StackRadar

CVE-2026-69243

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
175
of 17,781 indexed, latest versions
Container images
176
deployed by those charts
Fix available
1 of 2
affected packages

AIOHTTP: HTTP request smuggling via WebSocket upgrade

Carried by container images the latest versions of 175 of 17,781 indexed charts deploy, on 176 images.

Affected packageAffected versionsFixed inImages
aiohttppypi3.4.4, 3.5.4, 3.6.2, 3.7.1+34 more3.14.2176
python-aiohttpdeb3.8.4-1, 3.11.16-1+deb13u1no fix listed2
OSV records
DEBIAN-CVE-2026-69243GHSA-mfx4-hv73-q22v
Also known as
PYSEC-2026-3546

Charts affected

175 by stars
ChartLatestAffected imagesRadar Score
verostakewise0.8.31 of 2See more

vero stakewise 0.8.3

1 of the 2 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
aiohttp@3.10.10
3.14.2

Open the chart page →

3,458
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
aiohttp@3.9.5
3.14.2

Open the chart page →

13,390
surogate-hubsurogate-hubVerified publisher2.1.51 of 1See more

surogate-hub surogate-hub 2.1.5

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
aiohttp@3.13.5
3.14.2

Open the chart page →

3,460
svc-lb-muxsvc-lb-mux0.1.31 of 1See more

svc-lb-mux svc-lb-mux 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/nowakeai/svc-lb-mux:0.1.37d8fb8e996b6
aiohttp@3.13.5
3.14.2

Open the chart page →

1,419
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
aiohttp@3.10.5
3.14.2

Open the chart page →

4,393
chatqnatest-opea1.0.05 of 11See more

chatqna test-opea 1.0.0

5 of the 11 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
opea/chatqna:1.038c51b791efa
aiohttp@3.10.5
3.14.2
opea/embedding-tei:1.05c9639de61c1
aiohttp@3.10.5
3.14.2
opea/llm-tgi:1.00c25aab3f106
aiohttp@3.10.5
3.14.2
opea/reranking-tei:1.0e48613afb191
aiohttp@3.10.5
3.14.2
opea/retriever-redis:1.0eb746b263705
aiohttp@3.10.5
3.14.2

Open the chart page →

39,090
codegentest-opea1.0.02 of 5See more

codegen test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
opea/codegen:1.058f91683892d
aiohttp@3.10.5
3.14.2
opea/llm-tgi:1.00c25aab3f106
aiohttp@3.10.5
3.14.2

Open the chart page →

28,814
codetranstest-opea1.0.02 of 5See more

codetrans test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
opea/codetrans:1.0e2436483b73d
aiohttp@3.10.5
3.14.2
opea/llm-tgi:1.00c25aab3f106
aiohttp@3.10.5
3.14.2

Open the chart page →

28,385
docsumtest-opea1.0.02 of 5See more

docsum test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
opea/docsum:1.03eaa91849512
aiohttp@3.10.5
3.14.2
opea/llm-docsum-tgi:1.002f9e8fa5d71
aiohttp@3.10.5
3.14.2

Open the chart page →

28,858
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
aiohttp@3.10.5
3.14.2

Open the chart page →

5,185
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
aiohttp@3.10.5
3.14.2

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
aiohttp@3.10.5
3.14.2

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
aiohttp@3.10.5
3.14.2

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
aiohttp@3.10.5
3.14.2

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
aiohttp@3.10.5
3.14.2

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
aiohttp@3.10.5
3.14.2

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
aiohttp@3.10.5
3.14.2

Open the chart page →

5,350
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
aiohttp@3.9.5
3.14.2

Open the chart page →

1,515
traefik-external-dns-operatortraefik-external-dns-operator1.0.11 of 1See more

traefik-external-dns-operator traefik-external-dns-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
aiohttp@3.11.14
3.14.2

Open the chart page →

1,083
orchestratremolo3.1.551 of 5See more

orchestra tremolo 3.1.55

1 of the 5 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
ghcr.io/tremolosecurity/python-slim-nonroot/python3:1.0.079bb14620fe9
aiohttp@3.14.0
3.14.2

Open the chart page →

7,637
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
aiohttp@3.8.1
3.14.2

Open the chart page →

8,607
wasabi-s3-operatorwasabi-s3-operatorVerified publisher0.2.71 of 1See more

wasabi-s3-operator wasabi-s3-operator 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
aiohttp@3.13.5
3.14.2

Open the chart page →

628
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
aiohttp@3.7.4
3.14.2

Open the chart page →

11,119
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.14.2

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69243.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
aiohttp@3.8.1
3.14.2

Open the chart page →

1,636

Container images carrying it

176 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
aiohttp@3.13.5
3.14.2
1
ghcr.io/nowakeai/svc-lb-mux:0.1.37d8fb8e996b6
aiohttp@3.13.5
3.14.2
1
ghcr.io/open-telemetry/demo:3.0.0-mcp654f860148ba
aiohttp@3.14.1
3.14.2
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
aiohttp@3.12.13
3.14.2
1
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
aiohttp@3.10.10
3.14.2
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
aiohttp@3.13.5
3.14.2
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
aiohttp@3.8.3
3.14.2
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
aiohttp@3.8.3
3.14.2
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
aiohttp@3.10.11
3.14.2
1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
aiohttp@3.8.3
3.14.2
1
ghcr.io/tremolosecurity/python-slim-nonroot/python3:1.0.079bb14620fe9
aiohttp@3.14.0
3.14.2
1
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
aiohttp@3.14.1
3.14.2
1
ghcr.io/vinny1892/octantis:latest45459c0910fc
aiohttp@3.13.3
3.14.2
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
aiohttp@3.11.11
3.14.2
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
aiohttp@3.10.10
3.14.2
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
aiohttp@3.11.11
3.14.2
1
quay.io/evl.ms/argocd-exporter:0.0.136ea8f34aa6b
aiohttp@3.7.4.post0
3.14.2
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
aiohttp@3.13.5
3.14.2
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
aiohttp@3.13.5
3.14.2
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
aiohttp@3.9.1
3.14.2
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
aiohttp@3.13.5
3.14.2
1
quay.io/maxiv/pieeat:0.9.3099715479210
aiohttp@3.13.5
3.14.2
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
aiohttp@3.8.1
3.14.2
1
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
aiohttp@3.14.1
3.14.2
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
aiohttp@3.9.5
3.14.2
1
quay.io/stackgres/operator:1.19.1f241b0b20326
aiohttp@3.14.1
3.14.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.