StackRadar

CVE-2026-7246

High

Advisory

Published 30 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
576
of 17,781 indexed, latest versions
Container images
614
deployed by those charts
Fix available
2 of 3
affected packages

Security update for python-click

Carried by container images the latest versions of 576 of 17,781 indexed charts deploy, on 614 images.

Affected packageAffected versionsFixed inImages
clickpypi6.7, 7.0, 7.1.1, 7.1.2+16 more8.3.3614
python-clickdeb8.1.3-2no fix listed8
python-clickrpm8.2.1-160000.2.28.2.1-160000.3.11
OSV records
DEBIAN-CVE-2026-7246PYSEC-2026-2132SUSE-SU-2026:22321-1
Also known as
GHSA-47fr-3ffg-hgmw

Charts affected

576 by stars
ChartLatestAffected imagesRadar Score
helpdeskdoubanVerified publisher0.3.31 of 2See more

helpdesk douban 0.3.3

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
douz/helpdesk:latest4384103d0219
click@8.1.3
8.3.3

Open the chart page →

4,550
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
click@8.0.3
8.3.3

Open the chart page →

30,699
rook-cephdtrdnk-helm-chartsVerified publisher0.0.11 of 2See more

rook-ceph dtrdnk-helm-charts 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
rook/ceph:v1.19.2944a1dd70496
click@8.0.3
8.3.3

Open the chart page →

1,990
temporaldtrdnk-helm-chartsVerified publisher0.35.01 of 13See more

temporal dtrdnk-helm-charts 0.35.0

1 of the 13 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.4258958fe2ff2
click@8.1.7
8.3.3

Open the chart page →

20,205
amundsenduyet1.1.03 of 7See more

amundsen duyet 1.1.0

3 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
click@7.1.1
8.3.3
amundsendev/amundsen-metadata:2.5.44d98eb21f5f9
click@6.7
8.3.3
amundsendev/amundsen-search:2.4.099dda9502c3e
click@6.7
8.3.3

Open the chart page →

11,174
pritunldysnixVerified publisher0.2.71 of 3See more

pritunl dysnix 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
dysnix/pritunl:v1.29-r819951e3e7a32
click@7.1.2
8.3.3

Open the chart page →

5,055
aerios-k8s-shimeclipse-aeriosVerified publisher1.0.01 of 1See more

aerios-k8s-shim eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/aerios-k8s-shim:v1.0.0d4ed3d8e5db4
click@8.1.7
8.3.3

Open the chart page →

1,434
hlo-data-aggregatoreclipse-aeriosVerified publisher3.0.01 of 1See more

hlo-data-aggregator eclipse-aerios 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/hlo-data-aggregator:v3.0.0b433c2b9f5dc
click@8.1.7
8.3.3

Open the chart page →

1,643
hlo-deployment-engineeclipse-aeriosVerified publisher3.0.01 of 1See more

hlo-deployment-engine eclipse-aerios 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/hlo-deployment-engine:v3.0.0d582d39208c7
click@8.1.7
8.3.3

Open the chart page →

1,653
hlo-fe-engineeclipse-aeriosVerified publisher3.0.01 of 1See more

hlo-fe-engine eclipse-aerios 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/hlo-fe-engine:v3.0.08ed2df4ca692
click@8.1.7
8.3.3

Open the chart page →

1,643
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
click@8.3.1
8.3.3

Open the chart page →

13,391
self-awarenesseclipse-aeriosVerified publisher1.4.42 of 2See more

self-awareness eclipse-aerios 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/self-awareness-hardware-info:1.4.434b72f45b46a
click@8.3.1
8.3.3
eclipseaerios/self-awareness-power-consumption:1.3.3c8af377c709f
click@8.3.1
8.3.3

Open the chart page →

2,219
trustmanagereclipse-aeriosVerified publisher1.0.01 of 1See more

trustmanager eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/trust-manager:1.0.0f55442e2c0ed
click@8.1.8
8.3.3

Open the chart page →

1,895
home-assistantegebackVerified publisher2.0.351 of 1See more

home-assistant egeback 2.0.35

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
click@8.1.8
8.3.3

Open the chart page →

2,158
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
click@8.1.3
python-click@8.1.3-2
8.3.3
no fix listed

Open the chart page →

30,159
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
click@8.1.3
8.3.3

Open the chart page →

25,122
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
click@8.1.3
8.3.3

Open the chart page →

9,334
rommernail-romm1.0.11 of 1See more

romm ernail-romm 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
rommapp/romm:4.4.1b909e95d1aab
click@8.2.1
8.3.3

Open the chart page →

2,896
extended-ceph-exporterextended-ceph-exporterVerified publisher1.10.01 of 2See more

extended-ceph-exporter extended-ceph-exporter 1.10.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
quay.io/ceph/ceph:v21.1.05ff3692d2f3f
click@8.1.7
8.3.3

Open the chart page →

2,885
external-secrets-reloaderexternal-secrets-reloader0.1.01 of 1See more

external-secrets-reloader external-secrets-reloader 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/bensoer/external-secrets-reloader:v0.1.38e31b5a81853
click@8.3.1
8.3.3

Open the chart page →

1,030
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
click@8.1.3
8.3.3

Open the chart page →

4,085
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
stratospire/activityrelay:0.2.3a4c34cb01117
click@8.1.3
8.3.3

Open the chart page →

13,450
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.418cd5711fc9a
click@8.1.7
8.3.3

Open the chart page →

12,454
kodiakfikaworks1.1.41 of 2See more

kodiak fikaworks 1.1.4

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cdignam/kodiak:v0.54.05a6a55b39cee
click@8.0.1
8.3.3

Open the chart page →

3,892
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-product-service:1.0c49ff7c141c0
click@8.1.8
8.3.3

Open the chart page →

7,691
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
click@8.1.7
8.3.3

Open the chart page →

5,704
bae-activation-servicefiware0.1.21 of 1See more

bae-activation-service fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
fiware/bae-activation-service:v0.0.33e3ec88d59ed
click@7.1.2
8.3.3

Open the chart page →

3,186
ishare-satellitefiware1.3.21 of 1See more

ishare-satellite fiware 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
click@8.1.3
8.3.3

Open the chart page →

1,778
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
click@8.1.7
8.3.3

Open the chart page →

5,704
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
click@8.1.8
8.3.3

Open the chart page →

4,073
flaskappflaskwebapp0.1.01 of 1See more

flaskapp flaskwebapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
nabinchhetri/flask-app:v2.0be189fbf3411
click@8.1.3
8.3.3

Open the chart page →

512
kube-ops-viewfluent-operatorVerified publisher0.1.21 of 1See more

kube-ops-view fluent-operator 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:20.4.058221b57d4d2
click@7.1.1
8.3.3

Open the chart page →

1,848
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
louislam/uptime-kuma:13d632903e6af
click@7.0
8.3.3

Open the chart page →

3,474
forms-catalogueforms-catalogue0.1.01 of 2See more

forms-catalogue forms-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
click@7.1.2
8.3.3

Open the chart page →

2,188
powerdnsfsdrw080.1.31 of 4See more

powerdns fsdrw08 0.1.3

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
click@8.1.3
8.3.3

Open the chart page →

1,958
borgmaticgabe565Verified publisher0.10.11 of 1See more

borgmatic gabe565 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
click@8.1.8
8.3.3

Open the chart page →

2,438
spectergaloymoney0.3.11 of 1See more

specter galoymoney 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
lncm/specter-desktop:v1.10.536eaa06f99f4
click@8.1.1
8.3.3

Open the chart page →

1,691
spectergaloymoney20.3.11 of 1See more

specter galoymoney2 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
lncm/specter-desktop:v1.10.536eaa06f99f4
click@8.1.1
8.3.3

Open the chart page →

1,691
beetsgeek-cookbookVerified publisher1.4.21 of 1See more

beets geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
linuxserver/beets:1.5.0e36d16f7341c
click@8.0.3
8.3.3

Open the chart page →

1,150
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
click@7.1.2
8.3.3

Open the chart page →

16,123
changedetection-iogeek-cookbookVerified publisher1.5.21 of 1See more

changedetection-io geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
click@7.1.2
8.3.3

Open the chart page →

1,950
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
click@6.7
8.3.3

Open the chart page →

13,551
ihatemoneygeek-cookbookVerified publisher1.1.21 of 1See more

ihatemoney geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ihatemoney/ihatemoney:5.2.0457fda1feb32
click@8.1.2
8.3.3

Open the chart page →

1,526
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
click@8.1.3
8.3.3

Open the chart page →

12,076
powerdns-admingeek-cookbookVerified publisher1.2.21 of 1See more

powerdns-admin geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
click@8.0.3
8.3.3

Open the chart page →

2,643
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
click@8.0.1
8.3.3

Open the chart page →

24,293
searxgeek-cookbookVerified publisher5.6.21 of 4See more

searx geek-cookbook 5.6.2

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
searx/searx:1.0.0-211-968b28993dbb3a6d9419
click@8.0.1
8.3.3

Open the chart page →

7,470
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
click@8.1.8
8.3.3

Open the chart page →

8,923
speedtest-exportergeek-cookbookVerified publisher5.4.21 of 1See more

speedtest-exporter geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.2.29e36964bce26
click@8.0.1
8.3.3

Open the chart page →

1,772
whooglegeek-cookbookVerified publisher3.4.21 of 1See more

whoogle geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
benbusby/whoogle-search:0.5.4f77f7e6e4ad2
click@7.0
8.3.3

Open the chart page →

2,061

Container images carrying it

614 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ahmetgrbzz/result_server:1.008e10f9c0f53
click@8.1.7
8.3.3
1
ahmetgrbzz/result_server:2.035c37ae2bafd
click@8.1.7
8.3.3
1
ahmetgrbzz/web_server:1.02e7fef69c29f
click@8.1.7
8.3.3
1
ahmetgrbzz/web_server:2.0f018bafd2b0c
click@8.1.7
8.3.3
1
airbyte/manifest-server:7.23.73b3a670af168
click@8.1.8
8.3.3
1
alakaganaguathoork/local-business:latest7eb27b0f4a5a
click@8.3.0
8.3.3
1
alerta/alerta-web:8.5.04786b9eaa606
click@8.0.3
8.3.3
1
alexvm6/pythonalex:latest89a05786879c
click@8.1.3
8.3.3
1
allegroai/clearml:2.0.0-613713ae38f7daf
click@8.1.8
8.3.3
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
click@8.1.3
8.3.3
1
amancevice/superset:0.28.1c8c04bfe3d66
click@6.7
8.3.3
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
click@7.1.1
8.3.3
1
amundsendev/amundsen-metadata:2.5.44d98eb21f5f9
click@6.7
8.3.3
1
amundsendev/amundsen-search:2.4.099dda9502c3e
click@6.7
8.3.3
1
anchore/anchore-engine:v0.10.0bde9eedf639d
click@7.0
8.3.3
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
click@7.0
8.3.3
1
andreymileshin/kube-info:v0.1.0f7b300bc9e66
click@8.1.8
8.3.3
1
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
click@8.1.8
8.3.3
1
apache/airflow:2.8.4-python3.964e58748b6b9
click@8.1.7
8.3.3
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
click@8.1.7
8.3.3
1
apache/airflow:2.8.1e5560ad0b86e
click@8.1.7
8.3.3
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
click@8.0.4
8.3.3
1
apache/superset:4.0.1ab9467fd712c
click@8.1.3
8.3.3
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
click@8.1.8
8.3.3
1
archish27/python-fastapi-postgres:latest6610071a2101
click@8.1.3
8.3.3
1
aristidetm/basic-notebook:3.6.5469dbc951224
click@8.1.7
8.3.3
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
click@8.1.7
8.3.3
1
arunvelsriram/utils:latest655ad18fd8d6
click@8.1.6
8.3.3
1
asdkant/fastapi-hello-world:latesta23d8bf7c885
click@7.1.2
8.3.3
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
click@7.0
8.3.3
1
assistiot/fl_repository:latest0fce3ea719a5
click@8.1.3
8.3.3
1
assistiot/fl_training_collector:latest792715dd3084
click@8.0.3
8.3.3
1
assistiot/open_api_backend:1.1.230812ba93555
click@8.1.7
8.3.3
1
assistiot/resource-provisioning_api:1.0.044a37b00d4f8
click@8.0.3
8.3.3
1
assistiot/resource-provisioning_im:1.0.0a942dc14030a
click@8.0.3
8.3.3
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
click@8.1.7
8.3.3
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
click@8.1.7
8.3.3
1
assistiot/traffic-classification_api:2.0.0e32b87786142
click@8.0.3
8.3.3
1
avinash263/pyredis263:latestaa2b8727f1a6
click@8.1.3
8.3.3
1
azhar008/flaskapplication:latesta1e827b0adea
click@8.0.3
8.3.3
1
badsmoke/wunderground_exporter:0.0.5c54c004f24cc
click@7.1.2
8.3.3
1
baserow/backend:2.3.37c00549b3a6f
click@8.3.1
8.3.3
1
baserow/backend:1.31.1e0b3c8130b91
click@8.1.7
8.3.3
1
baserow/baserow:1.30.1df0c42eb67e8
click@8.1.7
8.3.3
1
behnambm/docker-sample:v1bd3ad88afff9
click@8.1.7
8.3.3
1
benbusby/whoogle-search:0.5.4f77f7e6e4ad2
click@7.0
8.3.3
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
click@8.1.8
8.3.3
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
click@8.1.8
8.3.3
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
click@7.1.2
8.3.3
1
bmeares/meerschaum:2.8.48e9c5bacaa82
click@8.1.8
8.3.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.