StackRadar

CVE-2026-8643

High

Advisory

Published 1 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.0
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,282
of 17,790 indexed, latest versions
Container images
1,231
deployed by those charts
Fix available
1 of 2
affected packages

pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory

Carried by container images the latest versions of 1,282 of 17,790 indexed charts deploy, on 1,231 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+67 more26.1.21,224
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 moreno fix listed141
OSV records
GHSA-wf93-45jw-7689UBUNTU-CVE-2026-8643DEBIAN-CVE-2026-8643
Also known as
PYSEC-2026-196

Charts affected

1,282 by stars
ChartLatestAffected imagesRadar Score
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3411 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
speckle/speckle-monitor-deployment:2.18.12-branch.testing3.88744-f55b34181335b40696a
pip@23.0.1
26.1.2

Open the chart page →

14,299
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
speckle/speckle-monitor-deployment:2.20.2-branch.testing4.134160-9fad4b23c8fbe855665
pip@23.0.1
26.1.2

Open the chart page →

16,114
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
speckle/speckle-monitor-deployment:2.21.3-branch.testing5.219631-2153befcf72ad0f25fb
pip@23.0.1
26.1.2

Open the chart page →

15,725
speedtest-exporterspeedtest-exporter0.2.21 of 1See more

speedtest-exporter speedtest-exporter 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.5.4f1064d49124c
pip@22.3
26.1.2

Open the chart page →

741
downscalersqream-chartsVerified publisher1.0.01 of 1See more

downscaler sqream-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.05d328c003efe
pip@22.3.1
26.1.2

Open the chart page →

1,009
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,242
servicexssl-hep1.8.512 of 16See more

servicex ssl-hep 1.8.5

12 of the 16 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/python:3.1070c9cc675605
pip@23.0.1
26.1.2
ncsa/checks:main0b738bbc8d70
pip@24.0
26.1.2
sslhep/servicex_app:v1.8.51d12f943cec5
pip@23.0.1
26.1.2
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
pip@23.0.1
26.1.2
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
pip@23.0.1
26.1.2
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
pip@23.0.1
26.1.2
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
pip@23.0.1
26.1.2
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
pip@23.0.1
26.1.2
sslhep/servicex-did-finder:v1.8.5ab0090083567
pip@26.0.1
26.1.2
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
pip@26.0.1
26.1.2
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
pip@26.0.1
26.1.2
sslhep/x509-secrets:v1.8.5d9e9ecb12d59
pip@22.3.1
26.1.2

Open the chart page →

67,262
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
pip@9.0.3
26.1.2

Open the chart page →

28,515
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
pip@19.0.3
26.1.2

Open the chart page →

2,060
restful-distributed-lock-managerstakaterVerified publisher1.0.41 of 1See more

restful-distributed-lock-manager stakater 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
pip@9.0.1
26.1.2

Open the chart page →

3,117
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
pip@23.2.1
26.1.2

Open the chart page →

20,321
horcruxstakewise1.0.11 of 1See more

horcrux stakewise 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
stakewiselabs/bls-horcrux:v1.0.02afd0c0b34cb
pip@21.0
26.1.2

Open the chart page →

1,421
verostakewise0.8.31 of 2See more

vero stakewise 0.8.3

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
pip@24.2
26.1.2

Open the chart page →

3,475
stalwartstalwart-helmVerified publisher0.7.181 of 2See more

stalwart stalwart-helm 0.7.18

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/python:3.12-alpineb64631e04e49
pip@25.0.1
26.1.2

Open the chart page →

1,425
open-appsec-injectorstartechnicaVerified publisher1.1.21 of 3See more

open-appsec-injector startechnica 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
pip@23.0.1
26.1.2

Open the chart page →

4,326
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.12.089739be9ff38
pip@21.0.1
26.1.2

Open the chart page →

16,537
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
pip@20.2.3
26.1.2

Open the chart page →

3,044
prometheus-operatorstatcan0.2.21 of 7See more

prometheus-operator statcan 0.2.2

1 of the 7 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
pip@20.1
26.1.2

Open the chart page →

12,251
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,242
storageclass-routerstorageclass-routerVerified publisher0.4.11 of 1See more

storageclass-router storageclass-router 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/maxiv/storageclass-router:0.4.160725dab588c
pip@24.0
26.1.2

Open the chart page →

1,057
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
pip@20.0.2
python-pip@20.0.2-5ubuntu1.10
26.1.2
no fix listed

Open the chart page →

10,214
studygovernorstudy-governorVerified publisher0.1.381 of 3See more

studygovernor study-governor 0.1.38

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
pip@22.0.4
26.1.2

Open the chart page →

1,447
artifactory-cleanupsubshellVerified publisher1.0.11 of 1See more

artifactory-cleanup subshell 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
devopshq/artifactory-cleanup:1.0.1830e093bffa91
pip@23.0.1
26.1.2

Open the chart page →

2,551
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
pip@24.0
26.1.2

Open the chart page →

4,799
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
pip@23.0.1
26.1.2

Open the chart page →

13,463
3d-printing-cost-calculatorssudo-kraken-3d-printing-cost-calculatorsVerified publisher0.1.41 of 1See more

3d-printing-cost-calculators sudo-kraken-3d-printing-cost-calculators 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/3d-printing-cost-calculators:v1.1.1220c5e4e1a3d
pip@25.2
26.1.2

Open the chart page →

2,693
authentik-webfinger-proxysudo-kraken-authentik-webfinger-proxyVerified publisher0.1.41 of 1See more

authentik-webfinger-proxy sudo-kraken-authentik-webfinger-proxy 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/authentik-webfinger-proxy:v1.1.1e1351a977607
pip@25.2
26.1.2

Open the chart page →

2,773
fantasy-dice-chambersudo-kraken-fantasy-dice-chamberVerified publisher0.1.31 of 1See more

fantasy-dice-chamber sudo-kraken-fantasy-dice-chamber 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/fantasy-dice-chamber:v1.3.299fd4cb0f4fe
pip@25.2
26.1.2

Open the chart page →

2,805
finances-trackersudo-kraken-finances-trackerVerified publisher0.1.51 of 1See more

finances-tracker sudo-kraken-finances-tracker 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/finances-tracker:v1.1.1c73527cde81c
pip@25.2
26.1.2

Open the chart page →

2,773
flaresolverrsudo-kraken-flaresolverrVerified publisher2.1.41 of 1See more

flaresolverr sudo-kraken-flaresolverr 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
pip@25.2
26.1.2

Open the chart page →

33,864
jf-pushover-webhooksudo-kraken-jf-pushover-webhookVerified publisher0.1.31 of 1See more

jf-pushover-webhook sudo-kraken-jf-pushover-webhook 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/jf-pushover-webhook:v1.1.0ee9cf22a39ab
pip@25.2
26.1.2

Open the chart page →

2,773
qbittorrentsudo-kraken-qbittorrentVerified publisher5.1.51 of 2See more

qbittorrent sudo-kraken-qbittorrent 5.1.5

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/home-operations/qbittorrent:5.1.4bb82ad6668f8
pip@25.3
26.1.2

Open the chart page →

2,137
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,242
surogate-hubsurogate-hubVerified publisher2.1.51 of 1See more

surogate-hub surogate-hub 2.1.5

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
pip@26.1.1
26.1.2

Open the chart page →

3,494
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
mher/flower:2.051c3c3db5be3
pip@23.1.2
26.1.2

Open the chart page →

4,701
csv-viewsvtech-public-helm-charts1.0.01 of 1See more

csv-view svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
svtechnmaa/svtech_csv:v1.0.1b9d7ecf8de24
pip@20.2.2
26.1.2

Open the chart page →

1,220
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
pip@20.2.4
26.1.2

Open the chart page →

12,712
icinga2svtech-public-helm-charts1.0.01 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
pip@9.0.3
26.1.2

Open the chart page →

5,535
icinga2-reportsvtech-public-helm-charts1.0.01 of 1See more

icinga2-report svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
trungkien210493/icinga2-report:v1.7.12cc8c3763c4c
pip@20.1.1
26.1.2

Open the chart page →

1,779
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
pip@20.2.4
26.1.2

Open the chart page →

5,883
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
pip@24.0
26.1.2

Open the chart page →

18,846
rundeck-option-providersvtech-public-helm-charts1.0.01 of 2See more

rundeck-option-provider svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
pip@20.2.2
26.1.2

Open the chart page →

1,428
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
pip@25.1.1
26.1.2

Open the chart page →

2,402
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
pip@23.0.1
26.1.2

Open the chart page →

11,272
gtmetrix-bqt3n1.0.01 of 1See more

gtmetrix-bq t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
t3nde/gtmetrix-bq:0.2.0d2939e9a719b
pip@20.1
26.1.2

Open the chart page →

1,287
take-the-helmtake-the-helm0.1.01 of 1See more

take-the-helm take-the-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
cadmusthefounder/lnd:take-the-helm-0.1.0e596c5fbf80f
pip@22.0.4
26.1.2

Open the chart page →

805
democharttech-challenge0.1.02 of 4See more

demochart tech-challenge 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
alexvm6/generator:latestfb99ee4f760a
pip@22.3.1
26.1.2
alexvm6/pythonalex:latest89a05786879c
pip@22.3.1
26.1.2

Open the chart page →

3,630
rundeck-exportertechpreta0.1.91 of 1See more

rundeck-exporter techpreta 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
phsmith/rundeck-exporter:2.6.10265a7616ae8
pip@22.3.1
26.1.2

Open the chart page →

1,104
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
pip@8.1.2
26.1.2

Open the chart page →

4,240
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
pip@23.1.2
26.1.2

Open the chart page →

21,040

Container images carrying it

1,231 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
pip@23.0.1
26.1.2
1
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
pip@9.0.3
26.1.2
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.1.2
no fix listed
1
ghcr.io/aws-exporters/prometheus-ecr-exporter:0.1.442b0c87470d6
pip@20.3.4
26.1.2
1
ghcr.io/aws-exporters/prometheus-inspector-exporter:0.0.29c7c11293b3c
pip@20.3.4
26.1.2
1
ghcr.io/axoflow/axosyslog:4.5.0aa7831e207cd
pip@23.3.1
26.1.2
1
ghcr.io/bensoer/external-secrets-reloader:v0.1.38e31b5a81853
pip@24.0
26.1.2
1
ghcr.io/bensoer/sibyl:v0.2.06dca4455fde3
pip@24.0
26.1.2
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
pip@25.2
26.1.2
1
ghcr.io/b-it-projects-gmbh/nvme_exporter:lateste70307b193c6
pip@23.0.1
26.1.2
1
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
pip@24.2
26.1.2
1
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
pip@20.3.4
26.1.2
1
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
pip@20.3.4
26.1.2
1
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
pip@25.0
26.1.2
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
pip@24.0
python-pip@24.0+dfsg-1ubuntu1.3
26.1.2
no fix listed
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
pip@24.0
python-pip@24.0+dfsg-1ubuntu1.3
26.1.2
no fix listed
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
pip@24.0
python-pip@24.0+dfsg-1ubuntu1.3
26.1.2
no fix listed
1
ghcr.io/caas-team/py-kube-downscaler:26.4.0af05a098b0d2
pip@25.0.1
26.1.2
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
pip@24.3.1
26.1.2
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
pip@24.3.1
26.1.2
1
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
pip@25.0.1
26.1.2
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.1.2
no fix listed
1
ghcr.io/cleanuparr/cleanuparr:2.10.68136c3beda7a
pip@24.0
python-pip@24.0+dfsg-1ubuntu1.3
26.1.2
no fix listed
1
ghcr.io/cloudnative-pg/postgresql:18899d3ed526b6
pip@20.3.4
26.1.2
1
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
pip@20.3.4
26.1.2
1
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
pip@24.3.1
26.1.2
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
pip@23.0.1
26.1.2
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
pip@24.2
26.1.2
1
ghcr.io/ctfd/ctfd:3.8.2870e396fddf8
pip@24.0
26.1.2
1
ghcr.io/cunningpike/fediblockhole:0.4.22abc5f0350dc
pip@22.3.1
26.1.2
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
pip@24.3.1
26.1.2
1
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latestf9f34c8ed688
pip@25.0.1
26.1.2
1
ghcr.io/dask/dask:2024.1.0080150de7d86
pip@23.2.1
26.1.2
1
ghcr.io/dask/dask-gateway-server:2024.1.0881e7acfc5a0
pip@23.2.1
26.1.2
1
ghcr.io/dask/dask-gateway-server:2026.3.0afa5a729114e
pip@25.2
26.1.2
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
pip@25.0.1
26.1.2
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
pip@23.3.2
26.1.2
1
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
pip@25.1.1
26.1.2
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
pip@23.0.1
26.1.2
1
ghcr.io/dgtlmoon/changedetection.io:0.60.47bb6963b730d
pip@24.0
26.1.2
1
ghcr.io/dgtlmoon/changedetection.io:0.60.6eb4a9f718801
pip@24.0
26.1.2
1
ghcr.io/dgtlmoon/changedetection.io:0.60.3:latestecacd9fd0c66
pip@24.0
26.1.2
1
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
pip@21.2.4
26.1.2
1
ghcr.io/dgtlmoon/changedetection.io:0.60.5f69554198005
pip@24.0
26.1.2
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
pip@24.0
python-pip@24.0+dfsg-1ubuntu1.1
26.1.2
no fix listed
1
ghcr.io/dmunozv04/isponsorblocktv:v2.9.05b8cfa805cb6
pip@25.3
26.1.2
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
pip@22.0.4
26.1.2
1
ghcr.io/dodevops/azure-app-exporter/azure-app-exporter:0.1.38b472877847f5
pip@21.2.4
26.1.2
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
pip@23.2.1
26.1.2
1
ghcr.io/dynamia-ai/hami-enterprise:v2.10.0-r0-openshift.c4e22e88745504757300
pip@9.0.3
26.1.2
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.