StackRadar

CVE-2026-6873

Medium

Advisory

Published 3 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.002
16th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
92
of 17,781 indexed, latest versions
Container images
93
deployed by those charts
Fix available
1 of 1
affected package

Django: signed cookies are vulnerable to salt namespace collisions

Carried by container images the latest versions of 92 of 17,781 indexed charts deploy, on 93 images.

Affected packageAffected versionsFixed inImages
djangopypi1.11.11, 1.11.24, 1.11.29, 2.2.13+60 more5.2.1593
OSV records
PYSEC-2026-199GHSA-h7pc-vwp9-298g
Also known as
BIT-django-2026-6873

Charts affected

92 by stars
ChartLatestAffected imagesRadar Score
linkdingdeimosfr-charts1.0.31 of 1See more

linkding deimosfr-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.35.00c5dddf0b37c
django@5.1.1
5.2.15

Open the chart page →

6,075
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
django@3.2.16
5.2.15

Open the chart page →

14,856
devops-diplomdevops-diplom-chartVerified publisher0.8.01 of 2See more

devops-diplom devops-diplom-chart 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
alexeyr7/sf-test-app:latestdf0b41fdbd53
django@4.0.5
5.2.15

Open the chart page →

2,548
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
django@5.2.13
5.2.15

Open the chart page →

7,459
codecovdoubanVerified publisher0.2.42 of 8See more

codecov douban 0.2.4

2 of the 8 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
codecov/self-hosted-api:24.4.10475cb1c3136
django@4.2.7
5.2.15
codecov/self-hosted-worker:24.4.1837f546b479b
django@4.2.11
5.2.15

Open the chart page →

24,917
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
django@3.2.14
5.2.15

Open the chart page →

25,122
escvmschedulerescvmscheduler1.0.71 of 3See more

escvmscheduler escvmscheduler 1.0.7

1 of the 3 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
swisscomcloud/esc-vm-scheduler-web:latestb6639d1a922e
django@3.2.16
5.2.15

Open the chart page →

4,678
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
django@3.2.8
5.2.15

Open the chart page →

64,489
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
django@4.2.18
5.2.15

Open the chart page →

2,183
babybuddygeek-cookbookVerified publisher1.2.21 of 1See more

babybuddy geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
linuxserver/babybuddy:1.10.2f7d7c7704249
django@4.0.2
5.2.15

Open the chart page →

1,489
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
django@2.2.14
5.2.15

Open the chart page →

24,293
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
django@3.1.1
5.2.15

Open the chart page →

7,984
archiveboxhelmforgeVerified publisher1.1.121 of 1See more

archivebox helmforge 1.1.12

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
archivebox/archivebox:0.7.41a5a37331091
django@3.1.14
5.2.15

Open the chart page →

7,633
chiefonboardinghelmforgeVerified publisher1.1.141 of 3See more

chiefonboarding helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
django@5.2.12
5.2.15

Open the chart page →

10,849
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
django@4.2.7
5.2.15

Open the chart page →

16,384
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
django@1.11.29
5.2.15

Open the chart page →

6,501
healthchecksimprowisedVerified publisher1.1.11 of 2See more

healthchecks improwised 1.1.1

1 of the 2 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
linuxserver/healthchecks:2.7.2023033194696dab3c50
django@4.1.7
5.2.15

Open the chart page →

2,628
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
django@5.1.15
5.2.15

Open the chart page →

3,157
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
django@4.2.27
5.2.15

Open the chart page →

17,852
ja-shortenerja-shortenerVerified publisher0.1.01 of 2See more

ja-shortener ja-shortener 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
cr0hn/ja-shortener:v0.1.414482d0bc4a1
django@5.2.3
5.2.15

Open the chart page →

2,089
shynetjuniorjpdj0.1.301 of 1See more

shynet juniorjpdj 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.13.1ba54f7797a6b
django@4.1.10
5.2.15

Open the chart page →

2,581
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
django@5.2.7
5.2.15

Open the chart page →

9,103
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
django@5.2.11
5.2.15

Open the chart page →

4,568
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
django@3.2.16
5.2.15

Open the chart page →

16,417
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
django@5.0.14
5.2.15

Open the chart page →

8,405
large-systems-djangolarge-systems-djangoVerified publisher1.0.01 of 1See more

large-systems-django large-systems-django 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
ha33ona/python:test6affdfc644d0
django@2.2.26
5.2.15

Open the chart page →

3,891
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
django@5.1.10
5.2.15

Open the chart page →

37,942
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
django@5.2.7
5.2.15

Open the chart page →

11,950
comacopencord1.0.02 of 9See more

comac opencord 1.0.0

2 of the 9 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
django@1.11.11
5.2.15
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
django@1.11.11
5.2.15

Open the chart page →

88,546
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
django@1.11.11
5.2.15

Open the chart page →

26,211
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
django@6.0
5.2.15

Open the chart page →

3,854
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
django@3.2.14
5.2.15

Open the chart page →

22,084
libretimepodzone-chartsVerified publisher0.4.11 of 9See more

libretime podzone-charts 0.4.1

1 of the 9 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-api:latesteae026cc8909
django@4.2.23
5.2.15

Open the chart page →

11,149
reviewboardrock8sVerified publisher0.0.11 of 3See more

reviewboard rock8s 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
beanbag/reviewboard:latest6b840f546e1c
django@4.2.30
5.2.15

Open the chart page →

6,084
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
django@5.2.7
5.2.15

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
django@5.2.8
5.2.15

Open the chart page →

4,499
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
django@6.0.5
5.2.15

Open the chart page →

1,577
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
django@6.0.5
5.2.15

Open the chart page →

19,560
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
django@4.2.30
5.2.15

Open the chart page →

11,636
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
django@3.0.4
5.2.15

Open the chart page →

8,694
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
django@4.2.16
5.2.15

Open the chart page →

4,731
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6873.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
django@4.0.5
5.2.15

Open the chart page →

3,392

Container images carrying it

93 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
cloudve/cloudlaunch-server:latest4a3d7fae90bb
django@3.2.9
5.2.15
3
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
django@1.11.11
5.2.15
2
safeglobal/safe-config-service:latest09a5e495c219
django@6.0.5
5.2.15
2
taigaio/taiga-back:latest4beed8f62c9f
django@3.2.25
5.2.15
2
weblate/weblate:4.2.2-169c160d37a3c
django@3.1.1
5.2.15
2
alexeyr7/sf-test-app:latestdf0b41fdbd53
django@4.0.5
5.2.15
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
django@5.0.14
5.2.15
1
archivebox/archivebox:0.7.41a5a37331091
django@3.1.14
5.2.15
1
baserow/backend:1.31.1e0b3c8130b91
django@5.0.9
5.2.15
1
baserow/baserow:1.30.1df0c42eb67e8
django@5.0.9
5.2.15
1
beanbag/reviewboard:latest6b840f546e1c
django@4.2.30
5.2.15
1
camerahub/camerahub:0.36.23a5af37dd6e1b
django@3.2.18
5.2.15
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
django@5.2.12
5.2.15
1
codecov/self-hosted-api:24.4.10475cb1c3136
django@4.2.7
5.2.15
1
codecov/self-hosted-worker:24.4.1837f546b479b
django@4.2.11
5.2.15
1
cr0hn/ja-shortener:v0.1.414482d0bc4a1
django@5.2.3
5.2.15
1
datamate/seafile-professional:11.0.202dd66b722464
django@4.2.23
5.2.15
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
django@4.2.11
5.2.15
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
django@5.0.7
5.2.15
1
ddosify/selfhosted_backend:3.2.93c11e3182652
django@4.1.13
5.2.15
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
django@4.1.13
5.2.15
1
ddosify/selfhosted_hammermanager:1.2.471b8768f49bc
django@3.2.24
5.2.15
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
django@4.1.13
5.2.15
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
django@3.2.8
5.2.15
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
django@2.2.17
5.2.15
1
galaxy/cloudman-server:lateste5c265fe9fcd
django@4.0.7
5.2.15
1
gethue/hue:4.11.011b649636e68
django@3.2.16
5.2.15
1
gethue/hue:4.10.05702b2c37ff9
django@3.2.4
5.2.15
1
gethue/hue:latest7d5c1b9f8a79
django@4.2.23
5.2.15
1
grafana/oncall:v1.16.5499851658393
django@4.2.22
5.2.15
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
django@2.2.13
5.2.15
1
ha33ona/python:test6affdfc644d0
django@2.2.26
5.2.15
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
django@4.2
5.2.15
1
heartexlabs/label-studio:latestaa461572e8f9
django@5.1.15
5.2.15
1
hhyo/archery:v1.9.11aa41843419e
django@4.1.1
5.2.15
1
improwised/erpnext-worker:v13.4.197280b55cbd4
django@1.11.29
5.2.15
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
django@4.2.27
5.2.15
1
kobotoolbox/kobocat:2.022.24ab15679454415
django@2.2.28
5.2.15
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
django@2.2.27
5.2.15
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
django@4.0.5
5.2.15
1
linuxserver/babybuddy:1.10.2f7d7c7704249
django@4.0.2
5.2.15
1
linuxserver/healthchecks:version-v1.20.050792a72fc71
django@3.2
5.2.15
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
django@4.1.7
5.2.15
1
mathesar/mathesar:0.12.0091757cb01fe
django@4.2.29
5.2.15
1
milesmcc/shynet:v0.13.1ba54f7797a6b
django@4.1.10
5.2.15
1
milesmcc/shynet:v0.12.0e821e31140f7
django@3.2.10
5.2.15
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
django@1.11.24
5.2.15
1
netboxcommunity/netbox:v3.2.83d652dca5351
django@4.0.7
5.2.15
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
django@4.2.11
5.2.15
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
django@4.2.30
5.2.15
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.