StackRadar

CVE-2026-7246

High

Advisory

Published 30 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
576
of 17,781 indexed, latest versions
Container images
614
deployed by those charts
Fix available
2 of 3
affected packages

Security update for python-click

Carried by container images the latest versions of 576 of 17,781 indexed charts deploy, on 614 images.

Affected packageAffected versionsFixed inImages
clickpypi6.7, 7.0, 7.1.1, 7.1.2+16 more8.3.3614
python-clickdeb8.1.3-2no fix listed8
python-clickrpm8.2.1-160000.2.28.2.1-160000.3.11
OSV records
DEBIAN-CVE-2026-7246PYSEC-2026-2132SUSE-SU-2026:22321-1
Also known as
GHSA-47fr-3ffg-hgmw

Charts affected

576 by stars
ChartLatestAffected imagesRadar Score
timetaggerchristianhuthVerified publisher2.2.01 of 1See more

timetagger christianhuth 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
click@8.3.1
8.3.3

Open the chart page →

1,958
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
click@8.0.3
8.3.3

Open the chart page →

20,900
daskcloudnativeapp2.2.12 of 2See more

dask cloudnativeapp 2.2.1

2 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
daskdev/dask:1.1.04ecd7bc35500
click@7.0
8.3.3
daskdev/dask-notebook:1.1.0052630f5ca04
click@7.0
8.3.3

Open the chart page →

29,901
locustcloudnativeapp1.0.01 of 1See more

locust cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
greenbirdit/locust:0.9.0e99d53bdc944
click@7.0
8.3.3

Open the chart page →

1,352
supersetcloudnativeapp1.1.61 of 1See more

superset cloudnativeapp 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
amancevice/superset:0.28.1c8c04bfe3d66
click@6.7
8.3.3

Open the chart page →

5,060
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
click@8.1.6
8.3.3

Open the chart page →

25,151
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
robotshop/rs-payment:latest774b52c6180d
click@8.0.1
8.3.3

Open the chart page →

29,555
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
click@7.1.2
8.3.3

Open the chart page →

12,457
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
click@7.1.2
8.3.3

Open the chart page →

12,131
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
click@7.1.2
8.3.3

Open the chart page →

11,592
galaxykubemancloudve2.10.11 of 7See more

galaxykubeman cloudve 2.10.1

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
click@8.1.3
8.3.3

Open the chart page →

16,069
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
click@8.0.3
8.3.3

Open the chart page →

8,009
pbcore-utilcluster-deploy0.0.11 of 1See more

pbcore-util cluster-deploy 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
click@8.3.1
8.3.3

Open the chart page →

9,128
cobbler-tftpcobbler0.1.11 of 1See more

cobbler-tftp cobbler 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/cobbler/cobbler-tftp:v0.1.0a7fef3ca80baa4
click@8.2.1
python-click@8.2.1-160000.2.2
8.3.3
8.2.1-160000.3.1

Open the chart page →

304
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
kfserving/models-web-app:v0.6.1f322d6ffdfa3
click@8.0.1
8.3.3

Open the chart page →

3,830
wopiservercs3orgOfficialVerified publisher0.9.21 of 1See more

wopiserver cs3org 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cs3org/wopiserver:v9.4.202a9e78757b4
click@8.1.3
8.3.3

Open the chart page →

2,348
csghubcsghubVerified publisher2.4.33 of 34See more

csghub csghub 2.4.3

3 of the 34 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
click@8.2.1
8.3.3
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
click@8.3.1
8.3.3
opencsghq/label-studio:v2.4.0b4e849fcf94a
click@8.1.7
8.3.3

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opencsghq/csgship-agentic:v0.4.02cd29671a03e
click@8.2.1
8.3.3
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
click@8.2.1
8.3.3

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
click@8.1.7
8.3.3

Open the chart page →

6,632
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
click@8.1.3
8.3.3

Open the chart page →

13,852
cspconsolecspconsole1.3.111 of 5See more

cspconsole cspconsole 1.3.11

1 of the 5 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cspconsole/report-collector:1.0.15839750248193b
click@8.3.1
8.3.3

Open the chart page →

12,274
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
click@8.1.7
8.3.3

Open the chart page →

16,604
daejeon_2-3daejeon2-30.1.01 of 2See more

daejeon_2-3 daejeon2-3 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
clsen2024/daejeon_2-3:latest1156cd87c8fb
click@8.1.7
8.3.3

Open the chart page →

1,141
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
click@8.1.7
8.3.3

Open the chart page →

6,179
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
click@8.1.3
8.3.3

Open the chart page →

5,062
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
click@6.7
8.3.3

Open the chart page →

27,728
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
click@7.1.2
8.3.3

Open the chart page →

18,863
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
click@8.1.8
8.3.3

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
click@8.1.8
8.3.3

Open the chart page →

5,974
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
click@6.7
8.3.3

Open the chart page →

22,405
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
click@8.1.8
8.3.3

Open the chart page →

6,172
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
click@6.7
8.3.3

Open the chart page →

24,335
linkdingdeimosfr-charts1.0.31 of 1See more

linkding deimosfr-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.35.00c5dddf0b37c
click@8.1.7
8.3.3

Open the chart page →

6,075
mlflowdeliveryheroVerified publisher1.0.101 of 1See more

mlflow deliveryhero 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
click@7.1.2
8.3.3

Open the chart page →

4,422
prometheus-aws-costs-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-aws-costs-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
nachomillangarcia/prometheus_aws_cost_exporter:lateste4ce056f2d6d
click@6.7
8.3.3

Open the chart page →

3,553
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
click@8.2.1
8.3.3

Open the chart page →

2,305
deployhubdeployhubVerified publisher10.0.4157 of 11See more

deployhub deployhub 10.0.415

7 of the 11 container images this version deploys carry CVE-2026-7246.

Open the chart page →

11,160
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
click@8.1.3
8.3.3

Open the chart page →

14,856
design-cataloguedesign-catalogue0.1.01 of 2See more

design-catalogue design-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
click@7.1.2
8.3.3

Open the chart page →

2,770
kube-openid-connectdevopstalesVerified publisher1.1.01 of 1See more

kube-openid-connect devopstales 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
devopstales/kube-openid-connector:1.042c40a0e9f1b
click@8.0.4
8.3.3

Open the chart page →

1,333
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
click@8.1.7
8.3.3

Open the chart page →

9,607
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
click@8.1.7
8.3.3

Open the chart page →

9,607
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
click@8.1.8
8.3.3

Open the chart page →

19,224
alertifydjjudas21Verified publisher0.1.01 of 1See more

alertify djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
djjudas21/alertify:0.1.0ba22be670c37
click@8.2.1
8.3.3

Open the chart page →

2,378
ecowitt-exporterdjjudas21Verified publisher2.2.21 of 1See more

ecowitt-exporter djjudas21 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
djjudas21/ecowitt-exporter:2.2.073aab45ef10d
click@8.2.1
8.3.3

Open the chart page →

1,006
liturgical-colourdjjudas21Verified publisher99.99.991 of 1See more

liturgical-colour djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
djjudas21/liturgical-colour-app:0.7.2954935971d42
click@8.2.1
8.3.3

Open the chart page →

872
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
click@7.0
8.3.3

Open the chart page →

4,217
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
click@8.1.7
8.3.3

Open the chart page →

14,627
dominodomino-iisasVerified publisher0.3.11 of 3See more

domino domino-iisas 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/iisas/domino-rest:latest3009350bfc11
click@8.3.1
8.3.3

Open the chart page →

10,270
codecovdoubanVerified publisher0.2.43 of 8See more

codecov douban 0.2.4

3 of the 8 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
codecov/self-hosted-api:24.4.10475cb1c3136
click@8.0.4
8.3.3
codecov/self-hosted-worker:24.4.1837f546b479b
click@8.1.7
8.3.3
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
click@8.0.3
8.3.3

Open the chart page →

24,917

Container images carrying it

614 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
dpage/pgadmin4:7.537946e4f3e7b
click@8.1.4
8.3.3
1
dpage/pgadmin4:9.11.050700ac17936
click@8.3.1
8.3.3
1
dpage/pgadmin4:9.252cb72a9e3da
click@8.1.8
8.3.3
1
dpage/pgadmin4:8.13561c1f8f99f2
click@8.1.7
8.3.3
1
dpage/pgadmin4:4.5a5a656e1d5fd
click@7.0
8.3.3
1
dpage/pgadmin4:4.22b1f00b8163cf
click@7.1.2
8.3.3
1
drgrove/mtls-server:v0.14.2361721759a2b
click@7.0
8.3.3
1
dserio83/velero-api:0.3.16b3d9115fee2
click@8.1.8
8.3.3
1
dserio83/velero-watchdog:0.1.8d5deae589229
click@8.1.8
8.3.3
1
dysnix/pritunl:v1.29-r819951e3e7a32
click@7.1.2
8.3.3
1
eclipseaerios/aerios-k8s-shim:v1.0.0d4ed3d8e5db4
click@8.1.7
8.3.3
1
eclipseaerios/hlo-data-aggregator:v3.0.0b433c2b9f5dc
click@8.1.7
8.3.3
1
eclipseaerios/hlo-deployment-engine:v3.0.0d582d39208c7
click@8.1.7
8.3.3
1
eclipseaerios/hlo-fe-engine:v3.0.08ed2df4ca692
click@8.1.7
8.3.3
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
click@8.3.1
8.3.3
1
eclipseaerios/self-awareness-hardware-info:1.4.434b72f45b46a
click@8.3.1
8.3.3
1
eclipseaerios/self-awareness-power-consumption:1.3.3c8af377c709f
click@8.3.1
8.3.3
1
eclipseaerios/trust-manager:1.0.0f55442e2c0ed
click@8.1.8
8.3.3
1
elastichq/elasticsearch-hq:latestbb3bd22c2b87
click@7.0
8.3.3
1
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
click@8.2.1
8.3.3
1
errbotio/errbot:6.1.900ee4e0953ab
click@8.1.3
8.3.3
1
esphome/esphome:1.18.03f51ec10e823
click@7.1.2
8.3.3
1
esphome/esphome:2024.3.09ab8cc88b28c
click@8.1.7
8.3.3
1
esphome/esphome:2024.12.2b2c6322700ac
click@8.1.7
8.3.3
1
esphome/esphome:2025.3.0def8b6e4f517
click@8.1.7
8.3.3
1
evk02/mlflow:2.2.1ef6ff257ef35
click@8.1.3
8.3.3
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
click@8.1.3
8.3.3
1
fiware/bae-activation-service:v0.0.33e3ec88d59ed
click@7.1.2
8.3.3
1
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
click@8.1.3
8.3.3
1
flag5/clustersecret:0.0.94ad5748bfcc6
click@8.0.3
8.3.3
1
flyway/flyway:9.1545b5d7cdc75a
click@8.1.3
8.3.3
1
flyway/flyway:9.14.1-alpine80f12c80502b
click@8.1.3
8.3.3
1
forchaladtest/testwebapp:0.15909cf64ef53
click@7.1.2
8.3.3
1
fossology/fossology:4.2.18bd1f22ba7bb
click@8.1.3
8.3.3
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
click@8.0.4
8.3.3
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
click@8.0.4
8.3.3
1
freedom98/flask:k3.0d7ce1533f297
click@8.1.8
8.3.3
1
galaxy/cloudman-server:lateste5c265fe9fcd
click@8.1.3
8.3.3
1
geopython/pycsw:3.0.0-beta284662ea6b78b
click@8.3.1
8.3.3
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
click@7.1.2
8.3.3
1
gethue/hue:4.11.011b649636e68
click@8.1.3
8.3.3
1
gethue/hue:latest7d5c1b9f8a79
click@8.3.1
8.3.3
1
gmaas2/github-api:latest148fc2d9afe9
click@8.1.3
8.3.3
1
goofball222/pritunl:1.30.3070.5943c0743701d4
click@8.0.3
8.3.3
1
goofball222/pritunl:1.32.3602.807bf26032dfce
click@8.1.3
8.3.3
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
click@8.1.8
8.3.3
1
grafana/oncall:v1.16.5499851658393
click@8.2.1
8.3.3
1
greenbirdit/locust:0.9.0e99d53bdc944
click@7.0
8.3.3
1
halkeye/slack-resurrect:v0.1.477b05e95fdb5
click@7.0
8.3.3
1
hamidyousefi93/saam-test:latestc34f071f6ed0
click@8.1.7
8.3.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.