StackRadar

CVE-2026-82398

Medium

Advisory

Published 2 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.003
23rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,781 indexed, latest versions
Container images
15
deployed by those charts
Fix available
1 of 1
affected package

pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace

Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
pypdfpypi5.0.1, 5.1.0, 5.3.0, 5.4.0+5 more6.15.015
OSV records
GHSA-fc8x-2rww-xw9m
Also known as
PYSEC-2026-3912

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
difydify-helmVerified publisher0.38.02 of 11See more

dify dify-helm 0.38.0

2 of the 11 container images this version deploys carry CVE-2026-82398.

Container imageDigestPackageFixed in
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
pypdf@6.14.2
6.15.0
langgenius/dify-api:1.16.1dcefa5f7c47c
pypdf@6.14.2
6.15.0

Open the chart page →

22,002
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-82398.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
pypdf@6.4.2
6.15.0

Open the chart page →

4,477
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-82398.

Container imageDigestPackageFixed in
pretix/standalone:2026.7.05df3b7aa852e
pypdf@6.5.0
6.15.0

Open the chart page →

9,770
agentareaagentareaVerified publisher0.0.181 of 16See more

agentarea agentarea 0.0.18

1 of the 16 container images this version deploys carry CVE-2026-82398.

Container imageDigestPackageFixed in
agentarea/agentarea-mcp-runner:latestd3c209a5d531
pypdf@6.14.2
6.15.0

Open the chart page →

14,914
argonix-apiargonix0.2.01 of 4See more

argonix-api argonix 0.2.0

1 of the 4 container images this version deploys carry CVE-2026-82398.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.068e17a8aaa40
pypdf@6.14.2
6.15.0

Open the chart page →

4,923
calibre-webcharts-derwitt-devVerified publisher1.1.21 of 1See more

calibre-web charts-derwitt-dev 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-82398.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
pypdf@6.10.2
6.15.0

Open the chart page →

4,911
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2026-82398.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pypdf@5.1.0
6.15.0

Open the chart page →

58,897
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-82398.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
pypdf@5.3.0
6.15.0

Open the chart page →

19,224
rag-apihajowielandVerified publisher1.0.01 of 1See more

rag-api hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-82398.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latestf9f34c8ed688
pypdf@6.14.2
6.15.0

Open the chart page →

1,683
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-82398.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pypdf@5.4.0
6.15.0

Open the chart page →

8,405
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-82398.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
pypdf@6.10.2
6.15.0

Open the chart page →

7,436
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-82398.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pypdf@6.9.0
6.15.0

Open the chart page →

5,201
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-82398.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
pypdf@6.14.2
6.15.0

Open the chart page →

11,636
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-82398.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
pypdf@5.0.1
6.15.0

Open the chart page →

7,628

Container images carrying it

15 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
agentarea/agentarea-mcp-runner:latestd3c209a5d531
pypdf@6.14.2
6.15.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pypdf@5.4.0
6.15.0
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
pypdf@6.10.2
6.15.0
1
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
pypdf@6.14.2
6.15.0
1
langgenius/dify-api:1.0.0066035f93856
pypdf@5.3.0
6.15.0
1
langgenius/dify-api:1.16.1dcefa5f7c47c
pypdf@6.14.2
6.15.0
1
linuxserver/calibre-web:0.6.24241009026e6f
pypdf@5.0.1
6.15.0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pypdf@6.9.0
6.15.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pypdf@5.1.0
6.15.0
1
pretix/standalone:2026.7.05df3b7aa852e
pypdf@6.5.0
6.15.0
1
signalen/backend:2.50.14760256000738
pypdf@6.14.2
6.15.0
1
ghcr.io/argonix-io/argonix-api:1.0.068e17a8aaa40
pypdf@6.14.2
6.15.0
1
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latestf9f34c8ed688
pypdf@6.14.2
6.15.0
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
pypdf@6.4.2
6.15.0
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
pypdf@6.10.2
6.15.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.