StackRadar

CVE-2026-57585

High

Advisory

Published 19 Jun 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
273
of 17,781 indexed, latest versions
Container images
274
deployed by those charts
Fix available
1 of 3
affected packages

MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error

Carried by container images the latest versions of 273 of 17,781 indexed charts deploy, on 274 images.

Affected packageAffected versionsFixed inImages
msgpackpypi0.5.6, 0.6.0, 0.6.1, 0.6.2+10 more1.2.1181
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+22 moreno fix listed107
python-msgpackdeb1.0.3-1build1, 1.0.3-2+b1, 1.0.3-3build2no fix listed8
OSV records
DEBIAN-CVE-2026-57585GHSA-6v7p-g79w-8964UBUNTU-CVE-2026-57585
Also known as
PYSEC-2026-3625

Charts affected

273 by stars
ChartLatestAffected imagesRadar Score
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
msgpack@1.1.0
1.2.1

Open the chart page →

7,901
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
python-pip@20.0.2-5ubuntu1.6
no fix listed

Open the chart page →

30,687
downscalersqream-chartsVerified publisher1.0.01 of 1See more

downscaler sqream-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.05d328c003efe
msgpack@1.0.4
1.2.1

Open the chart page →

1,009
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python-pip@20.0.2-5ubuntu1.10
no fix listed

Open the chart page →

10,134
icinga2svtech-public-helm-charts1.0.01 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
msgpack@1.0.5
1.2.1

Open the chart page →

5,511
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
msgpack@1.0.4
1.2.1

Open the chart page →

18,756
rundeck-option-providersvtech-public-helm-charts1.0.01 of 2See more

rundeck-option-provider svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
msgpack@1.0.5
1.2.1

Open the chart page →

1,428
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
python-pip@22.0.2+dfsg-1
no fix listed

Open the chart page →

17,461
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
msgpack@1.0.4
1.2.1

Open the chart page →

3,164
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

9,347
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

4,305
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
msgpack@1.0.3
python-msgpack@1.0.3-1build1
1.2.1
no fix listed

Open the chart page →

13,459
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
python-pip@24.0+dfsg-1ubuntu1.2
no fix listed

Open the chart page →

7,628
kongwallarmVerified publisher4.6.32 of 7See more

kong wallarm 4.6.3

2 of the 7 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/ingress-collectd:4.6.0-1fcfa8ba405bd
msgpack@1.0.0
1.2.1
wallarm/ingress-python:4.6.0-15cb2ae08b40f
msgpack@0.5.6
1.2.1

Open the chart page →

11,405
kong-previewwallarmVerified publisher4.2.31 of 5See more

kong-preview wallarm 4.2.3

1 of the 5 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/ingress-collectd:4.2.1-124dc4ca1ee1b
msgpack@1.0.0
1.2.1

Open the chart page →

2,905
wallarm-node-nextwallarmVerified publisher0.5.31 of 2See more

wallarm-node-next wallarm 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/node-helpers:5.0.2-1097cadc42336
msgpack@1.0.3
1.2.1

Open the chart page →

2,408
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/node-helpers:6.10.1aecd88b24c51
msgpack@1.0.8
1.2.1

Open the chart page →

2,824
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
msgpack@1.0.2
1.2.1

Open the chart page →

7,085
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
msgpack@1.0.0
1.2.1

Open the chart page →

4,086
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
msgpack@1.0.2
1.2.1

Open the chart page →

2,643

Container images carrying it

274 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
cloudve/janis-terminal:latestaf56e77ca587
python-pip@9.0.1-2.3~ubuntu1.18.04.1
no fix listed
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
msgpack@1.1.0
1.2.1
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
msgpack@1.1.0
1.2.1
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
msgpack@1.1.0
1.2.1
1
daskdev/dask:1.1.04ecd7bc35500
msgpack@0.6.0
1.2.1
1
daskdev/dask-notebook:1.1.0052630f5ca04
msgpack@0.6.0
1.2.1
1
datamate/seafile-professional:11.0.202dd66b722464
python-pip@22.0.2+dfsg-1ubuntu0.6
no fix listed
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
msgpack@1.0.0
1.2.1
1
datawire/aes:1.13.62beb65062c8b
msgpack@1.0.0
1.2.1
1
datawire/emissary:2.0.2-ea9716efbdd24b
msgpack@1.0.0
1.2.1
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
msgpack@1.0.8
1.2.1
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
msgpack@1.0.8
1.2.1
1
ddosify/selfhosted_backend:3.2.93c11e3182652
msgpack@1.0.8
1.2.1
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
msgpack@1.0.8
1.2.1
1
deconzcommunity/deconz:2.29.2062de2362641
msgpack@1.0.3
python-msgpack@1.0.3-2+b1
1.2.1
no fix listed
1
djjudas21/autonodelabel:0.0.6f17233350c4f
msgpack@1.0.5
1.2.1
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
python-pip@20.0.2-5ubuntu1.11
no fix listed
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
msgpack@1.0.4
1.2.1
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
python-pip@20.0.2-5ubuntu1.11
no fix listed
1
flyway/flyway:9.1545b5d7cdc75a
python-pip@20.0.2-5ubuntu1.8
no fix listed
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
python-pip@9.0.1-2.3~ubuntu1.18.04.6
no fix listed
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
python-pip@9.0.1-2.3~ubuntu1.18.04.5
no fix listed
1
galaxy/cloudman-server:lateste5c265fe9fcd
msgpack@1.0.4
python-pip@20.0.2-5ubuntu1.6
1.2.1
no fix listed
1
galaxy/galaxy-init:v18.010267bad550e6
python-pip@1.5.4-1ubuntu4
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
python-pip@1.5.4-1ubuntu4
no fix listed
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
python-pip@22.0.2+dfsg-1ubuntu0.7
no fix listed
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
msgpack@1.0.0
python-pip@9.0.1-2.3~ubuntu1.18.04.2
1.2.1
no fix listed
1
gethue/hue:4.11.011b649636e68
msgpack@1.0.4
python-pip@20.0.2-5ubuntu1.6
1.2.1
no fix listed
1
gethue/hue:4.10.05702b2c37ff9
msgpack@1.0.2
python-pip@9.0.1-2.3~ubuntu1.18.04.5
1.2.1
no fix listed
1
gethue/hue:latest7d5c1b9f8a79
msgpack@1.1.2
python-pip@22.0.2+dfsg-1ubuntu0.6
1.2.1
no fix listed
1
gluufederation/opendj:4.3.0_011a1128b28b95
msgpack@1.0.2
1.2.1
1
gmelillo/registry:0.1.8c599d608a2f7
msgpack@1.0.2
1.2.1
1
grafana/oncall:v1.16.5499851658393
msgpack@1.1.0
1.2.1
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
msgpack@0.6.2
1.2.1
1
greenbirdit/locust:0.9.0e99d53bdc944
msgpack@0.6.0
1.2.1
1
hansehe/locust:1.1.0bc8e45262bc4
msgpack@1.1.0
1.2.1
1
hayk96/alerta-web:9.0.486377705e9e3
msgpack@1.0.8
1.2.1
1
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
python-pip@20.0.2-5ubuntu1.11
no fix listed
1
hjacobs/kube-downscaler:23.2.05d328c003efe
msgpack@1.0.4
1.2.1
1
hjacobs/kube-janitor:23.7.0fbb303ed463c
msgpack@1.0.5
1.2.1
1
hjacobs/kube-ops-view:23.5.0a4fae38f93d7
msgpack@1.0.5
1.2.1
1
hjacobs/kube-resource-report:21.2.145f93491c434
msgpack@1.0.2
1.2.1
1
hjacobs/kube-resource-report:22.11.0c173cd02f5af
msgpack@1.0.4
1.2.1
1
hjacobs/kube-web-view:23.8.0431f1bf013d0
msgpack@1.0.5
1.2.1
1
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
msgpack@1.0.0
1.2.1
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
msgpack@1.0.3
1.2.1
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
msgpack@1.0.7
1.2.1
1
homeassistant/home-assistant:2023.12.48d000332b09b
msgpack@1.0.7
1.2.1
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
msgpack@1.1.2
1.2.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.