StackRadar

CVE-2026-8643

High

Advisory

Published 1 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.0
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,275
of 17,790 indexed, latest versions
Container images
1,223
deployed by those charts
Fix available
1 of 2
affected packages

pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory

Carried by container images the latest versions of 1,275 of 17,790 indexed charts deploy, on 1,223 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+67 more26.1.21,217
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 moreno fix listed139
OSV records
GHSA-wf93-45jw-7689UBUNTU-CVE-2026-8643DEBIAN-CVE-2026-8643
Also known as
PYSEC-2026-196

Charts affected

1,275 by stars
ChartLatestAffected imagesRadar Score
servicexssl-hep1.8.512 of 16See more

servicex ssl-hep 1.8.5

12 of the 16 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/python:3.1070c9cc675605
pip@23.0.1
26.1.2
ncsa/checks:main0b738bbc8d70
pip@24.0
26.1.2
sslhep/servicex_app:v1.8.51d12f943cec5
pip@23.0.1
26.1.2
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
pip@23.0.1
26.1.2
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
pip@23.0.1
26.1.2
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
pip@23.0.1
26.1.2
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
pip@23.0.1
26.1.2
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
pip@23.0.1
26.1.2
sslhep/servicex-did-finder:v1.8.5ab0090083567
pip@26.0.1
26.1.2
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
pip@26.0.1
26.1.2
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
pip@26.0.1
26.1.2
sslhep/x509-secrets:v1.8.5d9e9ecb12d59
pip@22.3.1
26.1.2

Open the chart page →

65,130
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
pip@9.0.3
26.1.2

Open the chart page →

28,165
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
pip@19.0.3
26.1.2

Open the chart page →

2,060
restful-distributed-lock-managerstakaterVerified publisher1.0.41 of 1See more

restful-distributed-lock-manager stakater 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
pip@9.0.1
26.1.2

Open the chart page →

3,116
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
pip@23.2.1
26.1.2

Open the chart page →

18,426
horcruxstakewise1.0.11 of 1See more

horcrux stakewise 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
stakewiselabs/bls-horcrux:v1.0.02afd0c0b34cb
pip@21.0
26.1.2

Open the chart page →

1,421
verostakewise0.8.31 of 2See more

vero stakewise 0.8.3

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
pip@24.2
26.1.2

Open the chart page →

3,180
stalwartstalwart-helmVerified publisher0.7.181 of 2See more

stalwart stalwart-helm 0.7.18

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/python:3.12-alpineb64631e04e49
pip@25.0.1
26.1.2

Open the chart page →

1,381
open-appsec-injectorstartechnicaVerified publisher1.1.21 of 3See more

open-appsec-injector startechnica 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
pip@23.0.1
26.1.2

Open the chart page →

4,315
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.12.089739be9ff38
pip@21.0.1
26.1.2

Open the chart page →

16,508
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
pip@20.2.3
26.1.2

Open the chart page →

3,044
prometheus-operatorstatcan0.2.21 of 7See more

prometheus-operator statcan 0.2.2

1 of the 7 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
pip@20.1
26.1.2

Open the chart page →

12,237
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
storageclass-routerstorageclass-routerVerified publisher0.4.11 of 1See more

storageclass-router storageclass-router 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/maxiv/storageclass-router:0.4.160725dab588c
pip@24.0
26.1.2

Open the chart page →

1,057
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
pip@20.0.2
python-pip@20.0.2-5ubuntu1.10
26.1.2
no fix listed

Open the chart page →

10,182
studygovernorstudy-governorVerified publisher0.1.381 of 3See more

studygovernor study-governor 0.1.38

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
pip@22.0.4
26.1.2

Open the chart page →

1,447
artifactory-cleanupsubshellVerified publisher1.0.11 of 1See more

artifactory-cleanup subshell 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
devopshq/artifactory-cleanup:1.0.1830e093bffa91
pip@23.0.1
26.1.2

Open the chart page →

2,540
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
pip@24.0
26.1.2

Open the chart page →

4,782
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
pip@23.0.1
26.1.2

Open the chart page →

12,937
3d-printing-cost-calculatorssudo-kraken-3d-printing-cost-calculatorsVerified publisher0.1.41 of 1See more

3d-printing-cost-calculators sudo-kraken-3d-printing-cost-calculators 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/3d-printing-cost-calculators:v1.1.1220c5e4e1a3d
pip@25.2
26.1.2

Open the chart page →

2,577
authentik-webfinger-proxysudo-kraken-authentik-webfinger-proxyVerified publisher0.1.41 of 1See more

authentik-webfinger-proxy sudo-kraken-authentik-webfinger-proxy 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/authentik-webfinger-proxy:v1.1.1e1351a977607
pip@25.2
26.1.2

Open the chart page →

2,657
fantasy-dice-chambersudo-kraken-fantasy-dice-chamberVerified publisher0.1.31 of 1See more

fantasy-dice-chamber sudo-kraken-fantasy-dice-chamber 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/fantasy-dice-chamber:v1.3.299fd4cb0f4fe
pip@25.2
26.1.2

Open the chart page →

2,689
finances-trackersudo-kraken-finances-trackerVerified publisher0.1.51 of 1See more

finances-tracker sudo-kraken-finances-tracker 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/finances-tracker:v1.1.1c73527cde81c
pip@25.2
26.1.2

Open the chart page →

2,657
flaresolverrsudo-kraken-flaresolverrVerified publisher2.1.41 of 1See more

flaresolverr sudo-kraken-flaresolverr 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
pip@25.2
26.1.2

Open the chart page →

33,591
jf-pushover-webhooksudo-kraken-jf-pushover-webhookVerified publisher0.1.31 of 1See more

jf-pushover-webhook sudo-kraken-jf-pushover-webhook 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/jf-pushover-webhook:v1.1.0ee9cf22a39ab
pip@25.2
26.1.2

Open the chart page →

2,657
qbittorrentsudo-kraken-qbittorrentVerified publisher5.1.51 of 2See more

qbittorrent sudo-kraken-qbittorrent 5.1.5

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/home-operations/qbittorrent:5.1.4bb82ad6668f8
pip@25.3
26.1.2

Open the chart page →

2,130
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
surogate-hubsurogate-hubVerified publisher2.1.51 of 1See more

surogate-hub surogate-hub 2.1.5

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
pip@26.1.1
26.1.2

Open the chart page →

3,372
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
mher/flower:2.051c3c3db5be3
pip@23.1.2
26.1.2

Open the chart page →

4,687
csv-viewsvtech-public-helm-charts1.0.01 of 1See more

csv-view svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
svtechnmaa/svtech_csv:v1.0.1b9d7ecf8de24
pip@20.2.2
26.1.2

Open the chart page →

1,220
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
pip@20.2.4
26.1.2

Open the chart page →

12,708
icinga2svtech-public-helm-charts1.0.01 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
pip@9.0.3
26.1.2

Open the chart page →

5,101
icinga2-reportsvtech-public-helm-charts1.0.01 of 1See more

icinga2-report svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
trungkien210493/icinga2-report:v1.7.12cc8c3763c4c
pip@20.1.1
26.1.2

Open the chart page →

1,779
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
pip@20.2.4
26.1.2

Open the chart page →

5,880
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
pip@24.0
26.1.2

Open the chart page →

18,828
rundeck-option-providersvtech-public-helm-charts1.0.01 of 2See more

rundeck-option-provider svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
pip@20.2.2
26.1.2

Open the chart page →

1,428
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
pip@25.1.1
26.1.2

Open the chart page →

2,397
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
pip@23.0.1
26.1.2

Open the chart page →

10,545
gtmetrix-bqt3n1.0.01 of 1See more

gtmetrix-bq t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
t3nde/gtmetrix-bq:0.2.0d2939e9a719b
pip@20.1
26.1.2

Open the chart page →

1,287
take-the-helmtake-the-helm0.1.01 of 1See more

take-the-helm take-the-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
cadmusthefounder/lnd:take-the-helm-0.1.0e596c5fbf80f
pip@22.0.4
26.1.2

Open the chart page →

805
democharttech-challenge0.1.02 of 4See more

demochart tech-challenge 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
alexvm6/generator:latestfb99ee4f760a
pip@22.3.1
26.1.2
alexvm6/pythonalex:latest89a05786879c
pip@22.3.1
26.1.2

Open the chart page →

3,630
rundeck-exportertechpreta0.1.91 of 1See more

rundeck-exporter techpreta 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
phsmith/rundeck-exporter:2.6.10265a7616ae8
pip@22.3.1
26.1.2

Open the chart page →

1,104
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
pip@8.1.2
26.1.2

Open the chart page →

4,239
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
pip@23.1.2
26.1.2

Open the chart page →

21,004
tensor_apptensor-app0.2.22 of 3See more

tensor_app tensor-app 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
pip@23.0.1
26.1.2
xeladock/mysql_dns:latest4baf531453f1
pip@22.0.2
python-pip@22.0.2+dfsg-1
26.1.2
no fix listed

Open the chart page →

17,561
krokiteochenglim1.0.11 of 5See more

kroki teochenglim 1.0.1

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
pip@21.2.4
26.1.2

Open the chart page →

8,716
pagestest43221.0.01 of 3See more

pages test4322 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
flask-contactstest-configmap1.0.12 of 3See more

flask-contacts test-configmap 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2
shashkist/flask-contacts-app:latest581de1fd6084
pip@24.2
26.1.2

Open the chart page →

5,624
webapp1test-helm-chart-10.1.01 of 1See more

webapp1 test-helm-chart-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
devopsjourney1/mywebapp:latestbd1ec6838570
pip@22.0.4
26.1.2

Open the chart page →

1,469
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
pip@24.0
26.1.2

Open the chart page →

4,176

Container images carrying it

1,223 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
neilpeterson/aks-helloworld:v1fb47732ef36b
pip@9.0.1
26.1.2
1
neilpeterson/chart-tweet:latest64fd8dab075f
pip@9.0.1
26.1.2
1
neilpeterson/get-tweet:v28b645ac1a23e
pip@10.0.1
26.1.2
1
neilpeterson/osba-container-instances-demo:latest6527b05d5d03
pip@9.0.1
26.1.2
1
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
pip@9.0.1
26.1.2
1
neilpeterson/osba-mysql-demo:latest5859d68a6c9f
pip@9.0.2
26.1.2
1
neilpeterson/osba-storage-demo:latest29d229ab446e
pip@9.0.1
26.1.2
1
neilpeterson/osba-text-analytics-demo:latest969af3cb8466
pip@10.0.1
26.1.2
1
neilpeterson/process-tweet:latest39ce9f92e899
pip@10.0.1
26.1.2
1
netbirdio/dashboard:v2.22.215a3aab9a345
pip@20.3.4
26.1.2
1
netbirdio/dashboard:v2.90.101b59e1c905c9
pip@20.3.4
26.1.2
1
netbirdio/dashboard:v2.90.2332cc31f5f35
pip@20.3.4
26.1.2
1
netbirdio/dashboard:v2.13.188b5fb704a8c
pip@20.3.4
26.1.2
1
netboxcommunity/netbox:v3.2.83d652dca5351
pip@22.2.2
26.1.2
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
pip@24.0
26.1.2
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
pip@26.0.1
26.1.2
1
neuvector/manager:5.6.19e729010b7eb
pip@24.2
26.1.2
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
pip@20.2.3
26.1.2
1
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
pip@22.3.1
26.1.2
1
nlmacamp/check_mk:latest5dbb8589f824
pip@10.0.1
26.1.2
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
python-pip@25.1.1+dfsg-1
no fix listed
1
nyurik/alpine-python3-requests:lateste0553236e3eb
pip@21.1.3
26.1.2
1
octoprint/octoprint:1.4.0106c26efcd8a
pip@20.3.1
26.1.2
1
octoprint/octoprint:1.6.1ea3bffae2470
pip@21.1.2
26.1.2
1
odaniait/aws-kubectl:latest3fff8a8570ec
pip@20.0.2
26.1.2
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
pip@24.2
26.1.2
1
oled01/automx2:2025.1.105d3e398e675
pip@25.1.1
26.1.2
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
pip@9.0.1
python-pip@9.0.1-2.3~ubuntu1.18.04.1
26.1.2
no fix listed
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
pip@9.0.3
python-pip@8.1.1-2ubuntu0.4
26.1.2
no fix listed
1
omkara25/simple-microservice-app-order-service:v2.18327546c7aac
pip@23.0.1
26.1.2
1
omkara25/simple-microservice-app-payment-service:v2afff40172b6b
pip@23.0.1
26.1.2
1
omkara25/simple-microservice-app-user-service:v2d62cba548580
pip@23.0.1
26.1.2
1
onyxdotapp/onyx-backend:latest473fdffe4e67
pip@26.0.1
26.1.2
1
opea/asr:1.025dd26d9cd09
pip@24.0
26.1.2
1
opea/chatqna:1.038c51b791efa
pip@24.2
26.1.2
1
opea/codegen:1.058f91683892d
pip@24.2
26.1.2
1
opea/codetrans:1.0e2436483b73d
pip@24.2
26.1.2
1
opea/docsum:1.03eaa91849512
pip@24.2
26.1.2
1
opea/guardrails-tgi:1.0262c6048aab8
pip@24.2
26.1.2
1
opea/guardrails-tgi:latestf68bec6a1271
pip@24.3.1
26.1.2
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
pip@24.0
26.1.2
1
opea/speecht5:1.0249afad3d268
pip@24.2
26.1.2
1
opea/tts:1.0257ae94709e9
pip@24.0
26.1.2
1
opea/web-retriever-chroma:1.0fe08165d7770
pip@24.2
26.1.2
1
openbas/caldera-server:5.1.0a277796d9724
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.1.2
no fix listed
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pip@25.0.1
26.1.2
1
opencsghq/csgship-agentic:v0.4.02cd29671a03e
pip@25.2
26.1.2
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pip@25.2
26.1.2
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
pip@24.2
26.1.2
1
opencsghq/label-studio:v2.5.047e22aa71870
pip@25.1.1
26.1.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.