StackRadar

CVE-2023-45139

High

Advisory

Published 9 Jan 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.012
67th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

fonttools XML External Entity Injection (XXE) Vulnerability

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
fonttoolspypi4.29.1, 4.33.3, 4.37.4, 4.38.0+2 more4.43.010
OSV records
GHSA-6673-4983-2vx5
Also known as
PYSEC-2026-1388

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2023-45139.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
fonttools@4.33.3
4.43.0

Open the chart page →

7,705
mlflow-controllermlflow-deployment-controller0.1.81 of 2See more

mlflow-controller mlflow-deployment-controller 0.1.8

1 of the 2 container images this version deploys carry CVE-2023-45139.

Container imageDigestPackageFixed in
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
fonttools@4.38.0
4.43.0

Open the chart page →

8,957
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2023-45139.

Container imageDigestPackageFixed in
buntha/mlflow:2.1.1154542cc3083
fonttools@4.38.0
4.43.0

Open the chart page →

5,804
smartorchestratorassist-iot-smart-orchestrator4.0.01 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

1 of the 14 container images this version deploys carry CVE-2023-45139.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
fonttools@4.38.0
4.43.0

Open the chart page →

45,363
frigatebryopsida0.2.11 of 2See more

frigate bryopsida 0.2.1

1 of the 2 container images this version deploys carry CVE-2023-45139.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
fonttools@4.37.4
4.43.0

Open the chart page →

2,573
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2023-45139.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
fonttools@4.38.0
4.43.0

Open the chart page →

4,085
frigatek8s-home-lab-repo9.1.11 of 1See more

frigate k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2023-45139.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
fonttools@4.37.4
4.43.0

Open the chart page →

2,370
exposureloglsst-sqre0.2.11 of 1See more

exposurelog lsst-sqre 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-45139.

Container imageDigestPackageFixed in
lsstsqre/exposurelog:0.8.079b00fb67a65
fonttools@4.29.1
4.43.0

Open the chart page →

2,078
mlflowmondata-helm-chartsVerified publisher0.2.31 of 1See more

mlflow mondata-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-45139.

Container imageDigestPackageFixed in
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
fonttools@4.39.3
4.43.0

Open the chart page →

3,811
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2023-45139.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
fonttools@4.39.0
4.43.0

Open the chart page →

5,456
frigatesmarthallVerified publisher1.0.61 of 1See more

frigate smarthall 1.0.6

1 of the 1 container images this version deploys carry CVE-2023-45139.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
fonttools@4.39.3
4.43.0

Open the chart page →

2,243

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
blakeblackshear/frigate:0.11.18330b0a265b8
fonttools@4.37.4
4.43.0
2
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
fonttools@4.38.0
4.43.0
1
buntha/mlflow:2.1.1154542cc3083
fonttools@4.38.0
4.43.0
1
evk02/mlflow:2.2.1ef6ff257ef35
fonttools@4.39.0
4.43.0
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
fonttools@4.38.0
4.43.0
1
lsstsqre/exposurelog:0.8.079b00fb67a65
fonttools@4.29.1
4.43.0
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
fonttools@4.39.3
4.43.0
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
fonttools@4.38.0
4.43.0
1
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
fonttools@4.39.3
4.43.0
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
fonttools@4.33.3
4.43.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.