StackRadar

CVE-2026-6100

Critical

Advisory

Published 13 Apr 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
601
of 17,787 indexed, latest versions
Container images
579
deployed by those charts
Fix available
11 of 16
affected packages

Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure

Carried by container images the latest versions of 601 of 17,787 indexed charts deploy, on 579 images.

Affected packageAffected versionsFixed inImages
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+5 more3.11.2-6+deb12u8163
python3apk3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+4 more3.12.14-r063
python3.13deb3.13.5-2, 3.13.5-2+e30, 3.13.7-1ubuntu0.13.13.5-2+deb13u2, 3.13.5-2+e3623
python-3.14apk3.14.2-r2, 3.14.4-r23.14.4-r35
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-13.10.213
python-3.13apk3.13.7-r0, 3.13.10-r0, 3.13.12-r23.13.13-r23
python-3.12apk3.12.0-r1, 3.12.9-r13.12.13-r32
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 moreno fix listed100
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more3.10.12-1~22.04.1671
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 moreno fix listed54
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+8 more3.12.3-1ubuntu0.1548
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 moreno fix listed44
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9no fix listed25
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7no fix listed7
python3.14deb3.14.4-13.14.4-1ubuntu0.12
python3rpm3.12.9-13.azl33.12.9-141
OSV records
ALPINE-CVE-2026-6100BIT-python-2026-6100CGA-5m77-63wh-vhhhCGA-gw5v-fvh4-9pxrCGA-m7qp-99cp-h7qjDEBIAN-CVE-2026-6100UBUNTU-CVE-2026-6100AZL-83051ECHO-5806-1424-7b47
Also known as
BIT-libpython-2026-6100, BIT-python-min-2026-6100, CGA-hq26-pcqg-hvvp, CGA-mqvf-66wx-9p3p, CGA-r845-9w2j-fj7q, PSF-0000-CVE-2026-6100, PSF-2026-18, USN-8509-1

Charts affected

601 by stars
ChartLatestAffected imagesRadar Score
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-6100.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

14,100

Container images carrying it

579 by charts deploying them

A fixed version is listed for 11 of the 16 affected packages.

Container imageDigestPackageFixed inUsed by
ymuski/geo-checker:5.0.05ba7fd8c7bdc
python3@3.12.12-r0
3.12.14-r0
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
python3.12@3.12.3-1ubuntu0.4
3.12.3-1ubuntu0.15
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
python3.8@3.8.10-0ubuntu1~20.04.1
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
python3.12@3.12.3-1ubuntu0.11
3.12.3-1ubuntu0.15
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
python3.10@3.10.4-3ubuntu0.1
3.10.12-1~22.04.16
1
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
python3.5@3.5.2-2ubuntu0~16.04.5
no fix listed
1
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
python3.5@3.5.2-2ubuntu0~16.04.5
no fix listed
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
python3.11@3.11.2-6+deb12u3
3.11.2-6+deb12u8
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
python3.12@3.12.3-1ubuntu0.10
3.12.3-1ubuntu0.15
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
python3@3.12.13-r0
3.12.14-r0
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
python3.11@3.11.2-6+deb12u3
3.11.2-6+deb12u8
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
1
ghcr.io/base/node-reth:v1.1.18eb6e492fe3c
python3.12@3.12.3-1ubuntu0.13
3.12.3-1ubuntu0.15
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
python3.10@3.10.12-1~22.04.7
3.10.12-1~22.04.16
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
python-3.13@3.13.7-r0
3.13.13-r2
1
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
python3.8@3.8.10-0ubuntu1~20.04.6
no fix listed
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
python3.12@3.12.3-1ubuntu0.12
3.12.3-1ubuntu0.15
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
python3.11@3.11.2-6+deb12u2
3.11.2-6+deb12u8
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u8
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
python3.11@3.11.2-6+deb12u4
3.11.2-6+deb12u8
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u8
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
python3@3.12.10-r0
3.12.14-r0
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
python@3.12.8-0
3.10.21
1
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
python3@3.12.9-r0
3.12.14-r0
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
python3.12@3.12.3-1ubuntu0.3
3.12.3-1ubuntu0.15
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
python3.11@3.11.2-6
3.11.2-6+deb12u8
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
python3.6@3.6.9-1~18.04ubuntu1.4
no fix listed
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
python3@3.12.11-r0
3.12.14-r0
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
python3@3.12.11-r0
3.12.14-r0
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
python3.11@3.11.2-6+deb12u2
3.11.2-6+deb12u8
1
ghcr.io/grycap/im:latest06a16d4f279f
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.15
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
python2.7@2.7.18-1~20.04.1
python3.8@3.8.10-0ubuntu1~20.04.4
no fix listed
no fix listed
1
ghcr.io/hotio/qbittorrent:release-5.2.007198d49e5b4
python3@3.12.13-r0
3.12.14-r0
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
python3.11@3.11.2-6+deb12u7
3.11.2-6+deb12u8
1
ghcr.io/jeremylong/open-vulnerability-data-mirror:v9.0.49a69aa14dc3e
python3@3.12.12-r0
3.12.14-r0
1
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
python3.12@3.12.3-1ubuntu0.2
3.12.3-1ubuntu0.15
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
python3.6@3.6.9-1~18.04ubuntu1.12
no fix listed
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
python3.12@3.12.3-1ubuntu0.3
3.12.3-1ubuntu0.15
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
python3.12@3.12.3-1ubuntu0.3
3.12.3-1ubuntu0.15
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
python3.8@3.8.10-0ubuntu1~20.04.2
no fix listed
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
python3.8@3.8.10-0ubuntu1~20.04.2
no fix listed
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
python3.8@3.8.10-0ubuntu1~20.04
no fix listed
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
python3.10@3.10.4-3ubuntu0.1
3.10.12-1~22.04.16
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.