StackRadar

CVE-2026-7246

High

Advisory

Published 30 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
576
of 17,781 indexed, latest versions
Container images
614
deployed by those charts
Fix available
2 of 3
affected packages

Security update for python-click

Carried by container images the latest versions of 576 of 17,781 indexed charts deploy, on 614 images.

Affected packageAffected versionsFixed inImages
clickpypi6.7, 7.0, 7.1.1, 7.1.2+16 more8.3.3614
python-clickdeb8.1.3-2no fix listed8
python-clickrpm8.2.1-160000.2.28.2.1-160000.3.11
OSV records
DEBIAN-CVE-2026-7246PYSEC-2026-2132SUSE-SU-2026:22321-1
Also known as
GHSA-47fr-3ffg-hgmw

Charts affected

576 by stars
ChartLatestAffected imagesRadar Score
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
click@8.3.1
8.3.3

Open the chart page →

12,397
backendikusi-bk-chart1.0.32 of 3See more

backend ikusi-bk-chart 1.0.3

2 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
kyovint/kyoimgtransactions:1.0.048c19e3ae9a3
click@8.2.1
8.3.3
kyovint/kyoimgusers:1.0.080084149156e
click@8.2.1
8.3.3

Open the chart page →

5,940
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
click@8.1.7
8.3.3

Open the chart page →

15,712
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
click@8.0.4
8.3.3

Open the chart page →

7,129
iris-webappiris-webapp0.2.41 of 2See more

iris-webapp iris-webapp 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
click@8.1.8
8.3.3

Open the chart page →

11,764
jessejesse-chartVerified publisher0.0.461 of 6See more

jesse jesse-chart 0.0.46

1 of the 6 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
salehmir/jesse:1.10.101afa95f979e9
click@8.0.4
8.3.3

Open the chart page →

3,421
alertmanager-gchat-integrationjulb-meVerified publisher1.0.51 of 1See more

alertmanager-gchat-integration julb-me 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
julb/alertmanager-gchat-integration:1.0.5837c4038a0dd
click@7.1.2
8.3.3

Open the chart page →

2,110
jupyterhub-outpostjupyter-jscVerified publisher2.4.11 of 1See more

jupyterhub-outpost jupyter-jsc 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
jupyterjsc/jupyterhub-outpost:2.3.1aea53b13f235
click@8.3.2
8.3.3

Open the chart page →

1,678
kronickronic0.1.71 of 1See more

kronic kronic 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/mshade/kronic:v0.1.466e3043851cd
click@8.1.7
8.3.3

Open the chart page →

1,062
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
click@8.1.7
8.3.3

Open the chart page →

20,403
kubeseal-webguikubeseal-webgui6.0.41 of 2See more

kubeseal-webgui kubeseal-webgui 6.0.4

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/jaydee94/kubeseal-webgui/api:4.5.33cceb9462ae1
click@8.2.1
8.3.3

Open the chart page →

4,095
neuvectorlifen1.5.21 of 3See more

neuvector lifen 1.5.2

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
neuvector/manager:3.2.1f1b7d666eae0
click@6.7
8.3.3

Open the chart page →

2,747
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
click@8.1.7
8.3.3

Open the chart page →

4,292
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
click@8.3.1
8.3.3

Open the chart page →

7,201
locustlocustVerified publisher0.1.41 of 1See more

locust locust 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
hansehe/locust:1.1.0bc8e45262bc4
click@8.1.8
8.3.3

Open the chart page →

2,757
flask-appmarcinkujawski1.0.01 of 3See more

flask-app marcinkujawski 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
marcinkujawski/flask-app:2.0.1a455017b9d0e
click@8.0.4
8.3.3

Open the chart page →

2,912
mlflow-controllermlflow-deployment-controller0.1.82 of 2See more

mlflow-controller mlflow-deployment-controller 0.1.8

2 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
click@8.1.3
8.3.3
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
click@8.1.3
8.3.3

Open the chart page →

8,957
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
buntha/mlflow:2.1.1154542cc3083
click@8.1.3
8.3.3

Open the chart page →

5,804
clowder2ncsaVerified publisher1.9.73 of 12See more

clowder2 ncsa 1.9.7

3 of the 12 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
click@8.1.7
8.3.3
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
click@8.1.7
8.3.3
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
click@8.1.7
8.3.3

Open the chart page →

37,373
monitorneuvectorchartsVerified publisher2.11.11 of 1See more

monitor neuvectorcharts 2.11.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
neuvector/prometheus-exporter:1.0.181d78ed4eef40
click@8.1.7
8.3.3

Open the chart page →

203
opencveopencve1.2.01 of 3See more

opencve opencve 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cleveritcz/opencve:1.5.0c75c1636e0b7
click@7.1.2
8.3.3

Open the chart page →

2,097
open-notificatiesopen-zaak0.7.01 of 4See more

open-notificaties open-zaak 0.7.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
openzaak/open-notificaties:1.3.02e65313b9b10
click@8.0.4
8.3.3

Open the chart page →

2,850
opikopikOfficialVerified publisher2.2.591 of 13See more

opik opik 2.2.59

1 of the 13 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/comet-ml/opik/opik-python-backend:2.2.59269d0e55ea97
click@8.3.1
8.3.3

Open the chart page →

14,334
opta-agentopta-agentVerified publisher0.1.31 of 1See more

opta-agent opta-agent 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
runx1/opta-agent:latest0ca3867d3200
click@8.1.2
8.3.3

Open the chart page →

1,543
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
click@8.1.3
python-click@8.1.3-2
8.3.3
no fix listed

Open the chart page →

6,883
phonebook-chartphonebook-chart0.1.02 of 3See more

phonebook-chart phonebook-chart 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ahmetgrbzz/result_server:2.035c37ae2bafd
click@8.1.7
8.3.3
ahmetgrbzz/web_server:2.0f018bafd2b0c
click@8.1.7
8.3.3

Open the chart page →

3,034
home-assistantpree-helm-chartsVerified publisher1.80.01 of 1See more

home-assistant pree-helm-charts 1.80.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
click@8.1.8
8.3.3

Open the chart page →

2,133
pritunl-slack-apppritunl-slack-appVerified publisher0.1.71 of 1See more

pritunl-slack-app pritunl-slack-app 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
click@8.1.7
8.3.3

Open the chart page →

2,871
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
gpappsoft/privacyidea-docker:3.12.2af7841adad26
click@8.1.8
8.3.3

Open the chart page →

5,440
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
click@8.3.1
8.3.3

Open the chart page →

8,158
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg16d7db8f1085a3
click@8.0.3
8.3.3

Open the chart page →

12,930
mealiertomik-helm-chartsVerified publisher0.0.21 of 1See more

mealie rtomik-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
click@8.1.3
8.3.3

Open the chart page →

3,929
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
click@6.7
8.3.3

Open the chart page →

13,541
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
click@8.1.3
python-click@8.1.3-2
8.3.3
no fix listed

Open the chart page →

38,107
sceptresceptreai0.1.121 of 5See more

sceptre sceptreai 0.1.12

1 of the 5 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
maponyacharles/sceptreai:api-0.1.127b37b092130a
click@8.2.1
8.3.3

Open the chart page →

4,369
iopsciencemeshVerified publisher0.4.01 of 2See more

iop sciencemesh 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cs3org/wopiserver:v9.4.202a9e78757b4
click@8.1.3
8.3.3

Open the chart page →

4,052
sentry-k8ssentry-k8sVerified publisher1.4.12 of 11See more

sentry-k8s sentry-k8s 1.4.1

2 of the 11 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
click@8.2.1
8.3.3
ghcr.io/getsentry/snuba:26.7.210f8d164109b
click@8.1.7
8.3.3

Open the chart page →

16,449
vuiseriohub1.0.62 of 3See more

vui seriohub 1.0.6

2 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
dserio83/velero-api:0.3.16b3d9115fee2
click@8.1.8
8.3.3
dserio83/velero-watchdog:0.1.8d5deae589229
click@8.1.8
8.3.3

Open the chart page →

11,532
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
click@8.1.7
8.3.3

Open the chart page →

2,928
smarter-demosmarterOfficialVerified publisher0.1.51 of 7See more

smarter-demo smarter 0.1.5

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
click@7.0
8.3.3

Open the chart page →

45,832
snappasssnappassVerified publisher0.4.31 of 3See more

snappass snappass 0.4.3

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
click@8.3.1
8.3.3

Open the chart page →

2,995
alertasomeblackmagic0.2.31 of 2See more

alerta someblackmagic 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
alerta/alerta-web:8.5.04786b9eaa606
click@8.0.3
8.3.3

Open the chart page →

3,162
healthchecksstackhelmVerified publisher0.1.01 of 2See more

healthchecks stackhelm 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
healthchecks/healthchecks:v2.8.1e82bb0836e30
click@8.1.3
8.3.3

Open the chart page →

2,236
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
click@7.1.2
8.3.3

Open the chart page →

24,930
streamlit-appstreamlit-appVerified publisher0.2.01 of 1See more

streamlit-app streamlit-app 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
sruthitanneru/pi-sample:ui-lateste565ea454ffd
click@8.1.7
8.3.3

Open the chart page →

1,696
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
click@8.3.1
8.3.3

Open the chart page →

12,907
taigaunxwaresVerified publisher2026.3.81 of 6See more

taiga unxwares 2026.3.8

1 of the 6 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
click@8.3.1
8.3.3

Open the chart page →

9,148
phonebook-chartusuladamsVerified publisher0.1.52 of 3See more

phonebook-chart usuladams 0.1.5

2 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
paulkellerman/resultserver-app:1.0381eeccb0618
click@8.1.3
8.3.3
paulkellerman/webserver-app:latest5a37b74f61b9
click@8.1.3
8.3.3

Open the chart page →

3,176
verbacapverbacapVerified publisher1.0.71 of 1See more

verbacap verbacap 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
click@8.1.7
8.3.3

Open the chart page →

2,233
qleverzazukoVerified publisher0.7.01 of 2See more

qlever zazuko 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/zazukoians/qlever-server:v0.10.0f10fd24b2290
click@8.1.6
8.3.3

Open the chart page →

2,900

Container images carrying it

614 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
bootc/puppetboard:1.1.0f1383295e7be
click@7.0
8.3.3
1
buntha/mlflow:2.1.1154542cc3083
click@8.1.3
8.3.3
1
cadmusthefounder/lnd:take-the-helm-0.1.0e596c5fbf80f
click@8.1.3
8.3.3
1
cdignam/kodiak:v0.54.05a6a55b39cee
click@8.0.1
8.3.3
1
chandanteekinavar/findery-market-product-service:1.0c49ff7c141c0
click@8.1.8
8.3.3
1
chaostoolkit/back:latest734f3af86125
click@7.1.2
8.3.3
1
chaostoolkit/front:latest7f4a7eb9f7df
click@7.1.2
8.3.3
1
chaostoolkit/middle:latestb95ba4961cfc
click@7.1.2
8.3.3
1
chorss/docker-pgadmin4:4.115c549cacb8ab
click@7.0
8.3.3
1
citizenstig/httpbin:latestb81c818ccb86
click@6.7
8.3.3
1
ciuse99/suggestarr:v1.0.20d72768245ef5
click@8.1.7
8.3.3
1
ckan/ckan-base-datapusher:0.0.2184d11924549f
click@8.1.8
8.3.3
1
cleveritcz/opencve:1.5.0c75c1636e0b7
click@7.1.2
8.3.3
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
click@8.1.7
8.3.3
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
click@8.1.7
8.3.3
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
click@8.1.7
8.3.3
1
clsen2024/daejeon_2-3:latest1156cd87c8fb
click@8.1.7
8.3.3
1
clsen2024/gwangju_2-3:service-b-10ba9eff852c5
click@8.1.7
8.3.3
1
clsen2024/gwangju_2-3:service-a-151b1d45961cd
click@8.1.7
8.3.3
1
clsen2024/gwangju_2-3:service-c-1efb1586c8299
click@8.1.7
8.3.3
1
codecov/self-hosted-api:24.4.10475cb1c3136
click@8.0.4
8.3.3
1
codecov/self-hosted-worker:24.4.1837f546b479b
click@8.1.7
8.3.3
1
craigwillis/c2metadata-bd:latestae317d7e4724
click@7.1.2
8.3.3
1
cspconsole/report-collector:1.0.15839750248193b
click@8.3.1
8.3.3
1
dalibo/explain.dalibo.com:2.20.12a0b749c2f7f
click@8.3.1
8.3.3
1
danuk/telegram-sender:0.0.1026560388070
click@8.1.3
8.3.3
1
daskdev/dask:1.1.04ecd7bc35500
click@7.0
8.3.3
1
daskdev/dask-notebook:1.1.0052630f5ca04
click@7.0
8.3.3
1
datamate/seafile-professional:11.0.202dd66b722464
click@8.2.1
8.3.3
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
click@7.1.2
8.3.3
1
datawire/aes:1.13.62beb65062c8b
click@7.1.2
8.3.3
1
datawire/aes:3.11.195ec30b3c732
click@8.1.7
8.3.3
1
datawire/emissary:3.12.21f67a1292d2a
click@8.1.8
8.3.3
1
datawire/emissary:2.0.2-ea9716efbdd24b
click@7.1.2
8.3.3
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
click@8.1.7
8.3.3
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
click@8.1.7
8.3.3
1
ddosify/selfhosted_backend:3.2.93c11e3182652
click@8.1.7
8.3.3
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
click@8.1.7
8.3.3
1
ddosify/selfhosted_hammermanager:1.2.471b8768f49bc
click@8.1.7
8.3.3
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
click@8.1.7
8.3.3
1
deepflowce/deepflow-app:v6.2.6.5a1888d35e787
click@8.1.3
8.3.3
1
devopsgoofy/k8s-platform:latestad865312099f
click@8.1.7
8.3.3
1
devopstales/kubedash:3.1.08bb837da5aec
click@8.2.1
8.3.3
1
devopstales/kube-openid-connector:1.042c40a0e9f1b
click@8.0.4
8.3.3
1
devopstales/trivy-operator:2.575136aa7a26e
click@8.1.3
8.3.3
1
djjudas21/alertify:0.1.0ba22be670c37
click@8.2.1
8.3.3
1
djjudas21/ecowitt-exporter:2.2.073aab45ef10d
click@8.2.1
8.3.3
1
djjudas21/liturgical-colour-app:0.7.2954935971d42
click@8.2.1
8.3.3
1
douz/helpdesk:latest4384103d0219
click@8.1.3
8.3.3
1
dpage/pgadmin4:8.418cd5711fc9a
click@8.1.7
8.3.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.