StackRadar

CVE-2026-69248

High

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.3
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
693
of 17,781 indexed, latest versions
Container images
570
deployed by those charts
Fix available
1 of 2
affected packages

python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

Carried by container images the latest versions of 693 of 17,781 indexed charts deploy, on 570 images.

Affected packageAffected versionsFixed inImages
cryptographypypi1.7.2, 1.9, 2.1.4, 2.2.2+74 more49.0.0570
python-cryptographydeb38.0.4-3, 38.0.4-3+deb12u1, 43.0.0-3+deb13u1, 46.0.5-1ubuntu2no fix listed15
OSV records
DEBIAN-CVE-2026-69248GHSA-m2h6-j472-rp4cPYSEC-2026-3554UBUNTU-CVE-2026-69248

Charts affected

693 by stars
ChartLatestAffected imagesRadar Score
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
49.0.0

Open the chart page →

5,704
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
49.0.0

Open the chart page →

4,073
kube-ops-viewfluent-operatorVerified publisher0.1.21 of 1See more

kube-ops-view fluent-operator 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:20.4.058221b57d4d2
cryptography@2.9.2
49.0.0

Open the chart page →

1,848
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
louislam/uptime-kuma:13d632903e6af
cryptography@2.6.1
49.0.0

Open the chart page →

3,474
fluxcd-helm-upgraderfluxcd-helm-upgraderVerified publisher0.7.71 of 1See more

fluxcd-helm-upgrader fluxcd-helm-upgrader 0.7.7

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
cryptography@47.0.0
49.0.0

Open the chart page →

2,420
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
cryptography@48.0.0
49.0.0

Open the chart page →

3,463
forms-catalogueforms-catalogue0.1.01 of 2See more

forms-catalogue forms-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
cryptography@3.4.8
49.0.0

Open the chart page →

2,188
powerdnsfsdrw080.1.31 of 4See more

powerdns fsdrw08 0.1.3

1 of the 4 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
cryptography@36.0.2
49.0.0

Open the chart page →

1,958
changedetection-iogabe565Verified publisher0.12.01 of 2See more

changedetection-io gabe565 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:latestecacd9fd0c66
cryptography@44.0.0
49.0.0

Open the chart page →

2,595
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
cryptography@44.0.0
49.0.0

Open the chart page →

2,183
spectergaloymoney0.3.11 of 1See more

specter galoymoney 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
lncm/specter-desktop:v1.10.536eaa06f99f4
cryptography@3.4.7
49.0.0

Open the chart page →

1,691
spectergaloymoney20.3.11 of 1See more

specter galoymoney2 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
lncm/specter-desktop:v1.10.536eaa06f99f4
cryptography@3.4.7
49.0.0

Open the chart page →

1,691
pagesgary-pages1.0.01 of 3See more

pages gary-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
49.0.0

Open the chart page →

20,190
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
cryptography@3.4.8
49.0.0

Open the chart page →

16,123
changedetection-iogeek-cookbookVerified publisher1.5.21 of 1See more

changedetection-io geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
cryptography@3.4.8
49.0.0

Open the chart page →

1,950
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
cryptography@2.1.4
49.0.0

Open the chart page →

13,551
openemrgeek-cookbookVerified publisher5.2.01 of 1See more

openemr geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
openemr/openemr:6.1.089eaa6d9a4e3
cryptography@36.0.2
49.0.0

Open the chart page →

8,392
powerdns-admingeek-cookbookVerified publisher1.2.21 of 1See more

powerdns-admin geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
cryptography@35.0.0
49.0.0

Open the chart page →

2,643
pyloadgeek-cookbookVerified publisher6.4.21 of 1See more

pyload geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/pyload:version-5de90278d3c87933a5fd
cryptography@3.3.2
49.0.0

Open the chart page →

1,236
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
cryptography@43.0.3
49.0.0

Open the chart page →

8,923
wallabaggeek-cookbookVerified publisher7.2.01 of 1See more

wallabag geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
wallabag/wallabag:2.4.25e4c26a7fb4a
cryptography@2.9.2
49.0.0

Open the chart page →

4,358
whooglegeek-cookbookVerified publisher3.4.21 of 1See more

whoogle geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
benbusby/whoogle-search:0.5.4f77f7e6e4ad2
cryptography@3.3.2
49.0.0

Open the chart page →

2,061
mysqlgengxiankun-charts0.2.01 of 1See more

mysql gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
49.0.0

Open the chart page →

463
ldap-backupgluuVerified publisher1.6.111 of 1See more

ldap-backup gluu 1.6.11

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
gluufederation/opendj:4.3.0_011a1128b28b95
cryptography@3.3.2
49.0.0

Open the chart page →

3,064
kube-prometheus-stackgpg-dev84.0.01 of 6See more

kube-prometheus-stack gpg-dev 84.0.0

1 of the 6 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.6.0a6c101156d42
cryptography@46.0.7
49.0.0

Open the chart page →

4,288
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
cryptography@43.0.3
49.0.0

Open the chart page →

49,025
mysqlgroundhog2k3.1.41 of 1See more

mysql groundhog2k 3.1.4

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
library/mysql:9.7.2257388edf9c8
cryptography@46.0.5
49.0.0

Open the chart page →

463
rag-apihajowielandVerified publisher1.0.01 of 1See more

rag-api hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latestf9f34c8ed688
cryptography@48.0.1
49.0.0

Open the chart page →

1,683
pgadminhalkeye1.0.01 of 1See more

pgadmin halkeye 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
chorss/docker-pgadmin4:4.115c549cacb8ab
cryptography@2.7
49.0.0

Open the chart page →

2,555
tautullihalkeye1.1.41 of 2See more

tautulli halkeye 1.1.4

1 of the 2 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
tautulli/tautulli:v2.7.7c4da15f058ea
cryptography@3.4.8
49.0.0

Open the chart page →

1,473
helixhelix1.4.31 of 2See more

helix helix 1.4.3

1 of the 2 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
cryptography@46.0.7
49.0.0

Open the chart page →

5,568
pageshelm-chart-repos-camden1.0.01 of 3See more

pages helm-chart-repos-camden 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
49.0.0

Open the chart page →

20,190
esphomehelm-chart-roeiVerified publisher2025.3.01 of 1See more

esphome helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
esphome/esphome:2025.3.0def8b6e4f517
cryptography@44.0.2
49.0.0

Open the chart page →

6,008
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
cryptography@44.0.1
49.0.0

Open the chart page →

4,647
kube-downscalerhelm-charts-nr0.7.61 of 1See more

kube-downscaler helm-charts-nr 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
cryptography@41.0.1
49.0.0

Open the chart page →

4,293
mlflowhelm-charts-nr1.0.101 of 1See more

mlflow helm-charts-nr 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
cryptography@2.9.2
49.0.0

Open the chart page →

4,422
supersethelm-charts-nr1.1.31 of 1See more

superset helm-charts-nr 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
cryptography@46.0.5
49.0.0

Open the chart page →

2,305
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
cryptography@3.1
49.0.0

Open the chart page →

7,984
dbapphelmcourseVerified publisher0.3.31 of 2See more

dbapp helmcourse 0.3.3

1 of the 2 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
49.0.0

Open the chart page →

3,971
mysqlhelmcourseVerified publisher0.2.41 of 1See more

mysql helmcourse 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
49.0.0

Open the chart page →

1,518
chart-bookhelm-deploy-book0.1.01 of 3See more

chart-book helm-deploy-book 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
dannielkil/book-db:latest433290c5c1db
cryptography@42.0.7
49.0.0

Open the chart page →

9,122
appwritehelmforgeVerified publisher1.3.41 of 5See more

appwrite helmforge 1.3.4

1 of the 5 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.6adc7d0e7ec23
cryptography@46.0.7
49.0.0

Open the chart page →

6,952
changedetectionhelmforgeVerified publisher1.1.151 of 1See more

changedetection helmforge 1.1.15

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.3ecacd9fd0c66
cryptography@44.0.0
49.0.0

Open the chart page →

2,595
chiefonboardinghelmforgeVerified publisher1.1.141 of 3See more

chiefonboarding helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
cryptography@46.0.5
49.0.0

Open the chart page →

10,849
discount-bandithelmforgeVerified publisher2.0.81 of 3See more

discount-bandit helmforge 2.0.8

1 of the 3 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
library/mysql:9.7.2257388edf9c8
cryptography@46.0.5
49.0.0

Open the chart page →

29,817
drupalhelmforgeVerified publisher1.2.131 of 2See more

drupal helmforge 1.2.13

1 of the 2 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
library/mysql:9.7.2b2cf29815e62
cryptography@46.0.5
49.0.0

Open the chart page →

3,802
fastmcp-serverhelmforgeVerified publisher1.7.41 of 1See more

fastmcp-server helmforge 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.11.2fcb7017327d6
cryptography@46.0.7
49.0.0

Open the chart page →

3,281
ghosthelmforgeVerified publisher1.2.61 of 3See more

ghost helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
library/mysql:8.4.113466ba4a4828
cryptography@46.0.5
49.0.0

Open the chart page →

2,463
jupyterhubhelmforgeVerified publisher1.0.61 of 3See more

jupyterhub helmforge 1.0.6

1 of the 3 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
cryptography@48.0.0
49.0.0

Open the chart page →

5,341
mcp-serverhelmforgeVerified publisher1.0.01 of 1See more

mcp-server helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69248.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.2.061f759a1421f
cryptography@46.0.6
49.0.0

Open the chart page →

3,430

Container images carrying it

570 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
cryptography@36.0.2
49.0.0
1
nlmacamp/check_mk:latest5dbb8589f824
cryptography@2.3.1
49.0.0
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
cryptography@2.1.4
49.0.0
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
cryptography@2.3.1
49.0.0
1
onyxdotapp/onyx-backend:latest473fdffe4e67
cryptography@48.0.1
49.0.0
1
openbas/caldera-server:5.1.0a277796d9724
cryptography@44.0.1
49.0.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
cryptography@43.0.3
49.0.0
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
cryptography@46.0.3
49.0.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
cryptography@45.0.6
49.0.0
1
opencsghq/label-studio:v2.5.047e22aa71870
cryptography@44.0.2
49.0.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
cryptography@44.0.2
49.0.0
1
opendatacube/restcube:latest91870111837c
cryptography@2.7
49.0.0
1
opendatacube/wms:latest1b90cdf68831
cryptography@2.7
49.0.0
1
opendatacube/wps:latest80df355a660b
cryptography@45.0.4
49.0.0
1
openemr/openemr:6.1.089eaa6d9a4e3
cryptography@36.0.2
49.0.0
1
openmined/syft-backend:0.9.5b72f74a68b32
cryptography@44.0.1
49.0.0
1
openspeedtest/latest:v2.0.0d4d62f4b7d85
cryptography@38.0.3
49.0.0
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
cryptography@3.4.6
49.0.0
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
cryptography@3.4.6
49.0.0
1
openvpn/openvpn-as:latest2253c10ec652
cryptography@46.0.6
49.0.0
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
cryptography@2.5
49.0.0
1
openzaak/open-notificaties:1.3.02e65313b9b10
cryptography@3.4.8
49.0.0
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
cryptography@3.4.8
49.0.0
1
pangeo/base-notebook:2024.01.155fbe688a4f80
cryptography@41.0.3
49.0.0
1
percona/pmm-server:3.9.1003f9c25f842
cryptography@36.0.1
49.0.0
1
platzio/backend:v0.6.5d5e5972f344b
cryptography@44.0.3
49.0.0
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
cryptography@2.8
49.0.0
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
cryptography@41.0.3
49.0.0
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
cryptography@43.0.0
49.0.0
1
prompve/prometheus-pve-exporter:3.8.2e3d501a82df5
cryptography@46.0.5
49.0.0
1
prompve/prometheus-pve-exporter:3.4.2fcf041f0c24d
cryptography@42.0.4
49.0.0
1
prompve/prometheus-pve-exporter:2.0.1ff6749eb03b0
cryptography@2.9.2
49.0.0
1
prowlercloud/prowler-api:5.31.14f252d579be2
cryptography@46.0.7
49.0.0
1
pryorda/vmware_exporter:v0.18.479925e63e59f
cryptography@38.0.1
49.0.0
1
pryorda/vmware_exporter:v0.18.3e0f5ba8b7856
cryptography@36.0.2
49.0.0
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
cryptography@39.0.2
49.0.0
1
psono/psono-server:5.0.03b974b43ea03
cryptography@43.0.1
49.0.0
1
pyaephyohein/mysql2s3bk:alphafdee05f2d441
cryptography@41.0.3
49.0.0
1
qichenxu4pd/mysqlweb:1.2d758d41d9c6b
cryptography@41.0.7
49.0.0
1
qonstrukt/php:8.4-v8-apache089af7925aa1
cryptography@41.0.7
49.0.0
1
redash/redash:25.8.000d813437db5
cryptography@45.0.5
49.0.0
1
redash/redash:10.0.0.b503639392753c0376
cryptography@2.8
49.0.0
1
redash/redash:26.3.0c5c9148f5c38
cryptography@46.0.5
49.0.0
1
redislabs/redisinsight:1.14.0b03ab1426d0d
cryptography@39.0.1
49.0.0
1
rommapp/romm:4.4.1b909e95d1aab
cryptography@45.0.5
49.0.0
1
rook/ceph:v1.20.72f970c425617
cryptography@36.0.1
49.0.0
1
rook/ceph:v1.19.2944a1dd70496
cryptography@36.0.1
49.0.0
1
saidsef/scapy-containerised:v2025.02f17f7c435891
cryptography@44.0.1
49.0.0
1
salehmir/jesse:1.10.101afa95f979e9
cryptography@42.0.8
49.0.0
1
saltstack/salt:3006.3e9c7906b7a5c
cryptography@41.0.3
49.0.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.