StackRadar

CVE-2024-27454

High

Advisory

Published 26 Feb 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.012
66th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
18
of 17,781 indexed, latest versions
Container images
27
deployed by those charts
Fix available
1 of 1
affected package

orjson does not limit recursion for deeply nested JSON documents

Carried by container images the latest versions of 18 of 17,781 indexed charts deploy, on 27 images.

Affected packageAffected versionsFixed inImages
orjsonpypi2.6.1, 2.6.8, 3.3.1, 3.5.2+7 more3.9.1527
OSV records
GHSA-pwr2-4v36-6qpr
Also known as
PYSEC-2024-40

Charts affected

18 by stars
ChartLatestAffected imagesRadar Score
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
orjson@3.3.1
3.9.15

Open the chart page →

4,086
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
orjson@3.3.1
3.9.15

Open the chart page →

4,918
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
orjson@3.9.9
3.9.15

Open the chart page →

6,041
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
orjson@3.3.1
3.9.15

Open the chart page →

5,173
stackstorm-hastackstormVerified publisher1.1.011 of 17See more

stackstorm-ha stackstorm 1.1.0

11 of the 17 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
orjson@3.5.2
3.9.15
stackstorm/st2api:3.86f56d239d280
orjson@3.5.2
3.9.15
stackstorm/st2auth:3.833ecfda16608
orjson@3.5.2
3.9.15
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
orjson@3.5.2
3.9.15
stackstorm/st2notifier:3.8f190a6212195
orjson@3.5.2
3.9.15
stackstorm/st2rulesengine:3.8259503496ff9
orjson@3.5.2
3.9.15
stackstorm/st2scheduler:3.8b1de2055c362
orjson@3.5.2
3.9.15
stackstorm/st2sensorcontainer:3.8b1a338f64773
orjson@3.5.2
3.9.15
stackstorm/st2stream:3.81c8904a3bf67
orjson@3.5.2
3.9.15
stackstorm/st2timersengine:3.81bf35bfaf00c
orjson@3.5.2
3.9.15
stackstorm/st2workflowengine:3.819fdfffdbba8
orjson@3.5.2
3.9.15

Open the chart page →

96,419
clearml-servingallegroaiVerified publisher1.6.21 of 9See more

clearml-serving allegroai 1.6.2

1 of the 9 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
orjson@3.8.10
3.9.15

Open the chart page →

17,877
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
orjson@2.6.1
3.9.15

Open the chart page →

4,568
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
orjson@3.3.1
3.9.15

Open the chart page →

5,521
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
orjson@3.9.9
3.9.15

Open the chart page →

6,179
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
orjson@3.8.3
3.9.15

Open the chart page →

4,085
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
orjson@3.9.7
3.9.15

Open the chart page →

6,447
pavkrzwiatrzyk0.0.31 of 1See more

pav krzwiatrzyk 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
witcherek7/pav:0.0.342a744f29ac0
orjson@3.8.3
3.9.15

Open the chart page →

1,132
kafka-aggregatorlsst-sqre0.1.21 of 1See more

kafka-aggregator lsst-sqre 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
lsstsqre/kafkaaggregator:masterbe1b21060854
orjson@2.6.8
3.9.15

Open the chart page →

3,052
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
orjson@3.8.0
3.9.15

Open the chart page →

43,341
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
orjson@3.8.7
3.9.15

Open the chart page →

5,456
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
orjson@3.9.10
3.9.15

Open the chart page →

2,416
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
orjson@3.3.1
3.9.15

Open the chart page →

4,086
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2024-27454.

Container imageDigestPackageFixed in
datawire/emissary:3.12.21f67a1292d2a
orjson@3.9.10
3.9.15

Open the chart page →

10,843

Container images carrying it

27 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
datawire/aes:1.14.48588eafe6862
orjson@3.3.1
3.9.15
2
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
orjson@3.8.10
3.9.15
1
datadog/agent:7.22.08f20e56b5311
orjson@2.6.1
3.9.15
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
orjson@3.3.1
3.9.15
1
datawire/aes:1.13.62beb65062c8b
orjson@3.3.1
3.9.15
1
datawire/aes:3.11.195ec30b3c732
orjson@3.9.10
3.9.15
1
datawire/emissary:3.12.21f67a1292d2a
orjson@3.9.10
3.9.15
1
datawire/emissary:2.0.2-ea9716efbdd24b
orjson@3.3.1
3.9.15
1
evk02/mlflow:2.2.1ef6ff257ef35
orjson@3.8.7
3.9.15
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
orjson@3.8.3
3.9.15
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
orjson@3.9.7
3.9.15
1
homeassistant/home-assistant:2023.12.48d000332b09b
orjson@3.9.9
3.9.15
1
lsstsqre/kafkaaggregator:masterbe1b21060854
orjson@2.6.8
3.9.15
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
orjson@3.8.0
3.9.15
1
stackstorm/st2actionrunner:3.888235ba70cad
orjson@3.5.2
3.9.15
1
stackstorm/st2api:3.86f56d239d280
orjson@3.5.2
3.9.15
1
stackstorm/st2auth:3.833ecfda16608
orjson@3.5.2
3.9.15
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
orjson@3.5.2
3.9.15
1
stackstorm/st2notifier:3.8f190a6212195
orjson@3.5.2
3.9.15
1
stackstorm/st2rulesengine:3.8259503496ff9
orjson@3.5.2
3.9.15
1
stackstorm/st2scheduler:3.8b1de2055c362
orjson@3.5.2
3.9.15
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
orjson@3.5.2
3.9.15
1
stackstorm/st2stream:3.81c8904a3bf67
orjson@3.5.2
3.9.15
1
stackstorm/st2timersengine:3.81bf35bfaf00c
orjson@3.5.2
3.9.15
1
stackstorm/st2workflowengine:3.819fdfffdbba8
orjson@3.5.2
3.9.15
1
witcherek7/pav:0.0.342a744f29ac0
orjson@3.8.3
3.9.15
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
orjson@3.9.9
3.9.15
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.