StackRadar

CVE-2026-7246

High

Advisory

Published 30 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
576
of 17,781 indexed, latest versions
Container images
614
deployed by those charts
Fix available
2 of 3
affected packages

Security update for python-click

Carried by container images the latest versions of 576 of 17,781 indexed charts deploy, on 614 images.

Affected packageAffected versionsFixed inImages
clickpypi6.7, 7.0, 7.1.1, 7.1.2+16 more8.3.3614
python-clickdeb8.1.3-2no fix listed8
python-clickrpm8.2.1-160000.2.28.2.1-160000.3.11
OSV records
DEBIAN-CVE-2026-7246PYSEC-2026-2132SUSE-SU-2026:22321-1
Also known as
GHSA-47fr-3ffg-hgmw

Charts affected

576 by stars
ChartLatestAffected imagesRadar Score
helpdeskdoubanVerified publisher0.3.31 of 2See more

helpdesk douban 0.3.3

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
douz/helpdesk:latest4384103d0219
click@8.1.3
8.3.3

Open the chart page →

4,550
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
click@8.0.3
8.3.3

Open the chart page →

30,699
rook-cephdtrdnk-helm-chartsVerified publisher0.0.11 of 2See more

rook-ceph dtrdnk-helm-charts 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
rook/ceph:v1.19.2944a1dd70496
click@8.0.3
8.3.3

Open the chart page →

1,990
temporaldtrdnk-helm-chartsVerified publisher0.35.01 of 13See more

temporal dtrdnk-helm-charts 0.35.0

1 of the 13 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.4258958fe2ff2
click@8.1.7
8.3.3

Open the chart page →

20,205
amundsenduyet1.1.03 of 7See more

amundsen duyet 1.1.0

3 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
click@7.1.1
8.3.3
amundsendev/amundsen-metadata:2.5.44d98eb21f5f9
click@6.7
8.3.3
amundsendev/amundsen-search:2.4.099dda9502c3e
click@6.7
8.3.3

Open the chart page →

11,174
pritunldysnixVerified publisher0.2.71 of 3See more

pritunl dysnix 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
dysnix/pritunl:v1.29-r819951e3e7a32
click@7.1.2
8.3.3

Open the chart page →

5,055
aerios-k8s-shimeclipse-aeriosVerified publisher1.0.01 of 1See more

aerios-k8s-shim eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/aerios-k8s-shim:v1.0.0d4ed3d8e5db4
click@8.1.7
8.3.3

Open the chart page →

1,434
hlo-data-aggregatoreclipse-aeriosVerified publisher3.0.01 of 1See more

hlo-data-aggregator eclipse-aerios 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/hlo-data-aggregator:v3.0.0b433c2b9f5dc
click@8.1.7
8.3.3

Open the chart page →

1,643
hlo-deployment-engineeclipse-aeriosVerified publisher3.0.01 of 1See more

hlo-deployment-engine eclipse-aerios 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/hlo-deployment-engine:v3.0.0d582d39208c7
click@8.1.7
8.3.3

Open the chart page →

1,653
hlo-fe-engineeclipse-aeriosVerified publisher3.0.01 of 1See more

hlo-fe-engine eclipse-aerios 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/hlo-fe-engine:v3.0.08ed2df4ca692
click@8.1.7
8.3.3

Open the chart page →

1,643
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
click@8.3.1
8.3.3

Open the chart page →

13,391
self-awarenesseclipse-aeriosVerified publisher1.4.42 of 2See more

self-awareness eclipse-aerios 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/self-awareness-hardware-info:1.4.434b72f45b46a
click@8.3.1
8.3.3
eclipseaerios/self-awareness-power-consumption:1.3.3c8af377c709f
click@8.3.1
8.3.3

Open the chart page →

2,219
trustmanagereclipse-aeriosVerified publisher1.0.01 of 1See more

trustmanager eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
eclipseaerios/trust-manager:1.0.0f55442e2c0ed
click@8.1.8
8.3.3

Open the chart page →

1,895
home-assistantegebackVerified publisher2.0.351 of 1See more

home-assistant egeback 2.0.35

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
click@8.1.8
8.3.3

Open the chart page →

2,158
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
click@8.1.3
python-click@8.1.3-2
8.3.3
no fix listed

Open the chart page →

30,159
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
click@8.1.3
8.3.3

Open the chart page →

25,122
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
click@8.1.3
8.3.3

Open the chart page →

9,334
rommernail-romm1.0.11 of 1See more

romm ernail-romm 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
rommapp/romm:4.4.1b909e95d1aab
click@8.2.1
8.3.3

Open the chart page →

2,896
extended-ceph-exporterextended-ceph-exporterVerified publisher1.10.01 of 2See more

extended-ceph-exporter extended-ceph-exporter 1.10.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
quay.io/ceph/ceph:v21.1.05ff3692d2f3f
click@8.1.7
8.3.3

Open the chart page →

2,885
external-secrets-reloaderexternal-secrets-reloader0.1.01 of 1See more

external-secrets-reloader external-secrets-reloader 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/bensoer/external-secrets-reloader:v0.1.38e31b5a81853
click@8.3.1
8.3.3

Open the chart page →

1,030
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
click@8.1.3
8.3.3

Open the chart page →

4,085
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
stratospire/activityrelay:0.2.3a4c34cb01117
click@8.1.3
8.3.3

Open the chart page →

13,450
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.418cd5711fc9a
click@8.1.7
8.3.3

Open the chart page →

12,454
kodiakfikaworks1.1.41 of 2See more

kodiak fikaworks 1.1.4

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cdignam/kodiak:v0.54.05a6a55b39cee
click@8.0.1
8.3.3

Open the chart page →

3,892
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-product-service:1.0c49ff7c141c0
click@8.1.8
8.3.3

Open the chart page →

7,691
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
click@8.1.7
8.3.3

Open the chart page →

5,704
bae-activation-servicefiware0.1.21 of 1See more

bae-activation-service fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
fiware/bae-activation-service:v0.0.33e3ec88d59ed
click@7.1.2
8.3.3

Open the chart page →

3,186
ishare-satellitefiware1.3.21 of 1See more

ishare-satellite fiware 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
click@8.1.3
8.3.3

Open the chart page →

1,778
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
click@8.1.7
8.3.3

Open the chart page →

5,704
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
click@8.1.8
8.3.3

Open the chart page →

4,073
flaskappflaskwebapp0.1.01 of 1See more

flaskapp flaskwebapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
nabinchhetri/flask-app:v2.0be189fbf3411
click@8.1.3
8.3.3

Open the chart page →

512
kube-ops-viewfluent-operatorVerified publisher0.1.21 of 1See more

kube-ops-view fluent-operator 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:20.4.058221b57d4d2
click@7.1.1
8.3.3

Open the chart page →

1,848
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
louislam/uptime-kuma:13d632903e6af
click@7.0
8.3.3

Open the chart page →

3,474
forms-catalogueforms-catalogue0.1.01 of 2See more

forms-catalogue forms-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
click@7.1.2
8.3.3

Open the chart page →

2,188
powerdnsfsdrw080.1.31 of 4See more

powerdns fsdrw08 0.1.3

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
click@8.1.3
8.3.3

Open the chart page →

1,958
borgmaticgabe565Verified publisher0.10.11 of 1See more

borgmatic gabe565 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
click@8.1.8
8.3.3

Open the chart page →

2,438
spectergaloymoney0.3.11 of 1See more

specter galoymoney 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
lncm/specter-desktop:v1.10.536eaa06f99f4
click@8.1.1
8.3.3

Open the chart page →

1,691
spectergaloymoney20.3.11 of 1See more

specter galoymoney2 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
lncm/specter-desktop:v1.10.536eaa06f99f4
click@8.1.1
8.3.3

Open the chart page →

1,691
beetsgeek-cookbookVerified publisher1.4.21 of 1See more

beets geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
linuxserver/beets:1.5.0e36d16f7341c
click@8.0.3
8.3.3

Open the chart page →

1,150
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
click@7.1.2
8.3.3

Open the chart page →

16,123
changedetection-iogeek-cookbookVerified publisher1.5.21 of 1See more

changedetection-io geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
click@7.1.2
8.3.3

Open the chart page →

1,950
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
click@6.7
8.3.3

Open the chart page →

13,551
ihatemoneygeek-cookbookVerified publisher1.1.21 of 1See more

ihatemoney geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ihatemoney/ihatemoney:5.2.0457fda1feb32
click@8.1.2
8.3.3

Open the chart page →

1,526
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
click@8.1.3
8.3.3

Open the chart page →

12,076
powerdns-admingeek-cookbookVerified publisher1.2.21 of 1See more

powerdns-admin geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
click@8.0.3
8.3.3

Open the chart page →

2,643
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
click@8.0.1
8.3.3

Open the chart page →

24,293
searxgeek-cookbookVerified publisher5.6.21 of 4See more

searx geek-cookbook 5.6.2

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
searx/searx:1.0.0-211-968b28993dbb3a6d9419
click@8.0.1
8.3.3

Open the chart page →

7,470
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
click@8.1.8
8.3.3

Open the chart page →

8,923
speedtest-exportergeek-cookbookVerified publisher5.4.21 of 1See more

speedtest-exporter geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.2.29e36964bce26
click@8.0.1
8.3.3

Open the chart page →

1,772
whooglegeek-cookbookVerified publisher3.4.21 of 1See more

whoogle geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
benbusby/whoogle-search:0.5.4f77f7e6e4ad2
click@7.0
8.3.3

Open the chart page →

2,061

Container images carrying it

614 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
kubeflownotebookswg/jupyter-web-app:v1.9.2afb52057c997
click@8.1.7
8.3.3
1
kubeflownotebookswg/jupyter-web-app:v1.6.1d762690e21c1
click@8.1.3
8.3.3
1
kubeflownotebookswg/tensorboards-web-app:v1.6.10876fef1973b
click@8.1.3
8.3.3
1
kubeflownotebookswg/tensorboards-web-app:v1.9.277f07f52a84a
click@8.1.7
8.3.3
1
kubeflownotebookswg/volumes-web-app:v1.6.17299fa94db15
click@8.1.3
8.3.3
1
kubeflownotebookswg/volumes-web-app:v1.9.2f63c3e550af3
click@8.1.7
8.3.3
1
kubesphere/examples-bookinfo-productpage-v1:1.13.0378f49ec9c44
click@6.7
8.3.3
1
kunchalavikram/connectedcity:v14a559a47579e
click@7.1.2
8.3.3
1
kunchalavikram/connectedfactory:v152c13fb9b1d9
click@7.1.2
8.3.3
1
kyovint/kyoimgtransactions:1.0.048c19e3ae9a3
click@8.2.1
8.3.3
1
kyovint/kyoimgusers:1.0.080084149156e
click@8.2.1
8.3.3
1
kyso/kyso-nbdime:latest4aa9d38ee81d
click@8.1.3
8.3.3
1
langgenius/dify-api:1.0.0066035f93856
click@8.1.8
8.3.3
1
langgenius/dify-api:0.6.11fca918260dd6
click@8.1.7
8.3.3
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
click@8.3.1
8.3.3
1
linuxserver/beets:1.5.0e36d16f7341c
click@8.0.3
8.3.3
1
linuxserver/calibre-web:0.6.24241009026e6f
click@8.2.1
8.3.3
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
click@7.1.2
8.3.3
1
linuxserver/deluge:18.04.10ac871624394
click@6.7
8.3.3
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
click@6.7
8.3.3
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
click@8.1.3
8.3.3
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
click@8.0.1
8.3.3
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
click@7.1.2
8.3.3
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
click@8.1.7
8.3.3
1
lmacka/snappass:2.1.293f5c048b7d4
click@8.3.1
8.3.3
1
lnbitsdocker/lnbits-legend:latest26fae6327477
click@8.1.7
8.3.3
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
click@8.0.4
8.3.3
1
lncm/specter-desktop:v0.10.4bca14d04397d
click@7.1.2
8.3.3
1
localstack/localstack:3.19d278167f2b7
click@8.1.7
8.3.3
1
locustio/locust:2.24.151d866285170
click@8.1.7
8.3.3
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
click@8.1.3
python-click@8.1.3-2
8.3.3
no fix listed
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
click@7.0
8.3.3
1
louislam/uptime-kuma:13d632903e6af
click@7.0
8.3.3
1
louislam/uptime-kuma:2.5.33e24e96c89ef
click@8.1.3
python-click@8.1.3-2
8.3.3
no fix listed
1
louislam/uptime-kuma:2.0.24c364ef96aad
click@8.1.3
python-click@8.1.3-2
8.3.3
no fix listed
1
louislam/uptime-kuma:2.4.091e963bfda56
click@8.1.3
python-click@8.1.3-2
8.3.3
no fix listed
1
louislam/uptime-kuma:1.23.1396510915e6be
click@7.0
8.3.3
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
click@8.1.3
python-click@8.1.3-2
8.3.3
no fix listed
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
click@7.0
8.3.3
1
louislam/uptime-kuma:1.18.5a84767d7934f
click@7.0
8.3.3
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
click@7.0
8.3.3
1
lsstsqre/exposurelog:0.8.079b00fb67a65
click@8.0.3
8.3.3
1
lsstsqre/kafkaaggregator:masterbe1b21060854
click@7.1.2
8.3.3
1
lsstsqre/kafkaconnect:0.9.34143c7cd705e
click@8.0.3
8.3.3
1
lsstsqre/squash-api:0.5.34879415ec6ac
click@7.1.2
8.3.3
1
lsstsqre/strimzi-registry-operator:0.4.1e139fde946d7
click@8.0.3
8.3.3
1
makersquad/harp-proxy:0.8.1a40dd258c527
click@8.1.8
8.3.3
1
maponyacharles/sceptreai:api-0.1.127b37b092130a
click@8.2.1
8.3.3
1
marcinkujawski/flask-app:2.0.1a455017b9d0e
click@8.0.4
8.3.3
1
marcoimme/oidcmock:latestb6035c0721a8
click@8.3.1
8.3.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.