StackRadar

CVE-2026-7246

High

Advisory

Published 30 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
576
of 17,781 indexed, latest versions
Container images
614
deployed by those charts
Fix available
2 of 3
affected packages

Security update for python-click

Carried by container images the latest versions of 576 of 17,781 indexed charts deploy, on 614 images.

Affected packageAffected versionsFixed inImages
clickpypi6.7, 7.0, 7.1.1, 7.1.2+16 more8.3.3614
python-clickdeb8.1.3-2no fix listed8
python-clickrpm8.2.1-160000.2.28.2.1-160000.3.11
OSV records
DEBIAN-CVE-2026-7246PYSEC-2026-2132SUSE-SU-2026:22321-1
Also known as
GHSA-47fr-3ffg-hgmw

Charts affected

576 by stars
ChartLatestAffected imagesRadar Score
timetaggerchristianhuthVerified publisher2.2.01 of 1See more

timetagger christianhuth 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
click@8.3.1
8.3.3

Open the chart page →

1,958
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
click@8.0.3
8.3.3

Open the chart page →

20,900
daskcloudnativeapp2.2.12 of 2See more

dask cloudnativeapp 2.2.1

2 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
daskdev/dask:1.1.04ecd7bc35500
click@7.0
8.3.3
daskdev/dask-notebook:1.1.0052630f5ca04
click@7.0
8.3.3

Open the chart page →

29,901
locustcloudnativeapp1.0.01 of 1See more

locust cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
greenbirdit/locust:0.9.0e99d53bdc944
click@7.0
8.3.3

Open the chart page →

1,352
supersetcloudnativeapp1.1.61 of 1See more

superset cloudnativeapp 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
amancevice/superset:0.28.1c8c04bfe3d66
click@6.7
8.3.3

Open the chart page →

5,060
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
click@8.1.6
8.3.3

Open the chart page →

25,151
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
robotshop/rs-payment:latest774b52c6180d
click@8.0.1
8.3.3

Open the chart page →

29,555
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
click@7.1.2
8.3.3

Open the chart page →

12,457
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
click@7.1.2
8.3.3

Open the chart page →

12,131
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
click@7.1.2
8.3.3

Open the chart page →

11,592
galaxykubemancloudve2.10.11 of 7See more

galaxykubeman cloudve 2.10.1

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
click@8.1.3
8.3.3

Open the chart page →

16,069
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
click@8.0.3
8.3.3

Open the chart page →

8,009
pbcore-utilcluster-deploy0.0.11 of 1See more

pbcore-util cluster-deploy 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
click@8.3.1
8.3.3

Open the chart page →

9,128
cobbler-tftpcobbler0.1.11 of 1See more

cobbler-tftp cobbler 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/cobbler/cobbler-tftp:v0.1.0a7fef3ca80baa4
click@8.2.1
python-click@8.2.1-160000.2.2
8.3.3
8.2.1-160000.3.1

Open the chart page →

304
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
kfserving/models-web-app:v0.6.1f322d6ffdfa3
click@8.0.1
8.3.3

Open the chart page →

3,830
wopiservercs3orgOfficialVerified publisher0.9.21 of 1See more

wopiserver cs3org 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cs3org/wopiserver:v9.4.202a9e78757b4
click@8.1.3
8.3.3

Open the chart page →

2,348
csghubcsghubVerified publisher2.4.33 of 34See more

csghub csghub 2.4.3

3 of the 34 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
click@8.2.1
8.3.3
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
click@8.3.1
8.3.3
opencsghq/label-studio:v2.4.0b4e849fcf94a
click@8.1.7
8.3.3

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opencsghq/csgship-agentic:v0.4.02cd29671a03e
click@8.2.1
8.3.3
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
click@8.2.1
8.3.3

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
click@8.1.7
8.3.3

Open the chart page →

6,632
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
click@8.1.3
8.3.3

Open the chart page →

13,852
cspconsolecspconsole1.3.111 of 5See more

cspconsole cspconsole 1.3.11

1 of the 5 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cspconsole/report-collector:1.0.15839750248193b
click@8.3.1
8.3.3

Open the chart page →

12,274
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
click@8.1.7
8.3.3

Open the chart page →

16,604
daejeon_2-3daejeon2-30.1.01 of 2See more

daejeon_2-3 daejeon2-3 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
clsen2024/daejeon_2-3:latest1156cd87c8fb
click@8.1.7
8.3.3

Open the chart page →

1,141
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
click@8.1.7
8.3.3

Open the chart page →

6,179
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
click@8.1.3
8.3.3

Open the chart page →

5,062
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
click@6.7
8.3.3

Open the chart page →

27,728
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
click@7.1.2
8.3.3

Open the chart page →

18,863
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
click@8.1.8
8.3.3

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
click@8.1.8
8.3.3

Open the chart page →

5,974
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
click@6.7
8.3.3

Open the chart page →

22,405
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
click@8.1.8
8.3.3

Open the chart page →

6,172
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
click@6.7
8.3.3

Open the chart page →

24,335
linkdingdeimosfr-charts1.0.31 of 1See more

linkding deimosfr-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.35.00c5dddf0b37c
click@8.1.7
8.3.3

Open the chart page →

6,075
mlflowdeliveryheroVerified publisher1.0.101 of 1See more

mlflow deliveryhero 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
click@7.1.2
8.3.3

Open the chart page →

4,422
prometheus-aws-costs-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-aws-costs-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
nachomillangarcia/prometheus_aws_cost_exporter:lateste4ce056f2d6d
click@6.7
8.3.3

Open the chart page →

3,553
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
click@8.2.1
8.3.3

Open the chart page →

2,305
deployhubdeployhubVerified publisher10.0.4157 of 11See more

deployhub deployhub 10.0.415

7 of the 11 container images this version deploys carry CVE-2026-7246.

Open the chart page →

11,160
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
click@8.1.3
8.3.3

Open the chart page →

14,856
design-cataloguedesign-catalogue0.1.01 of 2See more

design-catalogue design-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
click@7.1.2
8.3.3

Open the chart page →

2,770
kube-openid-connectdevopstalesVerified publisher1.1.01 of 1See more

kube-openid-connect devopstales 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
devopstales/kube-openid-connector:1.042c40a0e9f1b
click@8.0.4
8.3.3

Open the chart page →

1,333
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
click@8.1.7
8.3.3

Open the chart page →

9,607
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
click@8.1.7
8.3.3

Open the chart page →

9,607
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
click@8.1.8
8.3.3

Open the chart page →

19,224
alertifydjjudas21Verified publisher0.1.01 of 1See more

alertify djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
djjudas21/alertify:0.1.0ba22be670c37
click@8.2.1
8.3.3

Open the chart page →

2,378
ecowitt-exporterdjjudas21Verified publisher2.2.21 of 1See more

ecowitt-exporter djjudas21 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
djjudas21/ecowitt-exporter:2.2.073aab45ef10d
click@8.2.1
8.3.3

Open the chart page →

1,006
liturgical-colourdjjudas21Verified publisher99.99.991 of 1See more

liturgical-colour djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
djjudas21/liturgical-colour-app:0.7.2954935971d42
click@8.2.1
8.3.3

Open the chart page →

872
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
click@7.0
8.3.3

Open the chart page →

4,217
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
click@8.1.7
8.3.3

Open the chart page →

14,627
dominodomino-iisasVerified publisher0.3.11 of 3See more

domino domino-iisas 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/iisas/domino-rest:latest3009350bfc11
click@8.3.1
8.3.3

Open the chart page →

10,270
codecovdoubanVerified publisher0.2.43 of 8See more

codecov douban 0.2.4

3 of the 8 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
codecov/self-hosted-api:24.4.10475cb1c3136
click@8.0.4
8.3.3
codecov/self-hosted-worker:24.4.1837f546b479b
click@8.1.7
8.3.3
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
click@8.0.3
8.3.3

Open the chart page →

24,917

Container images carrying it

614 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
mawad98/backstage-pyactions:demo99422c56a274
click@8.3.1
8.3.3
1
mher/flower:2.051c3c3db5be3
click@8.1.6
8.3.3
1
milesmcc/shynet:v0.13.1ba54f7797a6b
click@8.1.3
8.3.3
1
milesmcc/shynet:v0.12.0e821e31140f7
click@8.0.3
8.3.3
1
miltex/python-api:1.0.0dab12a7748d5
click@7.1.2
8.3.3
1
mindsdb/mindsdb:latest163011c09299
click@8.3.2
8.3.3
1
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
click@7.1.2
8.3.3
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
click@8.1.3
8.3.3
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
click@8.1.3
8.3.3
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
click@8.1.7
8.3.3
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
click@8.0.3
8.3.3
1
mshanley80/httpbin2022:latest5b189a70c0fb
click@8.1.3
8.3.3
1
muhammedgamal/fp23:latest74b4cd69b6fa
click@8.1.7
8.3.3
1
nabinchhetri/flask-app:v2.0be189fbf3411
click@8.1.3
8.3.3
1
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
click@8.1.7
8.3.3
1
neilpeterson/aks-helloworld:v1fb47732ef36b
click@6.7
8.3.3
1
neilpeterson/chart-tweet:latest64fd8dab075f
click@6.7
8.3.3
1
netboxcommunity/netbox:v3.2.83d652dca5351
click@8.1.3
8.3.3
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
click@8.1.7
8.3.3
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
click@8.3.2
8.3.3
1
neuvector/prometheus-exporter:1.0.181d78ed4eef40
click@8.1.7
8.3.3
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
click@7.1.2
8.3.3
1
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
click@8.1.3
8.3.3
1
octoprint/octoprint:1.4.0106c26efcd8a
click@7.1.2
8.3.3
1
octoprint/octoprint:1.6.1ea3bffae2470
click@7.1.2
8.3.3
1
oled01/automx2:2025.1.105d3e398e675
click@8.2.1
8.3.3
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
click@7.0
8.3.3
1
omkara25/simple-microservice-app-order-service:v2.18327546c7aac
click@8.2.1
8.3.3
1
omkara25/simple-microservice-app-payment-service:v2afff40172b6b
click@8.2.1
8.3.3
1
omkara25/simple-microservice-app-user-service:v2d62cba548580
click@8.2.1
8.3.3
1
opea/asr:1.025dd26d9cd09
click@8.1.7
8.3.3
1
opea/chatqna:1.038c51b791efa
click@8.1.7
8.3.3
1
opea/codegen:1.058f91683892d
click@8.1.7
8.3.3
1
opea/codetrans:1.0e2436483b73d
click@8.1.7
8.3.3
1
opea/docsum:1.03eaa91849512
click@8.1.7
8.3.3
1
opea/guardrails-tgi:1.0262c6048aab8
click@8.1.7
8.3.3
1
opea/guardrails-tgi:latestf68bec6a1271
click@8.1.8
8.3.3
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
click@8.1.7
8.3.3
1
opea/speecht5:1.0249afad3d268
click@8.1.7
8.3.3
1
opea/tts:1.0257ae94709e9
click@8.1.7
8.3.3
1
opea/web-retriever-chroma:1.0fe08165d7770
click@8.1.7
8.3.3
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
click@8.2.1
8.3.3
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
click@8.3.1
8.3.3
1
opencsghq/csgship-agentic:v0.4.02cd29671a03e
click@8.2.1
8.3.3
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
click@8.2.1
8.3.3
1
opencsghq/label-studio:v2.5.047e22aa71870
click@8.1.7
8.3.3
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
click@8.1.7
8.3.3
1
opendatacube/explorer:latest120457ffcd69
click@8.1.8
8.3.3
1
opendatacube/pipelines:wofs-1.225d810e8504b8
click@6.7
8.3.3
1
opendatacube/restcube:latest91870111837c
click@6.7
8.3.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.