CVE-2026-8328
MediumAdvisory
Published 13 May 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.9
- base score, highest
- EPSS
- 0.005
- 38th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 579
- of 17,781 indexed, latest versions
- Container images
- 556
- deployed by those charts
- Fix available
- 9 of 15
- affected packages
FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
Carried by container images the latest versions of 579 of 17,781 indexed charts deploy, on 556 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| python3.11deb | 3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more | no fix listed | 181 |
| python3.8deb | 3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more | no fix listed | 100 |
| python3.10deb | 3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+14 more | 3.10.12-1~22.04.16 | 71 |
| python2.7deb | 2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 more | no fix listed | 54 |
| python3.12deb | 3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+8 more | 3.12.3-1ubuntu0.15 | 48 |
| python3.6deb | 3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more | no fix listed | 44 |
| python3.13deb | 3.13.5-2, 3.13.5-2+deb13u2, 3.13.5-2+e30, 3.13.7-1ubuntu0.1 | 3.13.5-2+deb13u3, 3.13.5-2+e36 | 34 |
| python3.5deb | 3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9 | no fix listed | 25 |
| python3apk | 3.12.12-r0, 3.14.3-r0, 3.14.5-r0, 3.14.5-r1 | 3.14.7-r0 | 12 |
| python3.4deb | 3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7 | no fix listed | 7 |
| python-3.14apk | 3.14.2-r2, 3.14.4-r2 | 3.14.5-r1 | 5 |
| pythonbitnami | 3.11.11-0, 3.12.8-0, 3.13.5-1 | 3.10.21 | 3 |
| python-3.13apk | 3.13.7-r0, 3.13.10-r0, 3.13.12-r2 | 3.13.13-r6 | 3 |
| python-3.12apk | 3.12.0-r1, 3.12.9-r1 | 3.12.13-r6 | 2 |
| python3.14deb | 3.14.4-1 | 3.14.4-1ubuntu0.1 | 2 |
- OSV records
- ALPINE-CVE-2026-8328BIT-python-2026-8328CGA-4g64-jw7v-h3vmCGA-6397-4hmj-fqvgCGA-78m4-mcm2-67v9DEBIAN-CVE-2026-8328UBUNTU-CVE-2026-8328ECHO-1e9d-9cbe-8622
- Also known as
- BIT-libpython-2026-8328, BIT-python-min-2026-8328, CGA-fq4q-w246-9v3q, CGA-wmhg-q34j-hx98, CGA-x6w8-mwxf-4fqp, PSF-0000-CVE-2026-8328, PSF-2026-24, USN-8509-1
Charts affected
579 by stars
Container images carrying it
556 by charts deploying them
A fixed version is listed for 9 of the 15 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| felipecs8/ | 29e06c9c6385 | python3.11 | no fix listed | 1 |
| firefart/ | 0d6249906d8c | python3.11 | no fix listed | 1 |
| fiware/ | 29456835bb2c | python3.8 | no fix listed | 1 |
| fiware/ | d551a13e8278 | python3.11 | no fix listed | 1 |
| flanksource/ | 689687a7cf95 | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| flashcatcloud/ | 42e6ab16472e | python3.12 | 3.12.3-1ubuntu0.15 | 1 |
| fluent/ | e76397ef3983 | python3.11 | no fix listed | 1 |
| flyway/ | 45b5d7cdc75a | python3.8 | no fix listed | 1 |
| frankescobar/ | 8a4d7e9308de | python3.6 | no fix listed | 1 |
| frankescobar/ | cafa03b94dac | python3.6 | no fix listed | 1 |
| freeradius/ | af6fd34a5b78 | python2.7 python3.10 | no fix listed 3.10.12-1~22.04.16 | 1 |
| galaxy/ | e5c265fe9fcd | python3.8 | no fix listed | 1 |
| galaxy/ | 0267bad550e6 | python2.7 python3.4 | no fix listed no fix listed | 1 |
| galaxy/ | 8e577a626dfd | python2.7 python3.4 | no fix listed no fix listed | 1 |
| galaxy/ | e50a890e24c9 | python3.11 | no fix listed | 1 |
| geonode/ | 81b1d431b7e9 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| geopython/ | 84662ea6b78b | python3.11 | no fix listed | 1 |
| geoscienceaustralia/ | f4039b45572a | python3.6 | no fix listed | 1 |
| gethue/ | 11b649636e68 | python3.8 | no fix listed | 1 |
| gethue/ | 5702b2c37ff9 | python2.7 python3.6 | no fix listed no fix listed | 1 |
| gethue/ | 7d5c1b9f8a79 | python3.10 python3.11 | 3.10.12-1~22.04.16 no fix listed | 1 |
| gotenberg/ | 206a6c708fc6 | python3.13 | 3.13.5-2+deb13u3 | 1 |
| gotenberg/ | 67097317623a | python3.13 | 3.13.5-2+deb13u3 | 1 |
| gpappsoft/ | af7841adad26 | python-3.13 | 3.13.13-r6 | 1 |
| hasura/ | 0111b0204136 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| hasura/ | f6c1c4b957d2 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| haugene/ | 059216cfae4b | python3.8 | no fix listed | 1 |
| haveagitgat/ | 1256348872ce | python2.7 python3.8 | no fix listed no fix listed | 1 |
| haveagitgat/ | 1e3f9328327d | python3.8 | no fix listed | 1 |
| haveagitgat/ | 3ff0913202dd | python2.7 python3.8 | no fix listed no fix listed | 1 |
| helicone/ | 4c69b971a7e4 | python3.8 | no fix listed | 1 |
| helicone/ | 4a913936c97b | python3.11 | no fix listed | 1 |
| hyperglance/ | 467ad8491bc3 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| hyperglance/ | 9fd5faf1fe80 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| hyperglance/ | b2f8c6d52623 | python3.10 | 3.10.12-1~22.04.16 | 1 |
| hyperledger/ | c65891b6c237 | python2.7 python3.5 | no fix listed no fix listed | 1 |
| ibmcom/ | 7e4dc1e27cdf | python3.5 | no fix listed | 1 |
| ibmcom/ | b5d8c6714dbc | python2.7 python3.5 | no fix listed no fix listed | 1 |
| ibmcom/ | e17bdccc5030 | python2.7 | no fix listed | 1 |
| ibmcom/ | 395e60cc6e3d | python2.7 | no fix listed | 1 |
| ildarmukhametzyanov/ | 15d23720a3ee | python3.11 | no fix listed | 1 |
| inseefrlab/ | 31f04ca7436b | python3.10 | 3.10.12-1~22.04.16 | 1 |
| instill/ | c4a393e601ed | python3.13 | 3.13.5-2+deb13u3 | 1 |
| instill/ | ebe12f77a3f9 | python3.13 | 3.13.5-2+deb13u3 | 1 |
| instill/ | e980125e5ba5 | python3.13 | 3.13.5-2+deb13u3 | 1 |
| intel/ | aa8f5483a2ef | python3.8 | no fix listed | 1 |
| intel/ | 1a89327e499b | python3.8 | no fix listed | 1 |
| intelowlproject/ | 0b22e547ea6b | python3.11 | no fix listed | 1 |
| iofog/ | 7260cf861479 | python2.7 | no fix listed | 1 |
| iomesh/ | 1a151f602451 | python3.10 | 3.10.12-1~22.04.16 | 1 |