CVE-2026-59980
MediumAdvisory
Published 24 Sept 2026In the index since 25 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.3
- base score, highest
- EPSS
- 0.003
- 21st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 53
- of 17,926 indexed, latest versions
- Container images
- 52
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
hpack: Unbounded variable integer decoding can cause run-away computation on malformed input
Carried by container images the latest versions of 53 of 17,926 indexed charts deploy, on 52 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| hpackpypi | 3.0.0, 4.0.0, 4.1.0 | 4.2.0 | 52 |
| python-hpackdeb | 4.0.0-2 | no fix listed | 1 |
- OSV records
- GHSA-8v8h-hg4w-mvq2UBUNTU-CVE-2026-59980
Charts affected
53 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| dingtalk-botxxl-job-adminVerified publisher | 0.1.3 | 1 of 2See more | 3,385 |
| alertmanager-matrix-forwarderzloi-space | 1.0.1 | 1 of 2See more | 3,185 |
| grafana-matrix-forwarderzloi-space | 1.0.0 | 1 of 2See more | 1,687 |
Container images carrying it
52 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | b89f83345532 | hpack | 4.2.0 | 1 |
| ghcr.io/ | 7a37fc471447 | hpack | 4.2.0 | 1 |