StackRadar

CVE-2026-91992

Medium

Advisory

Published 15 Jun 2026In the index since 16 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
104
of 17,790 indexed, latest versions
Container images
109
deployed by those charts
Fix available
1 of 2
affected packages

Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

Carried by container images the latest versions of 104 of 17,790 indexed charts deploy, on 109 images.

Affected packageAffected versionsFixed inImages
tornadopypi2.4.1, 4.5.3, 5.1.1, 6.0.2+13 more6.5.7109
python-tornadodeb6.2.0-3+deb12u1no fix listed1
OSV records
DEBIAN-CVE-2026-91992GHSA-pw6j-qg29-8w7f

Charts affected

104 by stars
ChartLatestAffected imagesRadar Score
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-91992.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
tornado@6.2
6.5.7

Open the chart page →

8,642
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-91992.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
tornado@6.0.2
6.5.7

Open the chart page →

9,424
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-91992.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
tornado@6.4.2
6.5.7

Open the chart page →

7,679
webapp-chartwebappchart1.0.01 of 1See more

webapp-chart webappchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-91992.

Container imageDigestPackageFixed in
amagdi888/my-repo:hello-appd8a10fc8faf6
tornado@5.1.1
6.5.7

Open the chart page →

1,202

Container images carrying it

109 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
tornado@6.5.2
6.5.7
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
tornado@6.5.4
6.5.7
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
tornado@6.5.5
6.5.7
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
tornado@6.5.5
6.5.7
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
tornado@6.3.3
6.5.7
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
tornado@6.5.5
6.5.7
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
tornado@6.2
6.5.7
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
tornado@6.4
6.5.7
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
tornado@6.5.4
6.5.7
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.