StackRadar

CVE-2026-69249

High

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
698
of 17,787 indexed, latest versions
Container images
576
deployed by those charts
Fix available
1 of 2
affected packages

python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

Carried by container images the latest versions of 698 of 17,787 indexed charts deploy, on 576 images.

Affected packageAffected versionsFixed inImages
cryptographypypi1.7.2, 1.9, 2.1.4, 2.2.2+74 more49.0.0576
python-cryptographydeb38.0.4-3, 38.0.4-3+deb12u1, 43.0.0-3+deb13u1, 46.0.5-1ubuntu2no fix listed15
OSV records
DEBIAN-CVE-2026-69249GHSA-jwv3-5hgf-82wwPYSEC-2026-3553UBUNTU-CVE-2026-69249

Charts affected

698 by stars
ChartLatestAffected imagesRadar Score
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
cryptography@2.6.1
49.0.0

Open the chart page →

2,060
open-appsec-injectorstartechnicaVerified publisher1.1.21 of 3See more

open-appsec-injector startechnica 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
cryptography@46.0.7
49.0.0

Open the chart page →

4,315
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
cryptography@3.1.1
49.0.0

Open the chart page →

3,044
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
49.0.0

Open the chart page →

20,233
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
cryptography@43.0.1
49.0.0

Open the chart page →

4,782
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
cryptography@42.0.7
49.0.0

Open the chart page →

12,937
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
49.0.0

Open the chart page →

20,233
svc-lb-muxsvc-lb-mux0.1.31 of 1See more

svc-lb-mux svc-lb-mux 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
ghcr.io/nowakeai/svc-lb-mux:0.1.37d8fb8e996b6
cryptography@48.0.0
49.0.0

Open the chart page →

1,422
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
cryptography@41.0.3
49.0.0

Open the chart page →

12,708
icinga2svtech-public-helm-charts1.0.01 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
cryptography@40.0.2
49.0.0

Open the chart page →

5,101
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
cryptography@41.0.3
49.0.0

Open the chart page →

5,880
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
cryptography@2.5
49.0.0

Open the chart page →

18,828
agentssynapse0.1.301 of 9See more

agents synapse 0.1.30

1 of the 9 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
cryptography@37.0.2
49.0.0

Open the chart page →

7,244
scribesynapse0.2.161 of 7See more

scribe synapse 0.2.16

1 of the 7 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
cryptography@37.0.2
49.0.0

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
cryptography@37.0.2
49.0.0

Open the chart page →

1,955
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
cryptography@46.0.7
49.0.0

Open the chart page →

1,556
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
49.0.0

Open the chart page →

17,561
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
supabase/realtime:latestd3aa0c86c7b3
cryptography@43.0.0
python-cryptography@43.0.0-3+deb13u1
49.0.0
no fix listed

Open the chart page →

9,469
pagestest43221.0.01 of 3See more

pages test4322 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
49.0.0

Open the chart page →

20,233
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
49.0.0

Open the chart page →

5,624
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
cryptography@42.0.7
49.0.0

Open the chart page →

1,514
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
cryptography@41.0.7
49.0.0

Open the chart page →

7,336
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
49.0.0

Open the chart page →

20,233
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
49.0.0

Open the chart page →

20,233
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
49.0.0

Open the chart page →

6,974
netbirdtotmicro1.8.21 of 4See more

netbird totmicro 1.8.2

1 of the 4 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
netbirdio/dashboard:v2.22.215a3aab9a345
cryptography@3.3.2
49.0.0

Open the chart page →

5,966
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
cryptography@39.0.1
49.0.0

Open the chart page →

3,164
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
cryptography@38.0.1
49.0.0

Open the chart page →

8,370
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
cryptography@41.0.7
49.0.0

Open the chart page →

45,392
phonebook-chartusuladams2Verified publisher0.2.11 of 3See more

phonebook-chart usuladams2 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
cryptography@3.2.1
49.0.0

Open the chart page →

3,176
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
cryptography@44.0.2
49.0.0

Open the chart page →

4,769
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
cryptography@41.0.7
49.0.0

Open the chart page →

4,360
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
cryptography@3.4.8
49.0.0

Open the chart page →

13,563
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
49.0.0

Open the chart page →

20,233
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
cryptography@43.0.3
49.0.0

Open the chart page →

7,696
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
cryptography@46.0.5
49.0.0

Open the chart page →

20,233
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
cryptography@44.0.1
49.0.0

Open the chart page →

5,484
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
cryptography@3.3.2
49.0.0

Open the chart page →

11,167
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
cryptography@42.0.4
49.0.0

Open the chart page →

6,540
argocd-image-updaterwenerme1.3.11 of 1See more

argocd-image-updater wenerme 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-image-updater:v1.3.0cb009167015c
cryptography@47.0.0
49.0.0

Open the chart page →

718
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
cryptography@38.0.4
python-cryptography@38.0.4-3+deb12u1
49.0.0
no fix listed

Open the chart page →

8,824
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
49.0.0

Open the chart page →

10,286
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
49.0.0

Open the chart page →

11,785
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
cryptography@35.0.0
49.0.0

Open the chart page →

2,643
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
library/mysql:latest66aec17cd21a
cryptography@46.0.7
49.0.0

Open the chart page →

2,021
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
cryptography@44.0.2
49.0.0

Open the chart page →

569
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
49.0.0

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69249.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
49.0.0

Open the chart page →

1,636

Container images carrying it

576 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
cryptography@44.0.0
49.0.0
1
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
cryptography@46.0.5
49.0.0
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
cryptography@41.0.7
49.0.0
1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
cryptography@41.0.7
49.0.0
1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
cryptography@41.0.7
49.0.0
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
cryptography@41.0.7
49.0.0
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
cryptography@41.0.7
49.0.0
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
cryptography@41.0.7
49.0.0
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
cryptography@41.0.7
49.0.0
1
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
cryptography@41.0.7
49.0.0
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
cryptography@43.0.3
49.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
cryptography@43.0.1
49.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
cryptography@44.0.3
49.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
cryptography@44.0.3
49.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
cryptography@44.0.3
49.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
cryptography@37.0.4
49.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
cryptography@41.0.7
49.0.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
cryptography@44.0.3
49.0.0
1
ghcr.io/plausible/community-edition:v3.0.114c1afde21d6
cryptography@44.0.0
49.0.0
1
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
cryptography@42.0.7
49.0.0
1
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
cryptography@42.0.7
49.0.0
1
ghcr.io/porelli/firefox-sync:syncstorage-rs-mysql-0.18.27d244e514216
cryptography@43.0.1
49.0.0
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
cryptography@46.0.0
49.0.0
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
cryptography@48.0.0
49.0.0
1
ghcr.io/securo-finance/securo-backend:0.15.162e030110745
cryptography@46.0.7
49.0.0
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
cryptography@46.0.5
49.0.0
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
cryptography@46.0.3
49.0.0
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
cryptography@44.0.0
49.0.0
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
cryptography@46.0.6
49.0.0
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
cryptography@43.0.1
49.0.0
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
cryptography@44.0.0
49.0.0
1
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
cryptography@46.0.7
49.0.0
1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
cryptography@39.0.1
49.0.0
1
ghcr.io/vinny1892/octantis:latest45459c0910fc
cryptography@46.0.6
49.0.0
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
cryptography@38.0.4
python-cryptography@38.0.4-3
49.0.0
no fix listed
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
cryptography@43.0.3
49.0.0
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
cryptography@42.0.4
49.0.0
1
mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.76e43ba0bd009
cryptography@42.0.5
49.0.0
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
cryptography@45.0.6
49.0.0
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
cryptography@43.0.3
49.0.0
1
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
cryptography@43.0.1
49.0.0
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
cryptography@41.0.7
49.0.0
1
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
cryptography@46.0.7
49.0.0
1
quay.io/ceph/ceph:v21.1.05ff3692d2f3f
cryptography@43.0.0
49.0.0
1
quay.io/cephcsi/cephcsi:v3.5.128a674af1df2
cryptography@3.2.1
49.0.0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
cryptography@37.0.2
49.0.0
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
cryptography@41.0.3
49.0.0
1
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
cryptography@41.0.7
49.0.0
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
cryptography@48.0.0
49.0.0
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
cryptography@45.0.2
49.0.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.