StackRadar

CVE-2026-57585

High

Advisory

Published 19 Jun 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
273
of 17,781 indexed, latest versions
Container images
274
deployed by those charts
Fix available
1 of 3
affected packages

MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error

Carried by container images the latest versions of 273 of 17,781 indexed charts deploy, on 274 images.

Affected packageAffected versionsFixed inImages
msgpackpypi0.5.6, 0.6.0, 0.6.1, 0.6.2+10 more1.2.1181
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+22 moreno fix listed107
python-msgpackdeb1.0.3-1build1, 1.0.3-2+b1, 1.0.3-3build2no fix listed8
OSV records
DEBIAN-CVE-2026-57585GHSA-6v7p-g79w-8964UBUNTU-CVE-2026-57585
Also known as
PYSEC-2026-3625

Charts affected

273 by stars
ChartLatestAffected imagesRadar Score
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
msgpack@1.1.0
1.2.1

Open the chart page →

7,901
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
python-pip@20.0.2-5ubuntu1.6
no fix listed

Open the chart page →

30,687
downscalersqream-chartsVerified publisher1.0.01 of 1See more

downscaler sqream-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.05d328c003efe
msgpack@1.0.4
1.2.1

Open the chart page →

1,009
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python-pip@20.0.2-5ubuntu1.10
no fix listed

Open the chart page →

10,134
icinga2svtech-public-helm-charts1.0.01 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
msgpack@1.0.5
1.2.1

Open the chart page →

5,511
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
msgpack@1.0.4
1.2.1

Open the chart page →

18,756
rundeck-option-providersvtech-public-helm-charts1.0.01 of 2See more

rundeck-option-provider svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
msgpack@1.0.5
1.2.1

Open the chart page →

1,428
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
python-pip@22.0.2+dfsg-1
no fix listed

Open the chart page →

17,461
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
msgpack@1.0.4
1.2.1

Open the chart page →

3,164
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

9,347
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

4,305
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
msgpack@1.0.3
python-msgpack@1.0.3-1build1
1.2.1
no fix listed

Open the chart page →

13,459
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
python-pip@24.0+dfsg-1ubuntu1.2
no fix listed

Open the chart page →

7,628
kongwallarmVerified publisher4.6.32 of 7See more

kong wallarm 4.6.3

2 of the 7 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/ingress-collectd:4.6.0-1fcfa8ba405bd
msgpack@1.0.0
1.2.1
wallarm/ingress-python:4.6.0-15cb2ae08b40f
msgpack@0.5.6
1.2.1

Open the chart page →

11,405
kong-previewwallarmVerified publisher4.2.31 of 5See more

kong-preview wallarm 4.2.3

1 of the 5 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/ingress-collectd:4.2.1-124dc4ca1ee1b
msgpack@1.0.0
1.2.1

Open the chart page →

2,905
wallarm-node-nextwallarmVerified publisher0.5.31 of 2See more

wallarm-node-next wallarm 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/node-helpers:5.0.2-1097cadc42336
msgpack@1.0.3
1.2.1

Open the chart page →

2,408
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/node-helpers:6.10.1aecd88b24c51
msgpack@1.0.8
1.2.1

Open the chart page →

2,824
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
msgpack@1.0.2
1.2.1

Open the chart page →

7,085
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
msgpack@1.0.0
1.2.1

Open the chart page →

4,086
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
msgpack@1.0.2
1.2.1

Open the chart page →

2,643

Container images carrying it

274 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
josh5/unmanic:0.2.64d49c4816260
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
python-pip@20.0.2-5ubuntu1.1
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
kennethreitz/httpbin:latest599fe5e50731
python-pip@9.0.1-2.3~ubuntu1
no fix listed
1
kfirfer/scripts:0.0.2481e5c4e5d70e
msgpack@1.0.2
1.2.1
1
knspar/phronetis:0.1.4609499d2dc91a
msgpack@1.1.1
python-pip@24.0+dfsg-1ubuntu1.1
1.2.1
no fix listed
1
kong/httpbin:latesta6ac46531193
python-pip@22.0.2+dfsg-1ubuntu0.5
no fix listed
1
kusionstack/kusion:v0.14.0126c8f0b0976
python-pip@22.0.2+dfsg-1ubuntu0.5
no fix listed
1
langgenius/dify-api:1.0.0066035f93856
msgpack@1.1.0
1.2.1
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
lib42/borgserver:latestc9d081647df4
msgpack@1.0.3
1.2.1
1
librenms/librenms:22.4.14f1f3d667cc7
msgpack@1.0.2
1.2.1
1
linuxserver/babybuddy:1.10.2f7d7c7704249
msgpack@1.0.2
1.2.1
1
linuxserver/calibre-web:0.6.24241009026e6f
python-pip@24.0+dfsg-1ubuntu1.2
no fix listed
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
msgpack@1.0.0
1.2.1
1
lnbitsdocker/lnbits-legend:latest26fae6327477
msgpack@1.0.7
1.2.1
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
msgpack@1.0.5
1.2.1
1
locustio/locust:2.24.151d866285170
msgpack@1.0.8
1.2.1
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
msgpack@1.1.0
1.2.1
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
msgpack@1.0.3
1.2.1
1
matrixdotorg/synapse:v1.78.0def97fd537d8
msgpack@1.0.4
1.2.1
1
mediagis/nominatim:5.3.27923a8e67197
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
mediagis/nominatim:3.7c15e941485ef
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed
1
milesmcc/shynet:v0.13.1ba54f7797a6b
msgpack@1.0.5
1.2.1
1
milesmcc/shynet:v0.12.0e821e31140f7
msgpack@1.0.3
1.2.1
1
mshanley80/httpbin2022:latest5b189a70c0fb
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
msgpack@0.5.6
1.2.1
1
netbirdio/dashboard:v2.90.101b59e1c905c9
msgpack@1.0.2
1.2.1
1
netbirdio/dashboard:v2.90.2332cc31f5f35
msgpack@1.0.2
1.2.1
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
msgpack@1.0.0
1.2.1
1
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
msgpack@1.0.2
1.2.1
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
python-pip@9.0.1-2.3~ubuntu1.18.04.1
no fix listed
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
msgpack@0.5.6
python-pip@8.1.1-2ubuntu0.4
1.2.1
no fix listed
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
msgpack@1.1.1
1.2.1
1
opendatacube/explorer:latest120457ffcd69
msgpack@1.1.2
1.2.1
1
opendatacube/pipelines:wofs-1.225d810e8504b8
python-pip@9.0.1-2.3~ubuntu1
no fix listed
1
opendatacube/restcube:latest91870111837c
python-pip@9.0.1-2.3~ubuntu1
no fix listed
1
opendatacube/wms:latest1b90cdf68831
python-pip@9.0.1-2.3~ubuntu1
no fix listed
1
opendatacube/wps:latest80df355a660b
msgpack@1.1.0
1.2.1
1
openelevation/open-elevation:latest82fb21612e86
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
openemr/openemr:6.1.089eaa6d9a4e3
msgpack@1.0.2
1.2.1
1
openmined/syft-backend:0.9.5b72f74a68b32
msgpack@1.1.0
1.2.1
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
msgpack@1.0.2
1.2.1
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
msgpack@1.0.2
1.2.1
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
python-pip@9.0.1-2.3~ubuntu1.18.04.4
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.