StackRadar

CVE-2021-28363

Medium

Advisory

Published 15 Mar 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.021
81st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
26
of 17,781 indexed, latest versions
Container images
31
deployed by those charts
Fix available
1 of 1
affected package

Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection

Carried by container images the latest versions of 26 of 17,781 indexed charts deploy, on 31 images.

Affected packageAffected versionsFixed inImages
urllib3pypi1.26.0, 1.26.1, 1.26.2, 1.26.31.26.431
OSV records
GHSA-5phf-pp7p-vc2r
Also known as
PYSEC-2021-59

Charts affected

26 by stars
ChartLatestAffected imagesRadar Score
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
urllib3@1.26.3
1.26.4

Open the chart page →

4,086
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
urllib3@1.26.3
1.26.4

Open the chart page →

4,918
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
urllib3@1.26.3
1.26.4

Open the chart page →

5,173
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
urllib3@1.26.2
1.26.4

Open the chart page →

52,919
fritzbox-exporterpascaliskeVerified publisher3.0.01 of 1See more

fritzbox-exporter pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
sealife/fritzbox-exporter:1.0f5cc2f0f4c9b
urllib3@1.26.2
1.26.4

Open the chart page →

2,094
octoprinthalkeye0.1.11 of 1See more

octoprint halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
octoprint/octoprint:1.4.0106c26efcd8a
urllib3@1.26.2
1.26.4

Open the chart page →

3,608
git-configmap-syncjulb-meVerified publisher1.0.11 of 2See more

git-configmap-sync julb-me 1.0.1

1 of the 2 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
julb/kubernetes-configmap-sync:1.1.0d7d8836366ad
urllib3@1.26.2
1.26.4

Open the chart page →

2,618
kube-resource-reportslamdev0.1.31 of 2See more

kube-resource-report slamdev 0.1.3

1 of the 2 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
hjacobs/kube-resource-report:21.2.145f93491c434
urllib3@1.26.3
1.26.4

Open the chart page →

1,534
fritzbox-exporteralexvanderberkelVerified publisher2.0.31 of 1See more

fritzbox-exporter alexvanderberkel 2.0.3

1 of the 1 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
sealife/fritzbox-exporter:1.0f5cc2f0f4c9b
urllib3@1.26.2
1.26.4

Open the chart page →

2,094
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
urllib3@1.26.3
1.26.4
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
urllib3@1.26.3
1.26.4

Open the chart page →

22,568
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
urllib3@1.26.3
1.26.4

Open the chart page →

5,521
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
urllib3@1.26.2
1.26.4

Open the chart page →

6,695
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
urllib3@1.26.3
1.26.4
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
urllib3@1.26.3
1.26.4
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
urllib3@1.26.3
1.26.4
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
urllib3@1.26.3
1.26.4
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
urllib3@1.26.3
1.26.4
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
urllib3@1.26.3
1.26.4
confluentinc/cp-zookeeper:6.1.078c190f4472c
urllib3@1.26.3
1.26.4

Open the chart page →

58,857
bae-activation-servicefiware0.1.21 of 1See more

bae-activation-service fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
fiware/bae-activation-service:v0.0.33e3ec88d59ed
urllib3@1.26.2
1.26.4

Open the chart page →

3,186
mylargeek-cookbookVerified publisher4.4.21 of 1See more

mylar geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/mylar3:version-v0.5.3b96f0e97ab3f
urllib3@1.26.2
1.26.4

Open the chart page →

1,423
kibana-index-pattern-updaterkfirfer0.0.31 of 1See more

kibana-index-pattern-updater kfirfer 0.0.3

1 of the 1 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
kfirfer/kibana-index-pattern-updater:1.0.12e88cfcec5c93
urllib3@1.26.2
1.26.4

Open the chart page →

3,357
squash-apilsst-sqre0.1.61 of 3See more

squash-api lsst-sqre 0.1.6

1 of the 3 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
lsstsqre/squash-api:0.5.34879415ec6ac
urllib3@1.26.2
1.26.4

Open the chart page →

6,611
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.3.065095a82d4a1
urllib3@1.26.0
1.26.4

Open the chart page →

68,284
buildkite-exporterminaVerified publisher0.1.41 of 1See more

buildkite-exporter mina 0.1.4

1 of the 1 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
codaprotocol/buildkite-exporter:0.2.137c68e67a401
urllib3@1.26.3
1.26.4

Open the chart page →

2,599
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
urllib3@1.26.2
1.26.4

Open the chart page →

43,341
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
urllib3@1.26.1
1.26.4

Open the chart page →

55,726
digdagskyoo20030.5.21 of 4See more

digdag skyoo2003 0.5.2

1 of the 4 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
urllib3@1.26.2
1.26.4

Open the chart page →

6,949
marge-botslamdev0.0.11 of 1See more

marge-bot slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.11.07235809b43b3
urllib3@1.26.3
1.26.4

Open the chart page →

1,426
horcruxstakewise1.0.11 of 1See more

horcrux stakewise 1.0.1

1 of the 1 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
stakewiselabs/bls-horcrux:v1.0.02afd0c0b34cb
urllib3@1.26.2
1.26.4

Open the chart page →

1,421
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
urllib3@1.26.3
1.26.4

Open the chart page →

4,086
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2021-28363.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
urllib3@1.26.3
1.26.4

Open the chart page →

1,843

Container images carrying it

31 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
datawire/aes:1.14.48588eafe6862
urllib3@1.26.3
1.26.4
2
sealife/fritzbox-exporter:1.0f5cc2f0f4c9b
urllib3@1.26.2
1.26.4
2
codaprotocol/buildkite-exporter:0.2.137c68e67a401
urllib3@1.26.3
1.26.4
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
urllib3@1.26.3
1.26.4
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
urllib3@1.26.3
1.26.4
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
urllib3@1.26.3
1.26.4
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
urllib3@1.26.3
1.26.4
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
urllib3@1.26.3
1.26.4
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
urllib3@1.26.3
1.26.4
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
urllib3@1.26.3
1.26.4
1
craigwillis/c2metadata-bd:latestae317d7e4724
urllib3@1.26.1
1.26.4
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
urllib3@1.26.3
1.26.4
1
datawire/aes:1.13.62beb65062c8b
urllib3@1.26.3
1.26.4
1
datawire/emissary:2.0.2-ea9716efbdd24b
urllib3@1.26.3
1.26.4
1
fiware/bae-activation-service:v0.0.33e3ec88d59ed
urllib3@1.26.2
1.26.4
1
hiboxsystems/marge-bot:0.11.07235809b43b3
urllib3@1.26.3
1.26.4
1
hjacobs/kube-resource-report:21.2.145f93491c434
urllib3@1.26.3
1.26.4
1
julb/kubernetes-configmap-sync:1.1.0d7d8836366ad
urllib3@1.26.2
1.26.4
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
urllib3@1.26.2
1.26.4
1
kfirfer/kibana-index-pattern-updater:1.0.12e88cfcec5c93
urllib3@1.26.2
1.26.4
1
kiwigrid/k8s-sidecar:1.3.065095a82d4a1
urllib3@1.26.0
1.26.4
1
lsstsqre/squash-api:0.5.34879415ec6ac
urllib3@1.26.2
1.26.4
1
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
urllib3@1.26.2
1.26.4
1
octoprint/octoprint:1.4.0106c26efcd8a
urllib3@1.26.2
1.26.4
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
urllib3@1.26.3
1.26.4
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
urllib3@1.26.3
1.26.4
1
stakewiselabs/bls-horcrux:v1.0.02afd0c0b34cb
urllib3@1.26.2
1.26.4
1
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
urllib3@1.26.3
1.26.4
1
ghcr.io/linuxserver/mylar3:version-v0.5.3b96f0e97ab3f
urllib3@1.26.2
1.26.4
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
urllib3@1.26.2
1.26.4
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
urllib3@1.26.2
1.26.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.