StackRadar

CVE-2019-20477

Critical

Advisory

Published 19 Feb 2020In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.052
92nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

Deserialization of Untrusted Data in PyYAML

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
pyyamlpypi5.1, 5.1.1, 5.1.25.29
OSV records
GHSA-3pqx-4fqf-j49f
Also known as
PYSEC-2020-176

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
supersetcloudposse1.2.01 of 1See more

superset cloudposse 1.2.0

1 of the 1 container images this version deploys carry CVE-2019-20477.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
pyyaml@5.1.2
5.2

Open the chart page →

5,851
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2019-20477.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
pyyaml@5.1.2
5.2

Open the chart page →

52,919
aws-ecr-credentialarchitectminds1.4.21 of 1See more

aws-ecr-credential architectminds 1.4.2

1 of the 1 container images this version deploys carry CVE-2019-20477.

Container imageDigestPackageFixed in
architectminds/aws-kubectl:1.19735e59a1085
pyyaml@5.1
5.2

Open the chart page →

1,437
pghoardwiremindVerified publisher0.8.11 of 1See more

pghoard wiremind 0.8.1

1 of the 1 container images this version deploys carry CVE-2019-20477.

Container imageDigestPackageFixed in
wiremind/pghoard:12-2019-11-264dea42c8166c
pyyaml@5.1.2
5.2

Open the chart page →

2,952
aws-ecr-credentialaws-ecr-credentialVerified publisher1.5.21 of 1See more

aws-ecr-credential aws-ecr-credential 1.5.2

1 of the 1 container images this version deploys carry CVE-2019-20477.

Container imageDigestPackageFixed in
architectminds/aws-kubectl:1.19735e59a1085
pyyaml@5.1
5.2

Open the chart page →

1,437
prometheus-operatorcloudnativeapp6.4.01 of 7See more

prometheus-operator cloudnativeapp 6.4.0

1 of the 7 container images this version deploys carry CVE-2019-20477.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.0.186eb52513d59e
pyyaml@5.1.1
5.2

Open the chart page →

2,954
helpdeskdoubanVerified publisher0.3.31 of 2See more

helpdesk douban 0.3.3

1 of the 2 container images this version deploys carry CVE-2019-20477.

Container imageDigestPackageFixed in
douz/helpdesk:latest4384103d0219
pyyaml@5.1.2
5.2

Open the chart page →

4,550
redashinseefrlab2.1.01 of 3See more

redash inseefrlab 2.1.0

1 of the 3 container images this version deploys carry CVE-2019-20477.

Container imageDigestPackageFixed in
redash/redash:10.0.0.b503639392753c0376
pyyaml@5.1.2
5.2

Open the chart page →

3,314
marge-botmarge-bot1.1.01 of 1See more

marge-bot marge-bot 1.1.0

1 of the 1 container images this version deploys carry CVE-2019-20477.

Container imageDigestPackageFixed in
smarketshq/marge-bot:0.9.2cfc765b27e64
pyyaml@5.1
5.2

Open the chart page →

337
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2019-20477.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
pyyaml@5.1
5.2

Open the chart page →

88,546
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2019-20477.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
pyyaml@5.1
5.2

Open the chart page →

26,211
nem-monitoringopencord1.3.221 of 9See more

nem-monitoring opencord 1.3.22

1 of the 9 container images this version deploys carry CVE-2019-20477.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.20af151f677a63
pyyaml@5.1.2
5.2

Open the chart page →

4,612

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
amancevice/superset:0.35.212a0a9e66550
pyyaml@5.1.2
5.2
2
architectminds/aws-kubectl:1.19735e59a1085
pyyaml@5.1
5.2
2
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
pyyaml@5.1
5.2
2
douz/helpdesk:latest4384103d0219
pyyaml@5.1.2
5.2
1
kiwigrid/k8s-sidecar:0.0.186eb52513d59e
pyyaml@5.1.1
5.2
1
kiwigrid/k8s-sidecar:0.1.20af151f677a63
pyyaml@5.1.2
5.2
1
redash/redash:10.0.0.b503639392753c0376
pyyaml@5.1.2
5.2
1
smarketshq/marge-bot:0.9.2cfc765b27e64
pyyaml@5.1
5.2
1
wiremind/pghoard:12-2019-11-264dea42c8166c
pyyaml@5.1.2
5.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.