StackRadar

CVE-2026-9318

Medium

Advisory

Published 12 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.4
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
1 of 1
affected package

tablib: Stored XSS in the HTML export via unescaped dataset title

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
tablibpypi0.13.0, 3.2.0, 3.2.1, 3.6.1+2 more3.10.011
OSV records
GHSA-gqgw-jghv-mxwx
Also known as
PYSEC-2026-3702

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2026-9318.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
tablib@3.2.1
3.10.0

Open the chart page →

9,145
netboxstartechnicaVerified publisher5.1.01 of 4See more

netbox startechnica 5.1.0

1 of the 4 container images this version deploys carry CVE-2026-9318.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
tablib@3.6.1
3.10.0

Open the chart page →

1,650
squestchristianhuthVerified publisher6.6.71 of 4See more

squest christianhuth 6.6.7

1 of the 4 container images this version deploys carry CVE-2026-9318.

Container imageDigestPackageFixed in
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
tablib@3.6.1
3.10.0

Open the chart page →

9,971
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-9318.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
tablib@0.13.0
3.10.0

Open the chart page →

12,397
qleverzazukoVerified publisher0.7.01 of 2See more

qlever zazuko 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-9318.

Container imageDigestPackageFixed in
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
tablib@3.9.0
3.10.0

Open the chart page →

2,900
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-9318.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
tablib@0.13.0
3.10.0

Open the chart page →

22,891
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-9318.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
tablib@3.8.0
3.10.0

Open the chart page →

11,335
babybuddygeek-cookbookVerified publisher1.2.21 of 1See more

babybuddy geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-9318.

Container imageDigestPackageFixed in
linuxserver/babybuddy:1.10.2f7d7c7704249
tablib@3.2.0
3.10.0

Open the chart page →

1,489
inventreeinventreeOfficialVerified publisher0.4.281 of 2See more

inventree inventree 0.4.28

1 of the 2 container images this version deploys carry CVE-2026-9318.

Container imageDigestPackageFixed in
inventree/inventree:1.5.4a946ec09da3e
tablib@3.9.0
3.10.0

Open the chart page →

5,788
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-9318.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
tablib@0.13.0
3.10.0

Open the chart page →

16,417
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-9318.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
tablib@3.9.0
3.10.0

Open the chart page →

11,636

Container images carrying it

11 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gethue/hue:4.11.011b649636e68
tablib@0.13.0
3.10.0
1
gethue/hue:4.10.05702b2c37ff9
tablib@0.13.0
3.10.0
1
gethue/hue:latest7d5c1b9f8a79
tablib@0.13.0
3.10.0
1
inventree/inventree:1.5.4a946ec09da3e
tablib@3.9.0
3.10.0
1
linuxserver/babybuddy:1.10.2f7d7c7704249
tablib@3.2.0
3.10.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
tablib@3.2.1
3.10.0
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
tablib@3.6.1
3.10.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
tablib@3.8.0
3.10.0
1
signalen/backend:2.50.14760256000738
tablib@3.9.0
3.10.0
1
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
tablib@3.9.0
3.10.0
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
tablib@3.6.1
3.10.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.