StackRadar

CVE-2026-6019

Medium

Advisory

Published 22 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
553
of 17,781 indexed, latest versions
Container images
536
deployed by those charts
Fix available
13 of 16
affected packages

BaseCookie.js_output() does not neutralize embedded characters

Carried by container images the latest versions of 553 of 17,781 indexed charts deploy, on 536 images.

Affected packageAffected versionsFixed inImages
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more3.11.0~rc1-1~22.04.1+esm2181
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more3.8.10-0ubuntu1~20.04.18+esm7100
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more3.10.12-1~22.04.1671
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+8 more3.12.3-1ubuntu0.1548
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more3.6.9-1~18.04ubuntu1.13+esm1044
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+9 more2.7.6-8ubuntu0.6+esm30, 2.7.12-1ubuntu0~16.04.18+esm22, 2.7.17-1~18.04ubuntu1.13+esm15, 2.7.18-13ubuntu1.5+esm943
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.93.5.2-2ubuntu0~16.04.13+esm2525
python3.13deb3.13.5-2, 3.13.5-2+e30, 3.13.7-1ubuntu0.13.13.5-2+deb13u2, 3.13.5-2+e3623
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.73.4.3-1ubuntu1~14.04.7+esm217
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-13.13.143
python3.14deb3.14.4-13.14.4-1ubuntu0.12
python3rpm3.12.9-13.azl3no fix listed1
python-3.12apk3.12.0-r1, 3.12.9-r1, 3.12.14-r2, 3.12.14-r6no fix listed8
python-3.14apk3.14.2-r2, 3.14.4-r23.14.4-r45
python-3.13apk3.13.7-r0, 3.13.10-r0, 3.13.12-r23.13.13-r33
python-3.11apk3.11.16-r5no fix listed1
OSV records
BIT-python-2026-6019DEBIAN-CVE-2026-6019UBUNTU-CVE-2026-6019CGA-2rxc-qq2g-w4hfCGA-477g-5pph-75mjCGA-4q3r-438p-rwv3CGA-6rw5-pv82-g8jwAZL-84728ECHO-1e4c-228c-95ee
Also known as
BIT-libpython-2026-6019, BIT-python-min-2026-6019, CGA-g7j7-w4vj-6cfx, CGA-hjp9-xq8m-3jr3, CGA-qpp8-2qh9-qw2x, CGA-qxmw-675j-q4q2, PSF-2026-21, USN-8509-1, USN-8744-1

Charts affected

553 by stars
ChartLatestAffected imagesRadar Score
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

10,598
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

10,154
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
python3.8@3.8.10-0ubuntu1~20.04.1
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

10,628
coreinstill-aiOfficialVerified publisher0.1.753 of 15See more

core instill-ai 0.1.75

3 of the 15 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
instill/artifact-backend:b28766ac4a393e601ed
python3.13@3.13.5-2
3.13.5-2+deb13u2
instill/mgmt-backend:d0933d4ebe12f77a3f9
python3.13@3.13.5-2
3.13.5-2+deb13u2
instill/model-backend:611f0f2e980125e5ba5
python3.13@3.13.5-2
3.13.5-2+deb13u2

Open the chart page →

30,816
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
python3.12@3.12.3-1ubuntu0.2
3.12.3-1ubuntu0.15

Open the chart page →

4,309
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
python3.8@3.8.10-0ubuntu1~20.04.18
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

11,582
lightsteplightstepsatellite1.2.41 of 1See more

lightstep lightstepsatellite 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
python3.5@3.5.2-2ubuntu0~16.04.5
3.5.2-2ubuntu0~16.04.13+esm25

Open the chart page →

15,330
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
python3.11@3.11.2-6+deb12u7
no fix listed

Open the chart page →

5,218
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
python3.12@3.12.3-1ubuntu0.9
3.12.3-1ubuntu0.15

Open the chart page →

107,811
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.48.10f6c1c4b957d2
python3.10@3.10.12-1~22.04.11
3.10.12-1~22.04.16

Open the chart page →

13,521
nominatimrobjuz6.4.11 of 4See more

nominatim robjuz 6.4.1

1 of the 4 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
mediagis/nominatim:5.3.27923a8e67197
python3.12@3.12.3-1ubuntu0.13
3.12.3-1ubuntu0.15

Open the chart page →

8,690
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

24,488
freeradiusstartechnicaVerified publisher1.2.01 of 1See more

freeradius startechnica 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.2.8af6fd34a5b78
python2.7@2.7.18-13ubuntu1.5
python3.10@3.10.12-1~22.04.10
2.7.18-13ubuntu1.5+esm9
3.10.12-1~22.04.16

Open the chart page →

5,751
sn-platformstreamnative1.11.441 of 9See more

sn-platform streamnative 1.11.44

1 of the 9 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python3.8@3.8.10-0ubuntu1~20.04.9
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

15,477
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
wger/server:2.6997ead43aabd
python3.12@3.12.3-1ubuntu0.13
3.12.3-1ubuntu0.15

Open the chart page →

8,491
github-actions-runneradwerx0.10.31 of 1See more

github-actions-runner adwerx 0.10.3

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
python3.8@3.8.5-1~20.04
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

13,635
agentareaagentareaVerified publisher0.0.181 of 16See more

agentarea agentarea 0.0.18

1 of the 16 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
agentarea/agentarea-mcp-runner:latestd3c209a5d531
python3.11@3.11.2-6+deb12u8
no fix listed

Open the chart page →

14,914
akeyless-api-gatewayakeyless-services-helmVerified publisher1.62.221 of 1See more

akeyless-api-gateway akeyless-services-helm 1.62.22

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
akeyless/base:latest759e4289fae8
python3.12@3.12.3-1ubuntu0.13
3.12.3-1ubuntu0.15

Open the chart page →

2,358
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
python3.6@3.6.9-1~18.04ubuntu1.7
3.6.9-1~18.04ubuntu1.13+esm10

Open the chart page →

12,046
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
python3.10@3.10.12-1~22.04.10
3.10.12-1~22.04.16

Open the chart page →

7,740
dltbrokerassist-iot-distributed-broker0.2.02 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
python2.7@2.7.12-1ubuntu0~16.04.3
python3.5@3.5.2-2ubuntu0~16.04.4
2.7.12-1ubuntu0~16.04.18+esm22
3.5.2-2ubuntu0~16.04.13+esm25
hyperledger/fabric-couchdb:0.4.15f6c724592abf
python2.7@2.7.12-1ubuntu0~16.04.4
python3.5@3.5.2-2ubuntu0~16.04.5
2.7.12-1ubuntu0~16.04.18+esm22
3.5.2-2ubuntu0~16.04.13+esm25

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.02 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

2 of the 9 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
python2.7@2.7.12-1ubuntu0~16.04.3
python3.5@3.5.2-2ubuntu0~16.04.4
2.7.12-1ubuntu0~16.04.18+esm22
3.5.2-2ubuntu0~16.04.13+esm25
hyperledger/fabric-couchdb:0.4.15f6c724592abf
python2.7@2.7.12-1ubuntu0~16.04.4
python3.5@3.5.2-2ubuntu0~16.04.5
2.7.12-1ubuntu0~16.04.18+esm22
3.5.2-2ubuntu0~16.04.13+esm25

Open the chart page →

77,687
autonomous-plant-opsautonomous-plant-opsOfficialVerified publisher0.3.04 of 5See more

autonomous-plant-ops autonomous-plant-ops 0.3.0

4 of the 5 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/thotischner/autonomous-plant-ops/dashboard-api:1.1.0af663f4ba6e4
python-3.12@3.12.14-r6
no fix listed
ghcr.io/thotischner/autonomous-plant-ops/llm-agent:1.1.059e362c2b669
python-3.12@3.12.14-r6
no fix listed
ghcr.io/thotischner/autonomous-plant-ops/orchestrator:1.1.01beb0658f9e3
python-3.12@3.12.14-r6
no fix listed
ghcr.io/thotischner/autonomous-plant-ops/sensor-simulator:1.1.0f02bb7b28e8a
python-3.12@3.12.14-r6
no fix listed

Open the chart page →

470
open-elevationbeeinventor0.1.01 of 2See more

open-elevation beeinventor 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
openelevation/open-elevation:latest82fb21612e86
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

13,145
aramid-indexerbiatec-repoVerified publisher3.9.03 of 5See more

aramid-indexer biatec-repo 3.9.0

3 of the 5 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.15
scholtz2/aramid-conduit:v1.9.0-stable3a3b3d3277d2
python3.14@3.14.4-1
3.14.4-1ubuntu0.1
scholtz2/aramid-indexer:v3.9.0-stable6770214bc881
python3.14@3.14.4-1
3.14.4-1ubuntu0.1

Open the chart page →

13,357
aramid-participationbiatec-repoVerified publisher4.4.11 of 1See more

aramid-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
python3.10@3.10.12-1~22.04.6
3.10.12-1~22.04.16

Open the chart page →

7,190
aramid-relaybiatec-repoVerified publisher4.4.11 of 1See more

aramid-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.15

Open the chart page →

5,059
voimain-participationbiatec-repoVerified publisher4.4.11 of 1See more

voimain-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
python3.10@3.10.12-1~22.04.6
3.10.12-1~22.04.16

Open the chart page →

7,190
self-hostbitwarden2.4.01 of 11See more

self-host bitwarden 2.4.0

1 of the 11 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
python3.12@3.12.3-1ubuntu0.13
3.12.3-1ubuntu0.15

Open the chart page →

5,190
tensorflow-notebookcloudnativeapp0.1.21 of 1See more

tensorflow-notebook cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
tensorflow/tensorflow:1.6.0-devel1e3172090703
python2.7@2.7.12-1ubuntu0~16.04.3
python3.5@3.5.2-2ubuntu0~16.04.4
2.7.12-1ubuntu0~16.04.18+esm22
3.5.2-2ubuntu0~16.04.13+esm25

Open the chart page →

36,094
cosmotech-copilot-apicosmotech-apiVerified publisher0.1.11 of 1See more

cosmotech-copilot-api cosmotech-api 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
python3.13@3.13.5-2
3.13.5-2+deb13u2

Open the chart page →

11,205
datacube-explorerdatacube-charts0.5.321 of 1See more

datacube-explorer datacube-charts 0.5.32

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
opendatacube/explorer:latest120457ffcd69
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.15

Open the chart page →

4,854
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
python3.10@3.10.12-1~22.04.5
3.10.12-1~22.04.16

Open the chart page →

10,858
dragonfly-stackdragonflyVerified publisher0.1.21 of 7See more

dragonfly-stack dragonfly 0.1.2

1 of the 7 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
dragonflyoss/client:v0.1.82edf3e921f4e0
python3.11@3.11.2-6
no fix listed

Open the chart page →

18,376
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
python3.12@3.12.3-1ubuntu0.5
3.12.3-1ubuntu0.15

Open the chart page →

5,670
enbuildenbuildVerified publisher0.0.501 of 6See more

enbuild enbuild 0.0.50

1 of the 6 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
python3.11@3.11.2-6+deb12u7
no fix listed

Open the chart page →

31,510
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
python3.11@3.11.2-6+deb12u2
no fix listed

Open the chart page →

11,458
mcrouterevryfs-ossVerified publisher0.4.01 of 2See more

mcrouter evryfs-oss 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
python3.6@3.6.9-1~18.04ubuntu1.8
3.6.9-1~18.04ubuntu1.13+esm10

Open the chart page →

6,500
zabbix-server-mysqlfermosit3.0.21 of 4See more

zabbix-server-mysql fermosit 3.0.2

1 of the 4 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
python3.12@3.12.3-1ubuntu0.4
3.12.3-1ubuntu0.15

Open the chart page →

12,840
bazarrgeek-cookbookVerified publisher10.6.21 of 1See more

bazarr geek-cookbook 10.6.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

17,377
games-on-whalesgeek-cookbookVerified publisher1.8.21 of 7See more

games-on-whales geek-cookbook 1.8.2

1 of the 7 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

35,305
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

15,653
lazylibrariangeek-cookbookVerified publisher7.4.21 of 1See more

lazylibrarian geek-cookbook 7.4.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
linuxserver/lazylibrarian:version-1152df82f93d2560e233
python3.6@3.6.9-1~18.04ubuntu1.4
3.6.9-1~18.04ubuntu1.13+esm10

Open the chart page →

11,662
prowlarrgeek-cookbookVerified publisher4.5.21 of 1See more

prowlarr geek-cookbook 4.5.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

11,558
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
python3.8@3.8.5-1~20.04.3
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

10,231
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
python3.8@3.8.5-1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

15,856
tdarrgeek-cookbookVerified publisher4.6.22 of 2See more

tdarr geek-cookbook 4.6.2

2 of the 2 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
haveagitgat/tdarr:2.00.181256348872ce
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm7
haveagitgat/tdarr_node:2.00.101e3f9328327d
python3.8@3.8.5-1~20.04
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

31,000
valheimgeek-cookbookVerified publisher4.4.21 of 1See more

valheim geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/lloesche/valheim-server:latest20fde516ce31
python3.13@3.13.5-2
3.13.5-2+deb13u2

Open the chart page →

4,879
IMgrycapOfficialVerified publisher1.8.01 of 3See more

IM grycap 1.8.0

1 of the 3 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
ghcr.io/grycap/im:latest06a16d4f279f
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.15

Open the chart page →

4,132
castopodh2mVerified publisher1.12.101 of 3See more

castopod h2m 1.12.10

1 of the 3 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
castopod/castopod:1.12.101fd37280cbb2
python3.11@3.11.2-6+deb12u3
no fix listed

Open the chart page →

10,072

Container images carrying it

536 by charts deploying them

A fixed version is listed for 13 of the 16 affected packages.

Container imageDigestPackageFixed inUsed by
bnjbvr/kresus:0.22.137e216b182c8
python3.11@3.11.2-6+deb12u4
no fix listed
1
boky/postfix:5.1.0aafc77238423
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
boky/postfix:4.4.0f3f247fd4252
python3.11@3.11.2-6+deb12u5
no fix listed
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm7
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
python3.11@3.11.2-6+deb12u4
no fix listed
1
castopod/castopod:1.12.101fd37280cbb2
python3.11@3.11.2-6+deb12u3
no fix listed
1
cccs/assemblyline-rust:4.7.4.stable17468326853ec5
python3.11@3.11.2-6+deb12u8
no fix listed
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
python3.10@3.10.12-1~22.04.15
3.10.12-1~22.04.16
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
python3.4@3.4.3-1ubuntu1~14.04.7
3.4.3-1ubuntu1~14.04.7+esm21
1
chetangautamm/repo:sipp.v3e7f7049e1544
python3.8@3.8.5-1~20.04
3.8.10-0ubuntu1~20.04.18+esm7
1
cheyang/distributed-tf:1.6.046cc34755493
python2.7@2.7.12-1ubuntu0~16.04.3
python3.5@3.5.2-2ubuntu0~16.04.4
2.7.12-1ubuntu0~16.04.18+esm22
3.5.2-2ubuntu0~16.04.13+esm25
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
chriseaton/adventureworks:latest54c3384ce701
python3.10@3.10.12-1~22.04.9
3.10.12-1~22.04.16
1
citizenstig/httpbin:latestb81c818ccb86
python3.5@3.5.2-2ubuntu0~16.04.1
3.5.2-2ubuntu0~16.04.13+esm25
1
cloudve/janis-terminal:latestaf56e77ca587
python3.6@3.6.9-1~18.04ubuntu1
3.6.9-1~18.04ubuntu1.13+esm10
1
cloudve/ttyd:latestd79c1c5881c0
python3.6@3.6.9-1~18.04ubuntu1
3.6.9-1~18.04ubuntu1.13+esm10
1
codedesignplus/ms-emails-grpc:lateste336012bc781
python3.11@3.11.2-6+deb12u8
no fix listed
1
codedesignplus/ms-emails-rest:latestac84661c605e
python3.11@3.11.2-6+deb12u8
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7
1
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
python3.11@3.11.2-6+deb12u6
no fix listed
1
dariomader/twampy:v0.0.2d2f4a8c5e690
python-3.12@3.12.0-r1
no fix listed
1
daskdev/dask-notebook:1.1.0052630f5ca04
python3.6@3.6.7-1~18.04
3.6.9-1~18.04ubuntu1.13+esm10
1
datamate/seafile-professional:11.0.202dd66b722464
python3.10@3.10.12-1~22.04.11
3.10.12-1~22.04.16
1
deconzcommunity/deconz:2.29.2062de2362641
python3.11@3.11.2-6+deb12u5
no fix listed
1
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
python3.8@3.8.10-0ubuntu1~20.04.18
3.8.10-0ubuntu1~20.04.18+esm7
1
dragonflyoss/client:v1.5.4a1b52779c4dd
python3.11@3.11.2-6+deb12u8
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
python3.11@3.11.2-6
no fix listed
1
drumsergio/genieacs:1.2.16.028244054e1bf
python3.11@3.11.2-6+deb12u6
no fix listed
1
dserio83/velero-api:0.3.16b3d9115fee2
python3.11@3.11.2-6+deb12u6
no fix listed
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
python3.6@3.6.9-1~18.04ubuntu1.4
3.6.9-1~18.04ubuntu1.13+esm10
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
python3.6@3.6.9-1~18.04ubuntu1.4
3.6.9-1~18.04ubuntu1.13+esm10
1
esphome/esphome:2024.3.09ab8cc88b28c
python3.11@3.11.2-6
no fix listed
1
esphome/esphome:2024.12.2b2c6322700ac
python3.11@3.11.2-6+deb12u4
no fix listed
1
esphome/esphome:2025.3.0def8b6e4f517
python3.11@3.11.2-6+deb12u5
no fix listed
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
python2.7@2.7.12-1ubuntu0~16.04.2
2.7.12-1ubuntu0~16.04.18+esm22
1
felipecs8/app-db-connection-test:v129e06c9c6385
python3.11@3.11.2-6+deb12u4
no fix listed
1
firefart/requesttracker:5.0.40d6249906d8c
python3.11@3.11.2-6
no fix listed
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
python3.8@3.8.10-0ubuntu1~20.04.18
3.8.10-0ubuntu1~20.04.18+esm7
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
python3.11@3.11.2-6+deb12u6
no fix listed
1
flanksource/batch-runner:v1.0.44689687a7cf95
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.15
1
flashcatcloud/categraf:latest42e6ab16472e
python3.12@3.12.3-1ubuntu0.12
3.12.3-1ubuntu0.15
1
fluent/fluent-bit:4.0-debuge76397ef3983
python3.11@3.11.2-6+deb12u6
no fix listed
1
flyway/flyway:9.1545b5d7cdc75a
python3.8@3.8.10-0ubuntu1~20.04.6
3.8.10-0ubuntu1~20.04.18+esm7
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
python3.6@3.6.9-1~18.04ubuntu1.9
3.6.9-1~18.04ubuntu1.13+esm10
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
python3.6@3.6.9-1~18.04ubuntu1.8
3.6.9-1~18.04ubuntu1.13+esm10
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
python2.7@2.7.18-13ubuntu1.5
python3.10@3.10.12-1~22.04.10
2.7.18-13ubuntu1.5+esm9
3.10.12-1~22.04.16
1
galaxy/cloudman-server:lateste5c265fe9fcd
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7
1
galaxy/galaxy-init:v18.010267bad550e6
python2.7@2.7.6-8ubuntu0.4
python3.4@3.4.3-1ubuntu1~14.04.6
2.7.6-8ubuntu0.6+esm30
3.4.3-1ubuntu1~14.04.7+esm21
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.