StackRadar

CVE-2026-59980

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
53
of 17,926 indexed, latest versions
Container images
52
deployed by those charts
Fix available
1 of 2
affected packages

hpack: Unbounded variable integer decoding can cause run-away computation on malformed input

Carried by container images the latest versions of 53 of 17,926 indexed charts deploy, on 52 images.

Affected packageAffected versionsFixed inImages
hpackpypi3.0.0, 4.0.0, 4.1.04.2.052
python-hpackdeb4.0.0-2no fix listed1
OSV records
GHSA-8v8h-hg4w-mvq2UBUNTU-CVE-2026-59980

Charts affected

53 by stars
ChartLatestAffected imagesRadar Score
dingtalk-botxxl-job-adminVerified publisher0.1.31 of 2See more

dingtalk-bot xxl-job-admin 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-59980.

Container imageDigestPackageFixed in
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
hpack@4.1.0
4.2.0

Open the chart page →

3,385
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-59980.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
hpack@4.0.0
4.2.0

Open the chart page →

3,185
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-59980.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
hpack@4.0.0
4.2.0

Open the chart page →

1,687

Container images carrying it

52 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
hpack@4.1.0
4.2.0
1
ghcr.io/radiorabe/catpage:2.2.17a37fc471447
hpack@4.1.0
4.2.0
1

syft 1.42.1 · advisories as of 28 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.