StackRadar

CVE-2026-85078

Medium

Advisory

Published 17 Sept 2026In the index since 18 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3
of 18,026 indexed, latest versions
Container images
3
deployed by those charts
Fix available
1 of 1
affected package

sanic chunked trailer request smuggling allows hidden second request execution

Carried by container images the latest versions of 3 of 18,026 indexed charts deploy, on 3 images.

Affected packageAffected versionsFixed inImages
sanicpypi18.12.0, 21.3.424.12.13
OSV records
GHSA-wmj6-g64g-j7q5
Also known as
PYSEC-2026-4162

Charts affected

3 by stars
ChartLatestAffected imagesRadar Score
deepflowdeepflow6.2.2011 of 8See more

deepflow deepflow 6.2.201

1 of the 8 container images this version deploys carry CVE-2026-85078.

Container imageDigestPackageFixed in
deepflowce/deepflow-app:v6.2.2aa9468ad4d96
sanic@18.12.0
24.12.1

Open the chart page →

20,189
sensitive-dataapicheck1.0.01 of 1See more

sensitive-data apicheck 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-85078.

Container imageDigestPackageFixed in
bbvalabs/sensitive-data:1.0.13ea299ae63c0
sanic@21.3.4
24.12.1

Open the chart page →

1,884
deepflowkubesphere-stable6.2.6061 of 8See more

deepflow kubesphere-stable 6.2.606

1 of the 8 container images this version deploys carry CVE-2026-85078.

Container imageDigestPackageFixed in
deepflowce/deepflow-app:v6.2.6.5a1888d35e787
sanic@18.12.0
24.12.1

Open the chart page →

22,851

Container images carrying it

3 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bbvalabs/sensitive-data:1.0.13ea299ae63c0
sanic@21.3.4
24.12.1
1
deepflowce/deepflow-app:v6.2.6.5a1888d35e787
sanic@18.12.0
24.12.1
1
deepflowce/deepflow-app:v6.2.2aa9468ad4d96
sanic@18.12.0
24.12.1
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.