StackRadar

CVE-2026-6100

Critical

Advisory

Published 13 Apr 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
602
of 17,787 indexed, latest versions
Container images
580
deployed by those charts
Fix available
11 of 16
affected packages

Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure

Carried by container images the latest versions of 602 of 17,787 indexed charts deploy, on 580 images.

Affected packageAffected versionsFixed inImages
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+5 more3.11.2-6+deb12u8163
python3apk3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+4 more3.12.14-r063
python3.13deb3.13.5-2, 3.13.5-2+e30, 3.13.7-1ubuntu0.13.13.5-2+deb13u2, 3.13.5-2+e3623
python-3.14apk3.14.2-r2, 3.14.4-r23.14.4-r35
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-13.10.213
python-3.13apk3.13.7-r0, 3.13.10-r0, 3.13.12-r23.13.13-r23
python-3.12apk3.12.0-r1, 3.12.9-r13.12.13-r32
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 moreno fix listed100
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more3.10.12-1~22.04.1671
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 moreno fix listed54
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3+9 more3.12.3-1ubuntu0.1549
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 moreno fix listed44
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9no fix listed25
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7no fix listed7
python3.14deb3.14.4-13.14.4-1ubuntu0.12
python3rpm3.12.9-13.azl33.12.9-141
OSV records
ALPINE-CVE-2026-6100BIT-python-2026-6100CGA-5m77-63wh-vhhhCGA-gw5v-fvh4-9pxrCGA-m7qp-99cp-h7qjDEBIAN-CVE-2026-6100UBUNTU-CVE-2026-6100AZL-83051ECHO-5806-1424-7b47
Also known as
BIT-libpython-2026-6100, BIT-python-min-2026-6100, CGA-hq26-pcqg-hvvp, CGA-mqvf-66wx-9p3p, CGA-r845-9w2j-fj7q, PSF-0000-CVE-2026-6100, PSF-2026-18, USN-8509-1

Charts affected

602 by stars
ChartLatestAffected imagesRadar Score
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-6100.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

9,296
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-6100.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

14,172

Container images carrying it

580 by charts deploying them

A fixed version is listed for 11 of the 16 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
python3.10@3.10.4-3ubuntu0.1
3.10.12-1~22.04.16
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
python3.8@3.8.5-1~20.04.2
no fix listed
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
python3.8@3.8.10-0ubuntu1~20.04.4
no fix listed
1
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
python3.8@3.8.10-0ubuntu1~20.04.4
no fix listed
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
python3.8@3.8.5-1~20.04.3
no fix listed
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
python3.8@3.8.10-0ubuntu1~20.04.1
no fix listed
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
python3.8@3.8.10-0ubuntu1~20.04.5
no fix listed
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
python3.8@3.8.10-0ubuntu1~20.04.4
no fix listed
1
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
python3.8@3.8.10-0ubuntu1~20.04.18
no fix listed
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
python3@3.12.11-r0
3.12.14-r0
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
python3@3.12.11-r0
3.12.14-r0
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
python3.6@3.6.9-1~18.04ubuntu1.9
no fix listed
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
python3.8@3.8.10-0ubuntu1~20.04.18
no fix listed
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
python3.8@3.8.10-0ubuntu1~20.04.2
no fix listed
1
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
python3@3.12.12-r0
3.12.14-r0
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
python3.11@3.11.2-6+deb12u3
3.11.2-6+deb12u8
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
python3@3.12.10-r0
3.12.14-r0
1
ghcr.io/linuxserver/syslog-ng:4.10.247fae7f540f9
python3@3.12.13-r0
3.12.14-r0
1
ghcr.io/lloesche/valheim-server:latest20fde516ce31
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
python3.12@3.12.3-1ubuntu0.5
3.12.3-1ubuntu0.15
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
python3.12@3.12.3-1ubuntu0.3
3.12.3-1ubuntu0.15
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
python3.11@3.11.2-6+deb12u7
3.11.2-6+deb12u8
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
python3.11@3.11.2-6+deb12u2
3.11.2-6+deb12u8
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
python3.11@3.11.2-6+deb12u7
3.11.2-6+deb12u8
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
python3.11@3.11.2-6+deb12u7
3.11.2-6+deb12u8
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u8
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
python2.7@2.7.18-1~20.04.1
python3.8@3.8.10-0ubuntu1~20.04.4
no fix listed
no fix listed
1
ghcr.io/plausible/community-edition:v3.0.114c1afde21d6
python3@3.12.10-r0
3.12.14-r0
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u8
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
python3.8@3.8.10-0ubuntu1~20.04.5
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
python3.8@3.8.10-0ubuntu1~20.04.5
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
python3.8@3.8.10-0ubuntu1~20.04.5
no fix listed
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
python3.12@3.12.3-1ubuntu0.12
3.12.3-1ubuntu0.15
1
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
python3.12@3.12.3-1ubuntu0.9
3.12.3-1ubuntu0.15
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.15
1
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
python3.12@3.12.3-1ubuntu0.9
3.12.3-1ubuntu0.15
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.15
1
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
python3.12@3.12.3-1ubuntu0.10
3.12.3-1ubuntu0.15
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
python3.8@3.8.10-0ubuntu1~20.04.13
no fix listed
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
python3.8@3.8.10-0ubuntu1~20.04.13
no fix listed
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
python3.12@3.12.3-1ubuntu0.13
3.12.3-1ubuntu0.15
1
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
python-3.14@3.14.4-r2
3.14.4-r3
1
ghcr.io/thoroslives/zilean:v3.10.1bce6aca0f6ca
python3@3.11.12-r1
3.12.14-r0
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
python3.10@3.10.12-1~22.04.6
3.10.12-1~22.04.16
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
python3.11@3.11.2-6
3.11.2-6+deb12u8
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.