CVE-2024-35195
MediumAdvisory
Published 20 May 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.6
- base score, highest
- EPSS
- 0.003
- 27th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 598
- of 17,781 indexed, latest versions
- Container images
- 651
- deployed by those charts
- Fix available
- 3 of 4
- affected packages
Requests `Session` object does not verify requests after making first request with verify=False
Carried by container images the latest versions of 598 of 17,781 indexed charts deploy, on 651 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| requestspypi | 2.2.1, 2.6.0, 2.9.1, 2.10.0+22 more | 2.32.0 | 606 |
| python-pipdeb | 1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+22 more | 22.0.2+dfsg-1ubuntu0.7+esm1, 24.0+dfsg-1ubuntu1.3+esm1 | 107 |
| requestsdeb | 2.2.1-1, 2.2.1-1ubuntu0.3, 2.9.1-3, 2.9.1-3ubuntu0.1+8 more | no fix listed | 72 |
| python-requestsrpm | 2.20.0-2.1.el8_1, 2.20.0-3.el8_6, 2.20.0-3.el8_8, 2.25.1-7.el9_2+1 more | 0:2.20.0-5.el8_10, 0:2.25.1-9.el9 | 42 |
- OSV records
- DEBIAN-CVE-2024-35195GHSA-9wx4-h78v-vm56RHSA-2025:0012RHSA-2025:7049UBUNTU-CVE-2024-35195
- Also known as
- PYSEC-2026-1873, USN-8344-1
Charts affected
598 by stars
Container images carrying it
651 by charts deploying them
A fixed version is listed for 3 of the 4 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| benbusby/ | f77f7e6e4ad2 | requests | 2.32.0 | 1 |
| bicarus/ | b1dab0721e1c | python-pip | no fix listed | 1 |
| billimek/ | 801bba1228ac | requests | 2.32.0 | 1 |
| billimek/ | f14ccd7aad0e | requests | 2.32.0 | 1 |
| billimek/ | bf8158556035 | requests | 2.32.0 | 1 |
| blacktop/ | fc5e68e2f5ab | requests | 2.32.0 | 1 |
| blakeblackshear/ | ae269270ad9e | python-pip | no fix listed | 1 |
| bootc/ | f1383295e7be | requests | 2.32.0 | 1 |
| browserless/ | c81ae5585b47 | requests requests | no fix listed 2.32.0 | 1 |
| buildkite/ | aec38cfaae0e | requests | 2.32.0 | 1 |
| buntha/ | 154542cc3083 | requests | 2.32.0 | 1 |
| camerahub/ | a5af37dd6e1b | requests | 2.32.0 | 1 |
| camptocamp/ | acfafc308d88 | requests | 2.32.0 | 1 |
| camptocamp/ | 35c91d5fda04 | requests | 2.32.0 | 1 |
| camptocamp/ | bff736b15623 | requests | 2.32.0 | 1 |
| camptocamp/ | 2924b43dbf40 | requests | 2.32.0 | 1 |
| cdignam/ | 5a6a55b39cee | requests | 2.32.0 | 1 |
| ceph/ | 90f30824a96e | requests | 2.32.0 | 1 |
| chetangautamm/ | e7f7049e1544 | requests requests | no fix listed 2.32.0 | 1 |
| chubaofs/ | 15ff74209ce7 | requests | 2.32.0 | 1 |
| chubaofs/ | 205030e045f2 | requests | 2.32.0 | 1 |
| citizenstig/ | b81c818ccb86 | python-pip | no fix listed | 1 |
| ckan/ | 84d11924549f | requests | 2.32.0 | 1 |
| cleveritcz/ | c75c1636e0b7 | requests | 2.32.0 | 1 |
| cloudve/ | af56e77ca587 | python-pip requests | no fix listed 2.32.0 | 1 |
| cloudve/ | d79c1c5881c0 | requests | 2.32.0 | 1 |
| clowder/ | 11f3d844e4c0 | requests | 2.32.0 | 1 |
| clowder/ | 14155326c7b9 | requests | 2.32.0 | 1 |
| clowder/ | bf146f1ca24f | requests | 2.32.0 | 1 |
| codaprotocol/ | 37c68e67a401 | requests | 2.32.0 | 1 |
| codaprotocol/ | 4ba4dd3a041f | requests | 2.32.0 | 1 |
| codecov/ | 0475cb1c3136 | requests | 2.32.0 | 1 |
| codecov/ | 837f546b479b | requests | 2.32.0 | 1 |
| confluentinc/ | f2975d507a2a | requests | 2.32.0 | 1 |
| confluentinc/ | 8f1544df1f48 | requests | 2.32.0 | 1 |
| confluentinc/ | 1bbda887bc53 | requests | 2.32.0 | 1 |
| confluentinc/ | 3bf359d5e340 | requests | 2.32.0 | 1 |
| confluentinc/ | c0224a1adf7a | requests | 2.32.0 | 1 |
| confluentinc/ | c87b1c07fb53 | requests | 2.32.0 | 1 |
| confluentinc/ | dc9b972db002 | requests | 2.32.0 | 1 |
| confluentinc/ | 4bc70a83ca6f | requests | 2.32.0 | 1 |
| confluentinc/ | b0b7aa26254a | requests | 2.32.0 | 1 |
| confluentinc/ | 8ec46c27982f | requests | 2.32.0 | 1 |
| confluentinc/ | ee403d5b9090 | requests | 2.32.0 | 1 |
| confluentinc/ | b651d4b6185a | requests | 2.32.0 | 1 |
| confluentinc/ | 0bec03c1f3ce | requests | 2.32.0 | 1 |
| confluentinc/ | 78c190f4472c | requests | 2.32.0 | 1 |
| countly/ | e3c238248f99 | requests requests | no fix listed 2.32.0 | 1 |
| craigwillis/ | ae317d7e4724 | requests | 2.32.0 | 1 |
| crazymax/ | fb307f5b87bf | requests | 2.32.0 | 1 |