StackRadar

CVE-2026-7246

High

Advisory

Published 30 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
576
of 17,781 indexed, latest versions
Container images
614
deployed by those charts
Fix available
2 of 3
affected packages

Security update for python-click

Carried by container images the latest versions of 576 of 17,781 indexed charts deploy, on 614 images.

Affected packageAffected versionsFixed inImages
clickpypi6.7, 7.0, 7.1.1, 7.1.2+16 more8.3.3614
python-clickdeb8.1.3-2no fix listed8
python-clickrpm8.2.1-160000.2.28.2.1-160000.3.11
OSV records
DEBIAN-CVE-2026-7246PYSEC-2026-2132SUSE-SU-2026:22321-1
Also known as
GHSA-47fr-3ffg-hgmw

Charts affected

576 by stars
ChartLatestAffected imagesRadar Score
helpdeskdoubanVerified publisher0.3.31 of 2See more

helpdesk douban 0.3.3

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
douz/helpdesk:latest4384103d0219
click@8.1.3
8.3.3

Open the chart page →

4,550
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
click@8.0.3
8.3.3

Open the chart page →

30,699
rook-cephdtrdnk-helm-chartsVerified publisher0.0.11 of 2See more

rook-ceph dtrdnk-helm-charts 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
rook/ceph:v1.19.2944a1dd70496
click@8.0.3
8.3.3

Open the chart page →

1,990
temporaldtrdnk-helm-chartsVerified publisher0.35.01 of 13See more

temporal dtrdnk-helm-charts 0.35.0

1 of the 13 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.4258958fe2ff2
click@8.1.7
8.3.3

Open the chart page →

20,205
amundsenduyet1.1.03 of 7See more

amundsen duyet 1.1.0

3 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
click@7.1.1
8.3.3
amundsendev/amundsen-metadata:2.5.44d98eb21f5f9
click@6.7
8.3.3
amundsendev/amundsen-search:2.4.099dda9502c3e
click@6.7
8.3.3

Open the chart page →

11,174
pritunldysnixVerified publisher0.2.71 of 3See more

pritunl dysnix 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
dysnix/pritunl:v1.29-r819951e3e7a32
click@7.1.2
8.3.3

Open the chart page →

5,055
aerios-k8s-shimeclipse-aeriosVerified publisher1.0.01 of 1See more

aerios-k8s-shim eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/aerios-k8s-shim:v1.0.0d4ed3d8e5db4
click@8.1.7
8.3.3

Open the chart page →

1,434
hlo-data-aggregatoreclipse-aeriosVerified publisher3.0.01 of 1See more

hlo-data-aggregator eclipse-aerios 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/hlo-data-aggregator:v3.0.0b433c2b9f5dc
click@8.1.7
8.3.3

Open the chart page →

1,643
hlo-deployment-engineeclipse-aeriosVerified publisher3.0.01 of 1See more

hlo-deployment-engine eclipse-aerios 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/hlo-deployment-engine:v3.0.0d582d39208c7
click@8.1.7
8.3.3

Open the chart page →

1,653
hlo-fe-engineeclipse-aeriosVerified publisher3.0.01 of 1See more

hlo-fe-engine eclipse-aerios 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/hlo-fe-engine:v3.0.08ed2df4ca692
click@8.1.7
8.3.3

Open the chart page →

1,643
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
click@8.3.1
8.3.3

Open the chart page →

13,391
self-awarenesseclipse-aeriosVerified publisher1.4.42 of 2See more

self-awareness eclipse-aerios 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/self-awareness-hardware-info:1.4.434b72f45b46a
click@8.3.1
8.3.3
eclipseaerios/self-awareness-power-consumption:1.3.3c8af377c709f
click@8.3.1
8.3.3

Open the chart page →

2,219
trustmanagereclipse-aeriosVerified publisher1.0.01 of 1See more

trustmanager eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/trust-manager:1.0.0f55442e2c0ed
click@8.1.8
8.3.3

Open the chart page →

1,895
home-assistantegebackVerified publisher2.0.351 of 1See more

home-assistant egeback 2.0.35

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
click@8.1.8
8.3.3

Open the chart page →

2,158
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
click@8.1.3
python-click@8.1.3-2
8.3.3
no fix listed

Open the chart page →

30,159
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
click@8.1.3
8.3.3

Open the chart page →

25,122
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
click@8.1.3
8.3.3

Open the chart page →

9,334
rommernail-romm1.0.11 of 1See more

romm ernail-romm 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
rommapp/romm:4.4.1b909e95d1aab
click@8.2.1
8.3.3

Open the chart page →

2,896
extended-ceph-exporterextended-ceph-exporterVerified publisher1.10.01 of 2See more

extended-ceph-exporter extended-ceph-exporter 1.10.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
quay.io/ceph/ceph:v21.1.05ff3692d2f3f
click@8.1.7
8.3.3

Open the chart page →

2,885
external-secrets-reloaderexternal-secrets-reloader0.1.01 of 1See more

external-secrets-reloader external-secrets-reloader 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/bensoer/external-secrets-reloader:v0.1.38e31b5a81853
click@8.3.1
8.3.3

Open the chart page →

1,030
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
click@8.1.3
8.3.3

Open the chart page →

4,085
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
stratospire/activityrelay:0.2.3a4c34cb01117
click@8.1.3
8.3.3

Open the chart page →

13,450
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.418cd5711fc9a
click@8.1.7
8.3.3

Open the chart page →

12,454
kodiakfikaworks1.1.41 of 2See more

kodiak fikaworks 1.1.4

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cdignam/kodiak:v0.54.05a6a55b39cee
click@8.0.1
8.3.3

Open the chart page →

3,892
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-product-service:1.0c49ff7c141c0
click@8.1.8
8.3.3

Open the chart page →

7,691
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
click@8.1.7
8.3.3

Open the chart page →

5,704
bae-activation-servicefiware0.1.21 of 1See more

bae-activation-service fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
fiware/bae-activation-service:v0.0.33e3ec88d59ed
click@7.1.2
8.3.3

Open the chart page →

3,186
ishare-satellitefiware1.3.21 of 1See more

ishare-satellite fiware 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
click@8.1.3
8.3.3

Open the chart page →

1,778
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
click@8.1.7
8.3.3

Open the chart page →

5,704
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
click@8.1.8
8.3.3

Open the chart page →

4,073
flaskappflaskwebapp0.1.01 of 1See more

flaskapp flaskwebapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
nabinchhetri/flask-app:v2.0be189fbf3411
click@8.1.3
8.3.3

Open the chart page →

512
kube-ops-viewfluent-operatorVerified publisher0.1.21 of 1See more

kube-ops-view fluent-operator 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:20.4.058221b57d4d2
click@7.1.1
8.3.3

Open the chart page →

1,848
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
louislam/uptime-kuma:13d632903e6af
click@7.0
8.3.3

Open the chart page →

3,474
forms-catalogueforms-catalogue0.1.01 of 2See more

forms-catalogue forms-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
click@7.1.2
8.3.3

Open the chart page →

2,188
powerdnsfsdrw080.1.31 of 4See more

powerdns fsdrw08 0.1.3

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
click@8.1.3
8.3.3

Open the chart page →

1,958
borgmaticgabe565Verified publisher0.10.11 of 1See more

borgmatic gabe565 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
click@8.1.8
8.3.3

Open the chart page →

2,438
spectergaloymoney0.3.11 of 1See more

specter galoymoney 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
lncm/specter-desktop:v1.10.536eaa06f99f4
click@8.1.1
8.3.3

Open the chart page →

1,691
spectergaloymoney20.3.11 of 1See more

specter galoymoney2 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
lncm/specter-desktop:v1.10.536eaa06f99f4
click@8.1.1
8.3.3

Open the chart page →

1,691
beetsgeek-cookbookVerified publisher1.4.21 of 1See more

beets geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
linuxserver/beets:1.5.0e36d16f7341c
click@8.0.3
8.3.3

Open the chart page →

1,150
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
click@7.1.2
8.3.3

Open the chart page →

16,123
changedetection-iogeek-cookbookVerified publisher1.5.21 of 1See more

changedetection-io geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
click@7.1.2
8.3.3

Open the chart page →

1,950
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
click@6.7
8.3.3

Open the chart page →

13,551
ihatemoneygeek-cookbookVerified publisher1.1.21 of 1See more

ihatemoney geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ihatemoney/ihatemoney:5.2.0457fda1feb32
click@8.1.2
8.3.3

Open the chart page →

1,526
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
click@8.1.3
8.3.3

Open the chart page →

12,076
powerdns-admingeek-cookbookVerified publisher1.2.21 of 1See more

powerdns-admin geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
click@8.0.3
8.3.3

Open the chart page →

2,643
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
click@8.0.1
8.3.3

Open the chart page →

24,293
searxgeek-cookbookVerified publisher5.6.21 of 4See more

searx geek-cookbook 5.6.2

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
searx/searx:1.0.0-211-968b28993dbb3a6d9419
click@8.0.1
8.3.3

Open the chart page →

7,470
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
click@8.1.8
8.3.3

Open the chart page →

8,923
speedtest-exportergeek-cookbookVerified publisher5.4.21 of 1See more

speedtest-exporter geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.2.29e36964bce26
click@8.0.1
8.3.3

Open the chart page →

1,772
whooglegeek-cookbookVerified publisher3.4.21 of 1See more

whoogle geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
benbusby/whoogle-search:0.5.4f77f7e6e4ad2
click@7.0
8.3.3

Open the chart page →

2,061

Container images carrying it

614 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
dpage/pgadmin4:7.537946e4f3e7b
click@8.1.4
8.3.3
1
dpage/pgadmin4:9.11.050700ac17936
click@8.3.1
8.3.3
1
dpage/pgadmin4:9.252cb72a9e3da
click@8.1.8
8.3.3
1
dpage/pgadmin4:8.13561c1f8f99f2
click@8.1.7
8.3.3
1
dpage/pgadmin4:4.5a5a656e1d5fd
click@7.0
8.3.3
1
dpage/pgadmin4:4.22b1f00b8163cf
click@7.1.2
8.3.3
1
drgrove/mtls-server:v0.14.2361721759a2b
click@7.0
8.3.3
1
dserio83/velero-api:0.3.16b3d9115fee2
click@8.1.8
8.3.3
1
dserio83/velero-watchdog:0.1.8d5deae589229
click@8.1.8
8.3.3
1
dysnix/pritunl:v1.29-r819951e3e7a32
click@7.1.2
8.3.3
1
eclipseaerios/aerios-k8s-shim:v1.0.0d4ed3d8e5db4
click@8.1.7
8.3.3
1
eclipseaerios/hlo-data-aggregator:v3.0.0b433c2b9f5dc
click@8.1.7
8.3.3
1
eclipseaerios/hlo-deployment-engine:v3.0.0d582d39208c7
click@8.1.7
8.3.3
1
eclipseaerios/hlo-fe-engine:v3.0.08ed2df4ca692
click@8.1.7
8.3.3
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
click@8.3.1
8.3.3
1
eclipseaerios/self-awareness-hardware-info:1.4.434b72f45b46a
click@8.3.1
8.3.3
1
eclipseaerios/self-awareness-power-consumption:1.3.3c8af377c709f
click@8.3.1
8.3.3
1
eclipseaerios/trust-manager:1.0.0f55442e2c0ed
click@8.1.8
8.3.3
1
elastichq/elasticsearch-hq:latestbb3bd22c2b87
click@7.0
8.3.3
1
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
click@8.2.1
8.3.3
1
errbotio/errbot:6.1.900ee4e0953ab
click@8.1.3
8.3.3
1
esphome/esphome:1.18.03f51ec10e823
click@7.1.2
8.3.3
1
esphome/esphome:2024.3.09ab8cc88b28c
click@8.1.7
8.3.3
1
esphome/esphome:2024.12.2b2c6322700ac
click@8.1.7
8.3.3
1
esphome/esphome:2025.3.0def8b6e4f517
click@8.1.7
8.3.3
1
evk02/mlflow:2.2.1ef6ff257ef35
click@8.1.3
8.3.3
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
click@8.1.3
8.3.3
1
fiware/bae-activation-service:v0.0.33e3ec88d59ed
click@7.1.2
8.3.3
1
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
click@8.1.3
8.3.3
1
flag5/clustersecret:0.0.94ad5748bfcc6
click@8.0.3
8.3.3
1
flyway/flyway:9.1545b5d7cdc75a
click@8.1.3
8.3.3
1
flyway/flyway:9.14.1-alpine80f12c80502b
click@8.1.3
8.3.3
1
forchaladtest/testwebapp:0.15909cf64ef53
click@7.1.2
8.3.3
1
fossology/fossology:4.2.18bd1f22ba7bb
click@8.1.3
8.3.3
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
click@8.0.4
8.3.3
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
click@8.0.4
8.3.3
1
freedom98/flask:k3.0d7ce1533f297
click@8.1.8
8.3.3
1
galaxy/cloudman-server:lateste5c265fe9fcd
click@8.1.3
8.3.3
1
geopython/pycsw:3.0.0-beta284662ea6b78b
click@8.3.1
8.3.3
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
click@7.1.2
8.3.3
1
gethue/hue:4.11.011b649636e68
click@8.1.3
8.3.3
1
gethue/hue:latest7d5c1b9f8a79
click@8.3.1
8.3.3
1
gmaas2/github-api:latest148fc2d9afe9
click@8.1.3
8.3.3
1
goofball222/pritunl:1.30.3070.5943c0743701d4
click@8.0.3
8.3.3
1
goofball222/pritunl:1.32.3602.807bf26032dfce
click@8.1.3
8.3.3
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
click@8.1.8
8.3.3
1
grafana/oncall:v1.16.5499851658393
click@8.2.1
8.3.3
1
greenbirdit/locust:0.9.0e99d53bdc944
click@7.0
8.3.3
1
halkeye/slack-resurrect:v0.1.477b05e95fdb5
click@7.0
8.3.3
1
hamidyousefi93/saam-test:latestc34f071f6ed0
click@8.1.7
8.3.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.