StackRadar

CVE-2026-8643

High

Advisory

Published 1 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.0
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,282
of 17,787 indexed, latest versions
Container images
1,231
deployed by those charts
Fix available
1 of 2
affected packages

pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory

Carried by container images the latest versions of 1,282 of 17,787 indexed charts deploy, on 1,231 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+67 more26.1.21,224
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 moreno fix listed141
OSV records
GHSA-wf93-45jw-7689UBUNTU-CVE-2026-8643DEBIAN-CVE-2026-8643
Also known as
PYSEC-2026-196

Charts affected

1,282 by stars
ChartLatestAffected imagesRadar Score
frigatebryopsida0.2.11 of 2See more

frigate bryopsida 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pip@20.3.4
26.1.2

Open the chart page →

2,573
pagescamden-pages1.0.01 of 3See more

pages camden-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
pip@22.0.4
26.1.2

Open the chart page →

2,507
bucket-clonercamptocamp31.0.41 of 1See more

bucket-cloner camptocamp3 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
camptocamp/bucket-cloner:latestacfafc308d88
pip@21.2.1
26.1.2

Open the chart page →

4,518
ekorrecamptocamp30.1.11 of 1See more

ekorre camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
camptocamp/ekorre:0.1.035c91d5fda04
pip@20.0.2
26.1.2

Open the chart page →

3,891
pghoardcamptocamp35.8.11 of 1See more

pghoard camptocamp3 5.8.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
camptocamp/pghoard:10bff736b15623
pip@18.1
26.1.2

Open the chart page →

2,813
prometheus-operatorcamptocamp35.15.11 of 5See more

prometheus-operator camptocamp3 5.15.1

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.0.16899ccd0b1f54
pip@19.0.3
26.1.2

Open the chart page →

2,490
snow-webhookcamptocamp31.0.01 of 1See more

snow-webhook camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
camptocamp/snow-webhook:latest2924b43dbf40
pip@18.1
26.1.2

Open the chart page →

1,310
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
pip@24.3.1
26.1.2

Open the chart page →

10,318
pagescarina-pages1.0.01 of 3See more

pages carina-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
pagescarmel-pages-dell1.0.01 of 3See more

pages carmel-pages-dell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
castai-hibernatecastaiVerified publisher0.2.121 of 1See more

castai-hibernate castai 0.2.12

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
castai/hibernate:v0.14da62858c8381
pip@23.0.1
26.1.2

Open the chart page →

1,158
temporalcastaiVerified publisher0.54.21 of 14See more

temporal castai 0.54.2

1 of the 14 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.26.237e2e33dbd7b
pip@24.0
26.1.2

Open the chart page →

16,197
catalyst-agentscatalyst-agents0.1.301 of 18See more

catalyst-agents catalyst-agents 0.1.30

1 of the 18 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
alpine/k8s:1.32.3eec354133193
pip@25.0.1
26.1.2

Open the chart page →

14,865
tsoragecetic0.4.111 of 8See more

tsorage cetic 0.4.11

1 of the 8 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.0.1c87b1c07fb53
pip@8.1.2
26.1.2

Open the chart page →

12,018
opencvecfi20170.1.22 of 7See more

opencve cfi2017 0.1.2

2 of the 7 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
pip@24.3.1
26.1.2
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
pip@25.0.1
26.1.2

Open the chart page →

14,964
pypi-servercgsimmons0.1.01 of 1See more

pypi-server cgsimmons 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
pypiserver/pypiserver:v1.3.2303ac89b2aa2
pip@19.3.1
26.1.2

Open the chart page →

506
ctk-walkthroughchaostoolkit-walkthrough0.1.03 of 3See more

ctk-walkthrough chaostoolkit-walkthrough 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
chaostoolkit/back:latest734f3af86125
pip@20.2.4
26.1.2
chaostoolkit/front:latest7f4a7eb9f7df
pip@20.2.4
26.1.2
chaostoolkit/middle:latestb95ba4961cfc
pip@20.3
26.1.2

Open the chart page →

5,557
suggestarrcharliecharts0.4.41 of 1See more

suggestarr charliecharts 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ciuse99/suggestarr:v1.0.20d72768245ef5
pip@24.3.1
26.1.2

Open the chart page →

1,124
chart-appchart-app0.3.01 of 2See more

chart-app chart-app 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
pip@25.3
26.1.2

Open the chart page →

1,775
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8b3b90af2a655
pip@25.3
26.1.2

Open the chart page →

5,528
kitchenowlchart-kitchenowl0.1.121 of 2See more

kitchenowl chart-kitchenowl 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
pip@26.0.1
26.1.2

Open the chart page →

4,783
calibre-webcharts-derwitt-devVerified publisher1.1.21 of 1See more

calibre-web charts-derwitt-dev 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
pip@25.0.1
26.1.2

Open the chart page →

4,919
home-assistant-otbrcharts-derwitt-devVerified publisher2.1.31 of 1See more

home-assistant-otbr charts-derwitt-dev 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/homeassistant-otbr:4.2.31b53b0b3488e
pip@25.1.1
python-pip@25.1.1+dfsg-1
26.1.2
no fix listed

Open the chart page →

2,358
chat-searchchat-searchVerified publisher0.1.71 of 1See more

chat-search chat-search 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/hemslo/chat-search:latest39d48995a5bd
pip@24.0
26.1.2

Open the chart page →

4,048
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
conduction/checkin-component-varnish:devef3a3fb0ad47
pip@9.0.1
26.1.2

Open the chart page →

8,408
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
pip@21.1.1
26.1.2
countly/frontend:25.05.42acbc11499b6
pip@21.1.1
26.1.2

Open the chart page →

7,295
kube-ops-viewchristianhuthVerified publisher8.3.31 of 1See more

kube-ops-view christianhuth 8.3.3

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:23.5.0a4fae38f93d7
pip@22.3.1
26.1.2

Open the chart page →

1,227
prometheus-pve-exporterchristianhuthVerified publisher2.10.01 of 1See more

prometheus-pve-exporter christianhuth 2.10.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
prompve/prometheus-pve-exporter:3.10.04867684c0a93
pip@26.1.1
26.1.2

Open the chart page →

349
syncserverchristianhuthVerified publisher1.3.01 of 1See more

syncserver christianhuth 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
mozilla/syncserver:latest016162bf39d8
pip@20.3.4
26.1.2

Open the chart page →

1,382
timetaggerchristianhuthVerified publisher2.2.01 of 1See more

timetagger christianhuth 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
pip@26.0
26.1.2

Open the chart page →

1,902
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pip@22.0.2
python-pip@22.0.2+dfsg-1ubuntu0.5
26.1.2
no fix listed

Open the chart page →

20,936
check-mkcloudnativeapp0.2.11 of 1See more

check-mk cloudnativeapp 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
nlmacamp/check_mk:latest5dbb8589f824
pip@10.0.1
26.1.2

Open the chart page →

2,408
couchdbcloudnativeapp1.1.31 of 3See more

couchdb cloudnativeapp 1.1.3

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kocolosk/couchdb-statefulset-assembler:1.2.06effb982154e
pip@9.0.1
26.1.2

Open the chart page →

2,110
daskcloudnativeapp2.2.12 of 2See more

dask cloudnativeapp 2.2.1

2 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
daskdev/dask:1.1.04ecd7bc35500
pip@10.0.1
26.1.2
daskdev/dask-notebook:1.1.0052630f5ca04
pip@18.1
26.1.2

Open the chart page →

29,922
distributed-tensorflowcloudnativeapp0.1.11 of 1See more

distributed-tensorflow cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
cheyang/distributed-tf:1.6.046cc34755493
pip@9.0.1
26.1.2

Open the chart page →

36,132
k8s-spot-termination-handlercloudnativeapp1.2.11 of 1See more

k8s-spot-termination-handler cloudnativeapp 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kubeaws/kube-spot-termination-notice-handler:1.13.0-1c9cd2ba4373a
pip@19.0.3
26.1.2

Open the chart page →

2,095
kube-huntercloudnativeapp1.0.21 of 1See more

kube-hunter cloudnativeapp 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
aquasec/kube-hunter:1950bf607ce9308
pip@18.1
26.1.2

Open the chart page →

1,305
locustcloudnativeapp1.0.01 of 1See more

locust cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
greenbirdit/locust:0.9.0e99d53bdc944
pip@18.1
26.1.2

Open the chart page →

1,352
prometheus-operatorcloudnativeapp6.4.01 of 7See more

prometheus-operator cloudnativeapp 6.4.0

1 of the 7 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.0.186eb52513d59e
pip@19.1.1
26.1.2

Open the chart page →

2,954
sentry-kubernetescloudnativeapp0.2.01 of 1See more

sentry-kubernetes cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
getsentry/sentry-kubernetes:latest6ac37974fd2a
pip@19.0.3
26.1.2

Open the chart page →

1,415
supersetcloudnativeapp1.1.61 of 1See more

superset cloudnativeapp 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
amancevice/superset:0.28.1c8c04bfe3d66
pip@19.0.3
26.1.2

Open the chart page →

5,060
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
pip@8.1.1
python-pip@8.1.1-2ubuntu0.4
26.1.2
no fix listed

Open the chart page →

77,798
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
pip@23.2.1
26.1.2

Open the chart page →

25,152
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
pip@22.0.4
26.1.2

Open the chart page →

6,696
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
pip@22.1.2
26.1.2

Open the chart page →

6,921
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
robotshop/rs-payment:latest774b52c6180d
pip@21.2.4
26.1.2

Open the chart page →

29,594
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
pip@20.0.2
python-pip@20.0.2-5ubuntu1.6
26.1.2
no fix listed

Open the chart page →

12,505
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
pip@20.0.2
python-pip@20.0.2-5ubuntu1.6
26.1.2
no fix listed

Open the chart page →

12,176
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
pip@20.0.2
python-pip@20.0.2-5ubuntu1.6
26.1.2
no fix listed

Open the chart page →

11,640

Container images carrying it

1,231 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
pip@25.0.1
26.1.2
1
langgenius/dify-api:1.0.0066035f93856
pip@25.0.1
26.1.2
1
langgenius/dify-api:1.16.1dcefa5f7c47c
pip@25.0.1
26.1.2
1
langgenius/dify-api:0.6.11fca918260dd6
pip@23.0.1
26.1.2
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
pip@24.0
python-pip@24.0+dfsg-1ubuntu1.3
26.1.2
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
pip@24.0
python-pip@24.0+dfsg-1ubuntu1.3
26.1.2
no fix listed
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
pip@24.0
python-pip@24.0+dfsg-1ubuntu1.3
26.1.2
no fix listed
1
langgenius/dify-sandbox:0.2.124e65e8a351a2
pip@23.0.1
26.1.2
1
langgenius/dify-sandbox:0.2.15750e1111426e
pip@26.0.1
26.1.2
1
lib42/deluge:20c4d1d326f95
pip@22.3.1
26.1.2
1
library/crate:4.7.0c7984a05e15b
pip@9.0.3
26.1.2
1
library/mysql:8.4.113466ba4a4828
pip@25.3
26.1.2
1
library/mysql:885b9bf2e29cf
pip@25.3
26.1.2
1
library/mysql:8.4.108dbcf531a03a
pip@25.3
26.1.2
1
library/mysql:8.0.41bf577825b52a
pip@24.2
26.1.2
1
library/python:3.8-alpine3d93b1f77efc
pip@23.0.1
26.1.2
1
library/python:3.1070c9cc675605
pip@23.0.1
26.1.2
1
library/python:3.11-slim9534e5a8e315
pip@24.0
26.1.2
1
library/python:3.12-alpineb64631e04e49
pip@25.0.1
26.1.2
1
library/python:3.8d41127070014
pip@23.0.1
26.1.2
1
library/python:3.9da5aee29682d
pip@23.0.1
26.1.2
1
library/python:3.12.9-bullseyeed4450bab88f
pip@24.3.1
26.1.2
1
library/python:3.14.3-alpine3.23faee120f7885
pip@25.3
26.1.2
1
librenms/librenms:24.11.00920bc9117a8
pip@24.3.1
26.1.2
1
librenms/librenms:22.4.14f1f3d667cc7
pip@22.0.4
26.1.2
1
libretranslate/libretranslate:v1.9.61de2d7056bb8
pip@24.0
26.1.2
1
linuxserver/babybuddy:1.10.2f7d7c7704249
pip@22.1
26.1.2
1
linuxserver/beets:1.5.0e36d16f7341c
pip@21.3.1
26.1.2
1
linuxserver/calibre-web:0.6.24241009026e6f
pip@25.2
python-pip@24.0+dfsg-1ubuntu1.2
26.1.2
no fix listed
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
pip@21.2.4
26.1.2
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
pip@19.0.1
26.1.2
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
pip@19.3.1
26.1.2
1
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
pip@25.1.1
26.1.2
1
linuxserver/healthchecks:version-v1.20.050792a72fc71
pip@21.1.1
26.1.2
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
pip@23.0.1
26.1.2
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
pip@21.1.2
26.1.2
1
linuxserver/medusa:v0.3.9-ls340a5f5114128b
pip@19.2.3
26.1.2
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
pip@19.3.1
26.1.2
1
linuxserver/yq:3.2.26f5b9586a93e
pip@23.2.1
26.1.2
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pip@26.0.1
26.1.2
1
lmacka/snappass:2.1.293f5c048b7d4
pip@25.0.1
26.1.2
1
lnbitsdocker/lnbits-legend:latest26fae6327477
pip@23.3.1
26.1.2
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
pip@23.0.1
26.1.2
1
lncm/specter-desktop:v0.10.4bca14d04397d
pip@20.2.3
26.1.2
1
localstack/localstack:3.19d278167f2b7
pip@23.3.2
26.1.2
1
locustio/locust:2.24.151d866285170
pip@24.0
26.1.2
1
logiqai/toolbox:2.0.155a574ec5b64
pip@18.1
26.1.2
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
pip@18.1
26.1.2
1
louislam/uptime-kuma:13d632903e6af
pip@18.1
26.1.2
1
louislam/uptime-kuma:1.23.1396510915e6be
pip@18.1
26.1.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.