StackRadar

CVE-2026-97688

Medium

Advisory

Published 29 Sept 2026In the index since 1 Oct 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.003
20th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
577
of 17,966 indexed, latest versions
Container images
435
deployed by those charts
Fix available
1 of 3
affected packages

urllib3: Chunked Deflate streaming can enter an infinite loop

Carried by container images the latest versions of 577 of 17,966 indexed charts deploy, on 435 images.

Affected packageAffected versionsFixed inImages
urllib3pypi2.6.2, 2.6.3, 2.7.02.8.0298
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+23 moreno fix listed114
python-urllib3deb1.7.1-1build1, 1.7.1-1ubuntu4, 1.13.1-2ubuntu0.16.04.1, 1.13.1-2ubuntu0.16.04.2+12 moreno fix listed62
OSV records
GHSA-gh4c-6fx4-qh6gUBUNTU-CVE-2026-97688

Charts affected

577 by stars
ChartLatestAffected imagesRadar Score
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.8.0

Open the chart page →

5,894
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.8.0

Open the chart page →

20,785
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.8.0

Open the chart page →

20,785
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.8.0

Open the chart page →

7,381
vaultwardenvaultwarden-helmVerified publisher1.2.71 of 2See more

vaultwarden vaultwarden-helm 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:18.4-system-trixie42708a75345b
urllib3@2.7.0
2.8.0

Open the chart page →

2,175
tdarrvhdirkVerified publisher5.0.52 of 2See more

tdarr vhdirk 5.0.5

2 of the 2 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
python-urllib3@1.25.8-2ubuntu0.2
no fix listed
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
python-urllib3@1.25.8-2ubuntu0.1
no fix listed

Open the chart page →

162,705
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
python-pip@22.0.2+dfsg-1ubuntu0.4
no fix listed

Open the chart page →

80,662
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
python-pip@24.0+dfsg-1ubuntu1.3
no fix listed

Open the chart page →

5,052
bugsinkvictorlane0.3.71 of 2See more

bugsink victorlane 0.3.7

1 of the 2 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
bugsink/bugsink:246fc01ffbd60
urllib3@2.7.0
2.8.0

Open the chart page →

4,493
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
python-urllib3@1.26.5-1~exp1ubuntu0.1
no fix listed

Open the chart page →

73,602
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.8.0

Open the chart page →

20,785
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
python-pip@24.0+dfsg-1ubuntu1.2
no fix listed

Open the chart page →

8,510
waldur-site-agentwaldur-site-agentVerified publisher1.0.71 of 1See more

waldur-site-agent waldur-site-agent 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
opennode/waldur-site-agent:1.0.76d2e3b97c8d2
urllib3@2.7.0
2.8.0

Open the chart page →

624
wallarm-node-nativewallarmVerified publisher0.25.81 of 2See more

wallarm-node-native wallarm 0.25.8

1 of the 2 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
wallarm/node-helpers:6.13.1f936a82d495c
urllib3@2.7.0
2.8.0

Open the chart page →

74
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
wallarm/node-helpers:6.10.1aecd88b24c51
urllib3@2.6.3
2.8.0

Open the chart page →

2,941
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
urllib3@2.6.3
2.8.0

Open the chart page →

20,785
wasabi-s3-operatorwasabi-s3-operatorVerified publisher0.2.71 of 1See more

wasabi-s3-operator wasabi-s3-operator 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
urllib3@2.6.3
2.8.0

Open the chart page →

731
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
urllib3@2.6.3
2.8.0

Open the chart page →

6,084
argocd-image-updaterwener1.3.11 of 1See more

argocd-image-updater wener 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-image-updater:v1.3.0cb009167015c
urllib3@2.7.0
2.8.0

Open the chart page →

820
kube-prometheus-stackwener91.8.21 of 6See more

kube-prometheus-stack wener 91.8.2

1 of the 6 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
urllib3@2.7.0
2.8.0

Open the chart page →

399
victoria-metrics-k8s-stackwener0.95.01 of 7See more

victoria-metrics-k8s-stack wener 0.95.0

1 of the 7 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
urllib3@2.7.0
2.8.0

Open the chart page →

832
argocd-image-updaterwenerme1.3.11 of 1See more

argocd-image-updater wenerme 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-image-updater:v1.3.0cb009167015c
urllib3@2.7.0
2.8.0

Open the chart page →

820
victoria-metrics-k8s-stackwenerme0.95.01 of 7See more

victoria-metrics-k8s-stack wenerme 0.95.0

1 of the 7 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.11.22912be006f62
urllib3@2.7.0
2.8.0

Open the chart page →

832
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
library/mysql:latestade067ae2fb1
urllib3@2.7.0
2.8.0

Open the chart page →

2,562
dingtalk-botxxl-job-adminVerified publisher0.1.31 of 2See more

dingtalk-bot xxl-job-admin 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
urllib3@2.6.2
2.8.0

Open the chart page →

3,565
ceph-exporterygqygq2Verified publisher1.0.01 of 1See more

ceph-exporter ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
digitalocean/ceph_exporter:latest3ba058e9a48d
python-urllib3@1.25.8-2ubuntu0.4
no fix listed

Open the chart page →

6,134
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-97688.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
urllib3@2.7.0
2.8.0

Open the chart page →

8,734

Container images carrying it

435 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
urllib3@2.6.3
2.8.0
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
urllib3@2.7.0
2.8.0
1
ghcr.io/mend/renovate-ee-server:15.6.087b77989f48d
python-urllib3@2.0.7-1ubuntu0.7
no fix listed
1
ghcr.io/mgd43b/metalnap:0.5.1ca2c03eadf05
urllib3@2.7.0
2.8.0
1
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
urllib3@2.7.0
2.8.0
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
urllib3@2.7.0
2.8.0
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
urllib3@2.6.3
2.8.0
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
urllib3@2.7.0
2.8.0
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
urllib3@2.7.0
2.8.0
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
urllib3@2.7.0
2.8.0
1
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
urllib3@2.7.0
2.8.0
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
urllib3@2.6.3
2.8.0
1
ghcr.io/observal/observal-api:1.13.1153b8b893232
urllib3@2.7.0
2.8.0
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
urllib3@2.6.3
2.8.0
1
ghcr.io/opendatacube/explorer:latest7c25578068cd
urllib3@2.7.0
2.8.0
1
ghcr.io/opendatacube/ows:latestf591c9d96c0f
urllib3@2.7.0
2.8.0
1
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
urllib3@2.7.0
2.8.0
1
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
urllib3@2.6.3
2.8.0
1
ghcr.io/openrelik/openrelik-server:latestce1132261523
urllib3@2.7.0
2.8.0
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
python-pip@24.0+dfsg-1ubuntu1.3
python-urllib3@2.0.7-1ubuntu0.7
urllib3@2.7.0
no fix listed
no fix listed
2.8.0
1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
python-pip@24.0+dfsg-1ubuntu1.3
python-urllib3@2.0.7-1ubuntu0.7
urllib3@2.7.0
no fix listed
no fix listed
2.8.0
1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
urllib3@2.7.0
2.8.0
1
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
urllib3@2.7.0
2.8.0
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
python-pip@24.0+dfsg-1ubuntu1.3
python-urllib3@2.0.7-1ubuntu0.7
urllib3@2.7.0
no fix listed
no fix listed
2.8.0
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
python-urllib3@2.0.7-1ubuntu0.7
urllib3@2.7.0
no fix listed
2.8.0
1
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
urllib3@2.7.0
2.8.0
1
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
urllib3@2.7.0
2.8.0
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
python-pip@24.0+dfsg-1ubuntu1.3
python-urllib3@2.0.7-1ubuntu0.7
urllib3@2.7.0
no fix listed
no fix listed
2.8.0
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
python-pip@24.0+dfsg-1ubuntu1.3
python-urllib3@2.0.7-1ubuntu0.7
urllib3@2.7.0
no fix listed
no fix listed
2.8.0
1
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
urllib3@2.7.0
2.8.0
1
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
urllib3@2.7.0
2.8.0
1
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
urllib3@2.7.0
2.8.0
1
ghcr.io/open-telemetry/demo:3.1.0-chatbot604b1f493c92
urllib3@2.7.0
2.8.0
1
ghcr.io/open-telemetry/demo:3.1.0-mcp81db69cdd0b6
urllib3@2.7.0
2.8.0
1
ghcr.io/open-telemetry/demo:3.1.0-load-generatorb130d6cee6cb
urllib3@2.7.0
2.8.0
1
ghcr.io/open-telemetry/demo:3.1.0-agentd0f4ae0b32a8
urllib3@2.7.0
2.8.0
1
ghcr.io/open-webui/terminals-operator:latest5e1ceb6b3b26
urllib3@2.7.0
2.8.0
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
ghcr.io/performancecopilot/pcp:latest70dde5f13f08
urllib3@2.7.0
2.8.0
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
urllib3@2.7.0
2.8.0
1
ghcr.io/quenchworks/images/airflow09760517014a
urllib3@2.7.0
2.8.0
1
ghcr.io/quenchworks/images/pgadmina989540d10b6
urllib3@2.7.0
2.8.0
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
urllib3@2.7.0
2.8.0
1
ghcr.io/securo-finance/securo-backend:0.16.2b1cd83ff7828
urllib3@2.7.0
2.8.0
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
urllib3@2.6.2
2.8.0
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
ghcr.io/stac-utils/titiler-pgstac:3.2.09a35f907dc70
urllib3@2.7.0
2.8.0
1
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
urllib3@2.6.3
2.8.0
1
ghcr.io/unique-ag/ai/search-proxy:2026.40.02bd74586650d
urllib3@2.7.0
2.8.0
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.