StackRadar

CVE-2026-6100

Critical

Advisory

Published 13 Apr 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
601
of 17,787 indexed, latest versions
Container images
579
deployed by those charts
Fix available
11 of 16
affected packages

Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure

Carried by container images the latest versions of 601 of 17,787 indexed charts deploy, on 579 images.

Affected packageAffected versionsFixed inImages
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+5 more3.11.2-6+deb12u8163
python3apk3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+4 more3.12.14-r063
python3.13deb3.13.5-2, 3.13.5-2+e30, 3.13.7-1ubuntu0.13.13.5-2+deb13u2, 3.13.5-2+e3623
python-3.14apk3.14.2-r2, 3.14.4-r23.14.4-r35
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-13.10.213
python-3.13apk3.13.7-r0, 3.13.10-r0, 3.13.12-r23.13.13-r23
python-3.12apk3.12.0-r1, 3.12.9-r13.12.13-r32
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 moreno fix listed100
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more3.10.12-1~22.04.1671
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 moreno fix listed54
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+8 more3.12.3-1ubuntu0.1548
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 moreno fix listed44
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9no fix listed25
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7no fix listed7
python3.14deb3.14.4-13.14.4-1ubuntu0.12
python3rpm3.12.9-13.azl33.12.9-141
OSV records
ALPINE-CVE-2026-6100BIT-python-2026-6100CGA-5m77-63wh-vhhhCGA-gw5v-fvh4-9pxrCGA-m7qp-99cp-h7qjDEBIAN-CVE-2026-6100UBUNTU-CVE-2026-6100AZL-83051ECHO-5806-1424-7b47
Also known as
BIT-libpython-2026-6100, BIT-python-min-2026-6100, CGA-hq26-pcqg-hvvp, CGA-mqvf-66wx-9p3p, CGA-r845-9w2j-fj7q, PSF-0000-CVE-2026-6100, PSF-2026-18, USN-8509-1

Charts affected

601 by stars
ChartLatestAffected imagesRadar Score
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-6100.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16

Open the chart page →

14,100

Container images carrying it

579 by charts deploying them

A fixed version is listed for 11 of the 16 affected packages.

Container imageDigestPackageFixed inUsed by
iofog/router:2.0.17260cf861479
python2.7@2.7.17-1~18.04ubuntu1.1
no fix listed
1
iomesh/csi-driver:v2.8.01a151f602451
python3.10@3.10.12-1~22.04.4
3.10.12-1~22.04.16
1
iomesh/csi-driver:v2.7.25d3f9bf9240b
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16
1
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
python3.8@3.8.10-0ubuntu1~20.04.2
no fix listed
1
ispras/svacer:11-2-042aa9fa9f189
python3.10@3.10.12-1~22.04.10
3.10.12-1~22.04.16
1
istio/install-cni:1.10.32232f365aed6
python3.6@3.6.9-1~18.04ubuntu1.4
no fix listed
1
istio/node-agent-k8s:1.2.9268ab879ea51
python3.5@3.5.2-2ubuntu0~16.04.5
no fix listed
1
istio/operator:1.10.3655eefa11c84
python3.6@3.6.9-1~18.04ubuntu1.4
no fix listed
1
istio/pilot:1.10.0294ca55bd1cc
python3.6@3.6.9-1~18.04ubuntu1.4
no fix listed
1
istio/pilot:1.2.9c09319753454
python3.5@3.5.2-2ubuntu0~16.04.5
no fix listed
1
istio/pilot:1.10.3e7e110a421c2
python3.6@3.6.9-1~18.04ubuntu1.4
no fix listed
1
istio/proxyv2:1.2.90c78be035e98
python3.5@3.5.2-2ubuntu0~16.04.5
no fix listed
1
istio/proxyv2:1.9.687a9db561d2e
python3.6@3.6.9-1~18.04ubuntu1.4
no fix listed
1
istio/proxyv2:1.10.088c6c693e67a
python3.6@3.6.9-1~18.04ubuntu1.4
no fix listed
1
jaedb/iris:latest048cfbf58d57
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u8
1
jakowenko/double-take:1.6.0b858bac9e32a
python3.8@3.8.10-0ubuntu1~20.04.1
no fix listed
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
python3@3.12.11-r0
3.12.14-r0
1
jedi132000/nextapp:latestdc2a81e92f23
python3.8@3.8.10-0ubuntu1~20.04.5
no fix listed
1
jmferrer/azure-devops-agent:latest030f68ec6998
python3.5@3.5.2-2ubuntu0~16.04.9
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
python3.11@3.11.2-6+deb12u7
3.11.2-6+deb12u8
1
josh5/unmanic:0.2.64d49c4816260
python3.10@3.10.12-1~22.04.3
3.10.12-1~22.04.16
1
jupyterhub/jupyterhub:5.4.63974ba945e65
python3.12@3.12.3-1ubuntu0.13
3.12.3-1ubuntu0.15
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
python3.8@3.8.5-1~20.04
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
python3.8@3.8.10-0ubuntu1~20.04.1
no fix listed
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
python3@3.12.13-r0
3.12.14-r0
1
kenchrcum/grafana-dashboard-converter:0.3.105310497aea3f
python3@3.12.12-r0
3.12.14-r0
1
kennethreitz/httpbin:latest599fe5e50731
python3.6@3.6.6-1~18.04
no fix listed
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
python3.8@3.8.10-0ubuntu1~20.04.6
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
1
knspar/phronetis:0.1.4609499d2dc91a
python3.12@3.12.3-1ubuntu0.5
3.12.3-1ubuntu0.15
1
knspar/phronetis-operator:0.1.60c4f0543ee58
python3.11@3.11.2-6
3.11.2-6+deb12u8
1
kong/httpbin:latesta6ac46531193
python3.10@3.10.12-1~22.04.7
3.10.12-1~22.04.16
1
kubearmor/kubearmor:stablea08141311045
python3@3.12.13-r0
3.12.14-r0
1
kubearmor/kubearmor-init:stable236ade6e67b1
python3@3.12.13-r0
3.12.14-r0
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
python3.6@3.6.9-1~18.04ubuntu1
no fix listed
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
python3.12@3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.15
1
kusionstack/kusion:v0.14.0126c8f0b0976
python3.10@3.10.12-1~22.04.8
3.10.12-1~22.04.16
1
laly9999/node-app:1dd0e503913e1
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
python3.12@3.12.3-1ubuntu0.13
3.12.3-1ubuntu0.15
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
python3.12@3.12.3-1ubuntu0.9
3.12.3-1ubuntu0.15
1
library/cassandra:3.11.10b095ff3248c6
python2.7@2.7.18-1~20.04.1
no fix listed
1
library/nextcloud:31.0.6-apache588609d76b21
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
1
library/nextcloud:31.0.10-apacheb7faa1653c39
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
library/node:208f693eaa7e0a
python3.11@3.11.2-6+deb12u6
3.11.2-6+deb12u8
1
library/python:3.8d41127070014
python3.11@3.11.2-6+deb12u3
3.11.2-6+deb12u8
1
library/python:3.9da5aee29682d
python3.13@3.13.5-2
3.13.5-2+deb13u2
1
library/rabbitmq:3.11.5-management1b0f675d2f24
python3.8@3.8.10-0ubuntu1~20.04.6
no fix listed
1
library/rabbitmq:3.7-managementb6dd45cc35b3
python3.6@3.6.9-1~18.04ubuntu1.1
no fix listed
1
library/varnish:7.5.04d0bb287d87b
python3.11@3.11.2-6+deb12u5
3.11.2-6+deb12u8
1
library/wordpress:6.4.3-apache8ae66efb09a2
python3.11@3.11.2-6
3.11.2-6+deb12u8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.