StackRadar

CVE-2024-35195

Medium

Advisory

Published 20 May 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.6
base score, highest
EPSS
0.003
27th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
603
of 17,790 indexed, latest versions
Container images
655
deployed by those charts
Fix available
3 of 4
affected packages

Requests `Session` object does not verify requests after making first request with verify=False

Carried by container images the latest versions of 603 of 17,790 indexed charts deploy, on 655 images.

Affected packageAffected versionsFixed inImages
requestspypi2.2.1, 2.6.0, 2.9.1, 2.10.0+22 more2.32.0611
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+23 more22.0.2+dfsg-1ubuntu0.7+esm1, 24.0+dfsg-1ubuntu1.3+esm1106
requestsdeb2.2.1-1, 2.2.1-1ubuntu0.3, 2.9.1-3, 2.9.1-3ubuntu0.1+8 moreno fix listed71
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_6, 2.20.0-3.el8_8, 2.25.1-7.el9_2+1 more0:2.20.0-5.el8_10, 0:2.25.1-9.el942
OSV records
DEBIAN-CVE-2024-35195GHSA-9wx4-h78v-vm56RHSA-2025:0012RHSA-2025:7049UBUNTU-CVE-2024-35195
Also known as
PYSEC-2026-1873, USN-8344-1

Charts affected

603 by stars
ChartLatestAffected imagesRadar Score
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
requests@2.31.0
2.32.0

Open the chart page →

5,548
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
requests@2.24.0
2.32.0

Open the chart page →

2,643
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
requests@2.28.2
2.32.0

Open the chart page →

1,838

Container images carrying it

655 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
frankescobar/allure-docker-service:2.19.0cafa03b94dac
python-pip@9.0.1-2.3~ubuntu1.18.04.5
requests@2.23.0
no fix listed
2.32.0
1
freeipa/freeipa-server:fedora-37-4.10.1c87d77342bf5
requests@2.28.1
2.32.0
1
galaxy/cloudman-server:lateste5c265fe9fcd
python-pip@20.0.2-5ubuntu1.6
requests@2.28.1
no fix listed
2.32.0
1
galaxy/galaxy-init:v18.010267bad550e6
python-pip@1.5.4-1ubuntu4
requests@2.2.1-1ubuntu0.3
requests@2.18.4
no fix listed
no fix listed
2.32.0
1
galaxy/galaxy-stable:v18.018e577a626dfd
python-pip@1.5.4-1ubuntu4
requests@2.2.1-1ubuntu0.3
requests@2.18.4
no fix listed
no fix listed
2.32.0
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
python-pip@22.0.2+dfsg-1ubuntu0.7
requests@2.31.0
22.0.2+dfsg-1ubuntu0.7+esm1
2.32.0
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
python-pip@9.0.1-2.3~ubuntu1.18.04.2
requests@2.24.0
no fix listed
2.32.0
1
gethue/hue:4.11.011b649636e68
python-pip@20.0.2-5ubuntu1.6
requests@2.27.1
no fix listed
2.32.0
1
gethue/hue:4.10.05702b2c37ff9
python-pip@9.0.1-2.3~ubuntu1.18.04.5
requests@2.25.1
no fix listed
2.32.0
1
gethue/hue:latest7d5c1b9f8a79
python-pip@22.0.2+dfsg-1ubuntu0.6
22.0.2+dfsg-1ubuntu0.7+esm1
1
getsentry/sentry-kubernetes:latest6ac37974fd2a
requests@2.21.0
2.32.0
1
gluufederation/opendj:4.3.0_011a1128b28b95
requests@2.25.1
2.32.0
1
gmaas2/github-api:latest148fc2d9afe9
requests@2.28.1
2.32.0
1
gmelillo/registry:0.1.8c599d608a2f7
requests@2.26.0
2.32.0
1
goofball222/pritunl:1.30.3070.5943c0743701d4
requests@2.26.0
2.32.0
1
goofball222/pritunl:1.32.3602.807bf26032dfce
requests@2.28.2
2.32.0
1
greenbirdit/locust:0.9.0e99d53bdc944
requests@2.21.0
2.32.0
1
gristlabs/grist:0.7.96e71b1914a7e
requests@2.27.1
2.32.0
1
grpl/grapple-cli:0.2.127c00aafee6629
python-pip@24.0+dfsg-1ubuntu1
24.0+dfsg-1ubuntu1.3+esm1
1
gurolakman/oam:4.0.0ed8fd2062548
python-requests@2.20.0-3.el8_8
requests@2.20.0
0:2.20.0-5.el8_10
2.32.0
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
python-requests@2.20.0-3.el8_8
requests@2.20.0
0:2.20.0-5.el8_10
2.32.0
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
python-requests@2.20.0-3.el8_8
requests@2.20.0
0:2.20.0-5.el8_10
2.32.0
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
python-requests@2.20.0-3.el8_8
requests@2.20.0
0:2.20.0-5.el8_10
2.32.0
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
python-requests@2.20.0-3.el8_8
requests@2.20.0
0:2.20.0-5.el8_10
2.32.0
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
python-requests@2.20.0-3.el8_8
requests@2.20.0
0:2.20.0-5.el8_10
2.32.0
1
gurolakman/ussigw-core:1.0.48739565c3ea2
python-requests@2.20.0-3.el8_8
requests@2.20.0
0:2.20.0-5.el8_10
2.32.0
1
haveagitgat/tdarr:2.00.181256348872ce
requests@2.22.0-2ubuntu1
requests@2.22.0
no fix listed
2.32.0
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
requests@2.22.0-2ubuntu1
requests@2.22.0
no fix listed
2.32.0
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
requests@2.22.0-2ubuntu1.1
requests@2.22.0
no fix listed
2.32.0
1
hcguersoy/cleanreg:v0.8.063b76fdcfbe1
requests@2.27.1
2.32.0
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
requests@2.28.2
2.32.0
1
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
python-pip@20.0.2-5ubuntu1.11
no fix listed
1
hhyo/archery:v1.9.11aa41843419e
requests@2.28.0
2.32.0
1
hiboxsystems/marge-bot:0.11.07235809b43b3
requests@2.25.1
2.32.0
1
hiboxsystems/marge-bot:0.12.1a96c10b61a59
requests@2.31.0
2.32.0
1
hiboxsystems/marge-bot:0.16.0b59f01bc0418
requests@2.31.0
2.32.0
1
hiboxsystems/marge-bot:0.14.0dcffb926e563
requests@2.31.0
2.32.0
1
hjacobs/kube-downscaler:23.2.05d328c003efe
requests@2.28.1
2.32.0
1
hjacobs/kube-janitor:23.7.0fbb303ed463c
requests@2.31.0
2.32.0
1
hjacobs/kube-ops-view:23.5.0a4fae38f93d7
requests@2.30.0
2.32.0
1
hjacobs/kube-resource-report:21.2.145f93491c434
requests@2.25.1
2.32.0
1
hjacobs/kube-resource-report:22.11.0c173cd02f5af
requests@2.28.1
2.32.0
1
hjacobs/kube-web-view:23.8.0431f1bf013d0
requests@2.31.0
2.32.0
1
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
requests@2.24.0
2.32.0
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
requests@2.27.1
2.32.0
1
hmdmph/mongo-pod-labeler:1.0.1-alpine79e4a170f3dc
requests@2.23.0
2.32.0
1
hmdmph/redis-pod-labeler:1.0.0-alpine7f1381fe0f3b
requests@2.23.0
2.32.0
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
requests@2.31.0
2.32.0
1
homeassistant/home-assistant:2023.12.48d000332b09b
requests@2.31.0
2.32.0
1
i4trust/activation-service:2.2.09f3719176893
requests@2.31.0
2.32.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.