StackRadar

CVE-2026-96749

High

Advisory

Published 24 Sept 2026In the index since 26 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
56
of 18,035 indexed, latest versions
Container images
67
deployed by those charts
Fix available
1 of 2
affected packages

PyMongo: PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding

Carried by container images the latest versions of 56 of 18,035 indexed charts deploy, on 67 images.

Affected packageAffected versionsFixed inImages
pymongopypi3.6.1, 3.8.0, 3.9.0, 3.10.0+20 more4.18.267
pymongodeb3.11.0-1+deb12u1no fix listed1
OSV records
DEBIAN-CVE-2026-96749GHSA-v4x9-3549-crwv

Charts affected

56 by stars
ChartLatestAffected imagesRadar Score
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-96749.

Container imageDigestPackageFixed in
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
pymongo@4.8.0
4.18.2

Open the chart page →

7,891
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-96749.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
pymongo@4.17.0
4.18.2

Open the chart page →

9,245
first-chartshashkist-test0.1.01 of 3See more

first-chart shashkist-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-96749.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
pymongo@4.10.1
4.18.2

Open the chart page →

3,642
servicexssl-hep1.8.61 of 16See more

servicex ssl-hep 1.8.6

1 of the 16 container images this version deploys carry CVE-2026-96749.

Container imageDigestPackageFixed in
ncsa/checks:main0b738bbc8d70
pymongo@3.13.0
4.18.2

Open the chart page →

61,371
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-96749.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
pymongo@4.10.1
4.18.2

Open the chart page →

6,337
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2026-96749.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
pymongo@4.10.1
4.18.2
hamzaarshad10/querypodpy:1.7154f38e8668e
pymongo@4.10.1
4.18.2

Open the chart page →

15,307

Container images carrying it

67 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ncsa/checks:1.0.1cc46a03e16ed
pymongo@3.12.3
4.18.2
4
shashkist/flask-contacts-app:latest581de1fd6084
pymongo@4.10.1
4.18.2
4
ncsa/checks:1.0.0abf6300b57b7
pymongo@3.11.0
4.18.2
2
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
pymongo@3.6.1
4.18.2
2
alerta/alerta-web:8.5.04786b9eaa606
pymongo@3.11.3
4.18.2
1
allegroai/clearml:2.0.0-613713ae38f7daf
pymongo@4.10.1
4.18.2
1
apsl/thumbor:6.7.051e2de5c2c70
pymongo@3.10.0
4.18.2
1
assistiot/fl_local_operations_inference:latest0518b63a2e69
pymongo@4.3.3
4.18.2
1
assistiot/fl_repository:latest0fce3ea719a5
pymongo@4.2.0
4.18.2
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
pymongo@4.6.2
4.18.2
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
pymongo@4.6.3
4.18.2
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
pymongo@4.6.2
4.18.2
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
pymongo@4.17.0
4.18.2
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
pymongo@4.8.0
4.18.2
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
pymongo@4.8.0
4.18.2
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
pymongo@4.8.0
4.18.2
1
datadog/agent:7.22.08f20e56b5311
pymongo@3.8.0
4.18.2
1
dysnix/pritunl:v1.29-r819951e3e7a32
pymongo@3.10.1
4.18.2
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
pymongo@4.3.3
4.18.2
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
pymongo@3.12.1
4.18.2
1
goofball222/pritunl:1.30.3070.5943c0743701d4
pymongo@3.12.1
4.18.2
1
goofball222/pritunl:1.32.3602.807bf26032dfce
pymongo@3.13.0
4.18.2
1
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
pymongo@4.10.1
4.18.2
1
hamzaarshad10/querypodpy:1.7154f38e8668e
pymongo@4.10.1
4.18.2
1
hayk96/alerta-web:9.0.486377705e9e3
pymongo@4.4.1
4.18.2
1
hhyo/archery:v1.9.11aa41843419e
pymongo@3.11.0
4.18.2
1
hmdmph/mongo-pod-labeler:1.0.1-alpine79e4a170f3dc
pymongo@3.10.1
4.18.2
1
jordan/icinga2:latestf75025fe8ea8
pymongo@3.11.0
pymongo@3.11.0-1+deb12u1
4.18.2
no fix listed
1
kobotoolbox/kobocat:2.022.24ab15679454415
pymongo@3.12.3
4.18.2
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
pymongo@3.12.3
4.18.2
1
langflowai/langflow:1.12.334055a07d446
pymongo@4.17.0
4.18.2
1
localstack/localstack:3.19d278167f2b7
pymongo@4.6.1
4.18.2
1
localstack/localstack:latestdf6b89814326
pymongo@4.18.1
4.18.2
1
makeplane/backend-commercial:v3.3.1000b3ea7451a
pymongo@4.6.3
4.18.2
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
pymongo@4.2.0
4.18.2
1
ncsa/checks:main0b738bbc8d70
pymongo@3.13.0
4.18.2
1
omkara25/simple-microservice-app-order-service:v2.18327546c7aac
pymongo@4.10.1
4.18.2
1
omkara25/simple-microservice-app-payment-service:v2afff40172b6b
pymongo@4.10.1
4.18.2
1
omkara25/simple-microservice-app-user-service:v2d62cba548580
pymongo@4.10.1
4.18.2
1
opencsghq/agenticflow:ee-v0.6.5-241cba9c366f1
pymongo@4.10.1
4.18.2
1
redash/redash:25.8.000d813437db5
pymongo@4.6.3
4.18.2
1
redash/redash:10.0.0.b503639392753c0376
pymongo@3.9.0
4.18.2
1
redash/redash:26.3.0c5c9148f5c38
pymongo@4.6.3
4.18.2
1
rezachalak/bzen-mongo:1.0.034f694325191
pymongo@4.4.1
4.18.2
1
stackstorm/st2actionrunner:3.888235ba70cad
pymongo@3.11.3
4.18.2
1
stackstorm/st2api:3.86f56d239d280
pymongo@3.11.3
4.18.2
1
stackstorm/st2auth:3.833ecfda16608
pymongo@3.11.3
4.18.2
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
pymongo@3.11.3
4.18.2
1
stackstorm/st2notifier:3.8f190a6212195
pymongo@3.11.3
4.18.2
1
stackstorm/st2rulesengine:3.8259503496ff9
pymongo@3.11.3
4.18.2
1

syft 1.42.1 · advisories as of 7 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.