StackRadar

CVE-2026-6100

Critical

Advisory

Published 13 Apr 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
601
of 17,781 indexed, latest versions
Container images
579
deployed by those charts
Fix available
11 of 16
affected packages

Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure

Carried by container images the latest versions of 601 of 17,781 indexed charts deploy, on 579 images.

Affected packageAffected versionsFixed inImages
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+5 more3.11.2-6+deb12u8163
python3apk3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+4 more3.12.14-r063
python3.13deb3.13.5-2, 3.13.5-2+e30, 3.13.7-1ubuntu0.13.13.5-2+deb13u2, 3.13.5-2+e3623
python-3.14apk3.14.2-r2, 3.14.4-r23.14.4-r35
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-13.10.213
python-3.13apk3.13.7-r0, 3.13.10-r0, 3.13.12-r23.13.13-r23
python-3.12apk3.12.0-r1, 3.12.9-r13.12.13-r32
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 moreno fix listed100
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more3.10.12-1~22.04.1671
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 moreno fix listed54
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+8 more3.12.3-1ubuntu0.1548
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 moreno fix listed44
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9no fix listed25
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7no fix listed7
python3.14deb3.14.4-13.14.4-1ubuntu0.12
python3rpm3.12.9-13.azl33.12.9-141
OSV records
ALPINE-CVE-2026-6100BIT-python-2026-6100CGA-5m77-63wh-vhhhCGA-gw5v-fvh4-9pxrCGA-m7qp-99cp-h7qjDEBIAN-CVE-2026-6100UBUNTU-CVE-2026-6100AZL-83051ECHO-5806-1424-7b47
Also known as
BIT-libpython-2026-6100, BIT-python-min-2026-6100, CGA-hq26-pcqg-hvvp, CGA-mqvf-66wx-9p3p, CGA-r845-9w2j-fj7q, PSF-0000-CVE-2026-6100, PSF-2026-18, USN-8509-1

Charts affected

601 by stars
ChartLatestAffected imagesRadar Score
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-6100.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

14,100

Container images carrying it

579 by charts deploying them

A fixed version is listed for 11 of the 16 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
python3.11@3.11.2-6+deb12u2
3.11.2-6+deb12u8
2
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
python2.7@2.7.17-1~18.04ubuntu1.2
no fix listed
2
ghcr.io/plausible/community-edition:v3.2.133e60bfb40f2
python3@3.12.13-r0
3.12.14-r0
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
python3.8@3.8.10-0ubuntu1~20.04.8
no fix listed
2
quay.io/frrouting/frr:10.4.38745af1f9bbb
python3@3.12.12-r0
3.12.14-r0
2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
python3@3.12.12-r0
3.12.14-r0
2
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
python3.11@3.11.2-6+deb12u7
3.11.2-6+deb12u8
2
a10networks/acos-prometheus-exporter:latest8dc58d434d71
python3.6@3.6.9-1~18.04ubuntu1
no fix listed
1
aboogie/login_test_backend:new9c41a4483ac8
python3.11@3.11.2-6+deb12u2
3.11.2-6+deb12u8
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
python3.8@3.8.5-1~20.04
no fix listed
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
python3.8@3.8.5-1~20.04.3
no fix listed
1
akeyless/base:latest759e4289fae8
python3.12@3.12.3-1ubuntu0.13
3.12.3-1ubuntu0.15
1
aktosecurity/mirror-api-logging:k8s_ebpffcf8be10bead
python3@3.12.13-r0
3.12.14-r0
1
allegroai/clearml:2.0.0-613713ae38f7daf
python3.11@3.11.2-6+deb12u4
3.11.2-6+deb12u8
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
python3.6@3.6.9-1~18.04ubuntu1.7
no fix listed
1
alpine/k8s:1.31.106dbe6f391eda
python3@3.12.11-r0
3.12.14-r0
1
alpine/k8s:1.31.137a319b15cfc9
python3@3.12.11-r0
3.12.14-r0
1
alpine/k8s:1.32.47e1e7d5b7a96
python3@3.12.10-r0
3.12.14-r0
1
alpine/k8s:1.31.49c4976d47656
python3@3.12.8-r1
3.12.14-r0
1
alpine/k8s:1.32.3eec354133193
python3@3.12.9-r0
3.12.14-r0
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
python3.10@3.10.12-1~22.04.2
3.10.12-1~22.04.16
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
python3.10@3.10.12-1~22.04.11
3.10.12-1~22.04.16
1
anujdatar/cups:25.07.01685df04a643b
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
1
apache/airflow:2.8.4-python3.964e58748b6b9
python3.11@3.11.2-6
3.11.2-6+deb12u8
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
python3.11@3.11.2-6+deb12u3
3.11.2-6+deb12u8
1
apache/airflow:2.8.1e5560ad0b86e
python3.11@3.11.2-6
3.11.2-6+deb12u8
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
python3.10@3.10.12-1~22.04.15
3.10.12-1~22.04.16
1
apache/hertzbeat:1.8.075d48a62748f
python3.12@3.12.3-1ubuntu0.11
3.12.3-1ubuntu0.15
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
python3.12@3.12.3-1ubuntu0.11
3.12.3-1ubuntu0.15
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
python3.10@3.10.12-1~22.04.2
3.10.12-1~22.04.16
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
python3.8@3.8.10-0ubuntu1~20.04.2
no fix listed
1
apachepulsar/pulsar:3.0.79c9947de139d
python3.10@3.10.12-1~22.04.6
3.10.12-1~22.04.16
1
apachepulsar/pulsar:2.9.0d056c89b7131
python3.8@3.8.10-0ubuntu1~20.04.1
no fix listed
1
apachepulsar/pulsar:2.8.2d538416d5afe
python3.8@3.8.10-0ubuntu1~20.04.2
no fix listed
1
apache/ranger:2.7.076c176e8a0e4
python3.10@3.10.12-1~22.04.10
3.10.12-1~22.04.16
1
appwrite/appwrite:1.9.01aaa70127114
python3@3.12.12-r0
3.12.14-r0
1
appwrite/appwrite:1.9.6adc7d0e7ec23
python3@3.12.13-r0
3.12.14-r0
1
archivebox/archivebox:0.7.41a5a37331091
python3.11@3.11.2-6+deb12u7
3.11.2-6+deb12u8
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
python3.11@3.11.2-6
3.11.2-6+deb12u8
1
arunvelsriram/utils:latest655ad18fd8d6
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.15
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
python2.7@2.7.18-1~20.04.3
no fix listed
1
assistiot/open_api_backend:1.1.230812ba93555
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
python3.11@3.11.2-6
3.11.2-6+deb12u8
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
python3.11@3.11.2-6
3.11.2-6+deb12u8
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
python3.11@3.11.2-6
3.11.2-6+deb12u8
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
python3.8@3.8.10-0ubuntu1~20.04.7
no fix listed
1
atlassian/confluence-server:7.10.03b9222ab32ef
python3.10@3.10.6-1~22.04.1
3.10.12-1~22.04.16
1
atlassian/jira-software:8.14.037bc46cbec1a
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16
1
atlassian/jira-software:9.7.264a75aa4ec4e
python3.12@3.12.3-1ubuntu0.5
3.12.3-1ubuntu0.15
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.