CVE-2026-8643
HighAdvisory
Published 1 Jun 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.0
- base score, highest
- EPSS
- 0.003
- 25th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,282
- of 17,787 indexed, latest versions
- Container images
- 1,231
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Carried by container images the latest versions of 1,282 of 17,787 indexed charts deploy, on 1,231 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pippypi | 1.5.4, 8.1.1, 8.1.2, 9.0.0+67 more | 26.1.2 | 1,224 |
| python-pipdeb | 1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+25 more | no fix listed | 141 |
- OSV records
- GHSA-wf93-45jw-7689UBUNTU-CVE-2026-8643DEBIAN-CVE-2026-8643
- Also known as
- PYSEC-2026-196
Charts affected
1,282 by stars
Container images carrying it
1,231 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | 7dcddc01f13b | pip | 26.1.2 | 89 |
| library/ | 4bc6bc963e6d | pip | 26.1.2 | 22 |
| library/ | b3b90af2a655 | pip | 26.1.2 | 16 |
| quay.io/ | a6b3f707f883 | pip | 26.1.2 | 13 |
| oomk8s/ | 875814cc853d | pip python-pip | 26.1.2 no fix listed | 11 |
| library/ | 257388edf9c8 | pip | 26.1.2 | 6 |
| oomk8s/ | 7daa08b81954 | pip python-pip | 26.1.2 no fix listed | 6 |
| flaresolverr/ | 139dfee1c6f8 | pip | 26.1.2 | 5 |
| library/ | 4b40b165f348 | pip | 26.1.2 | 4 |
| ncsa/ | cc46a03e16ed | pip | 26.1.2 | 4 |
| opea/ | 0c25aab3f106 | pip | 26.1.2 | 4 |
| shashkist/ | 581de1fd6084 | pip | 26.1.2 | 4 |
| apache/ | 16b50bbef664 | pip | 26.1.2 | 3 |
| argoproj/ | 830e86cacefd | pip | 26.1.2 | 3 |
| cloudve/ | 4a3d7fae90bb | pip python-pip | 26.1.2 no fix listed | 3 |
| dnationcloud/ | 78fed4f3c130 | pip | 26.1.2 | 3 |
| dpage/ | 781369df9994 | pip | 26.1.2 | 3 |
| kiwigrid/ | 170069ff0976 | pip | 26.1.2 | 3 |
| kiwigrid/ | 4166a019eeaf | pip | 26.1.2 | 3 |
| kiwigrid/ | 7b98eecdf6d1 | pip | 26.1.2 | 3 |
| kiwigrid/ | cdb361e67b1b | pip | 26.1.2 | 3 |
| library/ | 66aec17cd21a | pip | 26.1.2 | 3 |
| library/ | 78387bc3881b | pip | 26.1.2 | 3 |
| paulkellerman/ | 381eeccb0618 | pip | 26.1.2 | 3 |
| paulkellerman/ | 5a37b74f61b9 | pip | 26.1.2 | 3 |
| prompve/ | 4867684c0a93 | pip | 26.1.2 | 3 |
| quay.io/ | 6545dac92173 | pip | 26.1.2 | 3 |
| quay.io/ | 35654389f8a9 | pip | 26.1.2 | 3 |
| quay.io/ | f402e6039b3c | pip | 26.1.2 | 3 |
| quay.io/ | a7dff785d821 | pip | 26.1.2 | 3 |
| alpine/ | 048f8d9c8cc7 | pip | 26.1.2 | 2 |
| amancevice/ | 12a0a9e66550 | pip | 26.1.2 | 2 |
| aquasec/ | e64fe49f059f | pip | 26.1.2 | 2 |
| architectminds/ | 9735e59a1085 | pip | 26.1.2 | 2 |
| blakeblackshear/ | 8330b0a265b8 | pip | 26.1.2 | 2 |
| confluentinc/ | ac776fad95a5 | pip | 26.1.2 | 2 |
| confluentinc/ | 7610a50b13e7 | pip | 26.1.2 | 2 |
| confluentinc/ | cae577096489 | pip | 26.1.2 | 2 |
| cs3org/ | 02a9e78757b4 | pip | 26.1.2 | 2 |
| dagster/ | 5947f9ae481c | pip | 26.1.2 | 2 |
| datawire/ | 8588eafe6862 | pip | 26.1.2 | 2 |
| devopsjourney1/ | bd1ec6838570 | pip | 26.1.2 | 2 |
| gradiant/ | 97657d56e927 | pip | 26.1.2 | 2 |
| hjacobs/ | 4b2147f47425 | pip | 26.1.2 | 2 |
| hjacobs/ | 58221b57d4d2 | pip | 26.1.2 | 2 |
| homebridge/ | 77c685a40911 | pip python-pip | 26.1.2 no fix listed | 2 |
| ilum/ | 624fd09528c8 | pip | 26.1.2 | 2 |
| istio/ | 0a5eb4795952 | pip | 26.1.2 | 2 |
| istio/ | 22a0410f35a8 | pip | 26.1.2 | 2 |
| jvstein/ | 7645ba790ea8 | pip | 26.1.2 | 2 |