StackRadar

CVE-2021-21419

Medium

Advisory

Published 7 May 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.018
77th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
15
of 17,781 indexed, latest versions
Container images
16
deployed by those charts
Fix available
1 of 1
affected package

Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet

Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 16 images.

Affected packageAffected versionsFixed inImages
eventletpypi0.20.0, 0.24.1, 0.25.0, 0.25.1+2 more0.31.016
OSV records
GHSA-9p9m-jm8w-94p2
Also known as
PYSEC-2021-12

Charts affected

15 by stars
ChartLatestAffected imagesRadar Score
milvusmilvus4.0.311 of 5See more

milvus milvus 4.0.31

1 of the 5 container images this version deploys carry CVE-2021-21419.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
eventlet@0.25.1
0.31.0

Open the chart page →

32,259
milvusmilvus-helm5.0.271 of 4See more

milvus milvus-helm 5.0.27

1 of the 4 container images this version deploys carry CVE-2021-21419.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
eventlet@0.30.2
0.31.0

Open the chart page →

10,670
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2021-21419.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
eventlet@0.25.2
0.31.0

Open the chart page →

30,326
iris-webappiris-webapp0.2.41 of 2See more

iris-webapp iris-webapp 0.2.4

1 of the 2 container images this version deploys carry CVE-2021-21419.

Container imageDigestPackageFixed in
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
eventlet@0.30.2
0.31.0

Open the chart page →

11,764
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2021-21419.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
eventlet@0.30.2
0.31.0
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
eventlet@0.30.2
0.31.0

Open the chart page →

22,568
pulsarcnieg1.0.81 of 2See more

pulsar cnieg 1.0.8

1 of the 2 container images this version deploys carry CVE-2021-21419.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
eventlet@0.20.0
0.31.0

Open the chart page →

16,860
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2021-21419.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
eventlet@0.25.1
0.31.0

Open the chart page →

27,728
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2021-21419.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
eventlet@0.30.2
0.31.0

Open the chart page →

16,417
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2021-21419.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
eventlet@0.25.1
0.31.0

Open the chart page →

25,933
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-21419.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
eventlet@0.25.1
0.31.0

Open the chart page →

15,675
elasticsearch2ncsaVerified publisher0.2.21 of 2See more

elasticsearch2 ncsa 0.2.2

1 of the 2 container images this version deploys carry CVE-2021-21419.

Container imageDigestPackageFixed in
elastichq/elasticsearch-hq:latestbb3bd22c2b87
eventlet@0.25.0
0.31.0

Open the chart page →

4,911
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2021-21419.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
eventlet@0.30.2
0.31.0

Open the chart page →

9,005
comacopencord1.0.02 of 9See more

comac opencord 1.0.0

2 of the 9 container images this version deploys carry CVE-2021-21419.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
eventlet@0.24.1
0.31.0
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
eventlet@0.24.1
0.31.0

Open the chart page →

88,546
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2021-21419.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
eventlet@0.24.1
0.31.0

Open the chart page →

26,211
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2021-21419.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
eventlet@0.30.2
0.31.0

Open the chart page →

13,459

Container images carrying it

16 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
eventlet@0.24.1
0.31.0
2
apachepulsar/pulsar:3.1.016f9fdab3fa6
eventlet@0.30.2
0.31.0
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
eventlet@0.25.1
0.31.0
1
apachepulsar/pulsar:2.6.14db6ff0b4045
eventlet@0.20.0
0.31.0
1
apachepulsar/pulsar:3.0.79c9947de139d
eventlet@0.30.2
0.31.0
1
apachepulsar/pulsar:2.9.0d056c89b7131
eventlet@0.25.1
0.31.0
1
apachepulsar/pulsar:2.8.2d538416d5afe
eventlet@0.25.1
0.31.0
1
elastichq/elasticsearch-hq:latestbb3bd22c2b87
eventlet@0.25.0
0.31.0
1
gethue/hue:4.11.011b649636e68
eventlet@0.30.2
0.31.0
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
eventlet@0.25.2
0.31.0
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
eventlet@0.24.1
0.31.0
1
opendatacube/wms:latest1b90cdf68831
eventlet@0.25.1
0.31.0
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
eventlet@0.30.2
0.31.0
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
eventlet@0.30.2
0.31.0
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
eventlet@0.30.2
0.31.0
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
eventlet@0.30.2
0.31.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.