StackRadar

CVE-2026-6019

Medium

Advisory

Published 22 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
554
of 17,787 indexed, latest versions
Container images
537
deployed by those charts
Fix available
13 of 16
affected packages

BaseCookie.js_output() does not neutralize embedded characters

Carried by container images the latest versions of 554 of 17,787 indexed charts deploy, on 537 images.

Affected packageAffected versionsFixed inImages
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more3.11.0~rc1-1~22.04.1+esm2181
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more3.8.10-0ubuntu1~20.04.18+esm7100
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more3.10.12-1~22.04.1671
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3+9 more3.12.3-1ubuntu0.1549
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more3.6.9-1~18.04ubuntu1.13+esm1044
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+9 more2.7.6-8ubuntu0.6+esm30, 2.7.12-1ubuntu0~16.04.18+esm22, 2.7.17-1~18.04ubuntu1.13+esm15, 2.7.18-13ubuntu1.5+esm943
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.93.5.2-2ubuntu0~16.04.13+esm2525
python3.13deb3.13.5-2, 3.13.5-2+e30, 3.13.7-1ubuntu0.13.13.5-2+deb13u2, 3.13.5-2+e3623
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.73.4.3-1ubuntu1~14.04.7+esm217
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-13.13.143
python3.14deb3.14.4-13.14.4-1ubuntu0.12
python3rpm3.12.9-13.azl3no fix listed1
python-3.12apk3.12.0-r1, 3.12.9-r1, 3.12.14-r2, 3.12.14-r6no fix listed8
python-3.14apk3.14.2-r2, 3.14.4-r23.14.4-r45
python-3.13apk3.13.7-r0, 3.13.10-r0, 3.13.12-r23.13.13-r33
python-3.11apk3.11.16-r5no fix listed1
OSV records
BIT-python-2026-6019DEBIAN-CVE-2026-6019UBUNTU-CVE-2026-6019CGA-2rxc-qq2g-w4hfCGA-477g-5pph-75mjCGA-4q3r-438p-rwv3CGA-6rw5-pv82-g8jwAZL-84728ECHO-1e4c-228c-95ee
Also known as
BIT-libpython-2026-6019, BIT-python-min-2026-6019, CGA-g7j7-w4vj-6cfx, CGA-hjp9-xq8m-3jr3, CGA-qpp8-2qh9-qw2x, CGA-qxmw-675j-q4q2, PSF-2026-21, USN-8509-1, USN-8744-1

Charts affected

554 by stars
ChartLatestAffected imagesRadar Score
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
python3.11@3.11.2-6+deb12u8
no fix listed

Open the chart page →

8,824
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm7

Open the chart page →

15,287
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

9,296
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-6019.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

14,172

Container images carrying it

537 by charts deploying them

A fixed version is listed for 13 of the 16 affected packages.

Container imageDigestPackageFixed inUsed by
phan2410/falcon-asgi-server:0.1.04a86d138832d
python3.11@3.11.2-6+deb12u5
no fix listed
1
photoprism/photoprism:251130db16ee6b1ba3
python3.13@3.13.7-1ubuntu0.1
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
python3.12@3.12.3-1
3.12.3-1ubuntu0.15
1
project2team4/react:latest3ff031a08887
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm7
1
prowlercloud/prowler-api:5.31.14f252d579be2
python3.11@3.11.2-6+deb12u7
no fix listed
1
psorab/elibrary:latest53b68896c4ce
python3.8@3.8.10-0ubuntu1~20.04.7
3.8.10-0ubuntu1~20.04.18+esm7
1
puppet/puppet-agent:7.14.00b6fd9a6b7da
python3.6@3.6.9-1~18.04ubuntu1.6
3.6.9-1~18.04ubuntu1.13+esm10
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
python2.7@2.7.12-1ubuntu0~16.04.3
python3.5@3.5.2-2ubuntu0~16.04.4
2.7.12-1ubuntu0~16.04.18+esm22
3.5.2-2ubuntu0~16.04.13+esm25
1
razorbladex401/dayz:latest6a4d79248e7d
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16
1
redimp/otterwiki:2778bf30da3da
python3.11@3.11.2-6+deb12u8
no fix listed
1
redis/redis-stack-server:latest798ab84d9f26
python3.10@3.10.12-1~22.04.11
3.10.12-1~22.04.16
1
redis/redis-stack-server:7.4.0-v0887cf87cc744
python3.10@3.10.12-1~22.04.4
3.10.12-1~22.04.16
1
resouer/redis-slave:v2e2f198b49ba7
python2.7@2.7.6-8
python3.4@3.4.0-2ubuntu1
2.7.6-8ubuntu0.6+esm30
3.4.3-1ubuntu1~14.04.7+esm21
1
resurfaceio/resurface:3.7.84d5cda2f64109
python3.10@3.10.12-1~22.04.9
3.10.12-1~22.04.16
1
rezachalak/bzen-mongo:1.0.034f694325191
python3.8@3.8.10-0ubuntu1~20.04.8
3.8.10-0ubuntu1~20.04.18+esm7
1
rhasspy/wyoming-piper:2.3.169b7f797ae3a
python3.11@3.11.2-6+deb12u8
no fix listed
1
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
python3.11@3.11.2-6+deb12u6
no fix listed
1
rhasspy/wyoming-whisper:3.5.0308b7959a925
python3.11@3.11.2-6+deb12u7
no fix listed
1
rocketadmin/rocketadmin:1.17.710955ef540b9
python3.11@3.11.2-6+deb12u6
no fix listed
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
python3.10@3.10.12-1~22.04.9
3.10.12-1~22.04.16
1
santisbon/evwatcher:latestc4e994ca4540
python3.11@3.11.2-6
no fix listed
1
santisbon/evworker:lateste807283f8d69
python3.11@3.11.2-6
no fix listed
1
santisbon/speedtest:latest8ee3a1697227
python3.11@3.11.2-6
no fix listed
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
python3.11@3.11.2-6+deb12u3
no fix listed
1
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
python3.10@3.10.12-1~22.04.6
3.10.12-1~22.04.16
1
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
python3.10@3.10.12-1~22.04.6
3.10.12-1~22.04.16
1
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
python3.10@3.10.12-1~22.04.6
3.10.12-1~22.04.16
1
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.15
1
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.15
1
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.15
1
scholtz2/aramid-conduit:v1.9.0-stable3a3b3d3277d2
python3.14@3.14.4-1
3.14.4-1ubuntu0.1
1
scholtz2/aramid-indexer:v3.9.0-stable6770214bc881
python3.14@3.14.4-1
3.14.4-1ubuntu0.1
1
scrapinghub/splash:3.4.1a5f89bc84606
python3.6@3.6.9-1~18.04
3.6.9-1~18.04ubuntu1.13+esm10
1
seafileltd/seafile-mc:9.0.106693911bcc40
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7
1
seafileltd/seafile-mc:10.0.170628f29c663
python3.8@3.8.10-0ubuntu1~20.04.8
3.8.10-0ubuntu1~20.04.18+esm7
1
seafileltd/seafile-mc:9.0.97ac833196f60
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
python3.10@3.10.12-1~22.04.5
3.10.12-1~22.04.16
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm7
1
seldonio/locust-core:0.81d0da98a2d76
python2.7@2.7.12-1ubuntu0~16.04.4
2.7.12-1ubuntu0~16.04.18+esm22
1
shaowenchen/ops-server:latest315444f703f4
python3.10@3.10.12-1~22.04.11
3.10.12-1~22.04.16
1
signalen/backend:2.50.14760256000738
python3.11@3.11.2-6+deb12u8
no fix listed
1
sismics/docs:v1.10f4b0ef019cf1
python3.6@3.6.6-1~18.04
3.6.9-1~18.04ubuntu1.13+esm10
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
python3.11@3.11.2-6+deb12u6
no fix listed
1
snipe/snipe-it:v8.3.1141ebf2386fe
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.15
1
snipe/snipe-it:v6.0.1455fb7636a98c
python3.8@3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.18+esm7
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
python3.8@3.8.10-0ubuntu1~20.04.8
3.8.10-0ubuntu1~20.04.18+esm7
1
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
python3.6@3.6.9-1~18.04ubuntu1.12
3.6.9-1~18.04ubuntu1.13+esm10
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
python3.11@3.11.2-6
no fix listed
1
socialmediamacroscope/image_crawler:0.1.2f508216be63c
python3.6@3.6.9-1~18.04ubuntu1.12
3.6.9-1~18.04ubuntu1.13+esm10
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
python3.11@3.11.2-6
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.