StackRadar

CVE-2026-96749

High

Advisory

Published 24 Sept 2026In the index since 26 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
56
of 18,035 indexed, latest versions
Container images
67
deployed by those charts
Fix available
1 of 2
affected packages

PyMongo: PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding

Carried by container images the latest versions of 56 of 18,035 indexed charts deploy, on 67 images.

Affected packageAffected versionsFixed inImages
pymongopypi3.6.1, 3.8.0, 3.9.0, 3.10.0+20 more4.18.267
pymongodeb3.11.0-1+deb12u1no fix listed1
OSV records
DEBIAN-CVE-2026-96749GHSA-v4x9-3549-crwv

Charts affected

56 by stars
ChartLatestAffected imagesRadar Score
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-96749.

Container imageDigestPackageFixed in
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
pymongo@4.8.0
4.18.2

Open the chart page →

7,891
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-96749.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
pymongo@4.17.0
4.18.2

Open the chart page →

9,245
first-chartshashkist-test0.1.01 of 3See more

first-chart shashkist-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-96749.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
pymongo@4.10.1
4.18.2

Open the chart page →

3,642
servicexssl-hep1.8.61 of 16See more

servicex ssl-hep 1.8.6

1 of the 16 container images this version deploys carry CVE-2026-96749.

Container imageDigestPackageFixed in
ncsa/checks:main0b738bbc8d70
pymongo@3.13.0
4.18.2

Open the chart page →

61,371
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-96749.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
pymongo@4.10.1
4.18.2

Open the chart page →

6,337
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-96749.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
pymongo@4.10.1
4.18.2
hamzaarshad10/querypodpy:1.7154f38e8668e
pymongo@4.10.1
4.18.2

Open the chart page →

15,307

Container images carrying it

67 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
stackstorm/st2scheduler:3.8b1de2055c362
pymongo@3.11.3
4.18.2
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
pymongo@3.11.3
4.18.2
1
stackstorm/st2stream:3.81c8904a3bf67
pymongo@3.11.3
4.18.2
1
stackstorm/st2timersengine:3.81bf35bfaf00c
pymongo@3.11.3
4.18.2
1
stackstorm/st2workflowengine:3.819fdfffdbba8
pymongo@3.11.3
4.18.2
1
toniblyx/prowler:stablecf1ee9fc5b67
pymongo@4.15.1
4.18.2
1
ghcr.io/abcdesktopio/pyos:4.4.alpine_latest758edb8886a0
pymongo@4.6.3
4.18.2
1
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latest6f2ea2aae300
pymongo@4.18.1
4.18.2
1
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
pymongo@3.11.0
4.18.2
1
ghcr.io/grycap/im:latest06a16d4f279f
pymongo@4.15.1
4.18.2
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
pymongo@4.10.1
4.18.2
1
ghcr.io/performancecopilot/pcp:latest70dde5f13f08
pymongo@4.13.2
4.18.2
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
pymongo@4.8.0
4.18.2
1
ghcr.io/virtuos/librechat_exporter:2.0.050ea1cf0086f
pymongo@4.13.0
4.18.2
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
pymongo@4.8.0
4.18.2
1
quay.io/mongodb/farm-intro-backend:0.11a9ce0b8fbd4
pymongo@3.11.0
4.18.2
1
registry.gitlab.com/dyff/workflows-sink:0.16.4001e589acf2e
pymongo@4.16.0
4.18.2
1

syft 1.42.1 · advisories as of 7 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.