StackRadar

CVE-2026-63349

High

Advisory

Published 18 Sept 2026In the index since 19 Sept 2026
Severity
High
worst across findings
CVSS
7.0
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
17
of 17,805 indexed, latest versions
Container images
17
deployed by those charts
Fix available
1 of 1
affected package

AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups

Carried by container images the latest versions of 17 of 17,805 indexed charts deploy, on 17 images.

Affected packageAffected versionsFixed inImages
anyiopypi4.14.0, 4.14.14.14.217
OSV records
GHSA-3w57-8xmc-8v26

Charts affected

17 by stars
ChartLatestAffected imagesRadar Score
authentikgoauthentikOfficialVerified publisher2026.8.31 of 1See more

authentik goauthentik 2026.8.3

1 of the 1 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.8.3ab9b4e8cc4ab
anyio@4.14.1
4.14.2

Open the chart page →

988
difydify-helmVerified publisher0.38.02 of 11See more

dify dify-helm 0.38.0

2 of the 11 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
langgenius/dify-api:1.16.1dcefa5f7c47c
anyio@4.14.1
4.14.2
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
anyio@4.14.1
4.14.2

Open the chart page →

64,455
ilumilumOfficialVerified publisher6.7.31 of 19See more

ilum ilum 6.7.3

1 of the 19 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
anyio@4.14.1
4.14.2

Open the chart page →

23,639
aibrixdanchevVerified publisher0.7.01 of 5See more

aibrix danchev 0.7.0

1 of the 5 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
aibrix/metadata-service:v0.7.063fb81a64377
anyio@4.14.0
4.14.2

Open the chart page →

5,470
spoolmanideaplexusVerified publisher2.7.11 of 1See more

spoolman ideaplexus 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
anyio@4.14.1
4.14.2

Open the chart page →

1,848
opentelemetry-demoopentelemetry-helmOfficialVerified publisher0.42.02 of 34See more

opentelemetry-demo opentelemetry-helm 0.42.0

2 of the 34 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:3.1.0-mcp81db69cdd0b6
anyio@4.14.1
4.14.2
ghcr.io/open-telemetry/demo:3.1.0-agentd0f4ae0b32a8
anyio@4.14.1
4.14.2

Open the chart page →

20,097
akeyless-gatewayakeyless-services-helmVerified publisher3.5.61 of 2See more

akeyless-gateway akeyless-services-helm 3.5.6

1 of the 2 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
akeyless/gateway:5.4.0d4768a9b089c
anyio@4.14.1
4.14.2

Open the chart page →

1,414
spoolmandjjudas21Verified publisher0.1.81 of 1See more

spoolman djjudas21 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.24.042135965c42d
anyio@4.14.1
4.14.2

Open the chart page →

1,902
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
anyio@4.14.1
4.14.2

Open the chart page →

2,247
searxngkubeblocksVerified publisher0.1.01 of 1See more

searxng kubeblocks 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
searxng/searxng:2026.7.2-67973783d33aa33278be6
anyio@4.14.1
4.14.2

Open the chart page →

32
searxnglbenicio-communityVerified publisher0.1.11 of 1See more

searxng lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
searxng/searxng:2026.6.22-952896d293f52dca114d9
anyio@4.14.0
4.14.2

Open the chart page →

32
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
anyio@4.14.0
4.14.2

Open the chart page →

7,648
rawfile-localpvrawfile0.15.31 of 6See more

rawfile-localpv rawfile 0.15.3

1 of the 6 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
openebs/rawfile-localpv:v0.15.396fd7987ea79
anyio@4.14.0
4.14.2

Open the chart page →

2,800
spoolmanretsamedocVerified publisher26.9.01 of 1See more

spoolman retsamedoc 26.9.0

1 of the 1 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
anyio@4.14.1
4.14.2

Open the chart page →

1,848
rhbk-neurofacerhbk-neurofaceVerified publisher1.0.01 of 4See more

rhbk-neuroface rhbk-neuroface 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
anyio@4.14.0
4.14.2

Open the chart page →

4,022
spoolmanspoolmanVerified publisher0.2.61 of 1See more

spoolman spoolman 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
anyio@4.14.1
4.14.2

Open the chart page →

1,848
servicexssl-hep1.8.52 of 16See more

servicex ssl-hep 1.8.5

2 of the 16 container images this version deploys carry CVE-2026-63349.

Container imageDigestPackageFixed in
sslhep/servicex-did-finder:v1.8.5ab0090083567
anyio@4.14.1
4.14.2
sslhep/x509-secrets:v1.8.5d9e9ecb12d59
anyio@4.14.1
4.14.2

Open the chart page →

69,027

Container images carrying it

17 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
anyio@4.14.1
4.14.2
3
ilum/api:6.7.3624fd09528c8
anyio@4.14.1
4.14.2
2
aibrix/metadata-service:v0.7.063fb81a64377
anyio@4.14.0
4.14.2
1
akeyless/gateway:5.4.0d4768a9b089c
anyio@4.14.1
4.14.2
1
langgenius/dify-api:1.16.1dcefa5f7c47c
anyio@4.14.1
4.14.2
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
anyio@4.14.1
4.14.2
1
openebs/rawfile-localpv:v0.15.396fd7987ea79
anyio@4.14.0
4.14.2
1
searxng/searxng:2026.7.2-67973783d33aa33278be6
anyio@4.14.1
4.14.2
1
searxng/searxng:2026.6.22-952896d293f52dca114d9
anyio@4.14.0
4.14.2
1
sslhep/servicex-did-finder:v1.8.5ab0090083567
anyio@4.14.1
4.14.2
1
sslhep/x509-secrets:v1.8.5d9e9ecb12d59
anyio@4.14.1
4.14.2
1
ghcr.io/donkie/spoolman:0.24.042135965c42d
anyio@4.14.1
4.14.2
1
ghcr.io/goauthentik/server:2026.8.3ab9b4e8cc4ab
anyio@4.14.1
4.14.2
1
ghcr.io/open-telemetry/demo:3.1.0-mcp81db69cdd0b6
anyio@4.14.1
4.14.2
1
ghcr.io/open-telemetry/demo:3.1.0-agentd0f4ae0b32a8
anyio@4.14.1
4.14.2
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
anyio@4.14.0
4.14.2
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
anyio@4.14.0
4.14.2
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.