StackRadar

CVE-2026-91990

High

Advisory

Published 1 Sept 2026In the index since 16 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
115
of 17,790 indexed, latest versions
Container images
119
deployed by those charts
Fix available
1 of 2
affected packages

tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)

Carried by container images the latest versions of 115 of 17,790 indexed charts deploy, on 119 images.

Affected packageAffected versionsFixed inImages
python-tornadodeb6.2.0-3+deb12u1no fix listed1
tornadopypi2.4.1, 4.5.3, 5.1.1, 6.0.2+14 more6.5.8119
OSV records
DEBIAN-CVE-2026-91990GHSA-8423-8fgw-73vq

Charts affected

115 by stars
ChartLatestAffected imagesRadar Score
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-91990.

Container imageDigestPackageFixed in
safeglobal/safe-transaction-service:latest80db836cc5d5
tornado@6.5.7
6.5.8

Open the chart page →

16,739
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-91990.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
tornado@6.4
6.5.8

Open the chart page →

10,237
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-91990.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
tornado@6.1
6.5.8

Open the chart page →

22,349
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-91990.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
tornado@6.5.5
6.5.8

Open the chart page →

5,242
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-91990.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
tornado@6.5.7
6.5.8

Open the chart page →

11,711
srebotsrebot0.14.01 of 2See more

srebot srebot 0.14.0

1 of the 2 container images this version deploys carry CVE-2026-91990.

Container imageDigestPackageFixed in
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
tornado@6.5.4
6.5.8

Open the chart page →

1,565
restful-distributed-lock-managerstakaterVerified publisher1.0.41 of 1See more

restful-distributed-lock-manager stakater 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-91990.

Container imageDigestPackageFixed in
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
tornado@2.4.1
6.5.8

Open the chart page →

3,117
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-91990.

Container imageDigestPackageFixed in
mher/flower:2.051c3c3db5be3
tornado@6.3.3
6.5.8

Open the chart page →

4,701
icinga2-reportsvtech-public-helm-charts1.0.01 of 1See more

icinga2-report svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-91990.

Container imageDigestPackageFixed in
trungkien210493/icinga2-report:v1.7.12cc8c3763c4c
tornado@5.1.1
6.5.8

Open the chart page →

1,779
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-91990.

Container imageDigestPackageFixed in
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
tornado@6.1
6.5.8

Open the chart page →

5,322
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-91990.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
tornado@6.1
6.5.8

Open the chart page →

3,165
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-91990.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
tornado@6.2
6.5.8

Open the chart page →

8,642
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-91990.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
tornado@6.0.2
6.5.8

Open the chart page →

9,424
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-91990.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
tornado@6.4.2
6.5.8

Open the chart page →

7,679
webapp-chartwebappchart1.0.01 of 1See more

webapp-chart webappchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-91990.

Container imageDigestPackageFixed in
amagdi888/my-repo:hello-appd8a10fc8faf6
tornado@5.1.1
6.5.8

Open the chart page →

1,202

Container images carrying it

119 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/esphome/esphome:2026.4.078a82d810709
tornado@6.5.5
6.5.8
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
tornado@6.1
6.5.8
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
tornado@6.3.3
6.5.8
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
tornado@6.5.4
6.5.8
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
tornado@6.5.7
6.5.8
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
tornado@6.4.1
6.5.8
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
tornado@6.5.2
6.5.8
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
tornado@6.5.2
6.5.8
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
tornado@6.5.2
6.5.8
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
tornado@6.3.3
6.5.8
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
tornado@6.5.2
6.5.8
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
tornado@6.5.4
6.5.8
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
tornado@6.5.5
6.5.8
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
tornado@6.5.5
6.5.8
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
tornado@6.3.3
6.5.8
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
tornado@6.5.5
6.5.8
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
tornado@6.2
6.5.8
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
tornado@6.4
6.5.8
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
tornado@6.5.4
6.5.8
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.