StackRadar

CVE-2026-69243

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
175
of 17,781 indexed, latest versions
Container images
176
deployed by those charts
Fix available
1 of 2
affected packages

AIOHTTP: HTTP request smuggling via WebSocket upgrade

Carried by container images the latest versions of 175 of 17,781 indexed charts deploy, on 176 images.

Affected packageAffected versionsFixed inImages
aiohttppypi3.4.4, 3.5.4, 3.6.2, 3.7.1+34 more3.14.2176
python-aiohttpdeb3.8.4-1, 3.11.16-1+deb13u1no fix listed2
OSV records
DEBIAN-CVE-2026-69243GHSA-mfx4-hv73-q22v
Also known as
PYSEC-2026-3546

Charts affected

175 by stars
ChartLatestAffected imagesRadar Score
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
aiohttp@3.14.1
3.14.2

Open the chart page →

2,165
impulseimpulse1.0.161 of 1See more

impulse impulse 1.0.16

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/eslupmi/impulse:v3.7.03ded1b7ebca0
aiohttp@3.13.5
3.14.2

Open the chart page →

1,348
guardrails-usvcinfracloud-chartsVerified publisher1.0.11 of 1See more

guardrails-usvc infracloud-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
opea/guardrails-tgi:latestf68bec6a1271
aiohttp@3.11.11
3.14.2

Open the chart page →

5,062
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
aiohttp@3.13.5
3.14.2

Open the chart page →

17,852
shynetjuniorjpdj0.1.301 of 1See more

shynet juniorjpdj 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.13.1ba54f7797a6b
aiohttp@3.8.1
3.14.2

Open the chart page →

2,581
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
aiohttp@3.13.3
3.14.2

Open the chart page →

4,568
karbkarbVerified publisher1.0.31 of 1See more

karb karb 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/xeor/karb:main647a3c938d31
aiohttp@3.13.3
3.14.2

Open the chart page →

625
karb-chartkarbVerified publisher1.0.61 of 1See more

karb-chart karb 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/xeor/karb:1.0.6647a3c938d31
aiohttp@3.13.3
3.14.2

Open the chart page →

625
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
aiohttp@3.13.5
3.14.2

Open the chart page →

7,081
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
aiohttp@3.8.5
3.14.2

Open the chart page →

6,447
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
aiohttp@3.13.5
3.14.2

Open the chart page →

9,620
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
aiohttp@3.11.16
3.14.2

Open the chart page →

8,405
jupyterhubkubeblocksVerified publisher0.1.01 of 7See more

jupyterhub kubeblocks 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
aiohttp@3.8.5
3.14.2

Open the chart page →

7,356
deepflowkubesphere-stable6.2.6061 of 8See more

deepflow kubesphere-stable 6.2.606

1 of the 8 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
deepflowce/deepflow-app:v6.2.6.5a1888d35e787
aiohttp@3.4.4
3.14.2

Open the chart page →

18,316
kubevoipkubevoipOfficialVerified publisher0.6.81 of 1See more

kubevoip kubevoip 0.6.8

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/kubevoip/kubevoip:v0.6.841c603a93642
aiohttp@3.14.1
3.14.2

Open the chart page →

1,075
legendlegend0.1.21 of 1See more

legend legend 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/grofers/legend:0.1d6e901ad0ebd
aiohttp@3.7.1
3.14.2

Open the chart page →

4,067
calendar-apiliturgical0.1.51 of 1See more

calendar-api liturgical 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
aiohttp@3.12.15
3.14.2

Open the chart page →

1,556
liturgical-apiliturgical0.2.111 of 1See more

liturgical-api liturgical 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
aiohttp@3.13.4
3.14.2

Open the chart page →

1,004
kafka-aggregatorlsst-sqre0.1.21 of 1See more

kafka-aggregator lsst-sqre 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
lsstsqre/kafkaaggregator:masterbe1b21060854
aiohttp@3.7.4
3.14.2

Open the chart page →

3,052
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
aiohttp@3.8.1
3.14.2

Open the chart page →

17,779
miot-harnessmicroboxlabs0.7.01 of 1See more

miot-harness microboxlabs 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
aiohttp@3.14.1
3.14.2

Open the chart page →

1,140
buildkite-exporterminaVerified publisher0.1.41 of 1See more

buildkite-exporter mina 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
codaprotocol/buildkite-exporter:0.2.137c68e67a401
aiohttp@3.7.3
3.14.2

Open the chart page →

2,599
mum-discord-botmum-discord-botVerified publisher0.3.71 of 1See more

mum-discord-bot mum-discord-bot 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
aiohttp@3.9.1
3.14.2

Open the chart page →

13,686
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
aiohttp@3.8.4
3.14.2

Open the chart page →

5,456
object-clonerobject-clonerVerified publisher2.0.01 of 1See more

object-cloner object-cloner 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/ideamixes/object-cloner:2.0.031030fd2f192
aiohttp@3.8.5
3.14.2

Open the chart page →

1,588
ocellusaiocellusaiVerified publisher0.1.121 of 2See more

ocellusai ocellusai 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
aiohttp@3.14.1
3.14.2

Open the chart page →

1,162
octantisoctantis0.1.01 of 1See more

octantis octantis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/vinny1892/octantis:latest45459c0910fc
aiohttp@3.13.3
3.14.2

Open the chart page →

2,555
chatbot-ai-sampleopenshift0.1.61 of 4See more

chatbot-ai-sample openshift 0.1.6

1 of the 4 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
aiohttp@3.9.5
3.14.2

Open the chart page →

18,922
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
aiohttp@3.13.2
3.14.2

Open the chart page →

4,749
email-managerphntom0.1.221 of 2See more

email-manager phntom 0.1.22

1 of the 2 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
phntom/email-manager:0.1.22d8e2a9f2f085
aiohttp@3.8.4
3.14.2

Open the chart page →

2,565
phronetisphronetis0.1.271 of 2See more

phronetis phronetis 0.1.27

1 of the 2 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
knspar/phronetis-operator:0.1.60c4f0543ee58
aiohttp@3.12.13
3.14.2

Open the chart page →

16,196
pieeatpieeatOfficialVerified publisher0.9.31 of 1See more

pieeat pieeat 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
quay.io/maxiv/pieeat:0.9.3099715479210
aiohttp@3.13.5
3.14.2

Open the chart page →

1,416
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
aiohttp@3.12.13
3.14.2

Open the chart page →

4,272
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
aiohttp@3.10.5
3.14.2

Open the chart page →

21,211
radar-kafkaradar-baseVerified publisher0.4.11 of 2See more

radar-kafka radar-base 0.4.1

1 of the 2 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
aiohttp@3.8.1
3.14.2

Open the chart page →

4,219
kube-web-viewrlex0.5.01 of 1See more

kube-web-view rlex 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:23.8.0431f1bf013d0
aiohttp@3.8.4
3.14.2

Open the chart page →

4,908
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
aiohttp@3.10.10
3.14.2

Open the chart page →

9,607
imgtagrotationalVerified publisher0.2.01 of 1See more

imgtag rotational 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
aiohttp@3.11.13
3.14.2

Open the chart page →

3,312
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
aiohttp@3.11.13
3.14.2

Open the chart page →

3,512
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
aiohttp@3.11.13
3.14.2

Open the chart page →

4,718
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
aiohttp@3.13.5
3.14.2

Open the chart page →

7,436
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
aiohttp@3.12.15
3.14.2

Open the chart page →

4,499
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
aiohttp@3.13.5
3.14.2

Open the chart page →

1,577
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
aiohttp@3.13.5
3.14.2

Open the chart page →

19,560
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
aiohttp@3.9.1
3.14.2

Open the chart page →

10,209
scapyscapy-containerised0.3.41 of 2See more

scapy scapy-containerised 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
saidsef/scapy-containerised:v2025.02f17f7c435891
aiohttp@3.11.12
3.14.2

Open the chart page →

2,817
search-proxysearch-proxy2026.38.01 of 1See more

search-proxy search-proxy 2026.38.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
aiohttp@3.14.1
3.14.2

Open the chart page →

1,264
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
aiohttp@3.8.5
3.14.2

Open the chart page →

3,337
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
aiohttp@3.13.3
3.14.2

Open the chart page →

5,201
srebotsrebot0.14.01 of 2See more

srebot srebot 0.14.0

1 of the 2 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
aiohttp@3.13.5
3.14.2

Open the chart page →

1,542

Container images carrying it

176 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hayk96/alerta-web:9.0.486377705e9e3
aiohttp@3.10.5
3.14.2
1
hhyo/archery:v1.9.11aa41843419e
aiohttp@3.8.3
3.14.2
1
hjacobs/kube-web-view:23.8.0431f1bf013d0
aiohttp@3.8.4
3.14.2
1
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
aiohttp@3.6.2
3.14.2
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
aiohttp@3.8.5
3.14.2
1
homeassistant/home-assistant:2023.12.48d000332b09b
aiohttp@3.9.1
3.14.2
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
aiohttp@3.13.5
3.14.2
1
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
aiohttp@3.7.4
3.14.2
1
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
aiohttp@3.8.5
3.14.2
1
jupyterjsc/jupyterhub-outpost:2.3.1aea53b13f235
aiohttp@3.13.5
3.14.2
1
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
aiohttp@3.13.5
3.14.2
1
kenchrcum/hetzner-s3-operator:0.1.384dae7aeea5b
aiohttp@3.13.5
3.14.2
1
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
aiohttp@3.13.5
3.14.2
1
knspar/phronetis-operator:0.1.60c4f0543ee58
aiohttp@3.12.13
3.14.2
1
langgenius/dify-api:1.0.0066035f93856
aiohttp@3.11.12
3.14.2
1
langgenius/dify-api:1.16.1dcefa5f7c47c
aiohttp@3.14.1
3.14.2
1
langgenius/dify-api:0.6.11fca918260dd6
aiohttp@3.9.5
3.14.2
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
aiohttp@3.13.3
3.14.2
1
lsstsqre/kafkaaggregator:masterbe1b21060854
aiohttp@3.7.4
3.14.2
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
aiohttp@3.8.1
3.14.2
1
makersquad/harp-proxy:0.8.1a40dd258c527
aiohttp@3.11.18
3.14.2
1
mathesar/mathesar:0.12.0091757cb01fe
aiohttp@3.14.1
3.14.2
1
milesmcc/shynet:v0.13.1ba54f7797a6b
aiohttp@3.8.1
3.14.2
1
milesmcc/shynet:v0.12.0e821e31140f7
aiohttp@3.8.1
3.14.2
1
mindsdb/mindsdb:latest163011c09299
aiohttp@3.13.5
3.14.2
1
opea/asr:1.025dd26d9cd09
aiohttp@3.10.5
3.14.2
1
opea/chatqna:1.038c51b791efa
aiohttp@3.10.5
3.14.2
1
opea/codegen:1.058f91683892d
aiohttp@3.10.5
3.14.2
1
opea/codetrans:1.0e2436483b73d
aiohttp@3.10.5
3.14.2
1
opea/docsum:1.03eaa91849512
aiohttp@3.10.5
3.14.2
1
opea/guardrails-tgi:1.0262c6048aab8
aiohttp@3.10.5
3.14.2
1
opea/guardrails-tgi:latestf68bec6a1271
aiohttp@3.11.11
3.14.2
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
aiohttp@3.10.5
3.14.2
1
opea/speecht5:1.0249afad3d268
aiohttp@3.10.5
3.14.2
1
opea/tts:1.0257ae94709e9
aiohttp@3.10.5
3.14.2
1
opea/web-retriever-chroma:1.0fe08165d7770
aiohttp@3.10.5
3.14.2
1
openbas/caldera-server:5.1.0a277796d9724
aiohttp@3.10.8
3.14.2
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
aiohttp@3.12.13
3.14.2
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
aiohttp@3.10.11
3.14.2
1
opencsghq/csgship-agentic:v0.4.02cd29671a03e
aiohttp@3.12.15
3.14.2
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
aiohttp@3.12.15
3.14.2
1
opendatacube/restcube:latest91870111837c
aiohttp@3.6.2
3.14.2
1
opendatacube/wms:latest1b90cdf68831
aiohttp@3.6.2
3.14.2
1
openmined/syft-backend:0.9.5b72f74a68b32
aiohttp@3.11.12
3.14.2
1
pangeo/base-notebook:2024.01.155fbe688a4f80
aiohttp@3.9.1
3.14.2
1
phntom/email-manager:0.1.22d8e2a9f2f085
aiohttp@3.8.4
3.14.2
1
prowlercloud/prowler-api:5.31.14f252d579be2
aiohttp@3.14.0
3.14.2
1
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
aiohttp@3.13.5
3.14.2
1
rommapp/romm:4.4.1b909e95d1aab
aiohttp@3.12.14
3.14.2
1
runx1/opta-agent:latest0ca3867d3200
aiohttp@3.8.1
3.14.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.