StackRadar

CVE-2021-3572

Medium

Advisory

Published 10 Nov 2021In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.7
base score, highest
EPSS
0.018
78th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
376
of 17,781 indexed, latest versions
Container images
377
deployed by those charts
Fix available
3 of 3
affected packages

Improper Input Validation in pip

Carried by container images the latest versions of 376 of 17,781 indexed charts deploy, on 377 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+27 more21.1365
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+3 more1.5.4-1ubuntu4+esm1, 8.1.1-2ubuntu0.6+esm2, 9.0.1-2.3~ubuntu1.18.04.5+esm227
python-piprpm9.0.3-15.el8, 9.0.3-16.el8, 9.0.3-18.el8, 9.0.3-19.el80:9.0.3-20.el835
OSV records
GHSA-5xp3-jfq3-5q8xRHSA-2021:4455UBUNTU-CVE-2021-3572
Also known as
PYSEC-2021-437, USN-4961-2

Charts affected

376 by stars
ChartLatestAffected imagesRadar Score
cubefscubefs3.2.02 of 10See more

cubefs cubefs 3.2.0

2 of the 10 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
chubaofs/cfs-client:3.2.015ff74209ce7
pip@20.3.4
21.1
chubaofs/cfs-server:3.2.0205030e045f2
pip@20.3.4
21.1

Open the chart page →

15,891
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
apsl/thumbor:6.7.051e2de5c2c70
pip@19.3.1
21.1

Open the chart page →

38,346
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
pip@20.1.1
21.1

Open the chart page →

4,568
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
pip@20.2.2
21.1

Open the chart page →

7,984
jenkinsedu2.7.11 of 2See more

jenkins edu 2.7.1

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.193170069ff0976
pip@20.2.2
21.1

Open the chart page →

4,423
enbuildenbuildVerified publisher0.0.501 of 6See more

enbuild enbuild 0.0.50

1 of the 6 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
pip@9.0.3
python-pip@9.0.3-19.el8
21.1
0:9.0.3-20.el8

Open the chart page →

31,510
genesis-generatorethereum-helm-chartsVerified publisher0.2.31 of 2See more

genesis-generator ethereum-helm-charts 0.2.3

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
skylenet/ethereum-genesis-generator:latest210353ce7c89
pip@20.3.4
21.1

Open the chart page →

3,135
pgadmin4folio-org1.2.301 of 1See more

pgadmin4 folio-org 1.2.30

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.22b1f00b8163cf
pip@20.1.1
21.1

Open the chart page →

2,034
appdaemongeek-cookbookVerified publisher8.4.21 of 1See more

appdaemon geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
acockburn/appdaemon:4.0.83a93281d7e94
pip@21.0.1
21.1

Open the chart page →

3,461
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
pip@20.0.2
21.1

Open the chart page →

15,653
kube-ops-viewgeek-cookbookVerified publisher1.2.21 of 1See more

kube-ops-view geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:20.4.058221b57d4d2
pip@20.0.2
21.1

Open the chart page →

1,848
paperlessgeek-cookbookVerified publisher9.2.01 of 1See more

paperless geek-cookbook 9.2.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
pip@20.3.4
21.1

Open the chart page →

3,924
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
pip@18.1
21.1

Open the chart page →

5,079
uptimerobot-prometheusgeek-cookbookVerified publisher6.4.21 of 1See more

uptimerobot-prometheus geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
billimek/prometheus-uptimerobot-exporter:0.0.1f14ccd7aad0e
pip@20.1.1
21.1

Open the chart page →

2,265
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.31 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

1 of the 9 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.4.4c0224a1adf7a
pip@9.0.3
21.1

Open the chart page →

15,562
octoprinthalkeye0.1.11 of 1See more

octoprint halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
octoprint/octoprint:1.4.0106c26efcd8a
pip@20.3.1
21.1

Open the chart page →

3,608
powerdnsadminhalkeye0.3.11 of 1See more

powerdnsadmin halkeye 0.3.1

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
pip@20.2.3
21.1

Open the chart page →

3,345
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
pip@18.1
21.1

Open the chart page →

4,196
mongo-pod-labelerhmdmph1.0.21 of 1See more

mongo-pod-labeler hmdmph 1.0.2

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
hmdmph/mongo-pod-labeler:1.0.1-alpine79e4a170f3dc
pip@19.0.3
21.1

Open the chart page →

1,205
alertmanager-gchat-integrationjulb-meVerified publisher1.0.51 of 1See more

alertmanager-gchat-integration julb-me 1.0.5

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
julb/alertmanager-gchat-integration:1.0.5837c4038a0dd
pip@21.0.1
21.1

Open the chart page →

2,110
git-configmap-syncjulb-meVerified publisher1.0.11 of 2See more

git-configmap-sync julb-me 1.0.1

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
julb/kubernetes-configmap-sync:1.1.0d7d8836366ad
pip@20.2.4
21.1

Open the chart page →

2,618
helm-taigamvitale1989-helm-taigaVerified publisher0.2.51 of 2See more

helm-taiga mvitale1989-helm-taiga 0.2.5

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
pip@19.3.1
21.1

Open the chart page →

5,104
nessusnessus0.2.01 of 1See more

nessus nessus 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
tenableofficial/nessus:latestc88e43fe1a8c
pip@9.0.3
21.1

Open the chart page →

342
sentry-k8ssentry-k8sVerified publisher1.4.11 of 11See more

sentry-k8s sentry-k8s 1.4.1

1 of the 11 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.6.683dbca3efd2a
pip@20.2.4
21.1

Open the chart page →

16,449
kube-resource-reportslamdev0.1.31 of 2See more

kube-resource-report slamdev 0.1.3

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
hjacobs/kube-resource-report:21.2.145f93491c434
pip@21.0.1
21.1

Open the chart page →

1,534
smarter-demosmarterOfficialVerified publisher0.1.52 of 7See more

smarter-demo smarter 0.1.5

2 of the 7 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
pip@20.0.2
21.1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
pip@20.0.2
21.1

Open the chart page →

45,832
mysql-backupsoftonic2.2.31 of 1See more

mysql-backup softonic 2.2.3

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
softonic/mysql-backup:0.4.0d9487a8dd70f
pip@18.1
21.1

Open the chart page →

547
alertasomeblackmagic0.2.31 of 2See more

alerta someblackmagic 0.2.3

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
alerta/alerta-web:8.5.04786b9eaa606
pip@20.1.1
21.1

Open the chart page →

3,162
deschedulerstakaterVerified publisher1.0.101 of 1See more

descheduler stakater 1.0.10

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
stakater/descheduler:v0.3.0a47e96ebb285
pip@9.0.1
21.1

Open the chart page →

170
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
pip@20.0.2
21.1

Open the chart page →

24,930
prometheus-pve-exporterstenicVerified publisher0.1.11 of 1See more

prometheus-pve-exporter stenic 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
prompve/prometheus-pve-exporter:2.0.1ff6749eb03b0
pip@20.1.1
21.1

Open the chart page →

2,469
yugabytewenerme2026.1.11 of 1See more

yugabyte wenerme 2026.1.1

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
yugabytedb/yugabyte:2026.1.1.0-b91de2e00278645
pip@9.0.3
21.1

Open the chart page →

351
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
pip@20.0.2
21.1

Open the chart page →

7,835
pghoardwiremindVerified publisher0.8.11 of 1See more

pghoard wiremind 0.8.1

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
wiremind/pghoard:12-2019-11-264dea42c8166c
pip@19.3.1
21.1

Open the chart page →

2,952
acos-prometheus-exporter-helm-charta10-prometheus-exporter0.1.01 of 1See more

acos-prometheus-exporter-helm-chart a10-prometheus-exporter 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
a10networks/acos-prometheus-exporter:latest8dc58d434d71
pip@9.0.1
python-pip@9.0.1-2.3~ubuntu1.18.04.1
21.1
9.0.1-2.3~ubuntu1.18.04.5+esm2

Open the chart page →

12,007
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
pip@9.0.3
21.1

Open the chart page →

7,713
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
pip@20.0.2
21.1

Open the chart page →

25,443
aktoakto0.2.02 of 7See more

akto akto 0.2.0

2 of the 7 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
pip@9.0.3
21.1
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
pip@20.2.4
21.1

Open the chart page →

13,613
akto-mini-testing-kafkaakto1.42.12 of 5See more

akto-mini-testing-kafka akto 1.42.1

2 of the 5 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
pip@9.0.3
21.1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
pip@20.2.4
21.1

Open the chart page →

6,397
akto-protectionakto0.1.02 of 4See more

akto-protection akto 0.1.0

2 of the 4 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
pip@9.0.3
21.1
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
pip@20.2.4
21.1

Open the chart page →

11,285
wsealekcVerified publisher0.1.11 of 1See more

wse alekc 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
badsmoke/wunderground_exporter:0.0.5c54c004f24cc
pip@21.0.1
21.1

Open the chart page →

1,146
fritzbox-exporteralexvanderberkelVerified publisher2.0.31 of 1See more

fritzbox-exporter alexvanderberkel 2.0.3

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
sealife/fritzbox-exporter:1.0f5cc2f0f4c9b
pip@20.3.3
21.1

Open the chart page →

2,094
amorphieamorphie0.1.21 of 18See more

amorphie amorphie 0.1.2

1 of the 18 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
hazelcast/management-center:5.3.2f9d34300d330
pip@9.0.3
21.1

Open the chart page →

28,131
radosgwananace-chartsVerified publisher0.3.41 of 1See more

radosgw ananace-charts 0.3.4

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
ceph/daemon:latest-nautilus90f30824a96e
pip@9.0.3
21.1

Open the chart page →

1,650
monitoringantmediaVerified publisher1.0.01 of 6See more

monitoring antmedia 1.0.0

1 of the 6 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
pip@9.0.3
21.1

Open the chart page →

2,453
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
pip@19.0.3
21.1

Open the chart page →

2,730
sensitive-dataapicheck1.0.01 of 1See more

sensitive-data apicheck 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
bbvalabs/sensitive-data:1.0.13ea299ae63c0
pip@21.0.1
21.1

Open the chart page →

1,843
app-mobilityappmo0.1.01 of 5See more

app-mobility appmo 0.1.0

1 of the 5 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
pip@9.0.3
21.1

Open the chart page →

12,521
maxscaleappuio2.0.11 of 1See more

maxscale appuio 2.0.1

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
pip@9.0.3
21.1

Open the chart page →

2,903
snappassappuio1.0.01 of 3See more

snappass appuio 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
samueldg/snappass:latest3987195edbe6
pip@19.3.1
21.1

Open the chart page →

1,488

Container images carrying it

377 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
kiwigrid/k8s-sidecar:0.1.20af151f677a63
pip@19.2.1
21.1
1
kocolosk/couchdb-statefulset-assembler:1.2.06effb982154e
pip@9.0.1
21.1
1
kodekloud/webapp-color:latest99c3821ea49b
pip@18.1
21.1
1
kubeaws/kube-spot-termination-notice-handler:1.13.0-1c9cd2ba4373a
pip@19.0.3
21.1
1
kubesphere/examples-bookinfo-productpage-v1:1.13.0378f49ec9c44
pip@19.1.1
21.1
1
kunchalavikram/connectedcity:v14a559a47579e
pip@19.0.1
21.1
1
kunchalavikram/connectedfactory:v152c13fb9b1d9
pip@19.0.1
21.1
1
library/crate:4.7.0c7984a05e15b
pip@9.0.3
21.1
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
pip@19.0.1
21.1
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
pip@19.3.1
21.1
1
linuxserver/medusa:v0.3.9-ls340a5f5114128b
pip@19.2.3
21.1
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
pip@19.3.1
21.1
1
lncm/specter-desktop:v0.10.4bca14d04397d
pip@20.2.3
21.1
1
logiqai/toolbox:2.0.155a574ec5b64
pip@18.1
21.1
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
pip@18.1
21.1
1
louislam/uptime-kuma:13d632903e6af
pip@18.1
21.1
1
louislam/uptime-kuma:1.23.1396510915e6be
pip@18.1
21.1
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
pip@18.1
21.1
1
louislam/uptime-kuma:1.18.5a84767d7934f
pip@18.1
21.1
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
pip@18.1
21.1
1
lsstsqre/kafkaaggregator:masterbe1b21060854
pip@21.0.1
21.1
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
pip@20.0.2
21.1
1
lsstsqre/prepuller:latest19c2dfc4e4ff
pip@21.0.1
21.1
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
pip@21.0.1
21.1
1
lsstsqre/squash-api:0.5.34879415ec6ac
pip@20.3.2
21.1
1
lsstsqre/wfdispatcher:lateste9feb99f524d
pip@21.0.1
21.1
1
mediagis/nominatim:3.7c15e941485ef
pip@20.0.2
21.1
1
miltex/python-api:1.0.0dab12a7748d5
pip@20.0.2
21.1
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
pip@9.0.3
21.1
1
mirrorgitlabcontainers/gitlab-sidekiq-ce:v13.2.294d1431683fa
pip@20.1.1
21.1
1
mirrorgitlabcontainers/gitlab-task-runner-ce:v13.2.29efd73993c34
pip@20.1.1
21.1
1
mirrorgitlabcontainers/gitlab-webservice-ce:v13.2.230393f990f5c
pip@20.1.1
21.1
1
mozilla/syncserver:latest016162bf39d8
pip@20.3.4
21.1
1
mozilla/syncstorage-rs:0.15.893752877dced
pip@20.3.4
21.1
1
mshanley80/httpbin2022:latest5b189a70c0fb
pip@20.0.2
21.1
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
pip@19.3.1
21.1
1
mysql/mysql-cluster:8.0.20e4ea36622cdd
pip@19.0.3
21.1
1
neilpeterson/aks-helloworld:v1fb47732ef36b
pip@9.0.1
21.1
1
neilpeterson/chart-tweet:latest64fd8dab075f
pip@9.0.1
21.1
1
neilpeterson/get-tweet:v28b645ac1a23e
pip@10.0.1
21.1
1
neilpeterson/osba-container-instances-demo:latest6527b05d5d03
pip@9.0.1
21.1
1
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
pip@9.0.1
21.1
1
neilpeterson/osba-mysql-demo:latest5859d68a6c9f
pip@9.0.2
21.1
1
neilpeterson/osba-storage-demo:latest29d229ab446e
pip@9.0.1
21.1
1
neilpeterson/osba-text-analytics-demo:latest969af3cb8466
pip@10.0.1
21.1
1
neilpeterson/process-tweet:latest39ce9f92e899
pip@10.0.1
21.1
1
netbirdio/dashboard:v2.90.101b59e1c905c9
pip@20.3.4
21.1
1
netbirdio/dashboard:v2.90.2332cc31f5f35
pip@20.3.4
21.1
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
pip@20.2.3
21.1
1
nlmacamp/check_mk:latest5dbb8589f824
pip@10.0.1
21.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.