StackRadar

CVE-2024-24762

High

Advisory

Published 5 Feb 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
34
of 17,781 indexed, latest versions
Container images
36
deployed by those charts
Fix available
2 of 2
affected packages

python-multipart vulnerable to Content-Type Header ReDoS

Carried by container images the latest versions of 34 of 17,781 indexed charts deploy, on 36 images.

Affected packageAffected versionsFixed inImages
fastapipypi0.61.1, 0.63.0, 0.65.2, 0.70.0+17 more0.109.136
python-multipartpypi0.0.5, 0.0.60.0.717
OSV records
GHSA-2jv5-9r88-3w3pPYSEC-2024-38
Also known as
GHSA-qf9m-vfgh-m389, PYSEC-2026-1850

Charts affected

34 by stars
ChartLatestAffected imagesRadar Score
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
fastapi@0.78.0
python-multipart@0.0.5
0.109.1
0.0.7

Open the chart page →

7,579
clearml-servingallegroaiVerified publisher1.6.21 of 9See more

clearml-serving allegroai 1.6.2

1 of the 9 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
fastapi@0.95.0
python-multipart@0.0.6
0.109.1
0.0.7

Open the chart page →

17,877
rommcrystalnetVerified publisher0.2.201 of 3See more

romm crystalnet 0.2.20

1 of the 3 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
zurdi15/romm:2.3.12db88fe44c89
fastapi@0.103.1
python-multipart@0.0.6
0.109.1
0.0.7

Open the chart page →

1,944
dominodominoVerified publisher0.1.111 of 3See more

domino domino 0.1.11

1 of the 3 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
fastapi@0.104.1
0.109.1

Open the chart page →

8,823
clowder2ncsaVerified publisher1.9.73 of 12See more

clowder2 ncsa 1.9.7

3 of the 12 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
fastapi@0.95.1
python-multipart@0.0.6
0.109.1
0.0.7
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
fastapi@0.95.1
python-multipart@0.0.6
0.109.1
0.0.7
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
fastapi@0.95.1
python-multipart@0.0.6
0.109.1
0.0.7

Open the chart page →

37,373
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
assistiot/fl_repository:latest0fce3ea719a5
fastapi@0.83.0
python-multipart@0.0.5
0.109.1
0.0.7

Open the chart page →

4,367
trainingcollectorassist-iot-fl-training-collector1.1.01 of 1See more

trainingcollector assist-iot-fl-training-collector 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
assistiot/fl_training_collector:latest792715dd3084
fastapi@0.70.0
0.109.1

Open the chart page →

1,719
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
fastapi@0.105.0
python-multipart@0.0.6
0.109.1
0.0.7

Open the chart page →

18,277
azure-app-exporterazure-app-exporterVerified publisher0.4.21 of 2See more

azure-app-exporter azure-app-exporter 0.4.2

1 of the 2 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
ghcr.io/dodevops/azure-app-exporter/azure-app-exporter:0.1.38b472877847f5
fastapi@0.75.2
0.109.1

Open the chart page →

1,790
design-cataloguedesign-catalogue0.1.01 of 2See more

design-catalogue design-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
fastapi@0.65.2
0.109.1

Open the chart page →

2,770
helpdeskdoubanVerified publisher0.3.31 of 2See more

helpdesk douban 0.3.3

1 of the 2 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
douz/helpdesk:latest4384103d0219
fastapi@0.79.0
python-multipart@0.0.5
0.109.1
0.0.7

Open the chart page →

4,550
hlo-deployment-engineeclipse-aeriosVerified publisher3.0.01 of 1See more

hlo-deployment-engine eclipse-aerios 3.0.0

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
eclipseaerios/hlo-deployment-engine:v3.0.0d582d39208c7
fastapi@0.109.0
0.109.1

Open the chart page →

1,653
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
fastapi@0.85.2
python-multipart@0.0.5
0.109.1
0.0.7

Open the chart page →

4,085
forms-catalogueforms-catalogue0.1.01 of 2See more

forms-catalogue forms-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
fastapi@0.65.2
0.109.1

Open the chart page →

2,188
notediscoveryhelmforgeVerified publisher2.0.11 of 1See more

notediscovery helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
ghcr.io/gamosoft/notediscovery:0.31.5c06aa0fa9a85
fastapi@0.104.1
python-multipart@0.0.6
0.109.1
0.0.7

Open the chart page →

1,241
lnbitskronkltdVerified publisher0.1.01 of 1See more

lnbits kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
lnbitsdocker/lnbits-legend:latest26fae6327477
fastapi@0.103.1
0.109.1

Open the chart page →

1,444
pavkrzwiatrzyk0.0.31 of 1See more

pav krzwiatrzyk 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
witcherek7/pav:0.0.342a744f29ac0
fastapi@0.88.0
python-multipart@0.0.5
0.109.1
0.0.7

Open the chart page →

1,132
lnbitslnbits0.2.11 of 1See more

lnbits lnbits 0.2.1

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
fastapi@0.83.0
0.109.1

Open the chart page →

1,949
exposureloglsst-sqre0.2.11 of 1See more

exposurelog lsst-sqre 0.2.1

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
lsstsqre/exposurelog:0.8.079b00fb67a65
fastapi@0.73.0
0.109.1

Open the chart page →

2,078
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
fastapi@0.75.2
python-multipart@0.0.5
0.109.1
0.0.7

Open the chart page →

7,315
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
fastapi@0.85.1
python-multipart@0.0.5
0.109.1
0.0.7

Open the chart page →

43,341
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-backend:0.11a9ce0b8fbd4
fastapi@0.61.1
0.109.1

Open the chart page →

6,438
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi:x86bacb2ddd8394
fastapi@0.79.0
python-multipart@0.0.5
0.109.1
0.0.7

Open the chart page →

8,556
my-fastapi-chartmy-fastapi-template0.1.01 of 1See more

my-fastapi-chart my-fastapi-template 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
john19968010/fastapi-template:latest31a90f6bd69c
fastapi@0.94.1
python-multipart@0.0.5
0.109.1
0.0.7

Open the chart page →

967
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
fastapi@0.89.1
0.109.1

Open the chart page →

5,456
mockoidcoidcmockVerified publisher0.0.11 of 1See more

mockoidc oidcmock 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
marcoimme/oidcmock:latestb6035c0721a8
fastapi@0.109.0
python-multipart@0.0.6
0.109.1
0.0.7

Open the chart page →

2,298
python-fastapi-postgrespython-fastapi-postgres0.1.01 of 1See more

python-fastapi-postgres python-fastapi-postgres 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
archish27/python-fastapi-postgres:latest6610071a2101
fastapi@0.79.0
0.109.1

Open the chart page →

2,983
helm-redchefredchef0.1.01 of 3See more

helm-redchef redchef 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
sharanalwar/redchef-backend:latest8d3cab80df49
fastapi@0.104.1
0.109.1

Open the chart page →

4,763
request-registryrequest-registry0.1.01 of 2See more

request-registry request-registry 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
fastapi@0.65.2
0.109.1

Open the chart page →

2,201
test-helm-app1saam-helm-test0.1.01 of 1See more

test-helm-app1 saam-helm-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
hamidyousefi93/saam-test:latestc34f071f6ed0
fastapi@0.104.1
0.109.1

Open the chart page →

3,887
test-helm-app2saam-helm-test0.1.01 of 1See more

test-helm-app2 saam-helm-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
asdkant/fastapi-hello-world:latesta23d8bf7c885
fastapi@0.65.2
0.109.1

Open the chart page →

2,770
horcruxstakewise1.0.11 of 1See more

horcrux stakewise 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
stakewiselabs/bls-horcrux:v1.0.02afd0c0b34cb
fastapi@0.63.0
0.109.1

Open the chart page →

1,421
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
fastapi@0.102.0
0.109.1

Open the chart page →

13,390
take-the-helmtake-the-helm0.1.01 of 1See more

take-the-helm take-the-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24762.

Container imageDigestPackageFixed in
cadmusthefounder/lnd:take-the-helm-0.1.0e596c5fbf80f
fastapi@0.78.0
0.109.1

Open the chart page →

805

Container images carrying it

36 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
fastapi@0.95.0
python-multipart@0.0.6
0.109.1
0.0.7
1
archish27/python-fastapi-postgres:latest6610071a2101
fastapi@0.79.0
0.109.1
1
asdkant/fastapi-hello-world:latesta23d8bf7c885
fastapi@0.65.2
0.109.1
1
assistiot/fl_repository:latest0fce3ea719a5
fastapi@0.83.0
python-multipart@0.0.5
0.109.1
0.0.7
1
assistiot/fl_training_collector:latest792715dd3084
fastapi@0.70.0
0.109.1
1
assistiot/open_api_backend:1.1.230812ba93555
fastapi@0.105.0
python-multipart@0.0.6
0.109.1
0.0.7
1
cadmusthefounder/lnd:take-the-helm-0.1.0e596c5fbf80f
fastapi@0.78.0
0.109.1
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
fastapi@0.95.1
python-multipart@0.0.6
0.109.1
0.0.7
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
fastapi@0.95.1
python-multipart@0.0.6
0.109.1
0.0.7
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
fastapi@0.95.1
python-multipart@0.0.6
0.109.1
0.0.7
1
douz/helpdesk:latest4384103d0219
fastapi@0.79.0
python-multipart@0.0.5
0.109.1
0.0.7
1
eclipseaerios/hlo-deployment-engine:v3.0.0d582d39208c7
fastapi@0.109.0
0.109.1
1
evk02/mlflow:2.2.1ef6ff257ef35
fastapi@0.89.1
0.109.1
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
fastapi@0.85.2
python-multipart@0.0.5
0.109.1
0.0.7
1
hamidyousefi93/saam-test:latestc34f071f6ed0
fastapi@0.104.1
0.109.1
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
fastapi@0.78.0
python-multipart@0.0.5
0.109.1
0.0.7
1
john19968010/fastapi-template:latest31a90f6bd69c
fastapi@0.94.1
python-multipart@0.0.5
0.109.1
0.0.7
1
lnbitsdocker/lnbits-legend:latest26fae6327477
fastapi@0.103.1
0.109.1
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
fastapi@0.83.0
0.109.1
1
lsstsqre/exposurelog:0.8.079b00fb67a65
fastapi@0.73.0
0.109.1
1
marcoimme/oidcmock:latestb6035c0721a8
fastapi@0.109.0
python-multipart@0.0.6
0.109.1
0.0.7
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
fastapi@0.85.1
python-multipart@0.0.5
0.109.1
0.0.7
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
fastapi@0.79.0
python-multipart@0.0.5
0.109.1
0.0.7
1
sharanalwar/redchef-backend:latest8d3cab80df49
fastapi@0.104.1
0.109.1
1
stakewiselabs/bls-horcrux:v1.0.02afd0c0b34cb
fastapi@0.63.0
0.109.1
1
substratusai/verba:v0.4.0-baseURL261695be635eb
fastapi@0.102.0
0.109.1
1
witcherek7/pav:0.0.342a744f29ac0
fastapi@0.88.0
python-multipart@0.0.5
0.109.1
0.0.7
1
zurdi15/romm:2.3.12db88fe44c89
fastapi@0.103.1
python-multipart@0.0.6
0.109.1
0.0.7
1
ghcr.io/dodevops/azure-app-exporter/azure-app-exporter:0.1.38b472877847f5
fastapi@0.75.2
0.109.1
1
ghcr.io/gamosoft/notediscovery:0.31.5c06aa0fa9a85
fastapi@0.104.1
python-multipart@0.0.6
0.109.1
0.0.7
1
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
fastapi@0.75.2
python-multipart@0.0.5
0.109.1
0.0.7
1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
fastapi@0.104.1
0.109.1
1
quay.io/mongodb/farm-intro-backend:0.11a9ce0b8fbd4
fastapi@0.61.1
0.109.1
1
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
fastapi@0.65.2
0.109.1
1
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
fastapi@0.65.2
0.109.1
1
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
fastapi@0.65.2
0.109.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.