StackRadar

CVE-2026-6100

Critical

Advisory

Published 13 Apr 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
601
of 17,787 indexed, latest versions
Container images
579
deployed by those charts
Fix available
11 of 16
affected packages

Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure

Carried by container images the latest versions of 601 of 17,787 indexed charts deploy, on 579 images.

Affected packageAffected versionsFixed inImages
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+5 more3.11.2-6+deb12u8163
python3apk3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+4 more3.12.14-r063
python3.13deb3.13.5-2, 3.13.5-2+e30, 3.13.7-1ubuntu0.13.13.5-2+deb13u2, 3.13.5-2+e3623
python-3.14apk3.14.2-r2, 3.14.4-r23.14.4-r35
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-13.10.213
python-3.13apk3.13.7-r0, 3.13.10-r0, 3.13.12-r23.13.13-r23
python-3.12apk3.12.0-r1, 3.12.9-r13.12.13-r32
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 moreno fix listed100
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more3.10.12-1~22.04.1671
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 moreno fix listed54
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+8 more3.12.3-1ubuntu0.1548
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 moreno fix listed44
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9no fix listed25
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7no fix listed7
python3.14deb3.14.4-13.14.4-1ubuntu0.12
python3rpm3.12.9-13.azl33.12.9-141
OSV records
ALPINE-CVE-2026-6100BIT-python-2026-6100CGA-5m77-63wh-vhhhCGA-gw5v-fvh4-9pxrCGA-m7qp-99cp-h7qjDEBIAN-CVE-2026-6100UBUNTU-CVE-2026-6100AZL-83051ECHO-5806-1424-7b47
Also known as
BIT-libpython-2026-6100, BIT-python-min-2026-6100, CGA-hq26-pcqg-hvvp, CGA-mqvf-66wx-9p3p, CGA-r845-9w2j-fj7q, PSF-0000-CVE-2026-6100, PSF-2026-18, USN-8509-1

Charts affected

601 by stars
ChartLatestAffected imagesRadar Score
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-6100.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

14,100

Container images carrying it

579 by charts deploying them

A fixed version is listed for 11 of the 16 affected packages.

Container imageDigestPackageFixed inUsed by
firefart/requesttracker:5.0.40d6249906d8c
python3.11@3.11.2-6
3.11.2-6+deb12u8
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
python3.8@3.8.10-0ubuntu1~20.04.18
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
1
flanksource/batch-runner:v1.0.44689687a7cf95
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.15
1
flashcatcloud/categraf:latest42e6ab16472e
python3.12@3.12.3-1ubuntu0.12
3.12.3-1ubuntu0.15
1
fluent/fluent-bit:4.0-debuge76397ef3983
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
1
flyway/flyway:9.1545b5d7cdc75a
python3.8@3.8.10-0ubuntu1~20.04.6
no fix listed
1
fosrl/pangolin:1.13.0c32ad797ab96
python3@3.12.12-r0
3.12.14-r0
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
python3.6@3.6.9-1~18.04ubuntu1.9
no fix listed
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
python3.6@3.6.9-1~18.04ubuntu1.8
no fix listed
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
python2.7@2.7.18-13ubuntu1.5
python3.10@3.10.12-1~22.04.10
no fix listed
3.10.12-1~22.04.16
1
galaxy/cloudman-server:lateste5c265fe9fcd
python3.8@3.8.10-0ubuntu1~20.04.5
no fix listed
1
galaxy/galaxy-init:v18.010267bad550e6
python2.7@2.7.6-8ubuntu0.4
python3.4@3.4.3-1ubuntu1~14.04.6
no fix listed
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
python2.7@2.7.6-8ubuntu0.4
python3.4@3.4.3-1ubuntu1~14.04.6
no fix listed
no fix listed
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u8
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
python3.10@3.10.12-1~22.04.15
3.10.12-1~22.04.16
1
geopython/pycsw:3.0.0-beta284662ea6b78b
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
python3.6@3.6.9-1~18.04ubuntu1.1
no fix listed
1
gethue/hue:4.11.011b649636e68
python3.8@3.8.10-0ubuntu1~20.04.6
no fix listed
1
gethue/hue:4.10.05702b2c37ff9
python2.7@2.7.17-1~18.04ubuntu1.6
python3.6@3.6.9-1~18.04ubuntu1.4
no fix listed
no fix listed
1
gethue/hue:latest7d5c1b9f8a79
python3.10@3.10.12-1~22.04.10
python3.11@3.11.0~rc1-1~22.04
3.10.12-1~22.04.16
no fix listed
1
gomods/athens:v0.17.10f61d1e62359
python3@3.12.13-r0
3.12.14-r0
1
gomods/athens:v0.18.197cc113b34b0
python3@3.12.13-r0
3.12.14-r0
1
gotenberg/gotenberg:8.30206a6c708fc6
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
python-3.13@3.13.10-r0
3.13.13-r2
1
grafana/oncall:v1.16.5499851658393
python3@3.12.11-r0
3.12.14-r0
1
hasura/graphql-engine:v2.34.0-ce0111b0204136
python3.10@3.10.6-1~22.04.2ubuntu1.1
3.10.12-1~22.04.16
1
hasura/graphql-engine:v2.48.10f6c1c4b957d2
python3.10@3.10.12-1~22.04.11
3.10.12-1~22.04.16
1
haugene/transmission-openvpn:4.0059216cfae4b
python3.8@3.8.10-0ubuntu1~20.04
no fix listed
1
haveagitgat/tdarr:2.00.181256348872ce
python2.7@2.7.18-1~20.04.1
python3.8@3.8.10-0ubuntu1~20.04.4
no fix listed
no fix listed
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
python3.8@3.8.5-1~20.04
no fix listed
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
python2.7@2.7.18-1~20.04.3
python3.8@3.8.10-0ubuntu1~20.04.8
no fix listed
no fix listed
1
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
python3.8@3.8.10-0ubuntu1~20.04.13
no fix listed
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
python3.11@3.11.2-6
3.11.2-6+deb12u8
1
hyperglance/init:wildfly467ad8491bc3
python3.10@3.10.12-1~22.04.15
3.10.12-1~22.04.16
1
hyperglance/init:postgres9fd5faf1fe80
python3.10@3.10.12-1~22.04.15
3.10.12-1~22.04.16
1
hyperglance/init:apacheb2f8c6d52623
python3.10@3.10.12-1~22.04.15
3.10.12-1~22.04.16
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
python2.7@2.7.12-1ubuntu0~16.04.3
python3.5@3.5.2-2ubuntu0~16.04.4
no fix listed
no fix listed
1
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
python3.5@3.5.2-2ubuntu0~16.04.4
no fix listed
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
python2.7@2.7.12-1ubuntu0~16.04.3
python3.5@3.5.2-2ubuntu0~16.04.4
no fix listed
no fix listed
1
ibmcom/microclimate-theia:lateste17bdccc5030
python2.7@2.7.12-1ubuntu0~16.04.2
no fix listed
1
ibmcom/skydive:0.22.0395e60cc6e3d
python2.7@2.7.15~rc1-1ubuntu0.1
no fix listed
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
python3.11@3.11.2-6
3.11.2-6+deb12u8
1
inseefrlab/shelly:cloudshell31f04ca7436b
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16
1
instill/artifact-backend:b28766ac4a393e601ed
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
instill/model-backend:611f0f2e980125e5ba5
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
python3.8@3.8.10-0ubuntu1~20.04.4
no fix listed
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
python3.8@3.8.10-0ubuntu1~20.04.5
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
python3.11@3.11.2-6
3.11.2-6+deb12u8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.