CVE-2026-8643
HighAdvisory
Published 1 Jun 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.0
- base score, highest
- EPSS
- 0.003
- 25th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,282
- of 17,787 indexed, latest versions
- Container images
- 1,231
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Carried by container images the latest versions of 1,282 of 17,787 indexed charts deploy, on 1,231 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pippypi | 1.5.4, 8.1.1, 8.1.2, 9.0.0+67 more | 26.1.2 | 1,224 |
| python-pipdeb | 1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 more | no fix listed | 141 |
- OSV records
- GHSA-wf93-45jw-7689UBUNTU-CVE-2026-8643DEBIAN-CVE-2026-8643
- Also known as
- PYSEC-2026-196
Charts affected
1,282 by stars
Container images carrying it
1,231 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| alpine/ | e5c0b053fed7 | pip | 26.1.2 | 1 |
| alpine/ | eec354133193 | pip | 26.1.2 | 1 |
| alpine/ | fc059f056ad0 | pip | 26.1.2 | 1 |
| amagdi888/ | d8a10fc8faf6 | pip | 26.1.2 | 1 |
| amancevice/ | c8c04bfe3d66 | pip | 26.1.2 | 1 |
| amd64/ | e20a653e0f51 | pip | 26.1.2 | 1 |
| amundsendev/ | 69e7915e61c1 | pip | 26.1.2 | 1 |
| amundsendev/ | 4d98eb21f5f9 | pip | 26.1.2 | 1 |
| amundsendev/ | 99dda9502c3e | pip | 26.1.2 | 1 |
| anchore/ | bde9eedf639d | pip | 26.1.2 | 1 |
| anchore/ | ed9b3badd17c | pip | 26.1.2 | 1 |
| andrewgolikov55/ | fcc001b61c0e | pip python-pip | 26.1.2 no fix listed | 1 |
| andreymileshin/ | f7b300bc9e66 | pip | 26.1.2 | 1 |
| andreymileshin/ | e0825acc9e48 | pip | 26.1.2 | 1 |
| apache/ | 64e58748b6b9 | pip | 26.1.2 | 1 |
| apache/ | ce90bdc3d2af | pip | 26.1.2 | 1 |
| apache/ | e5560ad0b86e | pip | 26.1.2 | 1 |
| apache/ | a7d9970c148f | pip | 26.1.2 | 1 |
| apache/ | af361b20bec0 | pip | 26.1.2 | 1 |
| apachepulsar/ | 16f9fdab3fa6 | pip python-pip | 26.1.2 no fix listed | 1 |
| apachepulsar/ | 3b262ab7a7d9 | pip python-pip | 26.1.2 no fix listed | 1 |
| apachepulsar/ | 4db6ff0b4045 | pip | 26.1.2 | 1 |
| apachepulsar/ | 9c9947de139d | pip python-pip | 26.1.2 no fix listed | 1 |
| apachepulsar/ | d056c89b7131 | pip | 26.1.2 | 1 |
| apachepulsar/ | d538416d5afe | pip | 26.1.2 | 1 |
| apache/ | 76c176e8a0e4 | pip python-pip | 26.1.2 no fix listed | 1 |
| apache/ | 975ab033580d | pip | 26.1.2 | 1 |
| apache/ | ab9467fd712c | pip | 26.1.2 | 1 |
| apecloud/ | 8ac9947a2c84 | pip | 26.1.2 | 1 |
| apsl/ | 51e2de5c2c70 | pip | 26.1.2 | 1 |
| aquasec/ | 0bf607ce9308 | pip | 26.1.2 | 1 |
| archish27/ | 6610071a2101 | pip | 26.1.2 | 1 |
| archivebox/ | 1a5a37331091 | pip | 26.1.2 | 1 |
| arconixforge/ | c08d7c438966 | pip | 26.1.2 | 1 |
| aristidetm/ | 469dbc951224 | pip | 26.1.2 | 1 |
| aristidetm/ | ccb516cb8474 | pip | 26.1.2 | 1 |
| arthurjguerra18/ | f540af20b307 | pip | 26.1.2 | 1 |
| arunvelsriram/ | 655ad18fd8d6 | pip python-pip | 26.1.2 no fix listed | 1 |
| asdkant/ | a23d8bf7c885 | pip | 26.1.2 | 1 |
| assistiot/ | c3adbab6a3e7 | pip | 26.1.2 | 1 |
| assistiot/ | 0aacefac9677 | pip | 26.1.2 | 1 |
| assistiot/ | 0518b63a2e69 | pip | 26.1.2 | 1 |
| assistiot/ | 0fce3ea719a5 | pip | 26.1.2 | 1 |
| assistiot/ | 792715dd3084 | pip | 26.1.2 | 1 |
| assistiot/ | 0df4b4fa899a | pip | 26.1.2 | 1 |
| assistiot/ | 30812ba93555 | pip python-pip | 26.1.2 no fix listed | 1 |
| assistiot/ | 44a37b00d4f8 | pip | 26.1.2 | 1 |
| assistiot/ | a942dc14030a | pip | 26.1.2 | 1 |
| assistiot/ | 8b5d118bdf0e | pip | 26.1.2 | 1 |
| assistiot/ | 7d6a0d534c7f | pip | 26.1.2 | 1 |