StackRadar

CVE-2024-35195

Medium

Advisory

Published 20 May 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.6
base score, highest
EPSS
0.003
27th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
605
of 17,790 indexed, latest versions
Container images
657
deployed by those charts
Fix available
3 of 4
affected packages

Requests `Session` object does not verify requests after making first request with verify=False

Carried by container images the latest versions of 605 of 17,790 indexed charts deploy, on 657 images.

Affected packageAffected versionsFixed inImages
requestspypi2.2.1, 2.6.0, 2.9.1, 2.10.0+22 more2.32.0611
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+23 more22.0.2+dfsg-1ubuntu0.7+esm1, 24.0+dfsg-1ubuntu1.3+esm1108
requestsdeb2.2.1-1, 2.2.1-1ubuntu0.3, 2.9.1-3, 2.9.1-3ubuntu0.1+8 moreno fix listed71
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_6, 2.20.0-3.el8_8, 2.25.1-7.el9_2+1 more0:2.20.0-5.el8_10, 0:2.25.1-9.el942
OSV records
DEBIAN-CVE-2024-35195GHSA-9wx4-h78v-vm56RHSA-2025:0012RHSA-2025:7049UBUNTU-CVE-2024-35195
Also known as
PYSEC-2026-1873, USN-8344-1

Charts affected

605 by stars
ChartLatestAffected imagesRadar Score
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
requests@2.20.0
2.32.0

Open the chart page →

11,827
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
requests@2.25.1
2.32.0

Open the chart page →

1,843
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
requests@2.31.0
2.32.0

Open the chart page →

5,559
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
requests@2.24.0
2.32.0

Open the chart page →

2,643
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
requests@2.28.2
2.32.0

Open the chart page →

1,838

Container images carrying it

657 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
requests@2.22.0-2ubuntu1
requests@2.22.0
no fix listed
2.32.0
1
akeyless/base-rhel:0.0.14ba8900a0061
python-requests@2.20.0-3.el8_8
requests@2.31.0
0:2.20.0-5.el8_10
2.32.0
1
alerta/alerta-web:8.5.04786b9eaa606
requests@2.25.1
2.32.0
1
alexvm6/generator:latestfb99ee4f760a
requests@2.31.0
2.32.0
1
allegroai/clearml:2.0.0-613713ae38f7daf
requests@2.31.0
2.32.0
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
python-pip@9.0.1-2.3~ubuntu1.18.04.5
requests@2.25.1
no fix listed
2.32.0
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
requests@2.28.2
2.32.0
1
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
requests@2.25.1
2.32.0
1
amancevice/superset:0.28.1c8c04bfe3d66
requests@2.18.4
2.32.0
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
requests@2.20.0
2.32.0
1
amundsendev/amundsen-metadata:2.5.44d98eb21f5f9
requests@2.24.0
2.32.0
1
amundsendev/amundsen-search:2.4.099dda9502c3e
requests@2.24.0
2.32.0
1
anchore/anchore-engine:v0.10.0bde9eedf639d
python-requests@2.20.0-2.1.el8_1
requests@2.20.0
0:2.20.0-5.el8_10
2.32.0
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
requests@2.23.0
2.32.0
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
python-pip@22.0.2+dfsg-1ubuntu0.3
22.0.2+dfsg-1ubuntu0.7+esm1
1
andrianrf/backoffice:latest047a7837651e
python-requests@2.20.0-3.el8_8
requests@2.20.0
0:2.20.0-5.el8_10
2.32.0
1
apache/airflow:2.8.4-python3.964e58748b6b9
requests@2.31.0
2.32.0
1
apache/airflow:2.8.1e5560ad0b86e
requests@2.31.0
2.32.0
1
apache/couchdb:2.39f895c8ae371
requests@2.12.4
2.32.0
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
python-pip@22.0.2+dfsg-1ubuntu0.3
22.0.2+dfsg-1ubuntu0.7+esm1
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
python-pip@20.0.2-5ubuntu1.6
requests@2.27.1
no fix listed
2.32.0
1
apachepulsar/pulsar:2.6.14db6ff0b4045
requests@2.24.0
2.32.0
1
apachepulsar/pulsar:3.0.79c9947de139d
python-pip@22.0.2+dfsg-1ubuntu0.4
22.0.2+dfsg-1ubuntu0.7+esm1
1
apachepulsar/pulsar:2.9.0d056c89b7131
requests@2.26.0
2.32.0
1
apachepulsar/pulsar:2.8.2d538416d5afe
requests@2.26.0
2.32.0
1
apache/ranger:2.7.076c176e8a0e4
python-pip@22.0.2+dfsg-1ubuntu0.6
22.0.2+dfsg-1ubuntu0.7+esm1
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
requests@2.26.0
2.32.0
1
apache/superset:4.0.1ab9467fd712c
requests@2.31.0
2.32.0
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
requests@2.25.1
2.32.0
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
python-requests@2.20.0-3.el8_8
requests@2.20.0
0:2.20.0-5.el8_10
2.32.0
1
aquasec/kube-hunter:1950bf607ce9308
requests@2.20.1
2.32.0
1
aristidetm/k8s-hub:3.3.7ccb516cb8474
requests@2.31.0
2.32.0
1
arunvelsriram/utils:latest655ad18fd8d6
python-pip@24.0+dfsg-1ubuntu1.2
requests@2.31.0+dfsg-1ubuntu1.1
requests@2.31.0
24.0+dfsg-1ubuntu1.3+esm1
no fix listed
2.32.0
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
requests@2.25.1
2.32.0
1
assistiot/fl_local_operations_inference:latest0518b63a2e69
requests@2.28.2
2.32.0
1
assistiot/fl_repository:latest0fce3ea719a5
requests@2.28.1
2.32.0
1
assistiot/fl_training_collector:latest792715dd3084
requests@2.26.0
2.32.0
1
assistiot/open_api_backend:1.1.230812ba93555
python-pip@22.0.2+dfsg-1ubuntu0.4
requests@2.31.0
22.0.2+dfsg-1ubuntu0.7+esm1
2.32.0
1
assistiot/resource-provisioning_api:1.0.044a37b00d4f8
requests@2.27.1
2.32.0
1
assistiot/resource-provisioning_im:1.0.0a942dc14030a
requests@2.27.1
2.32.0
1
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
requests@2.27.1
2.32.0
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
requests@2.31.0
2.32.0
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
requests@2.31.0
2.32.0
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
requests@2.27.1
2.32.0
1
assistiot/traffic-classification_api:2.0.0e32b87786142
requests@2.27.1
2.32.0
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
python-pip@20.0.2-5ubuntu1.8
requests@2.22.0-2ubuntu1
requests@2.22.0
no fix listed
no fix listed
2.32.0
1
balihb/pod-pvc-mapping:0.2.4ee48e79f5d76
requests@2.27.1
2.32.0
1
baserow/backend:1.31.1e0b3c8130b91
requests@2.31.0
2.32.0
1
baserow/baserow:1.30.1df0c42eb67e8
requests@2.31.0
2.32.0
1
bbvalabs/sensitive-data:1.0.13ea299ae63c0
requests@2.25.1
2.32.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.