StackRadar

CVE-2026-57175

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
6.4
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
422
of 17,844 indexed, latest versions
Container images
393
deployed by those charts
Fix available
1 of 10
affected packages

social-auth-core has an Improper Authentication issue

Carried by container images the latest versions of 422 of 17,844 indexed charts deploy, on 393 images.

Affected packageAffected versionsFixed inImages
social-auth-corepypi3.2.0, 3.3.3, 4.3.0, 4.5.2+5 more5.0.010
python3.8deb3.8.0-3ubuntu1~18.04.2, 3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3+12 moreno fix listed102
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3+12 moreno fix listed89
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+17 moreno fix listed80
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+14 moreno fix listed62
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 moreno fix listed52
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9no fix listed23
python3.14deb3.14.4-1, 3.14.4-1ubuntu0.1, 3.14.4-1ubuntu0.2no fix listed9
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7no fix listed7
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1no fix listed2
OSV records
GHSA-vq6g-g6c7-5f2jUBUNTU-CVE-2026-57175
Trending
Rank 27 in indexed charts, since 25 Sept 2026. See the ranking →

Charts affected

422 by stars
ChartLatestAffected imagesRadar Score
todoapitodoapi-appVerified publisher0.1.01 of 2See more

todoapi todoapi-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
python2.7@2.7.17-1~18.04ubuntu1.11
python3.6@3.6.9-1~18.04ubuntu1.12
no fix listed
no fix listed

Open the chart page →

7,191
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.2.0-v10e44b2b49d059
python3.10@3.10.12-1~22.04.3
no fix listed

Open the chart page →

5,748
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
python3.12@3.12.3-1
no fix listed

Open the chart page →

46,049
lightstepupdater-lightstep-satellite1.2.21 of 1See more

lightstep updater-lightstep-satellite 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
python3.5@3.5.2-2ubuntu0~16.04.5
no fix listed

Open the chart page →

15,790
tdarrvhdirkVerified publisher5.0.52 of 2See more

tdarr vhdirk 5.0.5

2 of the 2 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
python2.7@2.7.18-1~20.04.3
python3.8@3.8.10-0ubuntu1~20.04.8
no fix listed
no fix listed
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
python2.7@2.7.18-1~20.04.1
python3.8@3.8.10-0ubuntu1~20.04.4
no fix listed
no fix listed

Open the chart page →

160,419
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
python3.10@3.10.12-1~22.04.3
no fix listed

Open the chart page →

78,951
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
python3.12@3.12.3-1ubuntu0.12
no fix listed

Open the chart page →

4,699
twenty-crmvictorlane0.0.12 of 3See more

twenty-crm victorlane 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
redis/redis-stack-server:latest798ab84d9f26
python3.10@3.10.12-1~22.04.11
no fix listed
twentycrm/twenty-postgres-spilo:latest2f78405a78be
python3.10@3.10.12-1~22.04.3
no fix listed

Open the chart page →

71,522
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
python3.12@3.12.3-1ubuntu0.8
no fix listed

Open the chart page →

8,304
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
python3.8@3.8.10-0ubuntu1~20.04.2
no fix listed

Open the chart page →

11,472
myweatherhelmwebapp11.3.502 of 8See more

myweatherhelm webapp1 1.3.50

2 of the 8 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
python3.12@3.12.3-1ubuntu0.9
no fix listed
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
python3.8@3.8.10-0ubuntu1~20.04.8
no fix listed

Open the chart page →

9,760
myweatherhelm-schedulingwebapp11.3.922 of 9See more

myweatherhelm-scheduling webapp1 1.3.92

2 of the 9 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
python3.12@3.12.3-1ubuntu0.9
no fix listed
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
python3.8@3.8.10-0ubuntu1~20.04.8
no fix listed

Open the chart page →

9,760
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
python3.8@3.8.10-0ubuntu1~20.04.1
no fix listed

Open the chart page →

14,815
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
python3.8@3.8.10-0ubuntu1~20.04.1
no fix listed

Open the chart page →

29,371
emissary-ingresswener8.12.21 of 2See more

emissary-ingress wener 8.12.2

1 of the 2 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
python3.6@3.6.9-1~18.04ubuntu1.1
no fix listed

Open the chart page →

77,130
longhornwener1.2.31 of 2See more

longhorn wener 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
python3.8@3.8.10-0ubuntu1~20.04.2
no fix listed

Open the chart page →

15,767
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
python3.6@3.6.9-1~18.04ubuntu1.1
no fix listed

Open the chart page →

77,130
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
python3.8@3.8.10-0ubuntu1~20.04.2
no fix listed

Open the chart page →

15,767
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
python3.10@3.10.12-1~22.04.3
no fix listed

Open the chart page →

9,589
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
python3.10@3.10.12-1~22.04.3
no fix listed

Open the chart page →

14,813
nightingalexxl-job-adminVerified publisher0.2.111 of 6See more

nightingale xxl-job-admin 0.2.11

1 of the 6 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
python3.12@3.12.3-1ubuntu0.12
no fix listed

Open the chart page →

10,103
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-57175.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
python3.10@3.10.12-1~22.04.16
no fix listed

Open the chart page →

8,360

Container images carrying it

393 by charts deploying them

A fixed version is listed for 1 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
oomk8s/readiness-check:2.0.2875814cc853d
python2.7@2.7.12-1ubuntu0~16.04.4
python3.5@3.5.2-2ubuntu0~16.04.5
no fix listed
no fix listed
11
library/rabbitmq:3.9-management8a279e9396a8
python3.10@3.10.12-1~22.04.3
no fix listed
10
library/rabbitmq:3.13-management:3-managemente582c0bc7766
python3.12@3.12.3-1ubuntu0.9
no fix listed
8
oomk8s/readiness-check:2.0.07daa08b81954
python2.7@2.7.12-1ubuntu0~16.04.3
python3.5@3.5.2-2ubuntu0~16.04.4
no fix listed
no fix listed
6
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
python2.7@2.7.12-1ubuntu0~16.04.3
python3.5@3.5.2-2ubuntu0~16.04.4
no fix listed
no fix listed
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
python2.7@2.7.12-1ubuntu0~16.04.4
python3.5@3.5.2-2ubuntu0~16.04.5
no fix listed
no fix listed
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
python3.10@3.10.12-1~22.04.3
no fix listed
4
library/rabbitmq:3.11-managementc3f70098e01d
python3.10@3.10.12-1~22.04.3
no fix listed
4
cloudve/cloudlaunch-server:latest4a3d7fae90bb
python3.8@3.8.10-0ubuntu1~20.04.1
no fix listed
3
dgraph/dgraph:v21.12.03b55ea83fffe
python3.8@3.8.10-0ubuntu1~20.04
no fix listed
3
istio/kubectl:1.5.10dbb7726d1bf0
python3.6@3.6.9-1~18.04ubuntu1.1
no fix listed
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
python2.7@2.7.12-1ubuntu0~16.04.4
no fix listed
3
selenium/hub:3.141.5902f251d48d5f
python3.8@3.8.10-0ubuntu1~20.04
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
python3.10@3.10.6-1~22.04.2
no fix listed
3
apache/tika:2.9.2.1-fullae0b86d3c4d0
python3.12@3.12.3-1
no fix listed
2
flashcatcloud/categraf:latest42e6ab16472e
python3.12@3.12.3-1ubuntu0.12
no fix listed
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
python2.7@2.7.17-1~18.04
no fix listed
2
homebridge/homebridge:latest77c685a40911
python3.12@3.12.3-1ubuntu0.16
no fix listed
2
hookiesolutions/webhookie:latest0629694246ba
python3.8@3.8.10-0ubuntu1~20.04.1
no fix listed
2
istio/pilot:1.10.0294ca55bd1cc
python3.6@3.6.9-1~18.04ubuntu1.4
no fix listed
2
istio/proxyv2:1.9.687a9db561d2e
python3.6@3.6.9-1~18.04ubuntu1.4
no fix listed
2
istio/proxyv2:1.10.088c6c693e67a
python3.6@3.6.9-1~18.04ubuntu1.4
no fix listed
2
istio/proxyv2:1.10.3a78b7a165744
python3.6@3.6.9-1~18.04ubuntu1.4
no fix listed
2
library/cassandra:3.11.65aa8400b4b3b
python2.7@2.7.17-1~18.04ubuntu1.1
no fix listed
2
library/cassandra:4.1.37cbcec0086ac
python3.10@3.10.12-1~22.04.3
no fix listed
2
library/rabbitmq:4.1.0-management935b3f84c1e4
python3.12@3.12.3-1ubuntu0.5
no fix listed
2
library/rabbitmq:3.12.1-managementf020c06da226
python3.10@3.10.6-1~22.04.2ubuntu1.1
no fix listed
2
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
python3.5@3.5.2-2ubuntu0~16.04.5
no fix listed
2
longhornio/longhorn-manager:v1.2.3dca34321452c
python3.8@3.8.10-0ubuntu1~20.04.2
no fix listed
2
memgraph/memgraph:3.13.1bd3fe13228f4
python3.12@3.12.3-1ubuntu0.17
no fix listed
2
nacos/nacos-server:latest1c191c30c8cd
python3.14@3.14.4-1ubuntu0.1
no fix listed
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
python2.7@2.7.12-1ubuntu0~16.04.4
python3.5@3.5.2-2ubuntu0~16.04.5
no fix listed
no fix listed
2
opendatacube/ows:latest668cbb41473c
python3.12@3.12.3-1ubuntu0.3
no fix listed
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
python3.10@3.10.12-1~22.04.3
no fix listed
2
redis/redis-stack-server:7.4.0:7.4.0-v172035434f455
python3.10@3.10.12-1~22.04.6
no fix listed
2
redis/redis-stack-server:7.2.0-v10e44b2b49d059
python3.10@3.10.12-1~22.04.3
no fix listed
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
python3.8@3.8.10-0ubuntu1~20.04.5
no fix listed
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python3.8@3.8.10-0ubuntu1~20.04.9
no fix listed
2
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
python3.10@3.10.4-3
no fix listed
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
python3.10@3.10.6-1~22.04.2ubuntu1
no fix listed
2
weblate/weblate:4.2.2-169c160d37a3c
social-auth-core@3.3.3
5.0.0
2
wurstmeister/zookeeper:latest7a7fd44a7210
python2.7@2.7.6-8
python3.4@3.4.0-2ubuntu1
no fix listed
no fix listed
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
python3.12@3.12.3-1ubuntu0.17
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
python3.12@3.12.3-1ubuntu0.5
no fix listed
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
python2.7@2.7.18-13ubuntu1.1
python3.10@3.10.6-1~22.04
no fix listed
no fix listed
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
python3.8@3.8.10-0ubuntu1~20.04
no fix listed
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
python3.8@3.8.10-0ubuntu1~20.04.8
no fix listed
2
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
python2.7@2.7.17-1~18.04ubuntu1.11
python3.6@3.6.9-1~18.04ubuntu1.12
no fix listed
no fix listed
2
a10networks/acos-prometheus-exporter:latest8dc58d434d71
python3.6@3.6.9-1~18.04ubuntu1
no fix listed
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
python3.8@3.8.5-1~20.04
no fix listed
1

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.