StackRadar

CVE-2026-8643

High

Advisory

Published 1 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.0
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,282
of 17,787 indexed, latest versions
Container images
1,231
deployed by those charts
Fix available
1 of 2
affected packages

pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory

Carried by container images the latest versions of 1,282 of 17,787 indexed charts deploy, on 1,231 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+67 more26.1.21,224
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 moreno fix listed141
OSV records
GHSA-wf93-45jw-7689UBUNTU-CVE-2026-8643DEBIAN-CVE-2026-8643
Also known as
PYSEC-2026-196

Charts affected

1,282 by stars
ChartLatestAffected imagesRadar Score
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3411 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
speckle/speckle-monitor-deployment:2.18.12-branch.testing3.88744-f55b34181335b40696a
pip@23.0.1
26.1.2

Open the chart page →

14,245
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
speckle/speckle-monitor-deployment:2.20.2-branch.testing4.134160-9fad4b23c8fbe855665
pip@23.0.1
26.1.2

Open the chart page →

16,050
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
speckle/speckle-monitor-deployment:2.21.3-branch.testing5.219631-2153befcf72ad0f25fb
pip@23.0.1
26.1.2

Open the chart page →

14,500
speedtest-exporterspeedtest-exporter0.2.21 of 1See more

speedtest-exporter speedtest-exporter 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.5.4f1064d49124c
pip@22.3
26.1.2

Open the chart page →

741
downscalersqream-chartsVerified publisher1.0.01 of 1See more

downscaler sqream-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.05d328c003efe
pip@22.3.1
26.1.2

Open the chart page →

1,009
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
servicexssl-hep1.8.512 of 16See more

servicex ssl-hep 1.8.5

12 of the 16 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/python:3.1070c9cc675605
pip@23.0.1
26.1.2
ncsa/checks:main0b738bbc8d70
pip@24.0
26.1.2
sslhep/servicex_app:v1.8.51d12f943cec5
pip@23.0.1
26.1.2
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
pip@23.0.1
26.1.2
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
pip@23.0.1
26.1.2
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
pip@23.0.1
26.1.2
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
pip@23.0.1
26.1.2
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
pip@23.0.1
26.1.2
sslhep/servicex-did-finder:v1.8.5ab0090083567
pip@26.0.1
26.1.2
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
pip@26.0.1
26.1.2
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
pip@26.0.1
26.1.2
sslhep/x509-secrets:v1.8.5d9e9ecb12d59
pip@22.3.1
26.1.2

Open the chart page →

65,130
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
pip@9.0.3
26.1.2

Open the chart page →

28,165
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
pip@19.0.3
26.1.2

Open the chart page →

2,060
restful-distributed-lock-managerstakaterVerified publisher1.0.41 of 1See more

restful-distributed-lock-manager stakater 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
pip@9.0.1
26.1.2

Open the chart page →

3,116
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
pip@23.2.1
26.1.2

Open the chart page →

18,426
horcruxstakewise1.0.11 of 1See more

horcrux stakewise 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
stakewiselabs/bls-horcrux:v1.0.02afd0c0b34cb
pip@21.0
26.1.2

Open the chart page →

1,421
verostakewise0.8.31 of 2See more

vero stakewise 0.8.3

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
pip@24.2
26.1.2

Open the chart page →

3,180
stalwartstalwart-helmVerified publisher0.7.181 of 2See more

stalwart stalwart-helm 0.7.18

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/python:3.12-alpineb64631e04e49
pip@25.0.1
26.1.2

Open the chart page →

1,381
open-appsec-injectorstartechnicaVerified publisher1.1.21 of 3See more

open-appsec-injector startechnica 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
pip@23.0.1
26.1.2

Open the chart page →

4,315
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.12.089739be9ff38
pip@21.0.1
26.1.2

Open the chart page →

16,508
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
pip@20.2.3
26.1.2

Open the chart page →

3,044
prometheus-operatorstatcan0.2.21 of 7See more

prometheus-operator statcan 0.2.2

1 of the 7 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
pip@20.1
26.1.2

Open the chart page →

12,237
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
storageclass-routerstorageclass-routerVerified publisher0.4.11 of 1See more

storageclass-router storageclass-router 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
quay.io/maxiv/storageclass-router:0.4.160725dab588c
pip@24.0
26.1.2

Open the chart page →

1,057
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
pip@20.0.2
python-pip@20.0.2-5ubuntu1.10
26.1.2
no fix listed

Open the chart page →

10,182
studygovernorstudy-governorVerified publisher0.1.381 of 3See more

studygovernor study-governor 0.1.38

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
pip@22.0.4
26.1.2

Open the chart page →

1,447
artifactory-cleanupsubshellVerified publisher1.0.11 of 1See more

artifactory-cleanup subshell 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
devopshq/artifactory-cleanup:1.0.1830e093bffa91
pip@23.0.1
26.1.2

Open the chart page →

2,540
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
pip@24.0
26.1.2

Open the chart page →

4,782
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
pip@23.0.1
26.1.2

Open the chart page →

12,937
3d-printing-cost-calculatorssudo-kraken-3d-printing-cost-calculatorsVerified publisher0.1.41 of 1See more

3d-printing-cost-calculators sudo-kraken-3d-printing-cost-calculators 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/3d-printing-cost-calculators:v1.1.1220c5e4e1a3d
pip@25.2
26.1.2

Open the chart page →

2,577
authentik-webfinger-proxysudo-kraken-authentik-webfinger-proxyVerified publisher0.1.41 of 1See more

authentik-webfinger-proxy sudo-kraken-authentik-webfinger-proxy 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/authentik-webfinger-proxy:v1.1.1e1351a977607
pip@25.2
26.1.2

Open the chart page →

2,657
fantasy-dice-chambersudo-kraken-fantasy-dice-chamberVerified publisher0.1.31 of 1See more

fantasy-dice-chamber sudo-kraken-fantasy-dice-chamber 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/fantasy-dice-chamber:v1.3.299fd4cb0f4fe
pip@25.2
26.1.2

Open the chart page →

2,689
finances-trackersudo-kraken-finances-trackerVerified publisher0.1.51 of 1See more

finances-tracker sudo-kraken-finances-tracker 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/finances-tracker:v1.1.1c73527cde81c
pip@25.2
26.1.2

Open the chart page →

2,657
flaresolverrsudo-kraken-flaresolverrVerified publisher2.1.41 of 1See more

flaresolverr sudo-kraken-flaresolverr 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
pip@25.2
26.1.2

Open the chart page →

33,591
jf-pushover-webhooksudo-kraken-jf-pushover-webhookVerified publisher0.1.31 of 1See more

jf-pushover-webhook sudo-kraken-jf-pushover-webhook 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/jf-pushover-webhook:v1.1.0ee9cf22a39ab
pip@25.2
26.1.2

Open the chart page →

2,657
qbittorrentsudo-kraken-qbittorrentVerified publisher5.1.51 of 2See more

qbittorrent sudo-kraken-qbittorrent 5.1.5

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/home-operations/qbittorrent:5.1.4bb82ad6668f8
pip@25.3
26.1.2

Open the chart page →

2,130
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pip@25.3
26.1.2

Open the chart page →

20,233
surogate-hubsurogate-hubVerified publisher2.1.51 of 1See more

surogate-hub surogate-hub 2.1.5

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
pip@26.1.1
26.1.2

Open the chart page →

3,372
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
mher/flower:2.051c3c3db5be3
pip@23.1.2
26.1.2

Open the chart page →

4,687
csv-viewsvtech-public-helm-charts1.0.01 of 1See more

csv-view svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
svtechnmaa/svtech_csv:v1.0.1b9d7ecf8de24
pip@20.2.2
26.1.2

Open the chart page →

1,220
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
pip@20.2.4
26.1.2

Open the chart page →

12,708
icinga2svtech-public-helm-charts1.0.01 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
pip@9.0.3
26.1.2

Open the chart page →

5,101
icinga2-reportsvtech-public-helm-charts1.0.01 of 1See more

icinga2-report svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
trungkien210493/icinga2-report:v1.7.12cc8c3763c4c
pip@20.1.1
26.1.2

Open the chart page →

1,779
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
pip@20.2.4
26.1.2

Open the chart page →

5,880
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
pip@24.0
26.1.2

Open the chart page →

18,828
rundeck-option-providersvtech-public-helm-charts1.0.01 of 2See more

rundeck-option-provider svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
pip@20.2.2
26.1.2

Open the chart page →

1,428
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
pip@25.1.1
26.1.2

Open the chart page →

2,397
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
pip@23.0.1
26.1.2

Open the chart page →

10,545
gtmetrix-bqt3n1.0.01 of 1See more

gtmetrix-bq t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
t3nde/gtmetrix-bq:0.2.0d2939e9a719b
pip@20.1
26.1.2

Open the chart page →

1,287
take-the-helmtake-the-helm0.1.01 of 1See more

take-the-helm take-the-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
cadmusthefounder/lnd:take-the-helm-0.1.0e596c5fbf80f
pip@22.0.4
26.1.2

Open the chart page →

805
democharttech-challenge0.1.02 of 4See more

demochart tech-challenge 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
alexvm6/generator:latestfb99ee4f760a
pip@22.3.1
26.1.2
alexvm6/pythonalex:latest89a05786879c
pip@22.3.1
26.1.2

Open the chart page →

3,630
rundeck-exportertechpreta0.1.91 of 1See more

rundeck-exporter techpreta 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
phsmith/rundeck-exporter:2.6.10265a7616ae8
pip@22.3.1
26.1.2

Open the chart page →

1,104
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
pip@8.1.2
26.1.2

Open the chart page →

4,239
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2026-8643.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
pip@23.1.2
26.1.2

Open the chart page →

21,004

Container images carrying it

1,231 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
pip@23.0.1
26.1.2
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.1.2
no fix listed
1
assistiot/traffic-classification_api:2.0.0e32b87786142
pip@23.0.1
26.1.2
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
pip@23.0.1
python-pip@20.0.2-5ubuntu1.8
26.1.2
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
pip@23.0.1
26.1.2
1
azhar008/flaskapplication:latesta1e827b0adea
pip@21.2.4
26.1.2
1
badsmoke/wunderground_exporter:0.0.5c54c004f24cc
pip@21.0.1
26.1.2
1
balihb/block-pvc-scanner:0.2.45b95e1cf1158
pip@21.2.4
26.1.2
1
balihb/pod-pvc-mapping:0.2.4ee48e79f5d76
pip@21.2.4
26.1.2
1
baserow/backend:1.31.1e0b3c8130b91
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.1.2
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.1.2
no fix listed
1
bbvalabs/sensitive-data:1.0.13ea299ae63c0
pip@21.0.1
26.1.2
1
behnambm/docker-sample:v1bd3ad88afff9
pip@23.0.1
26.1.2
1
benbusby/whoogle-search:0.5.4f77f7e6e4ad2
pip@21.1.2
26.1.2
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
pip@23.0.1
26.1.2
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pip@23.0.1
26.1.2
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
pip@20.0.2
python-pip@20.0.2-5ubuntu1.6
26.1.2
no fix listed
1
billimek/comcastusage-for-influxdb:latest801bba1228ac
pip@10.0.1
26.1.2
1
billimek/prometheus-uptimerobot-exporter:0.0.1f14ccd7aad0e
pip@20.1.1
26.1.2
1
billimek/sb6183-for-influxdb:latestbf8158556035
pip@9.0.1
26.1.2
1
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
pip@23.3.2
26.1.2
1
blacktop/httpie:latestfc5e68e2f5ab
pip@18.1
26.1.2
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
pip@20.0.2
python-pip@20.0.2-5ubuntu1.6
26.1.2
no fix listed
1
bmeares/meerschaum:2.8.48e9c5bacaa82
pip@25.0
26.1.2
1
bnjbvr/kresus:0.22.137e216b182c8
pip@23.0.1
python-pip@23.0.1+dfsg-1
26.1.2
no fix listed
1
boky/postfix:5.1.0aafc77238423
pip@25.1.1
26.1.2
1
bootc/puppetboard:1.1.0f1383295e7be
pip@19.2.3
26.1.2
1
bryanalves/sickrage:latest42f0a130001d
pip@9.0.0
26.1.2
1
bugsink/bugsink:2ecdd84587746
pip@25.0.1
26.1.2
1
buildkite/agent:3.25.0aec38cfaae0e
pip@20.2.4
26.1.2
1
buntha/mlflow:2.1.1154542cc3083
pip@22.0.4
26.1.2
1
cadmusthefounder/lnd:take-the-helm-0.1.0e596c5fbf80f
pip@22.0.4
26.1.2
1
camerahub/camerahub:0.36.23a5af37dd6e1b
pip@22.0.4
26.1.2
1
camptocamp/bucket-cloner:latestacfafc308d88
pip@21.2.1
26.1.2
1
camptocamp/ekorre:0.1.035c91d5fda04
pip@20.0.2
26.1.2
1
camptocamp/pghoard:10bff736b15623
pip@18.1
26.1.2
1
camptocamp/snow-webhook:latest2924b43dbf40
pip@18.1
26.1.2
1
castai/hibernate:v0.14da62858c8381
pip@23.0.1
26.1.2
1
cbanuka/pythonapp:latestc742770d4247
pip@9.0.0
26.1.2
1
cdignam/kodiak:v0.54.05a6a55b39cee
pip@22.1.2
26.1.2
1
ceph/daemon:latest-nautilus90f30824a96e
pip@9.0.3
26.1.2
1
ceticasbl/pg-ldap-sync:latest6c0aa7567145
pip@18.1
26.1.2
1
chandanteekinavar/findery-market-product-service:1.0c49ff7c141c0
pip@23.0.1
26.1.2
1
chaostoolkit/back:latest734f3af86125
pip@20.2.4
26.1.2
1
chaostoolkit/front:latest7f4a7eb9f7df
pip@20.2.4
26.1.2
1
chaostoolkit/middle:latestb95ba4961cfc
pip@20.3
26.1.2
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
pip@26.0.1
26.1.2
1
cheyang/distributed-tf:1.6.046cc34755493
pip@9.0.1
26.1.2
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
pip@25.3
26.1.2
1
chocobozzz/peertube:v8.1.5052712130691
pip@25.1.1
python-pip@25.1.1+dfsg-1
26.1.2
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.