StackRadar

CVE-2026-6019

Medium

Advisory

Published 22 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
553
of 17,781 indexed, latest versions
Container images
536
deployed by those charts
Fix available
13 of 16
affected packages

BaseCookie.js_output() does not neutralize embedded characters

Carried by container images the latest versions of 553 of 17,781 indexed charts deploy, on 536 images.

Affected packageAffected versionsFixed inImages
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more3.11.0~rc1-1~22.04.1+esm2181
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more3.8.10-0ubuntu1~20.04.18+esm7100
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more3.10.12-1~22.04.1671
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+8 more3.12.3-1ubuntu0.1548
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more3.6.9-1~18.04ubuntu1.13+esm1044
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+9 more2.7.6-8ubuntu0.6+esm30, 2.7.12-1ubuntu0~16.04.18+esm22, 2.7.17-1~18.04ubuntu1.13+esm15, 2.7.18-13ubuntu1.5+esm943
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.93.5.2-2ubuntu0~16.04.13+esm2525
python3.13deb3.13.5-2, 3.13.5-2+e30, 3.13.7-1ubuntu0.13.13.5-2+deb13u2, 3.13.5-2+e3623
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.73.4.3-1ubuntu1~14.04.7+esm217
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-13.13.143
python3.14deb3.14.4-13.14.4-1ubuntu0.12
python3rpm3.12.9-13.azl3no fix listed1
python-3.12apk3.12.0-r1, 3.12.9-r1, 3.12.14-r2, 3.12.14-r6no fix listed8
python-3.14apk3.14.2-r2, 3.14.4-r23.14.4-r45
python-3.13apk3.13.7-r0, 3.13.10-r0, 3.13.12-r23.13.13-r33
python-3.11apk3.11.16-r5no fix listed1
OSV records
BIT-python-2026-6019DEBIAN-CVE-2026-6019UBUNTU-CVE-2026-6019CGA-2rxc-qq2g-w4hfCGA-477g-5pph-75mjCGA-4q3r-438p-rwv3CGA-6rw5-pv82-g8jwAZL-84728ECHO-1e4c-228c-95ee
Also known as
BIT-libpython-2026-6019, BIT-python-min-2026-6019, CGA-g7j7-w4vj-6cfx, CGA-hjp9-xq8m-3jr3, CGA-qpp8-2qh9-qw2x, CGA-qxmw-675j-q4q2, PSF-2026-21, USN-8509-1, USN-8744-1

Charts affected

553 by stars
ChartLatestAffected imagesRadar Score
marblerun-coordinatoredgelesssysVerified publisher0.5.01 of 1See more

marblerun-coordinator edgelesssys 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
python3.6@3.6.9-1~18.04ubuntu1.4
3.6.9-1~18.04ubuntu1.13+esm10

Open the chart page →

10,981
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
python3.11@3.11.2-6+deb12u7
no fix listed

Open the chart page →

30,159
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

25,122
eolicplantseolicplantsVerified publisher0.1.01 of 7See more

eolicplants eolicplants 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
python3.12@3.12.3-1ubuntu0.9
3.12.3-1ubuntu0.15

Open the chart page →

27,291
eoloPlanteolo-plannerVerified publisher0.1.01 of 7See more

eoloPlant eolo-planner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
library/rabbitmq:3.11-managementc3f70098e01d
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

27,537
eoloplannereoloplannerVerified publisher0.1.01 of 7See more

eoloplanner eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
library/rabbitmq:3.9-management8a279e9396a8
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

32,205
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.01 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
library/rabbitmq:3.11-managementc3f70098e01d
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

27,537
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.01 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
python3.12@3.12.3-1ubuntu0.9
3.12.3-1ubuntu0.15

Open the chart page →

27,256
eoloplannereoloplanner-molynx-gat0.1.01 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
library/rabbitmq:3.9-management8a279e9396a8
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

28,482
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
library/rabbitmq:3.9-management8a279e9396a8
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

27,096
eoloplanteoloplant1.0.01 of 7See more

eoloplant eoloplant 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
library/rabbitmq:3.11-managementc3f70098e01d
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

27,537
eoloplantseoloplants-urjcVerified publisher0.1.01 of 7See more

eoloplants eoloplants-urjc 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
library/rabbitmq:3.9-management8a279e9396a8
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

27,721
servereoloserverVerified publisher0.1.01 of 7See more

server eoloserver 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
library/rabbitmq:3.9-management8a279e9396a8
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

32,205
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
python3.8@3.8.10-0ubuntu1~20.04.6
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

9,334
rabbitmqeosc-lot-1Verified publisher0.3.01 of 2See more

rabbitmq eosc-lot-1 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
library/rabbitmq:3.13-managemente582c0bc7766
python3.12@3.12.3-1ubuntu0.9
3.12.3-1ubuntu0.15

Open the chart page →

2,457
beeport-uiethersphereVerified publisher0.76.21 of 3See more

beeport-ui ethersphere 0.76.2

1 of the 3 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
python3.11@3.11.2-6+deb12u8
no fix listed

Open the chart page →

7,368
multichain-uiethersphereVerified publisher0.73.11 of 3See more

multichain-ui ethersphere 0.73.1

1 of the 3 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
python3.11@3.11.2-6+deb12u8
no fix listed

Open the chart page →

7,368
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
python3.8@3.8.5-1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

20,933
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
python3.5@3.5.2-2ubuntu0~16.04.9
3.5.2-2ubuntu0~16.04.13+esm25

Open the chart page →

14,673
ferriscompanyferriscompany0.1.01 of 1See more

ferriscompany ferriscompany 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
python3.11@3.11.2-6+deb12u3
no fix listed

Open the chart page →

10,741
business-api-ecosystemfiware1.1.02 of 4See more

business-api-ecosystem fiware 1.1.0

2 of the 4 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
python3.8@3.8.10-0ubuntu1~20.04.18
3.8.10-0ubuntu1~20.04.18+esm7
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
python3.11@3.11.2-6+deb12u6
no fix listed

Open the chart page →

64,489
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.15

Open the chart page →

5,292
mission-controlflanksourceVerified publisher0.1.3361 of 8See more

mission-control flanksource 0.1.336

1 of the 8 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
python3.11@3.11.2-6+deb12u6
no fix listed

Open the chart page →

8,902
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
python3.8@3.8.5-1~20.04.3
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

18,230
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

16,123
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
python3.6@3.6.9-1~18.04ubuntu1.4
3.6.9-1~18.04ubuntu1.13+esm10

Open the chart page →

13,551
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
python3.8@3.8.10-0ubuntu1~20.04.1
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

12,222
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

10,994
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
python3.11@3.11.2-6+deb12u7
no fix listed

Open the chart page →

9,077
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
python3.11@3.11.2-6+deb12u5
no fix listed

Open the chart page →

12,958
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
python3.10@3.10.4-3ubuntu0.1
3.10.12-1~22.04.16

Open the chart page →

12,076
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
python3.8@3.8.5-1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

17,702
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

27,949
puppeteergeek-cookbookVerified publisher1.2.21 of 1See more

puppeteer geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

15,730
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

11,807
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

24,293
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
python3.6@3.6.6-1~18.04
3.6.9-1~18.04ubuntu1.13+esm10

Open the chart page →

26,944
transmissiongeek-cookbookVerified publisher8.4.31 of 1See more

transmission geek-cookbook 8.4.3

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

11,861
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

17,929
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
python3.11@3.11.2-6+deb12u6
no fix listed

Open the chart page →

4,259
knativegitlabVerified publisher0.10.03 of 10See more

knative gitlab 0.10.0

3 of the 10 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
istio/node-agent-k8s:1.2.9268ab879ea51
python3.5@3.5.2-2ubuntu0~16.04.5
3.5.2-2ubuntu0~16.04.13+esm25
istio/pilot:1.2.9c09319753454
python3.5@3.5.2-2ubuntu0~16.04.5
3.5.2-2ubuntu0~16.04.13+esm25
istio/proxyv2:1.2.90c78be035e98
python3.5@3.5.2-2ubuntu0~16.04.5
3.5.2-2ubuntu0~16.04.13+esm25

Open the chart page →

36,102
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
python3.11@3.11.2-6+deb12u2
no fix listed

Open the chart page →

12,170
jaegergpg-dev3.3.32 of 5See more

jaeger gpg-dev 3.3.3

2 of the 5 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16
library/cassandra:3.11.65aa8400b4b3b
python2.7@2.7.17-1~18.04ubuntu1.1
2.7.17-1~18.04ubuntu1.13+esm15

Open the chart page →

19,229
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
python3.10@3.10.12-1~22.04.15
3.10.12-1~22.04.16

Open the chart page →

4,556
temporalgroundcover1.12.3571 of 2See more

temporal groundcover 1.12.357

1 of the 2 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
python3.13@3.13.5-2+e30
3.13.5-2+e36

Open the chart page →

2,013
hawk-envoy-pluginhawk0.1.01 of 4See more

hawk-envoy-plugin hawk 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
kong/httpbin:latesta6ac46531193
python3.10@3.10.12-1~22.04.7
3.10.12-1~22.04.16

Open the chart page →

9,096
heliconehelicone0.1.422 of 14See more

helicone helicone 0.1.42

2 of the 14 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
python3.8@3.8.10-0ubuntu1~20.04.13
3.8.10-0ubuntu1~20.04.18+esm7
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
python3.11@3.11.2-6
no fix listed

Open the chart page →

24,995
7dtdhelm-7dtd0.1.01 of 1See more

7dtd helm-7dtd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
vinanrra/7dtd-server:v0.4.4f9534490bd2b
python3.6@3.6.9-1~18.04ubuntu1.9
3.6.9-1~18.04ubuntu1.13+esm10

Open the chart page →

10,627
esphomehelm-chart-roeiVerified publisher2025.3.01 of 1See more

esphome helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
esphome/esphome:2025.3.0def8b6e4f517
python3.11@3.11.2-6+deb12u5
no fix listed

Open the chart page →

6,008
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
iofog/router:2.0.17260cf861479
python2.7@2.7.17-1~18.04ubuntu1.1
2.7.17-1~18.04ubuntu1.13+esm15

Open the chart page →

24,161

Container images carrying it

536 by charts deploying them

A fixed version is listed for 13 of the 16 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
python3.11@3.11.2-6+deb12u7
no fix listed
1
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
python3.12@3.12.3-1ubuntu0.2
3.12.3-1ubuntu0.15
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
python3.6@3.6.9-1~18.04ubuntu1.12
3.6.9-1~18.04ubuntu1.13+esm10
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
python3.12@3.12.3-1ubuntu0.3
3.12.3-1ubuntu0.15
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
python3.12@3.12.3-1ubuntu0.3
3.12.3-1ubuntu0.15
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
python3.10@3.10.4-3ubuntu0.1
3.10.12-1~22.04.16
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
python3.8@3.8.5-1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
python3.8@3.8.5-1~20.04.3
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
python3.8@3.8.10-0ubuntu1~20.04.1
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
python3.8@3.8.10-0ubuntu1~20.04.18
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
python3.6@3.6.9-1~18.04ubuntu1.9
3.6.9-1~18.04ubuntu1.13+esm10
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
python3.8@3.8.10-0ubuntu1~20.04.18
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
python3.11@3.11.2-6+deb12u3
no fix listed
1
ghcr.io/lloesche/valheim-server:latest20fde516ce31
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
python3.12@3.12.3-1ubuntu0.5
3.12.3-1ubuntu0.15
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
python3.11@3.11.2-6+deb12u6
no fix listed
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
python3.12@3.12.3-1ubuntu0.3
3.12.3-1ubuntu0.15
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
python3.11@3.11.2-6+deb12u6
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
python3.11@3.11.2-6+deb12u7
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
python3.11@3.11.2-6+deb12u6
no fix listed
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
python3.11@3.11.2-6+deb12u2
no fix listed
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
python3.11@3.11.2-6+deb12u7
no fix listed
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
python3.11@3.11.2-6+deb12u7
no fix listed
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
python3.11@3.11.2-6+deb12u5
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/quenchworks/images/airflow3f8281e23704
python-3.12@3.12.14-r2
no fix listed
1
ghcr.io/quenchworks/images/mlflowb6e937696995
python-3.12@3.12.14-r2
no fix listed
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
python3.11@3.11.2-6+deb12u8
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
python3.11@3.11.2-6+deb12u5
no fix listed
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
python3.12@3.12.3-1ubuntu0.12
3.12.3-1ubuntu0.15
1
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
python3.12@3.12.3-1ubuntu0.9
3.12.3-1ubuntu0.15
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.15
1
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
python3.12@3.12.3-1ubuntu0.9
3.12.3-1ubuntu0.15
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.15
1
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
python3.12@3.12.3-1ubuntu0.10
3.12.3-1ubuntu0.15
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
python3.8@3.8.10-0ubuntu1~20.04.13
3.8.10-0ubuntu1~20.04.18+esm7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.