StackRadar

CVE-2026-71852

Medium

Advisory

Published 7 Aug 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,787 indexed, latest versions
Container images
15
deployed by those charts
Fix available
1 of 1
affected package

pypdf: Possible long runtimes/large memory usage for large CID font width ranges

Carried by container images the latest versions of 14 of 17,787 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
pypdfpypi5.0.1, 5.1.0, 5.3.0, 5.4.0+5 more6.15.015
OSV records
GHSA-fwg2-594c-jp42
Also known as
PYSEC-2026-3656

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
difydify-helmVerified publisher0.38.02 of 11See more

dify dify-helm 0.38.0

2 of the 11 container images this version deploys carry CVE-2026-71852.

Container imageDigestPackageFixed in
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
pypdf@6.14.2
6.15.0
langgenius/dify-api:1.16.1dcefa5f7c47c
pypdf@6.14.2
6.15.0

Open the chart page →

22,115
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-71852.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
pypdf@6.4.2
6.15.0

Open the chart page →

4,546
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-71852.

Container imageDigestPackageFixed in
pretix/standalone:2026.7.05df3b7aa852e
pypdf@6.5.0
6.15.0

Open the chart page →

9,825
agentareaagentareaVerified publisher0.0.181 of 16See more

agentarea agentarea 0.0.18

1 of the 16 container images this version deploys carry CVE-2026-71852.

Container imageDigestPackageFixed in
agentarea/agentarea-mcp-runner:latestd3c209a5d531
pypdf@6.14.2
6.15.0

Open the chart page →

14,960
argonix-apiargonix0.2.31 of 4See more

argonix-api argonix 0.2.3

1 of the 4 container images this version deploys carry CVE-2026-71852.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
pypdf@6.14.2
6.15.0

Open the chart page →

4,819
calibre-webcharts-derwitt-devVerified publisher1.1.21 of 1See more

calibre-web charts-derwitt-dev 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-71852.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
pypdf@6.10.2
6.15.0

Open the chart page →

4,919
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2026-71852.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pypdf@5.1.0
6.15.0

Open the chart page →

59,131
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-71852.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
pypdf@5.3.0
6.15.0

Open the chart page →

19,063
rag-apihajowielandVerified publisher1.0.01 of 1See more

rag-api hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-71852.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latestf9f34c8ed688
pypdf@6.14.2
6.15.0

Open the chart page →

1,635
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-71852.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pypdf@5.4.0
6.15.0

Open the chart page →

8,455
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-71852.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
pypdf@6.10.2
6.15.0

Open the chart page →

7,491
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-71852.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pypdf@6.9.0
6.15.0

Open the chart page →

5,230
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-71852.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
pypdf@6.14.2
6.15.0

Open the chart page →

10,972
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-71852.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
pypdf@5.0.1
6.15.0

Open the chart page →

7,696

Container images carrying it

15 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
agentarea/agentarea-mcp-runner:latestd3c209a5d531
pypdf@6.14.2
6.15.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pypdf@5.4.0
6.15.0
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
pypdf@6.10.2
6.15.0
1
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
pypdf@6.14.2
6.15.0
1
langgenius/dify-api:1.0.0066035f93856
pypdf@5.3.0
6.15.0
1
langgenius/dify-api:1.16.1dcefa5f7c47c
pypdf@6.14.2
6.15.0
1
linuxserver/calibre-web:0.6.24241009026e6f
pypdf@5.0.1
6.15.0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pypdf@6.9.0
6.15.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pypdf@5.1.0
6.15.0
1
pretix/standalone:2026.7.05df3b7aa852e
pypdf@6.5.0
6.15.0
1
signalen/backend:2.50.14760256000738
pypdf@6.14.2
6.15.0
1
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
pypdf@6.14.2
6.15.0
1
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latestf9f34c8ed688
pypdf@6.14.2
6.15.0
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
pypdf@6.4.2
6.15.0
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
pypdf@6.10.2
6.15.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.