:latest016162bf39d8
webob@1.8.5
1.8.11

Open the chart page →

1,382
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
webob@1.8.9
1.8.11

Open the chart page →

4,601
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
webob@1.4.1
1.8.11

Open the chart page →

70,895
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
webob@1.8.9
1.8.11

Open the chart page →

6,162
errbotmidokura-communityVerified publisher0.0.51 of 1See more

errbot midokura-community 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
errbotio/errbot:6.1.900ee4e0953ab
webob@1.8.7
1.8.11

Open the chart page →

2,233
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
webob@1.8.2
1.8.11

Open the chart page →

55,726
comacopencord1.0.02 of 9See more

comac opencord 1.0.0

2 of the 9 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
webob@1.8.2
1.8.11
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
webob@1.8.2
1.8.11

Open the chart page →

88,546
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
webob@1.8.2
1.8.11

Open the chart page →

26,211
devpiowan-charts0.1.01 of 1See more

devpi owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
owanio1992/devpi:6.16.04ade8e1e4d7e
webob@1.8.9
1.8.11

Open the chart page →

510
syncstorageschichtelVerified publisher0.1.11 of 1See more

syncstorage schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
mozilla/syncstorage-rs:0.15.893752877dced
webob@1.8.7
1.8.11

Open the chart page →

1,318
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
webob@1.8.5
1.8.11

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-54770.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
webob@1.8.5
1.8.11

Open the chart page →

11,784

Container images carrying it

28 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
webob@1.8.2
1.8.11
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
webob@1.8.5
1.8.11
2
ceph/daemon:latest-nautilus90f30824a96e
webob@1.2.3
1.8.11
1
errbotio/errbot:6.1.900ee4e0953ab
webob@1.8.7
1.8.11
1
galaxy/galaxy-init:v18.010267bad550e6
webob@1.4.1
1.8.11
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
webob@1.8.9
1.8.11
1
jonasal/devpi-server:6.17.0-alpineec1eee99a18d
webob@1.8.9
1.8.11
1
mozilla/syncserver:latest016162bf39d8
webob@1.8.5
1.8.11
1
mozilla/syncstorage-rs:0.15.893752877dced
webob@1.8.7
1.8.11
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
webob@1.8.2
1.8.11
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
webob@1.8.2
1.8.11
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
webob@1.8.7
1.8.11
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
webob@1.8.7
1.8.11
1
owanio1992/devpi:6.16.04ade8e1e4d7e
webob@1.8.9
1.8.11
1
stackstorm/st2actionrunner:3.888235ba70cad
webob@1.8.7
1.8.11
1
stackstorm/st2api:3.86f56d239d280
webob@1.8.7
1.8.11
1
stackstorm/st2auth:3.833ecfda16608
webob@1.8.7
1.8.11
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
webob@1.8.7
1.8.11
1
stackstorm/st2notifier:3.8f190a6212195
webob@1.8.7
1.8.11
1
stackstorm/st2rulesengine:3.8259503496ff9
webob@1.8.7
1.8.11
1
stackstorm/st2scheduler:3.8b1de2055c362
webob@1.8.7
1.8.11
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
webob@1.8.7
1.8.11
1
stackstorm/st2stream:3.81c8904a3bf67
webob@1.8.7
1.8.11
1
stackstorm/st2timersengine:3.81bf35bfaf00c
webob@1.8.7
1.8.11
1
stackstorm/st2workflowengine:3.819fdfffdbba8
webob@1.8.7
1.8.11
1
statcan/ckan:2.93921305425b8
webob@1.8.5
1.8.11
1
ghcr.io/porelli/firefox-sync:syncstorage-rs-mysql-0.18.27d244e514216
webob@1.8.9
1.8.11
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
webob@1.8.9
1.8.11
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.