StackRadar

CVE-2026-57585

High

Advisory

Published 19 Jun 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
273
of 17,781 indexed, latest versions
Container images
274
deployed by those charts
Fix available
1 of 3
affected packages

MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error

Carried by container images the latest versions of 273 of 17,781 indexed charts deploy, on 274 images.

Affected packageAffected versionsFixed inImages
msgpackpypi0.5.6, 0.6.0, 0.6.1, 0.6.2+10 more1.2.1181
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+22 moreno fix listed107
python-msgpackdeb1.0.3-1build1, 1.0.3-2+b1, 1.0.3-3build2no fix listed8
OSV records
DEBIAN-CVE-2026-57585GHSA-6v7p-g79w-8964UBUNTU-CVE-2026-57585
Also known as
PYSEC-2026-3625

Charts affected

273 by stars
ChartLatestAffected imagesRadar Score
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
msgpack@1.1.0
1.2.1

Open the chart page →

7,901
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
python-pip@20.0.2-5ubuntu1.6
no fix listed

Open the chart page →

30,687
downscalersqream-chartsVerified publisher1.0.01 of 1See more

downscaler sqream-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.05d328c003efe
msgpack@1.0.4
1.2.1

Open the chart page →

1,009
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python-pip@20.0.2-5ubuntu1.10
no fix listed

Open the chart page →

10,134
icinga2svtech-public-helm-charts1.0.01 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
msgpack@1.0.5
1.2.1

Open the chart page →

5,511
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
msgpack@1.0.4
1.2.1

Open the chart page →

18,756
rundeck-option-providersvtech-public-helm-charts1.0.01 of 2See more

rundeck-option-provider svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
msgpack@1.0.5
1.2.1

Open the chart page →

1,428
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
python-pip@22.0.2+dfsg-1
no fix listed

Open the chart page →

17,461
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
msgpack@1.0.4
1.2.1

Open the chart page →

3,164
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

9,347
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

4,305
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
msgpack@1.0.3
python-msgpack@1.0.3-1build1
1.2.1
no fix listed

Open the chart page →

13,459
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
python-pip@24.0+dfsg-1ubuntu1.2
no fix listed

Open the chart page →

7,628
kongwallarmVerified publisher4.6.32 of 7See more

kong wallarm 4.6.3

2 of the 7 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/ingress-collectd:4.6.0-1fcfa8ba405bd
msgpack@1.0.0
1.2.1
wallarm/ingress-python:4.6.0-15cb2ae08b40f
msgpack@0.5.6
1.2.1

Open the chart page →

11,405
kong-previewwallarmVerified publisher4.2.31 of 5See more

kong-preview wallarm 4.2.3

1 of the 5 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/ingress-collectd:4.2.1-124dc4ca1ee1b
msgpack@1.0.0
1.2.1

Open the chart page →

2,905
wallarm-node-nextwallarmVerified publisher0.5.31 of 2See more

wallarm-node-next wallarm 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/node-helpers:5.0.2-1097cadc42336
msgpack@1.0.3
1.2.1

Open the chart page →

2,408
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/node-helpers:6.10.1aecd88b24c51
msgpack@1.0.8
1.2.1

Open the chart page →

2,824
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
msgpack@1.0.2
1.2.1

Open the chart page →

7,085
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
msgpack@1.0.0
1.2.1

Open the chart page →

4,086
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
msgpack@1.0.2
1.2.1

Open the chart page →

2,643

Container images carrying it

274 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
pangeo/base-notebook:2024.01.155fbe688a4f80
msgpack@1.0.7
1.2.1
1
prompve/prometheus-pve-exporter:2.0.1ff6749eb03b0
msgpack@1.0.0
1.2.1
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
msgpack@1.1.2
1.2.1
1
redash/redash:25.8.000d813437db5
msgpack@1.1.0
1.2.1
1
redash/redash:10.0.0.b503639392753c0376
msgpack@1.0.2
1.2.1
1
redash/redash:26.3.0c5c9148f5c38
msgpack@1.1.2
1.2.1
1
rezachalak/bzen-mongo:1.0.034f694325191
python-pip@20.0.2-5ubuntu1.9
no fix listed
1
salehmir/jesse:1.10.101afa95f979e9
msgpack@1.1.1
1.2.1
1
saltstack/salt:3006.3e9c7906b7a5c
msgpack@1.0.2
1.2.1
1
scrapinghub/splash:3.4.1a5f89bc84606
python-pip@9.0.1-2.3~ubuntu1.18.04.1
no fix listed
1
seafileltd/seafile-mc:9.0.106693911bcc40
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
seafileltd/seafile-mc:10.0.170628f29c663
python-pip@20.0.2-5ubuntu1.9
no fix listed
1
seafileltd/seafile-mc:9.0.97ac833196f60
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
searx/searx:1.0.0-211-968b28993dbb3a6d9419
msgpack@1.0.0
1.2.1
1
seldonio/locust-core:0.81d0da98a2d76
python-pip@8.1.1-2ubuntu0.4
no fix listed
1
shaowenchen/ops-controller-manager:latest26da43bb5b66
python-pip@22.0.2+dfsg-1ubuntu0.7
no fix listed
1
shaowenchen/ops-server:latest315444f703f4
python-pip@22.0.2+dfsg-1ubuntu0.6
no fix listed
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
python-pip@20.0.2-5ubuntu1.9
no fix listed
1
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
python-pip@9.0.1-2.3~ubuntu1.18.04.8
no fix listed
1
socialmediamacroscope/image_crawler:0.1.2f508216be63c
python-pip@9.0.1-2.3~ubuntu1.18.04.8
no fix listed
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
stackstorm/st2actionrunner:3.888235ba70cad
msgpack@1.0.7
1.2.1
1
stackstorm/st2api:3.86f56d239d280
msgpack@1.0.7
1.2.1
1
stackstorm/st2auth:3.833ecfda16608
msgpack@1.0.7
1.2.1
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
msgpack@1.0.7
1.2.1
1
stackstorm/st2notifier:3.8f190a6212195
msgpack@1.0.7
1.2.1
1
stackstorm/st2rulesengine:3.8259503496ff9
msgpack@1.0.7
1.2.1
1
stackstorm/st2scheduler:3.8b1de2055c362
msgpack@1.0.7
1.2.1
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
msgpack@1.0.7
1.2.1
1
stackstorm/st2stream:3.81c8904a3bf67
msgpack@1.0.7
1.2.1
1
stackstorm/st2timersengine:3.81bf35bfaf00c
msgpack@1.0.7
1.2.1
1
stackstorm/st2workflowengine:3.819fdfffdbba8
msgpack@1.0.7
1.2.1
1
statcan/ckan:2.93921305425b8
python-pip@20.0.2-5ubuntu1.5
no fix listed
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
python-pip@20.0.2-5ubuntu1.5
no fix listed
1
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
msgpack@1.0.5
1.2.1
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
msgpack@1.0.4
1.2.1
1
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
msgpack@1.0.5
1.2.1
1
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
msgpack@1.1.2
1.2.1
1
thijsvanloef/palworld-server-docker:v2.5.0b4ac9ee22483
msgpack@1.1.2
1.2.1
1
timescale/timescaledb-ha:pg16d7db8f1085a3
python-pip@22.0.2+dfsg-1ubuntu0.7
no fix listed
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
python-pip@22.0.2+dfsg-1ubuntu0.5
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
python-pip@8.1.1-2ubuntu0.4
no fix listed
1
tomsquest/docker-radicale:3.1.1.04759cc353a1d
msgpack@1.0.2
1.2.1
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
msgpack@1.0.3
python-msgpack@1.0.3-1build1
1.2.1
no fix listed
1
voltha/voltha-cli:1.6.0c4e41e92f046
python-pip@8.1.1-2ubuntu0.4
no fix listed
1
voltha/voltha-netconf:1.6.037f80524c207
python-pip@8.1.1-2ubuntu0.4
no fix listed
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
python-pip@8.1.1-2ubuntu0.4
no fix listed
1
voltha/voltha-tester:1.7.0655c3048a602
python-pip@8.1.1-2ubuntu0.4
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.