StackRadar

CVE-2026-69247

High

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
344
of 17,781 indexed, latest versions
Container images
237
deployed by those charts
Fix available
1 of 2
affected packages

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

Carried by container images the latest versions of 344 of 17,781 indexed charts deploy, on 237 images.

Affected packageAffected versionsFixed inImages
cryptographypypi44.0.0, 44.0.1, 44.0.2, 44.0.3+18 more50.0.0237
python-cryptographydeb46.0.5-1ubuntu2no fix listed1
OSV records
GHSA-g6cj-pr64-35w5UBUNTU-CVE-2026-69247
Also known as
PYSEC-2026-3552

Charts affected

344 by stars
ChartLatestAffected imagesRadar Score
pgadmin4eks-storageclass0.1.01 of 2See more

pgadmin4 eks-storageclass 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
dpage/pgadmin4:latest2f4ce946ddf8
cryptography@49.0.0
50.0.0

Open the chart page →

398
eoloPlanteolo-plannerVerified publisher0.1.01 of 7See more

eoloPlant eolo-planner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
cryptography@46.0.5
50.0.0

Open the chart page →

27,537
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.01 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
cryptography@46.0.5
50.0.0

Open the chart page →

27,537
eoloplanteoloplant1.0.01 of 7See more

eoloplant eoloplant 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
cryptography@46.0.5
50.0.0

Open the chart page →

27,537
rommernail-romm1.0.11 of 1See more

romm ernail-romm 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
rommapp/romm:4.4.1b909e95d1aab
cryptography@45.0.5
50.0.0

Open the chart page →

2,896
datadog-apmfairwinds-incubator2.0.01 of 1See more

datadog-apm fairwinds-incubator 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
cryptography@45.0.6
50.0.0

Open the chart page →

2,785
farm-observabilityfarm-observabilityOfficialVerified publisher0.27.21 of 18See more

farm-observability farm-observability 0.27.2

1 of the 18 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.7.3694950d736c8
cryptography@48.0.0
50.0.0

Open the chart page →

13,255
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
50.0.0

Open the chart page →

5,704
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
cryptography@47.0.0
50.0.0

Open the chart page →

64,489
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
cryptography@44.0.1
50.0.0

Open the chart page →

5,292
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
50.0.0

Open the chart page →

5,704
fluxcd-helm-upgraderfluxcd-helm-upgraderVerified publisher0.7.71 of 1See more

fluxcd-helm-upgrader fluxcd-helm-upgrader 0.7.7

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
cryptography@47.0.0
50.0.0

Open the chart page →

2,420
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
cryptography@48.0.0
50.0.0

Open the chart page →

3,463
changedetection-iogabe565Verified publisher0.12.01 of 2See more

changedetection-io gabe565 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:latestecacd9fd0c66
cryptography@44.0.0
50.0.0

Open the chart page →

2,595
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
cryptography@44.0.0
50.0.0

Open the chart page →

2,183
pagesgary-pages1.0.01 of 3See more

pages gary-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
50.0.0

Open the chart page →

20,190
mysqlgengxiankun-charts0.2.01 of 1See more

mysql gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
50.0.0

Open the chart page →

463
kube-prometheus-stackgpg-dev84.0.01 of 6See more

kube-prometheus-stack gpg-dev 84.0.0

1 of the 6 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.6.0a6c101156d42
cryptography@46.0.7
50.0.0

Open the chart page →

4,288
mysqlgroundhog2k3.1.41 of 1See more

mysql groundhog2k 3.1.4

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
library/mysql:9.7.2257388edf9c8
cryptography@46.0.5
50.0.0

Open the chart page →

463
rag-apihajowielandVerified publisher1.0.01 of 1See more

rag-api hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latestf9f34c8ed688
cryptography@48.0.1
50.0.0

Open the chart page →

1,683
helixhelix1.4.31 of 2See more

helix helix 1.4.3

1 of the 2 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
cryptography@46.0.7
50.0.0

Open the chart page →

5,568
pageshelm-chart-repos-camden1.0.01 of 3See more

pages helm-chart-repos-camden 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
50.0.0

Open the chart page →

20,190
esphomehelm-chart-roeiVerified publisher2025.3.01 of 1See more

esphome helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
esphome/esphome:2025.3.0def8b6e4f517
cryptography@44.0.2
50.0.0

Open the chart page →

6,008
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
cryptography@44.0.1
50.0.0

Open the chart page →

4,647
supersethelm-charts-nr1.1.31 of 1See more

superset helm-charts-nr 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
cryptography@46.0.5
50.0.0

Open the chart page →

2,305
appwritehelmforgeVerified publisher1.3.41 of 5See more

appwrite helmforge 1.3.4

1 of the 5 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.6adc7d0e7ec23
cryptography@46.0.7
50.0.0

Open the chart page →

6,952
changedetectionhelmforgeVerified publisher1.1.151 of 1See more

changedetection helmforge 1.1.15

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.3ecacd9fd0c66
cryptography@44.0.0
50.0.0

Open the chart page →

2,595
chiefonboardinghelmforgeVerified publisher1.1.141 of 3See more

chiefonboarding helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
cryptography@46.0.5
50.0.0

Open the chart page →

10,849
discount-bandithelmforgeVerified publisher2.0.81 of 3See more

discount-bandit helmforge 2.0.8

1 of the 3 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
library/mysql:9.7.2257388edf9c8
cryptography@46.0.5
50.0.0

Open the chart page →

29,817
drupalhelmforgeVerified publisher1.2.131 of 2See more

drupal helmforge 1.2.13

1 of the 2 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
library/mysql:9.7.2b2cf29815e62
cryptography@46.0.5
50.0.0

Open the chart page →

3,802
fastmcp-serverhelmforgeVerified publisher1.7.41 of 1See more

fastmcp-server helmforge 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.11.2fcb7017327d6
cryptography@46.0.7
50.0.0

Open the chart page →

3,281
ghosthelmforgeVerified publisher1.2.61 of 3See more

ghost helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
library/mysql:8.4.113466ba4a4828
cryptography@46.0.5
50.0.0

Open the chart page →

2,463
jupyterhubhelmforgeVerified publisher1.0.61 of 3See more

jupyterhub helmforge 1.0.6

1 of the 3 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
cryptography@48.0.0
50.0.0

Open the chart page →

5,341
mcp-serverhelmforgeVerified publisher1.0.01 of 1See more

mcp-server helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.2.061f759a1421f
cryptography@46.0.6
50.0.0

Open the chart page →

3,430
medikeephelmforgeVerified publisher2.0.01 of 3See more

medikeep helmforge 2.0.0

1 of the 3 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
ghcr.io/afairgiant/medikeep:v0.69.0766699daa9ac
cryptography@48.0.1
50.0.0

Open the chart page →

6,022
mysqlhelmforgeVerified publisher2.0.31 of 1See more

mysql helmforge 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
library/mysql:9.7.2257388edf9c8
cryptography@46.0.5
50.0.0

Open the chart page →

463
olivetinhelmforgeVerified publisher1.2.11 of 2See more

olivetin helmforge 1.2.1

1 of the 2 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
jamesread/olivetin:3000.19.0af9d7c4db6dc
cryptography@49.0.0
50.0.0

Open the chart page →

307
supersethelmforgeVerified publisher1.3.61 of 5See more

superset helmforge 1.3.6

1 of the 5 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
apache/superset:6.1.016b50bbef664
cryptography@46.0.5
50.0.0

Open the chart page →

5,714
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
cryptography@44.0.1
50.0.0

Open the chart page →

25,017
pageshelm-repo1.0.01 of 3See more

pages helm-repo 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
50.0.0

Open the chart page →

20,190
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
cryptography@49.0.0
50.0.0

Open the chart page →

2,165
plausible-analyticsimioVerified publisher0.4.21 of 5See more

plausible-analytics imio 0.4.2

1 of the 5 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v3.0.114c1afde21d6
cryptography@44.0.0
50.0.0

Open the chart page →

10,418
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
cryptography@46.0.5
50.0.0

Open the chart page →

3,157
pgadmininseefrlab3.2.01 of 1See more

pgadmin inseefrlab 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
dpage/pgadmin4:latest2f4ce946ddf8
cryptography@49.0.0
50.0.0

Open the chart page →

398
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
cryptography@46.0.7
50.0.0

Open the chart page →

17,852
esphomejeffrescVerified publisher0.2.21 of 1See more

esphome jeffresc 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:2026.4.078a82d810709
cryptography@46.0.7
50.0.0

Open the chart page →

5,040
mumbledjjuniorjpdj0.1.1991 of 2See more

mumbledj juniorjpdj 0.1.199

1 of the 2 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
ghcr.io/juniorjpdj/mumbledj:latest558cb7e2604d
cryptography@47.0.0
50.0.0

Open the chart page →

953
palworld-serverk8s-chartsVerified publisher1.2.11 of 1See more

palworld-server k8s-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.5.0b4ac9ee22483
cryptography@48.0.1
50.0.0

Open the chart page →

3,460
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
cryptography@44.0.3
50.0.0

Open the chart page →

9,103
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69247.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
cryptography@46.0.5
50.0.0

Open the chart page →

4,568

Container images carrying it

237 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
esphome/esphome:2026.7.44866347cb5b4
cryptography@49.0.0
50.0.0
1
esphome/esphome:2025.3.0def8b6e4f517
cryptography@44.0.2
50.0.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
cryptography@47.0.0
50.0.0
1
flanksource/batch-runner:v1.0.44689687a7cf95
cryptography@44.0.1
50.0.0
1
frankescobar/allure-docker-service:latestdc171ec796d5
cryptography@48.0.1
50.0.0
1
freedom98/flask:k3.0d7ce1533f297
cryptography@45.0.4
50.0.0
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
cryptography@44.0.3
50.0.0
1
gluufederation/cloudtools:4.5.17-1fe944d2e5d0f
cryptography@47.0.0
50.0.0
1
google/cloud-sdk:alpinef7d3e6d6d4f4
cryptography@46.0.7
50.0.0
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
cryptography@44.0.2
50.0.0
1
grafana/oncall:v1.16.5499851658393
cryptography@44.0.1
50.0.0
1
hansehe/locust:1.1.0bc8e45262bc4
cryptography@44.0.2
50.0.0
1
hayk96/alerta-web:9.0.486377705e9e3
cryptography@44.0.0
50.0.0
1
heartexlabs/label-studio:latestaa461572e8f9
cryptography@46.0.5
50.0.0
1
helmforge/fastmcp-server:0.2.061f759a1421f
cryptography@46.0.6
50.0.0
1
helmforge/fastmcp-server:0.11.2fcb7017327d6
cryptography@46.0.7
50.0.0
1
homeassistant/home-assistant:2026.75a531753cea9
cryptography@48.0.1
50.0.0
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
cryptography@46.0.7
50.0.0
1
jamesread/olivetin:3000.19.0af9d7c4db6dc
cryptography@49.0.0
50.0.0
1
jupyterhub/jupyterhub:5.4.63974ba945e65
cryptography@48.0.0
50.0.0
1
jupyterjsc/jupyterhub-outpost:2.3.1aea53b13f235
cryptography@46.0.7
50.0.0
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
cryptography@47.0.0
50.0.0
1
knspar/phronetis:0.1.4609499d2dc91a
cryptography@45.0.4
50.0.0
1
kyovint/kyoimgtransactions:1.0.048c19e3ae9a3
cryptography@45.0.7
50.0.0
1
kyovint/kyoimgusers:1.0.080084149156e
cryptography@45.0.7
50.0.0
1
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
cryptography@46.0.7
50.0.0
1
langgenius/dify-api:1.0.0066035f93856
cryptography@44.0.1
50.0.0
1
langgenius/dify-api:1.16.1dcefa5f7c47c
cryptography@49.0.0
50.0.0
1
library/mysql:8.4.113466ba4a4828
cryptography@46.0.5
50.0.0
1
library/mysql:885b9bf2e29cf
cryptography@46.0.5
50.0.0
1
library/mysql:8.4.108dbcf531a03a
cryptography@46.0.5
50.0.0
1
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
cryptography@45.0.3
50.0.0
1
linuxserver/deluge:2.2.09505c64720af
cryptography@48.0.1
50.0.0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
cryptography@46.0.5
50.0.0
1
maponyacharles/sceptreai:mlflow-0.1.1242d418654ebd
cryptography@48.0.1
50.0.0
1
maponyacharles/sceptreai:api-0.1.127b37b092130a
cryptography@48.0.1
50.0.0
1
mathesar/mathesar:0.12.0091757cb01fe
cryptography@49.0.0
50.0.0
1
matrixdotorg/synapse:v1.160.078de1d10bef0
cryptography@46.0.7
50.0.0
1
mawad98/backstage-pyactions:demo99422c56a274
cryptography@46.0.6
50.0.0
1
memgraph/mcp-memgraph:0.1.13ecdf7faea3f7
cryptography@48.0.0
50.0.0
1
mindsdb/mindsdb:latest163011c09299
cryptography@46.0.7
50.0.0
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
cryptography@44.0.3
50.0.0
1
netbirdio/dashboard:v2.91.0aae926912ca4
cryptography@47.0.0
50.0.0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
cryptography@46.0.7
50.0.0
1
onyxdotapp/onyx-backend:latest473fdffe4e67
cryptography@48.0.1
50.0.0
1
openbas/caldera-server:5.1.0a277796d9724
cryptography@44.0.1
50.0.0
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
cryptography@46.0.3
50.0.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
cryptography@45.0.6
50.0.0
1
opencsghq/label-studio:v2.5.047e22aa71870
cryptography@44.0.2
50.0.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
cryptography@44.0.2
50.0.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.