StackRadar

CVE-2021-21330

Low

Advisory

Published 26 Feb 2021In the index since 8 Sept 2026
Severity
Low
worst across findings
CVSS
3.1
base score, highest
EPSS
0.019
79th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
7
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
1 of 1
affected package

`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)

Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
aiohttppypi3.4.4, 3.5.4, 3.6.2, 3.7.1+1 more3.7.47
OSV records
GHSA-v6wp-4m6f-gcjg
Also known as
PYSEC-2021-76

Charts affected

7 by stars
ChartLatestAffected imagesRadar Score
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2021-21330.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
aiohttp@3.6.2
3.7.4

Open the chart page →

27,728
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2021-21330.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
aiohttp@3.6.2
3.7.4

Open the chart page →

24,335
kube-web-viewdecayofmind0.0.41 of 1See more

kube-web-view decayofmind 0.0.4

1 of the 1 container images this version deploys carry CVE-2021-21330.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
aiohttp@3.6.2
3.7.4

Open the chart page →

2,264
resurrectbothalkeye0.1.51 of 1See more

resurrectbot halkeye 0.1.5

1 of the 1 container images this version deploys carry CVE-2021-21330.

Container imageDigestPackageFixed in
halkeye/slack-resurrect:v0.1.477b05e95fdb5
aiohttp@3.5.4
3.7.4

Open the chart page →

3,809
deepflowkubesphere-stable6.2.6061 of 8See more

deepflow kubesphere-stable 6.2.606

1 of the 8 container images this version deploys carry CVE-2021-21330.

Container imageDigestPackageFixed in
deepflowce/deepflow-app:v6.2.6.5a1888d35e787
aiohttp@3.4.4
3.7.4

Open the chart page →

18,316
legendlegend0.1.21 of 1See more

legend legend 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-21330.

Container imageDigestPackageFixed in
ghcr.io/grofers/legend:0.1d6e901ad0ebd
aiohttp@3.7.1
3.7.4

Open the chart page →

4,067
buildkite-exporterminaVerified publisher0.1.41 of 1See more

buildkite-exporter mina 0.1.4

1 of the 1 container images this version deploys carry CVE-2021-21330.

Container imageDigestPackageFixed in
codaprotocol/buildkite-exporter:0.2.137c68e67a401
aiohttp@3.7.3
3.7.4

Open the chart page →

2,599

Container images carrying it

7 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
codaprotocol/buildkite-exporter:0.2.137c68e67a401
aiohttp@3.7.3
3.7.4
1
deepflowce/deepflow-app:v6.2.6.5a1888d35e787
aiohttp@3.4.4
3.7.4
1
halkeye/slack-resurrect:v0.1.477b05e95fdb5
aiohttp@3.5.4
3.7.4
1
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
aiohttp@3.6.2
3.7.4
1
opendatacube/restcube:latest91870111837c
aiohttp@3.6.2
3.7.4
1
opendatacube/wms:latest1b90cdf68831
aiohttp@3.6.2
3.7.4
1
ghcr.io/grofers/legend:0.1d6e901ad0ebd
aiohttp@3.7.1
3.7.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.