StackRadar

CVE-2026-77528

Medium

Advisory

Published 22 Sept 2026In the index since 23 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
13
of 17,832 indexed, latest versions
Container images
15
deployed by those charts
Fix available
1 of 1
affected package

Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation

Carried by container images the latest versions of 13 of 17,832 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
autobahnpypi21.2.1, 22.6.1, 23.1.1, 23.6.2+3 more26.7.115
OSV records
GHSA-hxp9-w8x3-p566

Charts affected

13 by stars
ChartLatestAffected imagesRadar Score
baserowbaserow-chartVerified publisher1.0.561 of 6See more

baserow baserow-chart 1.0.56

1 of the 6 container images this version deploys carry CVE-2026-77528.

Container imageDigestPackageFixed in
baserow/backend:2.3.37c00549b3a6f
autobahn@25.12.2
26.7.1

Open the chart page →

17,903
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-77528.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
autobahn@23.6.2
26.7.1

Open the chart page →

17,281
psonoankra-chartsVerified publisher1.2.01 of 2See more

psono ankra-charts 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-77528.

Container imageDigestPackageFixed in
psono/psono-server:5.0.03b974b43ea03
autobahn@24.4.2
26.7.1

Open the chart page →

2,398
anteonanteonVerified publisher2.6.42 of 13See more

anteon anteon 2.6.4

2 of the 13 container images this version deploys carry CVE-2026-77528.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
autobahn@24.4.2
26.7.1
ddosify/selfhosted_backend:3.2.93c11e3182652
autobahn@23.6.2
26.7.1

Open the chart page →

22,921
obicogabe565Verified publisher0.6.01 of 3See more

obico gabe565 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-77528.

Container imageDigestPackageFixed in
ghcr.io/gabe565/obico/web:latest122456be28c9
autobahn@24.4.2
26.7.1

Open the chart page →

1,974
paperlessgeek-cookbookVerified publisher9.2.01 of 1See more

paperless geek-cookbook 9.2.0

1 of the 1 container images this version deploys carry CVE-2026-77528.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
autobahn@22.6.1
26.7.1

Open the chart page →

3,952
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-77528.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
autobahn@25.11.1
26.7.1

Open the chart page →

62,341
ddosifyanteonVerified publisher1.7.52 of 13See more

ddosify anteon 1.7.5

2 of the 13 container images this version deploys carry CVE-2026-77528.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
autobahn@23.6.2
26.7.1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
autobahn@23.6.2
26.7.1

Open the chart page →

26,403
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-77528.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
autobahn@21.2.1
26.7.1

Open the chart page →

84,688
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-77528.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
autobahn@23.6.2
26.7.1

Open the chart page →

10,356
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-77528.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
autobahn@25.12.2
26.7.1

Open the chart page →

18,297
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-77528.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
autobahn@23.1.1
26.7.1

Open the chart page →

81,208
dingtalk-botxxl-job-adminVerified publisher0.1.31 of 2See more

dingtalk-bot xxl-job-admin 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-77528.

Container imageDigestPackageFixed in
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
autobahn@25.12.2
26.7.1

Open the chart page →

3,214

Container images carrying it

15 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
baserow/backend:2.3.37c00549b3a6f
autobahn@25.12.2
26.7.1
1
baserow/backend:1.31.1e0b3c8130b91
autobahn@23.6.2
26.7.1
1
baserow/baserow:1.30.1df0c42eb67e8
autobahn@23.6.2
26.7.1
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
autobahn@23.6.2
26.7.1
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
autobahn@24.4.2
26.7.1
1
ddosify/selfhosted_backend:3.2.93c11e3182652
autobahn@23.6.2
26.7.1
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
autobahn@23.6.2
26.7.1
1
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
autobahn@25.12.2
26.7.1
1
gethue/hue:4.11.011b649636e68
autobahn@23.1.1
26.7.1
1
gethue/hue:4.10.05702b2c37ff9
autobahn@21.2.1
26.7.1
1
gethue/hue:latest7d5c1b9f8a79
autobahn@25.11.1
26.7.1
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
autobahn@25.12.2
26.7.1
1
psono/psono-server:5.0.03b974b43ea03
autobahn@24.4.2
26.7.1
1
ghcr.io/gabe565/obico/web:latest122456be28c9
autobahn@24.4.2
26.7.1
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
autobahn@22.6.1
26.7.1
1

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.