StackRadar

CVE-2026-8643

High

Advisory

Published 1 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.0
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,275
of 17,790 indexed, latest versions
Container images
1,223
deployed by those charts
Fix available
1 of 2
affected packages

pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory

Carried by container images the latest versions of 1,275 of 17,790 indexed charts deploy, on 1,223 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+67 more26.1.21,217
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 moreno fix listed139
OSV records
GHSA-wf93-45jw-7689UBUNTU-CVE-2026-8643DEBIAN-CVE-2026-8643
Also known as
PYSEC-2026-196

Charts affected

1,275 by stars
ChartLatestAffected imagesRadar Score
kube-web-viewrlex0.5.01 of 1See more

kube-web-view rlex 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:23.8.0431f1bf013d0
pip@23.0.1
26.1.2

Open the chart page →

4,315
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.1.2
no fix listed

Open the chart page →

15,623
krr-enforcerrobusta0.3.51 of 2See more

krr-enforcer robusta 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
alpine/k8s:1.30.0bd01dae02676
pip@24.0
26.1.2

Open the chart page →

4,039
pagesroccohiggins-pages1.0.01 of 3See more

pages roccohiggins-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
pip@24.3.1
26.1.2

Open the chart page →

9,275
monitoringrocketchat-server0.0.171 of 9See more

monitoring rocketchat-server 0.0.17

1 of the 9 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.30.98c06e1ba643a
pip@25.2
26.1.2

Open the chart page →

6,860
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
pip@24.0
26.1.2

Open the chart page →

9,152
argocdromholdings1.8.11 of 3See more

argocd romholdings 1.8.1

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
pip@18.1
26.1.2

Open the chart page →

10,468
kube-prometheus-stackromholdings19.3.01 of 6See more

kube-prometheus-stack romholdings 19.3.0

1 of the 6 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.14.235654389f8a9
pip@21.2.4
26.1.2

Open the chart page →

8,645
rommromm-helm-chartVerified publisher1.5.51 of 3See more

romm romm-helm-chart 1.5.5

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
rommapp/romm:5.2.03512f2ca4557
pip@25.3
26.1.2

Open the chart page →

3,415
pagesronan-pages1.0.01 of 3See more

pages ronan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
imgtagrotationalVerified publisher0.2.01 of 1See more

imgtag rotational 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
pip@25.0.1
26.1.2

Open the chart page →

3,318
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
pip@24.0
26.1.2

Open the chart page →

3,406
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
pip@24.0
26.1.2

Open the chart page →

4,612
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
pip@26.0.1
26.1.2

Open the chart page →

7,491
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
pip@25.0.1
26.1.2

Open the chart page →

10,492
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
pip@25.3
26.1.2

Open the chart page →

4,537
flaresolverrrubxkubeVerified publisher0.1.11 of 1See more

flaresolverr rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
pip@24.0
26.1.2

Open the chart page →

27,282
linkdingrubxkubeVerified publisher1.2.31 of 1See more

linkding rubxkube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.46.20c0a9a04c7eb
pip@25.2
26.1.2

Open the chart page →

2,063
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
pip@26.0.1
26.1.2

Open the chart page →

5,833
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
pip@23.0.1
26.1.2

Open the chart page →

9,421
test-helm-app1saam-helm-test0.1.01 of 1See more

test-helm-app1 saam-helm-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
hamidyousefi93/saam-test:latestc34f071f6ed0
pip@23.0.1
26.1.2

Open the chart page →

3,374
test-helm-app2saam-helm-test0.1.01 of 1See more

test-helm-app2 saam-helm-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
asdkant/fastapi-hello-world:latesta23d8bf7c885
pip@20.3.3
26.1.2

Open the chart page →

2,771
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
pip@26.1.1
26.1.2

Open the chart page →

1,581
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
pip@26.1.1
26.1.2

Open the chart page →

17,736
pagessamanvithkaranth1.0.01 of 3See more

pages samanvithkaranth 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
evsantisbon0.2.02 of 5See more

ev santisbon 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
santisbon/evwatcher:latestc4e994ca4540
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.1.2
no fix listed
santisbon/evworker:lateste807283f8d69
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.1.2
no fix listed

Open the chart page →

12,090
speedtestsantisbon0.1.01 of 3See more

speedtest santisbon 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
santisbon/speedtest:latest8ee3a1697227
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.1.2
no fix listed

Open the chart page →

11,314
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
pip@18.1
26.1.2

Open the chart page →

4,744
pagessarubits-pages1.0.01 of 3See more

pages sarubits-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
pip@23.3.2
26.1.2

Open the chart page →

9,340
mlflowsb-helm-charts0.3.01 of 1See more

mlflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/python:3.11-slim9534e5a8e315
pip@24.0
26.1.2

Open the chart page →

885
pgadminsb-helm-charts0.3.01 of 1See more

pgadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.13561c1f8f99f2
pip@24.0
26.1.2

Open the chart page →

1,712
scapyscapy-containerised0.3.41 of 2See more

scapy scapy-containerised 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
saidsef/scapy-containerised:v2025.02f17f7c435891
pip@24.3.1
26.1.2

Open the chart page →

2,817
nvme-exporterschichtelVerified publisher0.1.61 of 1See more

nvme-exporter schichtel 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/b-it-projects-gmbh/nvme_exporter:lateste70307b193c6
pip@23.0.1
26.1.2

Open the chart page →

1,071
pev2schichtelVerified publisher0.3.01 of 1See more

pev2 schichtel 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
dalibo/explain.dalibo.com:2.20.12a0b749c2f7f
pip@25.3
26.1.2

Open the chart page →

1,179
syncstorageschichtelVerified publisher0.1.11 of 1See more

syncstorage schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
mozilla/syncstorage-rs:0.15.893752877dced
pip@20.3.4
26.1.2

Open the chart page →

1,318
mikrotik-exporterschoolguys-helmcharts0.2.41 of 1See more

mikrotik-exporter schoolguys-helmcharts 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/akpw/mktxp:1.2.17bd6f22f7db0a
pip@25.3
26.1.2

Open the chart page →

583
wyoming-faster-whisperschoolguys-helmcharts0.1.41 of 1See more

wyoming-faster-whisper schoolguys-helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
rhasspy/wyoming-whisper:3.5.0308b7959a925
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.1.2
no fix listed

Open the chart page →

2,196
wyoming-piperschoolguys-helmcharts0.1.41 of 1See more

wyoming-piper schoolguys-helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
rhasspy/wyoming-piper:2.3.169b7f797ae3a
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.1.2
no fix listed

Open the chart page →

1,770
sealed-secrets-uisealed-secrets-uiVerified publisher0.0.81 of 1See more

sealed-secrets-ui sealed-secrets-ui 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
pip@24.3.1
26.1.2

Open the chart page →

4,570
search-proxysearch-proxy2026.38.01 of 1See more

search-proxy search-proxy 2026.38.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
pip@25.0.1
26.1.2

Open the chart page →

1,262
seawise-dashboardseawiseVerified publisher1.7.11 of 1See more

seawise-dashboard seawise 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
shwcloud/seawise-backup:v1.7.1a97479a54df4
pip@24.0
26.1.2

Open the chart page →

1,078
pagessekharpkube1.0.01 of 3See more

pages sekharpkube 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
seldon-core-analyticsseldon1.17.11 of 8See more

seldon-core-analytics seldon 1.17.1

1 of the 8 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
pip@20.1
26.1.2

Open the chart page →

10,733
seldon-core-loadtestingseldon0.2.01 of 1See more

seldon-core-loadtesting seldon 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
seldonio/locust-core:0.81d0da98a2d76
pip@8.1.1
python-pip@8.1.1-2ubuntu0.4
26.1.2
no fix listed

Open the chart page →

23,022
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
pip@19.3.1
26.1.2

Open the chart page →

21,997
semaphoresemaphore-light1.0.01 of 1See more

semaphore semaphore-light 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
semaphoreui/semaphore:latest3996804607eb
pip@24.3.1
26.1.2

Open the chart page →

1,674
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.4.01bbda887bc53
pip@8.1.2
26.1.2

Open the chart page →

10,972
ccx-monitoringseveralnines0.6.211 of 7See more

ccx-monitoring severalnines 0.6.21

1 of the 7 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
pip@25.3
26.1.2

Open the chart page →

7,709

Container images carrying it

1,223 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
sirrend/helmup-notifications-service:0.1.3997866417011
pip@23.3.1
26.1.2
1
sissbruecker/linkding:1.46.20c0a9a04c7eb
pip@25.2
26.1.2
1
sissbruecker/linkding:1.35.00c5dddf0b37c
pip@24.2
26.1.2
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
pip@25.1.1
26.1.2
1
skylenet/ethereum-genesis-generator:latest210353ce7c89
pip@20.3.4
26.1.2
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
pip@20.0.2
python-pip@20.0.2-5ubuntu1.9
26.1.2
no fix listed
1
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
pip@22.0.4
26.1.2
1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
pip@22.0.4
26.1.2
1
socialmediamacroscope/classification_train:0.1.207477060bba8
pip@22.0.4
26.1.2
1
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
pip@22.0.4
26.1.2
1
socialmediamacroscope/clowder_create_dataset:0.1.09b4211832429
pip@22.0.4
26.1.2
1
socialmediamacroscope/clowder_create_space:0.1.0999f2ff2c128
pip@22.0.4
26.1.2
1
socialmediamacroscope/clowder_list:0.1.051cb17626519
pip@22.0.4
26.1.2
1
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
pip@22.0.4
26.1.2
1
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
pip@9.0.1
python-pip@9.0.1-2.3~ubuntu1.18.04.8
26.1.2
no fix listed
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
pip@23.0.1
26.1.2
1
socialmediamacroscope/image_crawler:0.1.2f508216be63c
pip@9.0.1
python-pip@9.0.1-2.3~ubuntu1.18.04.8
26.1.2
no fix listed
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
pip@23.0.1
26.1.2
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
pip@23.0.1
26.1.2
1
socialmediamacroscope/screen_name_prompt:0.1.2724f3f5702e0
pip@22.0.4
26.1.2
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
pip@23.0.1
26.1.2
1
softonic/gar-exporter:0.2.1a64d6c0e0ae5
pip@20.2.4
26.1.2
1
softonic/mysql-backup:0.4.0d9487a8dd70f
pip@18.1
26.1.2
1
sokushinbutsu/devnopes:latest0bbd90448671
pip@24.0
26.1.2
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
pip@20.0.2
python-pip@20.0.2-5ubuntu1.6
26.1.2
no fix listed
1
speckle/speckle-monitor-deployment:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb2faf1508c1d3
pip@23.0.1
26.1.2
1
speckle/speckle-monitor-deployment:2.20.2-branch.testing4.134160-9fad4b23c8fbe855665
pip@23.0.1
26.1.2
1
speckle/speckle-monitor-deployment:2.20.6-branch.testing1.154030-9b09114738c77eb6f97
pip@23.0.1
26.1.2
1
speckle/speckle-monitor-deployment:2.18.12-branch.testing3.88744-f55b34181335b40696a
pip@23.0.1
26.1.2
1
speckle/speckle-monitor-deployment:2.19.2-branch.hotfix-2.19.1.124125-665e7e1b696ac5022ab
pip@23.0.1
26.1.2
1
speckle/speckle-monitor-deployment:2.21.3-branch.testing5.219631-2153befcf72ad0f25fb
pip@23.0.1
26.1.2
1
speckle/speckle-monitor-deployment:2.18.11-branch.testing2.88634-335d469d6790a97ad47
pip@23.0.1
26.1.2
1
speckle/speckle-monitor-deployment:2.17.14-branch.testing.72707.921a5f8ff1641ac3f1b
pip@23.0.1
26.1.2
1
sruthitanneru/pi-sample:ui-lateste565ea454ffd
pip@24.3.1
26.1.2
1
sslhep/servicex_app:v1.8.51d12f943cec5
pip@23.0.1
26.1.2
1
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
pip@23.0.1
26.1.2
1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
pip@23.0.1
26.1.2
1
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
pip@23.0.1
26.1.2
1
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
pip@23.0.1
26.1.2
1
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
pip@23.0.1
26.1.2
1
sslhep/servicex-did-finder:v1.8.5ab0090083567
pip@26.0.1
26.1.2
1
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
pip@26.0.1
26.1.2
1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
pip@26.0.1
26.1.2
1
sslhep/x509-secrets:v1.8.5d9e9ecb12d59
pip@22.3.1
26.1.2
1
stackstorm/st2actionrunner:3.888235ba70cad
pip@20.3.3
26.1.2
1
stackstorm/st2api:3.86f56d239d280
pip@20.3.3
26.1.2
1
stackstorm/st2auth:3.833ecfda16608
pip@20.3.3
26.1.2
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
pip@20.3.3
26.1.2
1
stackstorm/st2notifier:3.8f190a6212195
pip@20.3.3
26.1.2
1
stackstorm/st2rulesengine:3.8259503496ff9
pip@20.3.3
26.1.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.