CVE-2026-6100
CriticalAdvisory
Published 13 Apr 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.1
- base score, highest
- EPSS
- 0.006
- 46th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 601
- of 17,781 indexed, latest versions
- Container images
- 579
- deployed by those charts
- Fix available
- 11 of 16
- affected packages
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
Carried by container images the latest versions of 601 of 17,781 indexed charts deploy, on 579 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| python3.11deb | 3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+5 more | 3.11.2-6+deb12u8 | 163 |
| python3apk | 3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+4 more | 3.12.14-r0 | 63 |
| python3.13deb | 3.13.5-2, 3.13.5-2+e30, 3.13.7-1ubuntu0.1 | 3.13.5-2+deb13u2, 3.13.5-2+e36 | 23 |
| python-3.14apk | 3.14.2-r2, 3.14.4-r2 | 3.14.4-r3 | 5 |
| pythonbitnami | 3.11.11-0, 3.12.8-0, 3.13.5-1 | 3.10.21 | 3 |
| python-3.13apk | 3.13.7-r0, 3.13.10-r0, 3.13.12-r2 | 3.13.13-r2 | 3 |
| python-3.12apk | 3.12.0-r1, 3.12.9-r1 | 3.12.13-r3 | 2 |
| python3.8deb | 3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more | no fix listed | 100 |
| python3.10deb | 3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more | 3.10.12-1~22.04.16 | 71 |
| python2.7deb | 2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 more | no fix listed | 54 |
| python3.12deb | 3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+8 more | 3.12.3-1ubuntu0.15 | 48 |
| python3.6deb | 3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more | no fix listed | 44 |
| python3.5deb | 3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9 | no fix listed | 25 |
| python3.4deb | 3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7 | no fix listed | 7 |
| python3.14deb | 3.14.4-1 | 3.14.4-1ubuntu0.1 | 2 |
| python3rpm | 3.12.9-13.azl3 | 3.12.9-14 | 1 |
- OSV records
- ALPINE-CVE-2026-6100BIT-python-2026-6100CGA-5m77-63wh-vhhhCGA-gw5v-fvh4-9pxrCGA-m7qp-99cp-h7qjDEBIAN-CVE-2026-6100UBUNTU-CVE-2026-6100AZL-83051ECHO-5806-1424-7b47
- Also known as
- BIT-libpython-2026-6100, BIT-python-min-2026-6100, CGA-hq26-pcqg-hvvp, CGA-mqvf-66wx-9p3p, CGA-r845-9w2j-fj7q, PSF-0000-CVE-2026-6100, PSF-2026-18, USN-8509-1
Charts affected
601 by stars
Container images carrying it
579 by charts deploying them
A fixed version is listed for 11 of the 16 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | cd264d33efd4 | python3.11 | 3.11.2-6+deb12u8 | 2 |
| ghcr.io/ | 4ee0764310e7 | python2.7 | no fix listed | 2 |
| ghcr.io/ | 33e60bfb40f2 | python3 | 3.12.14-r0 | 2 |
| ghcr.io/ | 4457b79b24cd | python3.11 | 3.11.2-6+deb12u8 | 2 |
| mcr.microsoft.com/ | 902628a8be89 | python3.8 | no fix listed | 2 |
| quay.io/ | 8745af1f9bbb | python3 | 3.12.14-r0 | 2 |
| registry.gitlab.com/ | b1198ea741d1 | python3 | 3.12.14-r0 | 2 |
| registry.k8s.io/ | dc7746bb081e | python3.11 | 3.11.2-6+deb12u8 | 2 |
| a10networks/ | 8dc58d434d71 | python3.6 | no fix listed | 1 |
| aboogie/ | 9c41a4483ac8 | python3.11 | 3.11.2-6+deb12u8 | 1 |
| adwerx/ | 840d2b078682 | python3.8 | no fix listed | 1 |
| airsonicadvanced/ | f7cbafac2806 | python3.8 | no fix listed | 1 |
| akeyless/ | 759e4289fae8 | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| aktosecurity/ | fcf8be10bead | python3 | 3.12.14-r0 | 1 |
| allegroai/ | 713ae38f7daf | python3.11 | 3.11.2-6+deb12u8 | 1 |
| allegroai/ | 772827a01bb5 | python3.6 | no fix listed | 1 |
| alpine/ | 6dbe6f391eda | python3 | 3.12.14-r0 | 1 |
| alpine/ | 7a319b15cfc9 | python3 | 3.12.14-r0 | 1 |
| alpine/ | 7e1e7d5b7a96 | python3 | 3.12.14-r0 | 1 |
| alpine/ | 9c4976d47656 | python3 | 3.12.14-r0 | 1 |
| alpine/ | eec354133193 | python3 | 3.12.14-r0 | 1 |
| andrewgolikov55/ | fcc001b61c0e | python3.10 | 3.10.12-1~22.04.16 | 1 |
| andrewmackrodt/ | 33f9080470c9 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| anujdatar/ | 685df04a643b | python3.11 | 3.11.2-6+deb12u8 | 1 |
| apache/ | 64e58748b6b9 | python3.11 | 3.11.2-6+deb12u8 | 1 |
| apache/ | ce90bdc3d2af | python3.11 | 3.11.2-6+deb12u8 | 1 |
| apache/ | e5560ad0b86e | python3.11 | 3.11.2-6+deb12u8 | 1 |
| apache/ | 80136ae753ee | python3.10 | 3.10.12-1~22.04.16 | 1 |
| apache/ | 75d48a62748f | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| apache/ | a2bab1be574c | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| apachepulsar/ | 16f9fdab3fa6 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| apachepulsar/ | 3b262ab7a7d9 | python3.8 | no fix listed | 1 |
| apachepulsar/ | 9c9947de139d | python3.10 | 3.10.12-1~22.04.16 | 1 |
| apachepulsar/ | d056c89b7131 | python3.8 | no fix listed | 1 |
| apachepulsar/ | d538416d5afe | python3.8 | no fix listed | 1 |
| apache/ | 76c176e8a0e4 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| appwrite/ | 1aaa70127114 | python3 | 3.12.14-r0 | 1 |
| appwrite/ | adc7d0e7ec23 | python3 | 3.12.14-r0 | 1 |
| archivebox/ | 1a5a37331091 | python3.11 | 3.11.2-6+deb12u8 | 1 |
| artur9010/ | 6b4de3ce8b0e | python3.11 | 3.11.2-6+deb12u8 | 1 |
| arunvelsriram/ | 655ad18fd8d6 | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| assistiot/ | 6a107f224c34 | python2.7 | no fix listed | 1 |
| assistiot/ | 30812ba93555 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| assistiot/ | 7d6a0d534c7f | python3.11 | 3.11.2-6+deb12u8 | 1 |
| assistiot/ | 38b003e55ff3 | python3.11 | 3.11.2-6+deb12u8 | 1 |
| assistiot/ | b1dbe4d62a03 | python3.11 | 3.11.2-6+deb12u8 | 1 |
| assistiot/ | e5ae539ce2cb | python3.8 | no fix listed | 1 |
| atlassian/ | 3b9222ab32ef | python3.10 | 3.10.12-1~22.04.16 | 1 |
| atlassian/ | 37bc46cbec1a | python3.10 | 3.10.12-1~22.04.16 | 1 |
| atlassian/ | 64a75aa4ec4e | python3.12 | 3.12.3-1ubuntu0.15 | 1 |