StackRadar

CVE-2026-28684

Medium

Advisory

Published 20 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.6
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
162
of 17,781 indexed, latest versions
Container images
158
deployed by those charts
Fix available
1 of 2
affected packages

python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback

Carried by container images the latest versions of 162 of 17,781 indexed charts deploy, on 158 images.

Affected packageAffected versionsFixed inImages
python-dotenvpypi0.9.1, 0.10.3, 0.11.0, 0.13.0+15 more1.2.2158
python-dotenvdeb0.9.1-1, 0.19.2-1no fix listed2
OSV records
GHSA-mf9w-mj56-hr94UBUNTU-CVE-2026-28684
Also known as
PYSEC-2026-2270

Charts affected

162 by stars
ChartLatestAffected imagesRadar Score
take-the-helmtake-the-helm0.1.01 of 1See more

take-the-helm take-the-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
cadmusthefounder/lnd:take-the-helm-0.1.0e596c5fbf80f
python-dotenv@0.20.0
1.2.2

Open the chart page →

805
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
python-dotenv@1.0.1
1.2.2

Open the chart page →

5,704
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
python-dotenv@1.0.1
1.2.2

Open the chart page →

39,090
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
opea/llm-docsum-tgi:1.002f9e8fa5d71
python-dotenv@1.0.1
1.2.2

Open the chart page →

28,858
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
python-dotenv@1.0.1
1.2.2

Open the chart page →

5,221
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
python-dotenv@1.0.1
1.2.2

Open the chart page →

5,198
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
python-dotenv@1.0.1
1.2.2

Open the chart page →

5,350
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
pysga1996/python-redis-web:latestfdeec30ad482
python-dotenv@0.21.1
1.2.2

Open the chart page →

4,661
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
python-dotenv@1.0.1
1.2.2

Open the chart page →

1,515
zookeepertwomartensVerified publisher0.2.21 of 1See more

zookeeper twomartens 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
python-dotenv@0.21.1
1.2.2

Open the chart page →

1,733
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
python-dotenv@1.1.1
1.2.2

Open the chart page →

7,628
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
python-dotenv@0.19.0
1.2.2

Open the chart page →

7,085

Container images carrying it

158 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
john19968010/fastapi-template:latest31a90f6bd69c
python-dotenv@0.20.0
1.2.2
1
kyovint/kyoimgtransactions:1.0.048c19e3ae9a3
python-dotenv@1.1.1
1.2.2
1
kyovint/kyoimgusers:1.0.080084149156e
python-dotenv@1.1.1
1.2.2
1
langgenius/dify-api:1.0.0066035f93856
python-dotenv@1.0.1
1.2.2
1
langgenius/dify-api:0.6.11fca918260dd6
python-dotenv@1.0.0
1.2.2
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
python-dotenv@1.2.1
1.2.2
1
librenms/librenms:24.11.00920bc9117a8
python-dotenv@1.0.1
1.2.2
1
librenms/librenms:22.4.14f1f3d667cc7
python-dotenv@0.20.0
1.2.2
1
linuxserver/babybuddy:1.10.2f7d7c7704249
python-dotenv@0.19.2
1.2.2
1
linuxserver/calibre-web:0.6.24241009026e6f
python-dotenv@1.1.1
1.2.2
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
python-dotenv@1.0.1
1.2.2
1
lnbitsdocker/lnbits-legend:latest26fae6327477
python-dotenv@1.0.0
1.2.2
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
python-dotenv@0.21.0
1.2.2
1
lncm/specter-desktop:v0.10.4bca14d04397d
python-dotenv@0.13.0
1.2.2
1
localstack/localstack:3.19d278167f2b7
python-dotenv@1.0.1
1.2.2
1
lsstsqre/exposurelog:0.8.079b00fb67a65
python-dotenv@0.19.0
1.2.2
1
makersquad/harp-proxy:0.8.1a40dd258c527
python-dotenv@1.0.1
1.2.2
1
marcoimme/oidcmock:latestb6035c0721a8
python-dotenv@1.2.1
1.2.2
1
mediagis/nominatim:3.7c15e941485ef
python-dotenv@0.9.1-1
python-dotenv@0.9.1
no fix listed
1.2.2
1
mediagis/nominatim:4.2d0eae7b51374
python-dotenv@0.19.2-1
python-dotenv@0.19.2
no fix listed
1.2.2
1
milesmcc/shynet:v0.13.1ba54f7797a6b
python-dotenv@0.18.0
1.2.2
1
milesmcc/shynet:v0.12.0e821e31140f7
python-dotenv@0.18.0
1.2.2
1
miltex/python-api:1.0.0dab12a7748d5
python-dotenv@0.18.0
1.2.2
1
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
python-dotenv@0.15.0
1.2.2
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
python-dotenv@0.21.0
1.2.2
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
python-dotenv@0.20.0
1.2.2
1
opea/guardrails-tgi:1.0262c6048aab8
python-dotenv@1.0.1
1.2.2
1
opea/guardrails-tgi:latestf68bec6a1271
python-dotenv@1.0.1
1.2.2
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
python-dotenv@1.0.1
1.2.2
1
opea/web-retriever-chroma:1.0fe08165d7770
python-dotenv@1.0.1
1.2.2
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
python-dotenv@1.1.1
1.2.2
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
python-dotenv@1.2.1
1.2.2
1
opencsghq/csgship-agentic:v0.4.02cd29671a03e
python-dotenv@1.1.1
1.2.2
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
python-dotenv@1.1.1
1.2.2
1
openmined/syft-backend:0.9.5b72f74a68b32
python-dotenv@1.0.1
1.2.2
1
openzaak/open-notificaties:1.3.02e65313b9b10
python-dotenv@0.20.0
1.2.2
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
python-dotenv@0.19.2
1.2.2
1
phan2410/dummy-service:0.0.89c6ed6de26ca
python-dotenv@1.1.0
1.2.2
1
pysga1996/python-redis-web:latestfdeec30ad482
python-dotenv@0.21.1
1.2.2
1
redash/redash:25.8.000d813437db5
python-dotenv@0.19.2
1.2.2
1
redash/redash:26.3.0c5c9148f5c38
python-dotenv@0.19.2
1.2.2
1
rommapp/romm:4.4.1b909e95d1aab
python-dotenv@1.0.1
1.2.2
1
salehmir/jesse:1.10.101afa95f979e9
python-dotenv@0.19.2
1.2.2
1
sharanalwar/redchef-backend:latest8d3cab80df49
python-dotenv@1.0.0
1.2.2
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
python-dotenv@1.0.1
1.2.2
1
sruthitanneru/pi-sample:ui-lateste565ea454ffd
python-dotenv@1.0.1
1.2.2
1
substratusai/verba:v0.4.0-baseURL261695be635eb
python-dotenv@1.0.0
1.2.2
1
taigaio/taiga-protected:6.4.036318831b3e7
python-dotenv@0.10.3
1.2.2
1
thelande/kasa_exporter:v0.2.3a1fdb8baa152
python-dotenv@1.0.1
1.2.2
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
python-dotenv@1.0.1
1.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.