StackRadar

CVE-2026-7246

High

Advisory

Published 30 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
576
of 17,781 indexed, latest versions
Container images
614
deployed by those charts
Fix available
2 of 3
affected packages

Security update for python-click

Carried by container images the latest versions of 576 of 17,781 indexed charts deploy, on 614 images.

Affected packageAffected versionsFixed inImages
clickpypi6.7, 7.0, 7.1.1, 7.1.2+16 more8.3.3614
python-clickdeb8.1.3-2no fix listed8
python-clickrpm8.2.1-160000.2.28.2.1-160000.3.11
OSV records
DEBIAN-CVE-2026-7246PYSEC-2026-2132SUSE-SU-2026:22321-1
Also known as
GHSA-47fr-3ffg-hgmw

Charts affected

576 by stars
ChartLatestAffected imagesRadar Score
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
click@8.3.1
8.3.3

Open the chart page →

12,397
backendikusi-bk-chart1.0.32 of 3See more

backend ikusi-bk-chart 1.0.3

2 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
kyovint/kyoimgtransactions:1.0.048c19e3ae9a3
click@8.2.1
8.3.3
kyovint/kyoimgusers:1.0.080084149156e
click@8.2.1
8.3.3

Open the chart page →

5,940
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
click@8.1.7
8.3.3

Open the chart page →

15,712
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
click@8.0.4
8.3.3

Open the chart page →

7,129
iris-webappiris-webapp0.2.41 of 2See more

iris-webapp iris-webapp 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
click@8.1.8
8.3.3

Open the chart page →

11,764
jessejesse-chartVerified publisher0.0.461 of 6See more

jesse jesse-chart 0.0.46

1 of the 6 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
salehmir/jesse:1.10.101afa95f979e9
click@8.0.4
8.3.3

Open the chart page →

3,421
alertmanager-gchat-integrationjulb-meVerified publisher1.0.51 of 1See more

alertmanager-gchat-integration julb-me 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
julb/alertmanager-gchat-integration:1.0.5837c4038a0dd
click@7.1.2
8.3.3

Open the chart page →

2,110
jupyterhub-outpostjupyter-jscVerified publisher2.4.11 of 1See more

jupyterhub-outpost jupyter-jsc 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
jupyterjsc/jupyterhub-outpost:2.3.1aea53b13f235
click@8.3.2
8.3.3

Open the chart page →

1,678
kronickronic0.1.71 of 1See more

kronic kronic 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/mshade/kronic:v0.1.466e3043851cd
click@8.1.7
8.3.3

Open the chart page →

1,062
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
click@8.1.7
8.3.3

Open the chart page →

20,403
kubeseal-webguikubeseal-webgui6.0.41 of 2See more

kubeseal-webgui kubeseal-webgui 6.0.4

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/jaydee94/kubeseal-webgui/api:4.5.33cceb9462ae1
click@8.2.1
8.3.3

Open the chart page →

4,095
neuvectorlifen1.5.21 of 3See more

neuvector lifen 1.5.2

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
neuvector/manager:3.2.1f1b7d666eae0
click@6.7
8.3.3

Open the chart page →

2,747
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
click@8.1.7
8.3.3

Open the chart page →

4,292
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
click@8.3.1
8.3.3

Open the chart page →

7,201
locustlocustVerified publisher0.1.41 of 1See more

locust locust 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
hansehe/locust:1.1.0bc8e45262bc4
click@8.1.8
8.3.3

Open the chart page →

2,757
flask-appmarcinkujawski1.0.01 of 3See more

flask-app marcinkujawski 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
marcinkujawski/flask-app:2.0.1a455017b9d0e
click@8.0.4
8.3.3

Open the chart page →

2,912
mlflow-controllermlflow-deployment-controller0.1.82 of 2See more

mlflow-controller mlflow-deployment-controller 0.1.8

2 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
click@8.1.3
8.3.3
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
click@8.1.3
8.3.3

Open the chart page →

8,957
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
buntha/mlflow:2.1.1154542cc3083
click@8.1.3
8.3.3

Open the chart page →

5,804
clowder2ncsaVerified publisher1.9.73 of 12See more

clowder2 ncsa 1.9.7

3 of the 12 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
click@8.1.7
8.3.3
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
click@8.1.7
8.3.3
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
click@8.1.7
8.3.3

Open the chart page →

37,373
monitorneuvectorchartsVerified publisher2.11.11 of 1See more

monitor neuvectorcharts 2.11.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
neuvector/prometheus-exporter:1.0.181d78ed4eef40
click@8.1.7
8.3.3

Open the chart page →

203
opencveopencve1.2.01 of 3See more

opencve opencve 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cleveritcz/opencve:1.5.0c75c1636e0b7
click@7.1.2
8.3.3

Open the chart page →

2,097
open-notificatiesopen-zaak0.7.01 of 4See more

open-notificaties open-zaak 0.7.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
openzaak/open-notificaties:1.3.02e65313b9b10
click@8.0.4
8.3.3

Open the chart page →

2,850
opikopikOfficialVerified publisher2.2.591 of 13See more

opik opik 2.2.59

1 of the 13 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/comet-ml/opik/opik-python-backend:2.2.59269d0e55ea97
click@8.3.1
8.3.3

Open the chart page →

14,334
opta-agentopta-agentVerified publisher0.1.31 of 1See more

opta-agent opta-agent 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
runx1/opta-agent:latest0ca3867d3200
click@8.1.2
8.3.3

Open the chart page →

1,543
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
click@8.1.3
python-click@8.1.3-2
8.3.3
no fix listed

Open the chart page →

6,883
phonebook-chartphonebook-chart0.1.02 of 3See more

phonebook-chart phonebook-chart 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ahmetgrbzz/result_server:2.035c37ae2bafd
click@8.1.7
8.3.3
ahmetgrbzz/web_server:2.0f018bafd2b0c
click@8.1.7
8.3.3

Open the chart page →

3,034
home-assistantpree-helm-chartsVerified publisher1.80.01 of 1See more

home-assistant pree-helm-charts 1.80.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
click@8.1.8
8.3.3

Open the chart page →

2,133
pritunl-slack-apppritunl-slack-appVerified publisher0.1.71 of 1See more

pritunl-slack-app pritunl-slack-app 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
click@8.1.7
8.3.3

Open the chart page →

2,871
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
gpappsoft/privacyidea-docker:3.12.2af7841adad26
click@8.1.8
8.3.3

Open the chart page →

5,440
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
click@8.3.1
8.3.3

Open the chart page →

8,158
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg16d7db8f1085a3
click@8.0.3
8.3.3

Open the chart page →

12,930
mealiertomik-helm-chartsVerified publisher0.0.21 of 1See more

mealie rtomik-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
click@8.1.3
8.3.3

Open the chart page →

3,929
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
click@6.7
8.3.3

Open the chart page →

13,541
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
click@8.1.3
python-click@8.1.3-2
8.3.3
no fix listed

Open the chart page →

38,107
sceptresceptreai0.1.121 of 5See more

sceptre sceptreai 0.1.12

1 of the 5 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
maponyacharles/sceptreai:api-0.1.127b37b092130a
click@8.2.1
8.3.3

Open the chart page →

4,369
iopsciencemeshVerified publisher0.4.01 of 2See more

iop sciencemesh 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cs3org/wopiserver:v9.4.202a9e78757b4
click@8.1.3
8.3.3

Open the chart page →

4,052
sentry-k8ssentry-k8sVerified publisher1.4.12 of 11See more

sentry-k8s sentry-k8s 1.4.1

2 of the 11 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
click@8.2.1
8.3.3
ghcr.io/getsentry/snuba:26.7.210f8d164109b
click@8.1.7
8.3.3

Open the chart page →

16,449
vuiseriohub1.0.62 of 3See more

vui seriohub 1.0.6

2 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
dserio83/velero-api:0.3.16b3d9115fee2
click@8.1.8
8.3.3
dserio83/velero-watchdog:0.1.8d5deae589229
click@8.1.8
8.3.3

Open the chart page →

11,532
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
click@8.1.7
8.3.3

Open the chart page →

2,928
smarter-demosmarterOfficialVerified publisher0.1.51 of 7See more

smarter-demo smarter 0.1.5

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
click@7.0
8.3.3

Open the chart page →

45,832
snappasssnappassVerified publisher0.4.31 of 3See more

snappass snappass 0.4.3

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
click@8.3.1
8.3.3

Open the chart page →

2,995
alertasomeblackmagic0.2.31 of 2See more

alerta someblackmagic 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
alerta/alerta-web:8.5.04786b9eaa606
click@8.0.3
8.3.3

Open the chart page →

3,162
healthchecksstackhelmVerified publisher0.1.01 of 2See more

healthchecks stackhelm 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
healthchecks/healthchecks:v2.8.1e82bb0836e30
click@8.1.3
8.3.3

Open the chart page →

2,236
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
click@7.1.2
8.3.3

Open the chart page →

24,930
streamlit-appstreamlit-appVerified publisher0.2.01 of 1See more

streamlit-app streamlit-app 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
sruthitanneru/pi-sample:ui-lateste565ea454ffd
click@8.1.7
8.3.3

Open the chart page →

1,696
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
click@8.3.1
8.3.3

Open the chart page →

12,907
taigaunxwaresVerified publisher2026.3.81 of 6See more

taiga unxwares 2026.3.8

1 of the 6 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
click@8.3.1
8.3.3

Open the chart page →

9,148
phonebook-chartusuladamsVerified publisher0.1.52 of 3See more

phonebook-chart usuladams 0.1.5

2 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
paulkellerman/resultserver-app:1.0381eeccb0618
click@8.1.3
8.3.3
paulkellerman/webserver-app:latest5a37b74f61b9
click@8.1.3
8.3.3

Open the chart page →

3,176
verbacapverbacapVerified publisher1.0.71 of 1See more

verbacap verbacap 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
click@8.1.7
8.3.3

Open the chart page →

2,233
qleverzazukoVerified publisher0.7.01 of 2See more

qlever zazuko 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/zazukoians/qlever-server:v0.10.0f10fd24b2290
click@8.1.6
8.3.3

Open the chart page →

2,900

Container images carrying it

614 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
sissbruecker/linkding:1.46.20c0a9a04c7eb
click@8.3.1
8.3.3
1
sissbruecker/linkding:1.35.00c5dddf0b37c
click@8.1.7
8.3.3
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
click@8.1.7
8.3.3
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
click@8.1.7
8.3.3
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
click@8.1.7
8.3.3
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
click@7.0
8.3.3
1
sruthitanneru/pi-sample:ui-lateste565ea454ffd
click@8.1.7
8.3.3
1
sslhep/servicex_app:v1.8.51d12f943cec5
click@8.3.2
8.3.3
1
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
click@8.1.8
8.3.3
1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
click@8.3.1
8.3.3
1
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
click@8.1.7
8.3.3
1
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
click@8.1.7
8.3.3
1
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
click@8.1.7
8.3.3
1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
click@8.1.7
8.3.3
1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
click@8.1.7
8.3.3
1
stackstorm/st2actionrunner:3.888235ba70cad
click@8.1.7
8.3.3
1
stackstorm/st2api:3.86f56d239d280
click@8.1.7
8.3.3
1
stackstorm/st2auth:3.833ecfda16608
click@8.1.7
8.3.3
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
click@8.1.7
8.3.3
1
stackstorm/st2notifier:3.8f190a6212195
click@8.1.7
8.3.3
1
stackstorm/st2rulesengine:3.8259503496ff9
click@8.1.7
8.3.3
1
stackstorm/st2scheduler:3.8b1de2055c362
click@8.1.7
8.3.3
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
click@8.1.7
8.3.3
1
stackstorm/st2stream:3.81c8904a3bf67
click@8.1.7
8.3.3
1
stackstorm/st2timersengine:3.81bf35bfaf00c
click@8.1.7
8.3.3
1
stackstorm/st2workflowengine:3.819fdfffdbba8
click@8.1.7
8.3.3
1
stakewiselabs/bls-horcrux:v1.0.02afd0c0b34cb
click@7.1.2
8.3.3
1
statcan/ckan:2.93921305425b8
click@7.1.2
8.3.3
1
stratospire/activityrelay:0.2.3a4c34cb01117
click@8.1.3
8.3.3
1
substratusai/verba:v0.4.0-baseURL261695be635eb
click@8.1.7
8.3.3
1
svtechnmaa/svtech_csv:v1.0.1b9d7ecf8de24
click@8.0.4
8.3.3
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
click@8.0.4
8.3.3
1
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
click@8.0.4
8.3.3
1
sysnet4admin/colosseum-rwd:log74ded2d92f07
click@8.1.8
8.3.3
1
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
click@8.1.3
8.3.3
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
click@8.1.3
8.3.3
1
taemon1337/image-api:0.0.1247bc1dc4f07
click@8.0.4
8.3.3
1
teknas09/bird-pod:latest12a1fa85c4aa
click@8.1.7
8.3.3
1
temporalio/admin-tools:1.22.4258958fe2ff2
click@8.1.7
8.3.3
1
temporalio/admin-tools:1.15.135034611d981
click@7.1.2
8.3.3
1
temporalio/admin-tools:1.26.237e2e33dbd7b
click@8.1.7
8.3.3
1
temporalio/admin-tools:1.22.0836af062af30
click@8.1.6
8.3.3
1
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
click@8.2.1
8.3.3
1
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
click@8.1.7
8.3.3
1
temporalio/admin-tools:1.28cfde8170c92f
click@8.3.1
8.3.3
1
thecloudspark/app-vote:1.0c7da7417a86a
click@8.1.3
8.3.3
1
thelande/kasa_exporter:v0.2.3a1fdb8baa152
click@8.1.7
8.3.3
1
thingsboard/toolbox:1.13.01bd61a0da6d3
click@8.1.7
8.3.3
1
thongngo3301/stakefish:latesta341af5976e3
click@8.1.7
8.3.3
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
click@8.0.3
8.3.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.