StackRadar

CVE-2026-6019

Medium

Advisory

Published 22 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
552
of 17,787 indexed, latest versions
Container images
535
deployed by those charts
Fix available
13 of 16
affected packages

BaseCookie.js_output() does not neutralize embedded characters

Carried by container images the latest versions of 552 of 17,787 indexed charts deploy, on 535 images.

Affected packageAffected versionsFixed inImages
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more3.11.0~rc1-1~22.04.1+esm2180
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more3.8.10-0ubuntu1~20.04.18+esm7100
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more3.10.12-1~22.04.1671
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+8 more3.12.3-1ubuntu0.1548
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more3.6.9-1~18.04ubuntu1.13+esm1044
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+9 more2.7.6-8ubuntu0.6+esm30, 2.7.12-1ubuntu0~16.04.18+esm22, 2.7.17-1~18.04ubuntu1.13+esm15, 2.7.18-13ubuntu1.5+esm943
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.93.5.2-2ubuntu0~16.04.13+esm2525
python3.13deb3.13.5-2, 3.13.5-2+e30, 3.13.7-1ubuntu0.13.13.5-2+deb13u2, 3.13.5-2+e3623
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.73.4.3-1ubuntu1~14.04.7+esm217
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-13.13.143
python3.14deb3.14.4-13.14.4-1ubuntu0.12
python3rpm3.12.9-13.azl3no fix listed1
python-3.12apk3.12.0-r1, 3.12.9-r1, 3.12.14-r2, 3.12.14-r6no fix listed8
python-3.14apk3.14.2-r2, 3.14.4-r23.14.4-r45
python-3.13apk3.13.7-r0, 3.13.10-r0, 3.13.12-r23.13.13-r33
python-3.11apk3.11.16-r5no fix listed1
OSV records
BIT-python-2026-6019DEBIAN-CVE-2026-6019UBUNTU-CVE-2026-6019CGA-2rxc-qq2g-w4hfCGA-477g-5pph-75mjCGA-4q3r-438p-rwv3CGA-6rw5-pv82-g8jwAZL-84728ECHO-1e4c-228c-95ee
Also known as
BIT-libpython-2026-6019, BIT-python-min-2026-6019, CGA-g7j7-w4vj-6cfx, CGA-hjp9-xq8m-3jr3, CGA-qpp8-2qh9-qw2x, CGA-qxmw-675j-q4q2, PSF-2026-21, USN-8509-1, USN-8744-1

Charts affected

552 by stars
ChartLatestAffected imagesRadar Score
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

9,248
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

14,100

Container images carrying it

535 by charts deploying them

A fixed version is listed for 13 of the 16 affected packages.

Container imageDigestPackageFixed inUsed by
mbround18/valheim:3.1.070bd4da591cd
python3.10@3.10.12-1~22.04.9
3.10.12-1~22.04.16
1
mediagis/nominatim:5.3.27923a8e67197
python3.12@3.12.3-1ubuntu0.13
3.12.3-1ubuntu0.15
1
mediagis/nominatim:3.7c15e941485ef
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7
1
mediagis/nominatim:4.2d0eae7b51374
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16
1
middlewareeng/middleware:0.3.1747d880812f1
python3.11@3.11.2-6+deb12u6
no fix listed
1
mindsdb/mindsdb:latest163011c09299
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
python3.11@3.11.2-6+deb12u5
no fix listed
1
mlikiowa/napcat-docker:latest1336a777f9a4
python3.10@3.10.12-1~22.04.6
3.10.12-1~22.04.16
1
moreillon/api-proxy:latestd7d4a5463525
python3.11@3.11.2-6+deb12u6
no fix listed
1
moreillon/food-manager:lateste8fd856e593d
python3.11@3.11.2-6+deb12u6
no fix listed
1
moreillon/group-manager:latest3caa8f710ee0
python3.11@3.11.2-6+deb12u6
no fix listed
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
python3.11@3.11.2-6
no fix listed
1
mshanley80/httpbin2022:latest5b189a70c0fb
python3.8@3.8.10-0ubuntu1~20.04.6
3.8.10-0ubuntu1~20.04.18+esm7
1
muhammedgamal/fp23:latest74b4cd69b6fa
python3.11@3.11.2-6
no fix listed
1
muluder/prograncontrollermcord:0.1.843b597a93da7
python2.7@2.7.12-1ubuntu0~16.04.3
python3.5@3.5.2-2ubuntu0~16.04.4
2.7.12-1ubuntu0~16.04.18+esm22
3.5.2-2ubuntu0~16.04.13+esm25
1
netboxcommunity/netbox:v3.2.83d652dca5351
python3.10@3.10.4-3ubuntu0.1
3.10.12-1~22.04.16
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
python3.11@3.11.2-6+deb12u6
no fix listed
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
python3.11@3.11.2-6+deb12u2
no fix listed
1
oled01/automx2:2025.1.105d3e398e675
python@3.13.5-1
python3.11@3.11.2-6+deb12u6
3.13.14
no fix listed
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
python3.6@3.6.9-1~18.04
3.6.9-1~18.04ubuntu1.13+esm10
1
omecproject/onos-progran:1.0.05715e5648aa0
python2.7@2.7.12-1ubuntu0~16.04.3
python3.5@3.5.2-2ubuntu0~16.04.4
2.7.12-1ubuntu0~16.04.18+esm22
3.5.2-2ubuntu0~16.04.13+esm25
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
python2.7@2.7.12-1ubuntu0~16.04.4
python3.5@3.5.2-2ubuntu0~16.04.5
2.7.12-1ubuntu0~16.04.18+esm22
3.5.2-2ubuntu0~16.04.13+esm25
1
oneuptime/probe:release6b2d98713711
python3.11@3.11.2-6+deb12u8
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
python3.11@3.11.2-6
no fix listed
1
opea/codetrans-ui:1.03ef121f34610
python3.11@3.11.2-6
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
python3.11@3.11.2-6
no fix listed
1
opea/speecht5:1.0249afad3d268
python3.11@3.11.2-6+deb12u3
no fix listed
1
openbas/caldera-server:5.1.0a277796d9724
python3.11@3.11.2-6+deb12u5
no fix listed
1
opendatacube/explorer:latest120457ffcd69
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.15
1
opendatacube/pipelines:wofs-1.225d810e8504b8
python3.6@3.6.7-1~18.04
3.6.9-1~18.04ubuntu1.13+esm10
1
opendatacube/restcube:latest91870111837c
python3.6@3.6.7-1~18.04
3.6.9-1~18.04ubuntu1.13+esm10
1
opendatacube/wms:latest1b90cdf68831
python3.6@3.6.7-1~18.04
3.6.9-1~18.04ubuntu1.13+esm10
1
opendatacube/wps:latest80df355a660b
python3.10@3.10.12-1~22.04.10
3.10.12-1~22.04.16
1
openelevation/open-elevation:latest82fb21612e86
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm7
1
openkm/openkm-ce:6.3.113bc465a7461b
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7
1
openmined/syft-backend:0.9.5b72f74a68b32
python-3.12@3.12.9-r1
no fix listed
1
openproject/hocuspocus:release-338001b288dc1359dfb5
python3.11@3.11.2-6+deb12u6
no fix listed
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
python3.8@3.8.10-0ubuntu1~20.04.8
3.8.10-0ubuntu1~20.04.18+esm7
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
python3.8@3.8.10-0ubuntu1~20.04.8
3.8.10-0ubuntu1~20.04.18+esm7
1
openthread/otbr:latestf307f59f6432
python2.7@2.7.17-1~18.04ubuntu1.11
python3.6@3.6.9-1~18.04ubuntu1.12
2.7.17-1~18.04ubuntu1.13+esm15
3.6.9-1~18.04ubuntu1.13+esm10
1
openvino/model_server:2025.2.11e7cd1d70cc1
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.15
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
python2.7@2.7.17-1~18.04ubuntu1.2
2.7.17-1~18.04ubuntu1.13+esm15
1
opsmx11/issuegen:v2.1.05c50ca123d88
python3.4@3.4.3-1ubuntu1~14.04.6
3.4.3-1ubuntu1~14.04.7+esm21
1
owncloud/server:10.15.051d9b74fc2a8
python3.8@3.8.10-0ubuntu1~20.04.11
3.8.10-0ubuntu1~20.04.18+esm7
1
owncloud/server:10.16.274c53d341076
python3.10@3.10.12-1~22.04.15
3.10.12-1~22.04.16
1
penpotapp/backend:2.2.147853d9bb9dd
python3.10@3.10.12-1~22.04.6
3.10.12-1~22.04.16
1
penpotapp/exporter:2.2.15c835ffd87ab
python3.10@3.10.12-1~22.04.6
3.10.12-1~22.04.16
1
phan2410/dummy-service:0.0.89c6ed6de26ca
python3.11@3.11.2-6+deb12u5
no fix listed
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
python3.11@3.11.2-6+deb12u5
no fix listed
1
photoprism/photoprism:251130db16ee6b1ba3
python3.13@3.13.7-1ubuntu0.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.