StackRadar

CVE-2026-8643

High

Advisory

Published 1 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.0
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,282
of 17,787 indexed, latest versions
Container images
1,231
deployed by those charts
Fix available
1 of 2
affected packages

pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory

Carried by container images the latest versions of 1,282 of 17,787 indexed charts deploy, on 1,231 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+67 more26.1.21,224
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 moreno fix listed141
OSV records
GHSA-wf93-45jw-7689UBUNTU-CVE-2026-8643DEBIAN-CVE-2026-8643
Also known as
PYSEC-2026-196

Charts affected

1,282 by stars
ChartLatestAffected imagesRadar Score
open-notificatiesopen-zaak0.7.01 of 4See more

open-notificaties open-zaak 0.7.0

1 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
openzaak/open-notificaties:1.3.02e65313b9b10
pip@22.0.4
26.1.2

Open the chart page →

2,850
opsopsVerified publisher1.2.02 of 2See more

ops ops 1.2.0

2 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
shaowenchen/ops-controller-manager:latest26da43bb5b66
pip@22.0.2
python-pip@22.0.2+dfsg-1ubuntu0.7
26.1.2
no fix listed
shaowenchen/ops-server:latest315444f703f4
pip@22.0.2
python-pip@22.0.2+dfsg-1ubuntu0.6
26.1.2
no fix listed

Open the chart page →

9,049
opta-agentopta-agentVerified publisher0.1.31 of 1See more

opta-agent opta-agent 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
runx1/opta-agent:latest0ca3867d3200
pip@22.0.4
26.1.2

Open the chart page →

1,543
ovh-snapshoterovh-snapshoterOfficialVerified publisher0.4.101 of 1See more

ovh-snapshoter ovh-snapshoter 0.4.10

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/hoverkraft-tech/ovh-snapshoter/app:0.4.1010d271f08ab3
pip@24.3.1
26.1.2

Open the chart page →

761
palworldpalworld-server-chartVerified publisher2.7.11 of 1See more

palworld palworld-server-chart 2.7.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.7.1401d3eb5c053
pip@25.1.1
python-pip@25.1.1+dfsg-1
26.1.2
no fix listed

Open the chart page →

3,694
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
pip@25.1.1
python-pip@25.1.1+dfsg-1
26.1.2
no fix listed

Open the chart page →

7,075
phonebook-chartphonebook-chart0.1.03 of 3See more

phonebook-chart phonebook-chart 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ahmetgrbzz/result_server:2.035c37ae2bafd
pip@24.0
26.1.2
ahmetgrbzz/web_server:2.0f018bafd2b0c
pip@24.0
26.1.2
library/mysql:5.74bc6bc963e6d
pip@23.0.1
26.1.2

Open the chart page →

3,032
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
pip@24.3.1
26.1.2

Open the chart page →

31,949
home-assistantpree-helm-chartsVerified publisher1.80.01 of 1See more

home-assistant pree-helm-charts 1.80.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
pip@26.0.1
26.1.2

Open the chart page →

2,139
pritunl-slack-apppritunl-slack-appVerified publisher0.1.71 of 1See more

pritunl-slack-app pritunl-slack-app 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
pip@22.2.2
26.1.2

Open the chart page →

2,871
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
gpappsoft/privacyidea-docker:3.12.2af7841adad26
pip@25.3
26.1.2

Open the chart page →

5,483
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
pip@25.0.1
26.1.2

Open the chart page →

8,203
pvc-exporterpvc-exporter0.1.31 of 1See more

pvc-exporter pvc-exporter 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
dockerid31415926/pvc-exporter:v0.1.35a1dd17e0e07
pip@21.2.4
26.1.2

Open the chart page →

1,762
kube-resource-reportrlex0.10.11 of 2See more

kube-resource-report rlex 0.10.1

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
hjacobs/kube-resource-report:22.11.0c173cd02f5af
pip@22.2.2
26.1.2

Open the chart page →

1,266
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg16d7db8f1085a3
pip@22.0.2
python-pip@22.0.2+dfsg-1ubuntu0.7
26.1.2
no fix listed

Open the chart page →

13,028
mealiertomik-helm-chartsVerified publisher0.0.21 of 1See more

mealie rtomik-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
pip@25.0.1
26.1.2

Open the chart page →

3,942
kyoorubxkubeVerified publisher0.1.102 of 9See more

kyoo rubxkube 0.1.10

2 of the 9 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
pip@24.3.1
26.1.2
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
pip@24.3.1
26.1.2

Open the chart page →

30,310
devpisb-helm-charts0.3.01 of 1See more

devpi sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
jonasal/devpi-server:6.17.0-alpineec1eee99a18d
pip@25.3
26.1.2

Open the chart page →

921
iopsciencemeshVerified publisher0.4.01 of 2See more

iop sciencemesh 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
cs3org/wopiserver:v9.4.202a9e78757b4
pip@23.0.1
26.1.2

Open the chart page →

4,052
viya4-home-dir-builderselerityVerified publisher1.1.01 of 2See more

viya4-home-dir-builder selerity 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/python:3.12-slim78387bc3881b
pip@25.0.1
26.1.2

Open the chart page →

864
sentry-k8ssentry-k8sVerified publisher1.4.13 of 11See more

sentry-k8s sentry-k8s 1.4.1

3 of the 11 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.6.683dbca3efd2a
pip@20.2.4
26.1.2
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
pip@24.3.1
26.1.2
ghcr.io/getsentry/snuba:26.7.210f8d164109b
pip@25.3
26.1.2

Open the chart page →

16,194
vuiseriohub1.0.62 of 3See more

vui seriohub 1.0.6

2 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
dserio83/velero-api:0.3.16b3d9115fee2
pip@25.1.1
python-pip@23.0.1+dfsg-1
26.1.2
no fix listed
dserio83/velero-watchdog:0.1.8d5deae589229
pip@23.0.1
26.1.2

Open the chart page →

11,545
k8s-appliershlomibendavidOfficialVerified publisher1.0.11 of 1See more

k8s-applier shlomibendavid 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
shlomibendavid/k8s-applier:0311240529a22ffbe0f04e
pip@24.0
26.1.2

Open the chart page →

1,206
kube-resource-reportslamdev0.1.31 of 2See more

kube-resource-report slamdev 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
hjacobs/kube-resource-report:21.2.145f93491c434
pip@21.0.1
26.1.2

Open the chart page →

1,534
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
pip@24.3.1
26.1.2

Open the chart page →

2,934
smallest-self-hostsmallest-self-hostVerified publisher0.2.21 of 12See more

smallest-self-host smallest-self-host 0.2.2

1 of the 12 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.26.1b8d5067137fe
pip@24.0
26.1.2

Open the chart page →

7,684
smarter-demosmarterOfficialVerified publisher0.1.52 of 7See more

smarter-demo smarter 0.1.5

2 of the 7 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
pip@20.0.2
python-pip@20.0.2-5ubuntu1.6
26.1.2
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
pip@20.0.2
python-pip@20.0.2-5ubuntu1.6
26.1.2
no fix listed

Open the chart page →

46,028
snappasssnappassVerified publisher0.4.31 of 3See more

snappass snappass 0.4.3

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
pip@25.0.1
26.1.2

Open the chart page →

3,019
mysql-backupsoftonic2.2.31 of 1See more

mysql-backup softonic 2.2.3

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
softonic/mysql-backup:0.4.0d9487a8dd70f
pip@18.1
26.1.2

Open the chart page →

547
alertasomeblackmagic0.2.31 of 2See more

alerta someblackmagic 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
alerta/alerta-web:8.5.04786b9eaa606
pip@20.1.1
26.1.2

Open the chart page →

3,162
healthchecksstackhelmVerified publisher0.1.01 of 2See more

healthchecks stackhelm 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
healthchecks/healthchecks:v2.8.1e82bb0836e30
pip@23.0.1
26.1.2

Open the chart page →

2,236
deschedulerstakaterVerified publisher1.0.101 of 1See more

descheduler stakater 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
stakater/descheduler:v0.3.0a47e96ebb285
pip@9.0.1
26.1.2

Open the chart page →

170
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
pip@21.1.2
python-pip@20.0.2-5ubuntu1.5
26.1.2
no fix listed

Open the chart page →

24,984
prometheus-pve-exporterstenicVerified publisher0.1.11 of 1See more

prometheus-pve-exporter stenic 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
prompve/prometheus-pve-exporter:2.0.1ff6749eb03b0
pip@20.1.1
26.1.2

Open the chart page →

2,469
streamlit-appstreamlit-appVerified publisher0.2.01 of 1See more

streamlit-app streamlit-app 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
sruthitanneru/pi-sample:ui-lateste565ea454ffd
pip@24.3.1
26.1.2

Open the chart page →

1,696
synapsesudermanjr1.1.51 of 1See more

synapse sudermanjr 1.1.5

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
pip@21.2.4
26.1.2

Open the chart page →

3,332
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.24.44138bea678f0
pip@23.1.2
26.1.2

Open the chart page →

9,108
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.24.44138bea678f0
pip@23.1.2
26.1.2

Open the chart page →

9,108
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
pip@24.0
26.1.2

Open the chart page →

12,910
taigaunxwaresVerified publisher2026.3.82 of 6See more

taiga unxwares 2026.3.8

2 of the 6 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
pip@24.0
26.1.2
taigaio/taiga-protected:latestfd4568a97a59
pip@26.1.1
26.1.2

Open the chart page →

9,172
upbot-operatorupbot-operator0.0.201 of 2See more

upbot-operator upbot-operator 0.0.20

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
alpine/k8s:1.28.13e5c0b053fed7
pip@24.2
26.1.2

Open the chart page →

4,461
urunnerurunnerOfficialVerified publisher0.7.01 of 1See more

urunner urunner 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/texano00/urunner:0.6.07c8be1dae3cd
pip@25.0.1
26.1.2

Open the chart page →

501
phonebook-chartusuladamsVerified publisher0.1.53 of 3See more

phonebook-chart usuladams 0.1.5

3 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
pip@23.0.1
26.1.2
paulkellerman/resultserver-app:1.0381eeccb0618
pip@22.3
26.1.2
paulkellerman/webserver-app:latest5a37b74f61b9
pip@22.3
26.1.2

Open the chart page →

3,176
verbacapverbacapVerified publisher1.0.71 of 1See more

verbacap verbacap 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
pip@23.3.1
26.1.2

Open the chart page →

2,232
sysbindingswallarmOfficialVerified publisher0.9.91 of 1See more

sysbindings wallarm 0.9.9

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
wallarm/sysbindings:v0.9.9c527865df85d
pip@22.2.1
26.1.2

Open the chart page →

657
yugabytewenerme2026.1.11 of 1See more

yugabyte wenerme 2026.1.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
yugabytedb/yugabyte:2026.1.1.0-b91de2e00278645
pip@9.0.3
26.1.2

Open the chart page →

355
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
pip@20.0.2
python-pip@20.0.2-5ubuntu1.11
26.1.2
no fix listed

Open the chart page →

7,883
pghoardwiremindVerified publisher0.8.11 of 1See more

pghoard wiremind 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
wiremind/pghoard:12-2019-11-264dea42c8166c
pip@19.3.1
26.1.2

Open the chart page →

2,952
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

7,728
wordpress-helmwordpress-helm0.2.91 of 4See more

wordpress-helm wordpress-helm 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:885b9bf2e29cf
pip@25.3
26.1.2

Open the chart page →

8,139

Container images carrying it

1,231 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/opsmxpublic/awsgit:v3-js15a6faada3d4
pip@22.0.4
26.1.2
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
pip@25.3
26.1.2
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
pip@9.0.3
26.1.2
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
pip@9.0.3
26.1.2
1
quay.io/opstree/k8s-sidecar:2.7.126aa9bb3386b
pip@26.0.1
26.1.2
1
quay.io/opstree/k8s-sidecar:2.7.37075d455b219
pip@26.1.1
26.1.2
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
pip@25.3
26.1.2
1
quay.io/ortelius/ms-dep-pkg-cud:main-v10.0.1670-g9abe110c0c881b509a
pip@25.3
26.1.2
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
pip@25.3
26.1.2
1
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
pip@25.3
26.1.2
1
quay.io/ortelius/ms-scorecard:main-v10.0.1276-g966a8a43337e52fdd4
pip@25.3
26.1.2
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
pip@25.3
26.1.2
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
pip@25.3
26.1.2
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
pip@24.0
26.1.2
1
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
pip@22.3.1
26.1.2
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
pip@20.2.4
26.1.2
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
pip@21.2.4
26.1.2
1
quay.io/stackgres/operator:1.19.1f241b0b20326
pip@23.2.1
26.1.2
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
pip@23.0.1
26.1.2
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
pip@24.0
python-pip@24.0+dfsg-1ubuntu1.3
26.1.2
no fix listed
1
registry.gitlab.com/dyff/dyff-api:0.57.4911acf4052e5
pip@25.0.1
26.1.2
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
pip@25.0.1
26.1.2
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
pip@25.0.1
26.1.2
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
pip@9.0.3
26.1.2
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
pip@20.0.2
python-pip@20.0.2-5ubuntu1.1
26.1.2
no fix listed
1
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
pip@20.3.3
26.1.2
1
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
pip@21.2.4
26.1.2
1
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
pip@21.2.4
26.1.2
1
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
pip@22.0.4
26.1.2
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
pip@23.3.2
26.1.2
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
pip@25.0.1
26.1.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.