StackRadar

CVE-2026-28684

Medium

Advisory

Published 20 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.6
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
162
of 17,781 indexed, latest versions
Container images
158
deployed by those charts
Fix available
1 of 2
affected packages

python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback

Carried by container images the latest versions of 162 of 17,781 indexed charts deploy, on 158 images.

Affected packageAffected versionsFixed inImages
python-dotenvpypi0.9.1, 0.10.3, 0.11.0, 0.13.0+15 more1.2.2158
python-dotenvdeb0.9.1-1, 0.19.2-1no fix listed2
OSV records
GHSA-mf9w-mj56-hr94UBUNTU-CVE-2026-28684
Also known as
PYSEC-2026-2270

Charts affected

162 by stars
ChartLatestAffected imagesRadar Score
take-the-helmtake-the-helm0.1.01 of 1See more

take-the-helm take-the-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
cadmusthefounder/lnd:take-the-helm-0.1.0e596c5fbf80f
python-dotenv@0.20.0
1.2.2

Open the chart page →

805
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
python-dotenv@1.0.1
1.2.2

Open the chart page →

5,704
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
python-dotenv@1.0.1
1.2.2

Open the chart page →

39,090
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
opea/llm-docsum-tgi:1.002f9e8fa5d71
python-dotenv@1.0.1
1.2.2

Open the chart page →

28,858
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
python-dotenv@1.0.1
1.2.2

Open the chart page →

5,221
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
python-dotenv@1.0.1
1.2.2

Open the chart page →

5,198
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
python-dotenv@1.0.1
1.2.2

Open the chart page →

5,350
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
pysga1996/python-redis-web:latestfdeec30ad482
python-dotenv@0.21.1
1.2.2

Open the chart page →

4,661
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
python-dotenv@1.0.1
1.2.2

Open the chart page →

1,515
zookeepertwomartensVerified publisher0.2.21 of 1See more

zookeeper twomartens 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
python-dotenv@0.21.1
1.2.2

Open the chart page →

1,733
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
python-dotenv@1.1.1
1.2.2

Open the chart page →

7,628
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28684.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
python-dotenv@0.19.0
1.2.2

Open the chart page →

7,085

Container images carrying it

158 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
shashkist/flask-contacts-app:latest581de1fd6084
python-dotenv@1.0.1
1.2.2
4
apache/superset:6.1.0:latest16b50bbef664
python-dotenv@1.1.0
1.2.2
3
quay.io/devtron/ai-agent:0.0.16545dac92173
python-dotenv@1.0.1
1.2.2
3
amancevice/superset:0.35.212a0a9e66550
python-dotenv@0.10.3
1.2.2
2
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
python-dotenv@0.21.1
1.2.2
2
confluentinc/cp-zookeeper:latest7610a50b13e7
python-dotenv@0.21.1
1.2.2
2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
python-dotenv@0.21.1
1.2.2
2
lncm/specter-desktop:v1.10.536eaa06f99f4
python-dotenv@0.13.0
1.2.2
2
opea/retriever-redis:1.0eb746b263705
python-dotenv@1.0.1
1.2.2
2
taigaio/taiga-protected:latestfd4568a97a59
python-dotenv@0.10.3
1.2.2
2
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
python-dotenv@1.0.1
1.2.2
2
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
python-dotenv@1.0.0
1.2.2
1
apache/airflow:2.8.4-python3.964e58748b6b9
python-dotenv@1.0.1
1.2.2
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
python-dotenv@1.0.1
1.2.2
1
apache/airflow:2.8.1e5560ad0b86e
python-dotenv@1.0.0
1.2.2
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
python-dotenv@0.19.0
1.2.2
1
apache/superset:4.0.1ab9467fd712c
python-dotenv@0.19.0
1.2.2
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
python-dotenv@1.1.0
1.2.2
1
asdkant/fastapi-hello-world:latesta23d8bf7c885
python-dotenv@0.15.0
1.2.2
1
assistiot/fl_training_collector:latest792715dd3084
python-dotenv@0.19.1
1.2.2
1
assistiot/open_api_backend:1.1.230812ba93555
python-dotenv@1.0.0
1.2.2
1
baserow/backend:1.31.1e0b3c8130b91
python-dotenv@1.0.1
1.2.2
1
baserow/baserow:1.30.1df0c42eb67e8
python-dotenv@1.0.1
1.2.2
1
benbusby/whoogle-search:0.5.4f77f7e6e4ad2
python-dotenv@0.16.0
1.2.2
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
python-dotenv@1.2.1
1.2.2
1
bmeares/meerschaum:2.8.48e9c5bacaa82
python-dotenv@1.0.1
1.2.2
1
cadmusthefounder/lnd:take-the-helm-0.1.0e596c5fbf80f
python-dotenv@0.20.0
1.2.2
1
castai/hibernate:v0.14da62858c8381
python-dotenv@0.21.1
1.2.2
1
chandanteekinavar/findery-market-product-service:1.0c49ff7c141c0
python-dotenv@0.19.0
1.2.2
1
ciuse99/suggestarr:v1.0.20d72768245ef5
python-dotenv@1.0.1
1.2.2
1
clsen2024/gwangju_2-3:service-b-10ba9eff852c5
python-dotenv@1.0.1
1.2.2
1
clsen2024/gwangju_2-3:service-a-151b1d45961cd
python-dotenv@1.0.1
1.2.2
1
clsen2024/gwangju_2-3:service-c-1efb1586c8299
python-dotenv@1.0.1
1.2.2
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
python-dotenv@0.20.0
1.2.2
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
python-dotenv@0.21.1
1.2.2
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
python-dotenv@0.21.1
1.2.2
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
python-dotenv@0.21.1
1.2.2
1
confluentinc/cp-kafka:7.5.1dc9b972db002
python-dotenv@0.21.1
1.2.2
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
python-dotenv@0.21.1
1.2.2
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
python-dotenv@0.21.1
1.2.2
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
python-dotenv@0.21.1
1.2.2
1
douz/helpdesk:latest4384103d0219
python-dotenv@0.20.0
1.2.2
1
dserio83/velero-api:0.3.16b3d9115fee2
python-dotenv@1.0.1
1.2.2
1
dserio83/velero-watchdog:0.1.8d5deae589229
python-dotenv@1.0.1
1.2.2
1
evk02/mlflow:2.2.1ef6ff257ef35
python-dotenv@1.0.0
1.2.2
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
python-dotenv@0.21.0
1.2.2
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
python-dotenv@0.15.0
1.2.2
1
freedom98/flask:k3.0d7ce1533f297
python-dotenv@1.1.1
1.2.2
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
python-dotenv@0.15.0
1.2.2
1
jamoos/kweather:history163e2e8a6e87
python-dotenv@1.0.1
1.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.