StackRadar

CVE-2026-7246

High

Advisory

Published 30 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
576
of 17,781 indexed, latest versions
Container images
614
deployed by those charts
Fix available
2 of 3
affected packages

Security update for python-click

Carried by container images the latest versions of 576 of 17,781 indexed charts deploy, on 614 images.

Affected packageAffected versionsFixed inImages
clickpypi6.7, 7.0, 7.1.1, 7.1.2+16 more8.3.3614
python-clickdeb8.1.3-2no fix listed8
python-clickrpm8.2.1-160000.2.28.2.1-160000.3.11
OSV records
DEBIAN-CVE-2026-7246PYSEC-2026-2132SUSE-SU-2026:22321-1
Also known as
GHSA-47fr-3ffg-hgmw

Charts affected

576 by stars
ChartLatestAffected imagesRadar Score
timetaggerchristianhuthVerified publisher2.2.01 of 1See more

timetagger christianhuth 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
click@8.3.1
8.3.3

Open the chart page →

1,958
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
click@8.0.3
8.3.3

Open the chart page →

20,900
daskcloudnativeapp2.2.12 of 2See more

dask cloudnativeapp 2.2.1

2 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
daskdev/dask:1.1.04ecd7bc35500
click@7.0
8.3.3
daskdev/dask-notebook:1.1.0052630f5ca04
click@7.0
8.3.3

Open the chart page →

29,901
locustcloudnativeapp1.0.01 of 1See more

locust cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
greenbirdit/locust:0.9.0e99d53bdc944
click@7.0
8.3.3

Open the chart page →

1,352
supersetcloudnativeapp1.1.61 of 1See more

superset cloudnativeapp 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
amancevice/superset:0.28.1c8c04bfe3d66
click@6.7
8.3.3

Open the chart page →

5,060
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
click@8.1.6
8.3.3

Open the chart page →

25,151
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
robotshop/rs-payment:latest774b52c6180d
click@8.0.1
8.3.3

Open the chart page →

29,555
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
click@7.1.2
8.3.3

Open the chart page →

12,457
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
click@7.1.2
8.3.3

Open the chart page →

12,131
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
click@7.1.2
8.3.3

Open the chart page →

11,592
galaxykubemancloudve2.10.11 of 7See more

galaxykubeman cloudve 2.10.1

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
click@8.1.3
8.3.3

Open the chart page →

16,069
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
click@8.0.3
8.3.3

Open the chart page →

8,009
pbcore-utilcluster-deploy0.0.11 of 1See more

pbcore-util cluster-deploy 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
click@8.3.1
8.3.3

Open the chart page →

9,128
cobbler-tftpcobbler0.1.11 of 1See more

cobbler-tftp cobbler 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/cobbler/cobbler-tftp:v0.1.0a7fef3ca80baa4
click@8.2.1
python-click@8.2.1-160000.2.2
8.3.3
8.2.1-160000.3.1

Open the chart page →

304
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
kfserving/models-web-app:v0.6.1f322d6ffdfa3
click@8.0.1
8.3.3

Open the chart page →

3,830
wopiservercs3orgOfficialVerified publisher0.9.21 of 1See more

wopiserver cs3org 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cs3org/wopiserver:v9.4.202a9e78757b4
click@8.1.3
8.3.3

Open the chart page →

2,348
csghubcsghubVerified publisher2.4.33 of 34See more

csghub csghub 2.4.3

3 of the 34 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
click@8.2.1
8.3.3
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
click@8.3.1
8.3.3
opencsghq/label-studio:v2.4.0b4e849fcf94a
click@8.1.7
8.3.3

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opencsghq/csgship-agentic:v0.4.02cd29671a03e
click@8.2.1
8.3.3
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
click@8.2.1
8.3.3

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
click@8.1.7
8.3.3

Open the chart page →

6,632
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
click@8.1.3
8.3.3

Open the chart page →

13,852
cspconsolecspconsole1.3.111 of 5See more

cspconsole cspconsole 1.3.11

1 of the 5 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
cspconsole/report-collector:1.0.15839750248193b
click@8.3.1
8.3.3

Open the chart page →

12,274
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
click@8.1.7
8.3.3

Open the chart page →

16,604
daejeon_2-3daejeon2-30.1.01 of 2See more

daejeon_2-3 daejeon2-3 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
clsen2024/daejeon_2-3:latest1156cd87c8fb
click@8.1.7
8.3.3

Open the chart page →

1,141
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
click@8.1.7
8.3.3

Open the chart page →

6,179
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
click@8.1.3
8.3.3

Open the chart page →

5,062
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
click@6.7
8.3.3

Open the chart page →

27,728
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
click@7.1.2
8.3.3

Open the chart page →

18,863
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
click@8.1.8
8.3.3

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
click@8.1.8
8.3.3

Open the chart page →

5,974
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
click@6.7
8.3.3

Open the chart page →

22,405
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
click@8.1.8
8.3.3

Open the chart page →

6,172
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
click@6.7
8.3.3

Open the chart page →

24,335
linkdingdeimosfr-charts1.0.31 of 1See more

linkding deimosfr-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.35.00c5dddf0b37c
click@8.1.7
8.3.3

Open the chart page →

6,075
mlflowdeliveryheroVerified publisher1.0.101 of 1See more

mlflow deliveryhero 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
click@7.1.2
8.3.3

Open the chart page →

4,422
prometheus-aws-costs-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-aws-costs-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
nachomillangarcia/prometheus_aws_cost_exporter:lateste4ce056f2d6d
click@6.7
8.3.3

Open the chart page →

3,553
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
click@8.2.1
8.3.3

Open the chart page →

2,305
deployhubdeployhubVerified publisher10.0.4157 of 11See more

deployhub deployhub 10.0.415

7 of the 11 container images this version deploys carry CVE-2026-7246.

Open the chart page →

11,160
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
click@8.1.3
8.3.3

Open the chart page →

14,856
design-cataloguedesign-catalogue0.1.01 of 2See more

design-catalogue design-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
click@7.1.2
8.3.3

Open the chart page →

2,770
kube-openid-connectdevopstalesVerified publisher1.1.01 of 1See more

kube-openid-connect devopstales 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
devopstales/kube-openid-connector:1.042c40a0e9f1b
click@8.0.4
8.3.3

Open the chart page →

1,333
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
click@8.1.7
8.3.3

Open the chart page →

9,607
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
click@8.1.7
8.3.3

Open the chart page →

9,607
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
click@8.1.8
8.3.3

Open the chart page →

19,224
alertifydjjudas21Verified publisher0.1.01 of 1See more

alertify djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
djjudas21/alertify:0.1.0ba22be670c37
click@8.2.1
8.3.3

Open the chart page →

2,378
ecowitt-exporterdjjudas21Verified publisher2.2.21 of 1See more

ecowitt-exporter djjudas21 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
djjudas21/ecowitt-exporter:2.2.073aab45ef10d
click@8.2.1
8.3.3

Open the chart page →

1,006
liturgical-colourdjjudas21Verified publisher99.99.991 of 1See more

liturgical-colour djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
djjudas21/liturgical-colour-app:0.7.2954935971d42
click@8.2.1
8.3.3

Open the chart page →

872
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
click@7.0
8.3.3

Open the chart page →

4,217
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
click@8.1.7
8.3.3

Open the chart page →

14,627
dominodomino-iisasVerified publisher0.3.11 of 3See more

domino domino-iisas 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
ghcr.io/iisas/domino-rest:latest3009350bfc11
click@8.3.1
8.3.3

Open the chart page →

10,270
codecovdoubanVerified publisher0.2.43 of 8See more

codecov douban 0.2.4

3 of the 8 container images this version deploys carry CVE-2026-7246.

Container imageDigestPackageFixed in
codecov/self-hosted-api:24.4.10475cb1c3136
click@8.0.4
8.3.3
codecov/self-hosted-worker:24.4.1837f546b479b
click@8.1.7
8.3.3
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
click@8.0.3
8.3.3

Open the chart page →

24,917

Container images carrying it

614 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
sissbruecker/linkding:1.46.20c0a9a04c7eb
click@8.3.1
8.3.3
1
sissbruecker/linkding:1.35.00c5dddf0b37c
click@8.1.7
8.3.3
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
click@8.1.7
8.3.3
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
click@8.1.7
8.3.3
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
click@8.1.7
8.3.3
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
click@7.0
8.3.3
1
sruthitanneru/pi-sample:ui-lateste565ea454ffd
click@8.1.7
8.3.3
1
sslhep/servicex_app:v1.8.51d12f943cec5
click@8.3.2
8.3.3
1
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
click@8.1.8
8.3.3
1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
click@8.3.1
8.3.3
1
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
click@8.1.7
8.3.3
1
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
click@8.1.7
8.3.3
1
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
click@8.1.7
8.3.3
1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
click@8.1.7
8.3.3
1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
click@8.1.7
8.3.3
1
stackstorm/st2actionrunner:3.888235ba70cad
click@8.1.7
8.3.3
1
stackstorm/st2api:3.86f56d239d280
click@8.1.7
8.3.3
1
stackstorm/st2auth:3.833ecfda16608
click@8.1.7
8.3.3
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
click@8.1.7
8.3.3
1
stackstorm/st2notifier:3.8f190a6212195
click@8.1.7
8.3.3
1
stackstorm/st2rulesengine:3.8259503496ff9
click@8.1.7
8.3.3
1
stackstorm/st2scheduler:3.8b1de2055c362
click@8.1.7
8.3.3
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
click@8.1.7
8.3.3
1
stackstorm/st2stream:3.81c8904a3bf67
click@8.1.7
8.3.3
1
stackstorm/st2timersengine:3.81bf35bfaf00c
click@8.1.7
8.3.3
1
stackstorm/st2workflowengine:3.819fdfffdbba8
click@8.1.7
8.3.3
1
stakewiselabs/bls-horcrux:v1.0.02afd0c0b34cb
click@7.1.2
8.3.3
1
statcan/ckan:2.93921305425b8
click@7.1.2
8.3.3
1
stratospire/activityrelay:0.2.3a4c34cb01117
click@8.1.3
8.3.3
1
substratusai/verba:v0.4.0-baseURL261695be635eb
click@8.1.7
8.3.3
1
svtechnmaa/svtech_csv:v1.0.1b9d7ecf8de24
click@8.0.4
8.3.3
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
click@8.0.4
8.3.3
1
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
click@8.0.4
8.3.3
1
sysnet4admin/colosseum-rwd:log74ded2d92f07
click@8.1.8
8.3.3
1
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
click@8.1.3
8.3.3
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
click@8.1.3
8.3.3
1
taemon1337/image-api:0.0.1247bc1dc4f07
click@8.0.4
8.3.3
1
teknas09/bird-pod:latest12a1fa85c4aa
click@8.1.7
8.3.3
1
temporalio/admin-tools:1.22.4258958fe2ff2
click@8.1.7
8.3.3
1
temporalio/admin-tools:1.15.135034611d981
click@7.1.2
8.3.3
1
temporalio/admin-tools:1.26.237e2e33dbd7b
click@8.1.7
8.3.3
1
temporalio/admin-tools:1.22.0836af062af30
click@8.1.6
8.3.3
1
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
click@8.2.1
8.3.3
1
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
click@8.1.7
8.3.3
1
temporalio/admin-tools:1.28cfde8170c92f
click@8.3.1
8.3.3
1
thecloudspark/app-vote:1.0c7da7417a86a
click@8.1.3
8.3.3
1
thelande/kasa_exporter:v0.2.3a1fdb8baa152
click@8.1.7
8.3.3
1
thingsboard/toolbox:1.13.01bd61a0da6d3
click@8.1.7
8.3.3
1
thongngo3301/stakefish:latesta341af5976e3
click@8.1.7
8.3.3
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
click@8.0.3
8.3.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.