StackRadar

CVE-2026-57585

High

Advisory

Published 19 Jun 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
273
of 17,781 indexed, latest versions
Container images
274
deployed by those charts
Fix available
1 of 3
affected packages

MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error

Carried by container images the latest versions of 273 of 17,781 indexed charts deploy, on 274 images.

Affected packageAffected versionsFixed inImages
msgpackpypi0.5.6, 0.6.0, 0.6.1, 0.6.2+10 more1.2.1181
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+22 moreno fix listed107
python-msgpackdeb1.0.3-1build1, 1.0.3-2+b1, 1.0.3-3build2no fix listed8
OSV records
DEBIAN-CVE-2026-57585GHSA-6v7p-g79w-8964UBUNTU-CVE-2026-57585
Also known as
PYSEC-2026-3625

Charts affected

273 by stars
ChartLatestAffected imagesRadar Score
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
no fix listed

Open the chart page →

25,769
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
msgpack@1.1.0
1.2.1

Open the chart page →

7,901
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
python-pip@20.0.2-5ubuntu1.6
no fix listed

Open the chart page →

30,687
downscalersqream-chartsVerified publisher1.0.01 of 1See more

downscaler sqream-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.05d328c003efe
msgpack@1.0.4
1.2.1

Open the chart page →

1,009
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python-pip@20.0.2-5ubuntu1.10
no fix listed

Open the chart page →

10,134
icinga2svtech-public-helm-charts1.0.01 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
msgpack@1.0.5
1.2.1

Open the chart page →

5,511
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
msgpack@1.0.4
1.2.1

Open the chart page →

18,756
rundeck-option-providersvtech-public-helm-charts1.0.01 of 2See more

rundeck-option-provider svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
msgpack@1.0.5
1.2.1

Open the chart page →

1,428
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
python-pip@22.0.2+dfsg-1
no fix listed

Open the chart page →

17,461
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
msgpack@1.0.4
1.2.1

Open the chart page →

3,164
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

9,347
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

4,305
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
msgpack@1.0.3
python-msgpack@1.0.3-1build1
1.2.1
no fix listed

Open the chart page →

13,459
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
python-pip@24.0+dfsg-1ubuntu1.2
no fix listed

Open the chart page →

7,628
kongwallarmVerified publisher4.6.32 of 7See more

kong wallarm 4.6.3

2 of the 7 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/ingress-collectd:4.6.0-1fcfa8ba405bd
msgpack@1.0.0
1.2.1
wallarm/ingress-python:4.6.0-15cb2ae08b40f
msgpack@0.5.6
1.2.1

Open the chart page →

11,405
kong-previewwallarmVerified publisher4.2.31 of 5See more

kong-preview wallarm 4.2.3

1 of the 5 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/ingress-collectd:4.2.1-124dc4ca1ee1b
msgpack@1.0.0
1.2.1

Open the chart page →

2,905
wallarm-node-nextwallarmVerified publisher0.5.31 of 2See more

wallarm-node-next wallarm 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/node-helpers:5.0.2-1097cadc42336
msgpack@1.0.3
1.2.1

Open the chart page →

2,408
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
wallarm/node-helpers:6.10.1aecd88b24c51
msgpack@1.0.8
1.2.1

Open the chart page →

2,824
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
msgpack@1.0.2
1.2.1

Open the chart page →

7,085
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
msgpack@1.0.0
1.2.1

Open the chart page →

4,086
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-57585.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
msgpack@1.0.2
1.2.1

Open the chart page →

2,643

Container images carrying it

274 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
voltha/voltha-voltha:1.6.0ff596b62de59
python-pip@8.1.1-2ubuntu0.4
no fix listed
1
wallarm/ingress-collectd:4.2.1-124dc4ca1ee1b
msgpack@1.0.0
1.2.1
1
wallarm/ingress-collectd:4.6.0-1fcfa8ba405bd
msgpack@1.0.0
1.2.1
1
wallarm/ingress-python:4.6.0-15cb2ae08b40f
msgpack@0.5.6
1.2.1
1
wallarm/node-helpers:5.0.2-1097cadc42336
msgpack@1.0.3
1.2.1
1
wallarm/node-helpers:6.10.1aecd88b24c51
msgpack@1.0.8
1.2.1
1
wiremind/pghoard:12-2019-11-264dea42c8166c
msgpack@0.6.2
1.2.1
1
xeladock/mysql_dns:latest4baf531453f1
python-pip@22.0.2+dfsg-1
no fix listed
1
gcr.io/google-samples/microservices-demo/loadgenerator:v0.2.3360130ab5850
msgpack@1.0.0
1.2.1
1
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
msgpack@1.1.0
1.2.1
1
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
msgpack@1.1.0
1.2.1
1
ghcr.io/aws-exporters/prometheus-ecr-exporter:0.1.442b0c87470d6
msgpack@1.0.2
1.2.1
1
ghcr.io/aws-exporters/prometheus-inspector-exporter:0.0.29c7c11293b3c
msgpack@1.0.2
1.2.1
1
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
msgpack@1.1.0
1.2.1
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/caas-team/py-kube-downscaler:26.4.0af05a098b0d2
msgpack@1.1.2
1.2.1
1
ghcr.io/cleanuparr/cleanuparr:2.10.5c7cd53ad559a
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/dask/dask:2024.1.0080150de7d86
msgpack@1.0.7
1.2.1
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
msgpack@1.1.2
1.2.1
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
msgpack@1.0.7
1.2.1
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
python-pip@24.0+dfsg-1ubuntu1.1
no fix listed
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
msgpack@1.0.8
1.2.1
1
ghcr.io/gabe565/obico/web:latesta5c1daef46c0
msgpack@1.1.0
1.2.1
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
msgpack@1.1.2
1.2.1
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
msgpack@1.1.2
1.2.1
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
msgpack@1.1.0
1.2.1
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
msgpack@1.1.2
1.2.1
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
msgpack@1.0.3
1.2.1
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
msgpack@1.0.7
1.2.1
1
ghcr.io/home-operations/bazarr:1.5.680cb090162b4
msgpack@1.1.0
1.2.1
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
msgpack@1.1.2
1.2.1
1
ghcr.io/hoverkraft-tech/ovh-snapshoter/app:0.4.1010d271f08ab3
msgpack@1.1.0
1.2.1
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
python-pip@20.0.2-5ubuntu1.11
no fix listed
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed
1
ghcr.io/linuxserver/mylar3:version-v0.5.3b96f0e97ab3f
msgpack@1.0.2
1.2.1
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
msgpack@1.0.8
1.2.1
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
msgpack@1.1.2
1.2.1
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
msgpack@1.1.2
1.2.1
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
msgpack@1.0.3
python-msgpack@1.0.3-3build2
python-pip@24.0+dfsg-1ubuntu1.3
1.2.1
no fix listed
no fix listed
1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
msgpack@1.0.3
python-msgpack@1.0.3-3build2
python-pip@24.0+dfsg-1ubuntu1.3
1.2.1
no fix listed
no fix listed
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
msgpack@1.0.3
python-msgpack@1.0.3-3build2
python-pip@24.0+dfsg-1ubuntu1.3
1.2.1
no fix listed
no fix listed
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
msgpack@1.0.3
python-msgpack@1.0.3-3build2
python-pip@24.0+dfsg-1ubuntu1.3
1.2.1
no fix listed
no fix listed
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
msgpack@1.0.3
python-msgpack@1.0.3-3build2
python-pip@24.0+dfsg-1ubuntu1.3
1.2.1
no fix listed
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
msgpack@1.0.7
1.2.1
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
msgpack@1.1.0
1.2.1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
msgpack@1.1.1
1.2.1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
msgpack@1.1.1
1.2.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.