StackRadar

CVE-2026-73229

Medium

Advisory

Published 1 Sept 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
86
of 17,781 indexed, latest versions
Container images
87
deployed by those charts
Fix available
1 of 1
affected package

Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

Carried by container images the latest versions of 86 of 17,781 indexed charts deploy, on 87 images.

Affected packageAffected versionsFixed inImages
djangorestframeworkpypi3.7.7, 3.11.0, 3.11.1, 3.12.1+10 more3.17.287
OSV records
GHSA-g47c-3xmw-q6m2
Also known as
PYSEC-2026-3828

Charts affected

86 by stars
ChartLatestAffected imagesRadar Score
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
djangorestframework@3.14.0
3.17.2

Open the chart page →

14,856
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
djangorestframework@3.15.2
3.17.2

Open the chart page →

7,459
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
codecov/self-hosted-api:24.4.10475cb1c3136
djangorestframework@3.14.0
3.17.2

Open the chart page →

24,917
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
djangorestframework@3.11.1
3.17.2

Open the chart page →

25,122
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
djangorestframework@3.15.2
3.17.2

Open the chart page →

2,183
babybuddygeek-cookbookVerified publisher1.2.21 of 1See more

babybuddy geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
linuxserver/babybuddy:1.10.2f7d7c7704249
djangorestframework@3.13.1
3.17.2

Open the chart page →

1,489
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
djangorestframework@3.11.1
3.17.2

Open the chart page →

24,293
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
djangorestframework@3.11.1
3.17.2

Open the chart page →

7,984
chiefonboardinghelmforgeVerified publisher1.1.141 of 3See more

chiefonboarding helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
djangorestframework@3.16.1
3.17.2

Open the chart page →

10,849
netboxhelmforgeVerified publisher2.0.11 of 4See more

netbox helmforge 2.0.1

1 of the 4 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
djangorestframework@3.17.1
3.17.2

Open the chart page →

4,243
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
djangorestframework@3.14.0
3.17.2

Open the chart page →

16,384
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
djangorestframework@3.15.2
3.17.2

Open the chart page →

3,157
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
djangorestframework@3.15.2
3.17.2

Open the chart page →

17,852
inventreeinventreeOfficialVerified publisher0.4.281 of 2See more

inventree inventree 0.4.28

1 of the 2 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
inventree/inventree:1.5.4a946ec09da3e
djangorestframework@3.17.1
3.17.2

Open the chart page →

5,788
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
djangorestframework@3.16.1
3.17.2

Open the chart page →

9,103
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
djangorestframework@3.16.1
3.17.2

Open the chart page →

4,568
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
djangorestframework@3.12.2
3.17.2

Open the chart page →

16,417
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
djangorestframework@3.15.2
3.17.2

Open the chart page →

37,942
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
djangorestframework@3.16.1
3.17.2

Open the chart page →

11,950
comacopencord1.0.02 of 9See more

comac opencord 1.0.0

2 of the 9 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
djangorestframework@3.7.7
3.17.2
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
djangorestframework@3.7.7
3.17.2

Open the chart page →

88,546
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
djangorestframework@3.7.7
3.17.2

Open the chart page →

26,211
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
djangorestframework@3.16.1
3.17.2

Open the chart page →

3,854
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
djangorestframework@3.11.1
3.17.2

Open the chart page →

22,084
libretimepodzone-chartsVerified publisher0.4.11 of 9See more

libretime podzone-charts 0.4.1

1 of the 9 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-api:latesteae026cc8909
djangorestframework@3.15.2
3.17.2

Open the chart page →

11,149
agentpolyaxon2.16.41 of 4See more

agent polyaxon 2.16.4

1 of the 4 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
polyaxon/polyaxon-streams:2.16.4c186bd9834c0
djangorestframework@3.16.1
3.17.2

Open the chart page →

10,046
polyaxonpolyaxon2.16.41 of 5See more

polyaxon polyaxon 2.16.4

1 of the 5 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
polyaxon/polyaxon-api:2.16.42b55c3265a90
djangorestframework@3.16.1
3.17.2

Open the chart page →

13,741
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
djangorestframework@3.16.1
3.17.2

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
djangorestframework@3.16.1
3.17.2

Open the chart page →

4,499
linkdingrubxkubeVerified publisher1.2.31 of 1See more

linkding rubxkube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.46.20c0a9a04c7eb
djangorestframework@3.16.1
3.17.2

Open the chart page →

2,051
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
djangorestframework@3.17.1
3.17.2

Open the chart page →

1,577
safe-stacksafe-global0.1.02 of 9See more

safe-stack safe-global 0.1.0

2 of the 9 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
djangorestframework@3.17.1
3.17.2
safeglobal/safe-transaction-service:latest80db836cc5d5
djangorestframework@3.17.1
3.17.2

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
safeglobal/safe-transaction-service:latest80db836cc5d5
djangorestframework@3.17.1
3.17.2

Open the chart page →

16,620
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
djangorestframework@3.15.2
3.17.2

Open the chart page →

11,636
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
djangorestframework@3.11.0
3.17.2

Open the chart page →

8,694
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
djangorestframework@3.15.2
3.17.2

Open the chart page →

4,731
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-73229.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
djangorestframework@3.13.1
3.17.2

Open the chart page →

3,392

Container images carrying it

87 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
redislabs/redisinsight:1.14.0b03ab1426d0d
djangorestframework@3.13.1
3.17.2
1
seafileltd/seafile-mc:9.0.106693911bcc40
djangorestframework@3.11.1
3.17.2
1
seafileltd/seafile-mc:10.0.170628f29c663
djangorestframework@3.14.0
3.17.2
1
seafileltd/seafile-mc:9.0.97ac833196f60
djangorestframework@3.11.1
3.17.2
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
djangorestframework@3.14.0
3.17.2
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
djangorestframework@3.11.1
3.17.2
1
signalen/backend:2.50.14760256000738
djangorestframework@3.15.2
3.17.2
1
sissbruecker/linkding:1.46.20c0a9a04c7eb
djangorestframework@3.16.1
3.17.2
1
sissbruecker/linkding:1.35.00c5dddf0b37c
djangorestframework@3.15.2
3.17.2
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
djangorestframework@3.15.2
3.17.2
1
vabene1111/recipes:2.3.50f8d061895e9
djangorestframework@3.16.1
3.17.2
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
djangorestframework@3.13.1
3.17.2
1
weblate/weblate:3.11.3-182848df56ecd
djangorestframework@3.11.0
3.17.2
1
wger/server:2.6997ead43aabd
djangorestframework@3.17.1
3.17.2
1
ghcr.io/argonix-io/argonix-api:1.0.068e17a8aaa40
djangorestframework@3.17.1
3.17.2
1
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
djangorestframework@3.15.2
3.17.2
1
ghcr.io/gabe565/obico/web:latesta5c1daef46c0
djangorestframework@3.15.1
3.17.2
1
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
djangorestframework@3.16.1
3.17.2
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
djangorestframework@3.16.1
3.17.2
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
djangorestframework@3.17.1
3.17.2
1
ghcr.io/goauthentik/server:2026.8.2ff8489a5af4f
djangorestframework@3.17.1
3.17.2
1
ghcr.io/libretime/libretime-api:latesteae026cc8909
djangorestframework@3.15.2
3.17.2
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
djangorestframework@3.15.1
3.17.2
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
djangorestframework@3.15.2
3.17.2
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
djangorestframework@3.16.1
3.17.2
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
djangorestframework@3.16.1
3.17.2
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
djangorestframework@3.16.1
3.17.2
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
djangorestframework@3.13.1
3.17.2
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
djangorestframework@3.14.0
3.17.2
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
djangorestframework@3.16.1
3.17.2
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
djangorestframework@3.15.2
3.17.2
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
djangorestframework@3.16.1
3.17.2
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
djangorestframework@3.15.2
3.17.2
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
djangorestframework@3.15.2
3.17.2
1
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
djangorestframework@3.16.0
3.17.2
1
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
djangorestframework@3.17.1
3.17.2
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
djangorestframework@3.16.0
3.17.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.