StackRadar

CVE-2024-35195

Medium

Advisory

Published 20 May 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.6
base score, highest
EPSS
0.003
27th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
605
of 17,787 indexed, latest versions
Container images
658
deployed by those charts
Fix available
3 of 4
affected packages

Requests `Session` object does not verify requests after making first request with verify=False

Carried by container images the latest versions of 605 of 17,787 indexed charts deploy, on 658 images.

Affected packageAffected versionsFixed inImages
requestspypi2.2.1, 2.6.0, 2.9.1, 2.10.0+22 more2.32.0612
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+23 more22.0.2+dfsg-1ubuntu0.7+esm1, 24.0+dfsg-1ubuntu1.3+esm1108
requestsdeb2.2.1-1, 2.2.1-1ubuntu0.3, 2.9.1-3, 2.9.1-3ubuntu0.1+8 moreno fix listed72
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_6, 2.20.0-3.el8_8, 2.25.1-7.el9_2+1 more0:2.20.0-5.el8_10, 0:2.25.1-9.el942
OSV records
DEBIAN-CVE-2024-35195GHSA-9wx4-h78v-vm56RHSA-2025:0012RHSA-2025:7049UBUNTU-CVE-2024-35195
Also known as
PYSEC-2026-1873, USN-8344-1

Charts affected

605 by stars
ChartLatestAffected imagesRadar Score
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
requests@2.20.0
2.32.0

Open the chart page →

11,785
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
requests@2.25.1
2.32.0

Open the chart page →

1,843
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
requests@2.31.0
2.32.0

Open the chart page →

5,548
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
requests@2.24.0
2.32.0

Open the chart page →

2,643
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
requests@2.28.2
2.32.0

Open the chart page →

1,838

Container images carrying it

658 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
marcoimme/oidcmock:latestb6035c0721a8
requests@2.31.0
2.32.0
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
requests@2.27.1
2.32.0
1
matrixdotorg/synapse:v1.78.0def97fd537d8
requests@2.27.1
2.32.0
1
mediagis/nominatim:5.3.27923a8e67197
python-pip@24.0+dfsg-1ubuntu1.3
requests@2.31.0+dfsg-1ubuntu1.1
requests@2.31.0
24.0+dfsg-1ubuntu1.3+esm1
no fix listed
2.32.0
1
mediagis/nominatim:3.7c15e941485ef
python-pip@20.0.2-5ubuntu1.6
requests@2.28.1
no fix listed
2.32.0
1
mediagis/nominatim:4.2d0eae7b51374
python-pip@22.0.2+dfsg-1ubuntu0.4
requests@2.31.0
22.0.2+dfsg-1ubuntu0.7+esm1
2.32.0
1
milesmcc/shynet:v0.13.1ba54f7797a6b
requests@2.31.0
2.32.0
1
milesmcc/shynet:v0.12.0e821e31140f7
requests@2.26.0
2.32.0
1
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
requests@2.25.1
2.32.0
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
requests@2.28.1
2.32.0
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
requests@2.28.2
2.32.0
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
requests@2.28.1
2.32.0
1
mozilla/syncserver:latest016162bf39d8
requests@2.22.0
2.32.0
1
mozilla/syncstorage-rs:0.15.893752877dced
requests@2.31.0
2.32.0
1
mshanley80/httpbin2022:latest5b189a70c0fb
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
muluder/prograncontrollermcord:0.1.843b597a93da7
requests@2.9.1-3
requests@2.9.1
no fix listed
2.32.0
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
requests@2.21.0
2.32.0
1
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
requests@2.31.0
2.32.0
1
neilpeterson/chart-tweet:latest64fd8dab075f
requests@2.18.4
2.32.0
1
neilpeterson/get-tweet:v28b645ac1a23e
requests@2.18.4
2.32.0
1
neilpeterson/osba-container-instances-demo:latest6527b05d5d03
requests@2.18.4
2.32.0
1
neilpeterson/osba-storage-demo:latest29d229ab446e
requests@2.18.4
2.32.0
1
neilpeterson/osba-text-analytics-demo:latest969af3cb8466
requests@2.18.4
2.32.0
1
neilpeterson/process-tweet:latest39ce9f92e899
requests@2.18.4
2.32.0
1
netbirdio/dashboard:v2.22.215a3aab9a345
requests@2.25.1
2.32.0
1
netbirdio/dashboard:v2.90.101b59e1c905c9
requests@2.25.1
2.32.0
1
netbirdio/dashboard:v2.90.2332cc31f5f35
requests@2.25.1
2.32.0
1
netbirdio/dashboard:v2.13.188b5fb704a8c
requests@2.25.1
2.32.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
requests@2.28.1
2.32.0
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
requests@2.31.0
2.32.0
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
requests@2.24.0
2.32.0
1
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
requests@2.24.0
2.32.0
1
nlmacamp/check_mk:latest5dbb8589f824
requests@2.16.0
2.32.0
1
nyurik/alpine-python3-requests:lateste0553236e3eb
requests@2.25.1
2.32.0
1
octoprint/octoprint:1.4.0106c26efcd8a
requests@2.25.0
2.32.0
1
octoprint/octoprint:1.6.1ea3bffae2470
requests@2.25.1
2.32.0
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
python-pip@9.0.1-2.3~ubuntu1.18.04.1
no fix listed
1
omecproject/onos-progran:1.0.05715e5648aa0
requests@2.9.1-3
requests@2.9.1
no fix listed
2.32.0
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
python-pip@8.1.1-2ubuntu0.4
requests@2.18.4
no fix listed
2.32.0
1
opendatacube/pipelines:wofs-1.225d810e8504b8
python-pip@9.0.1-2.3~ubuntu1
requests@2.20.1
no fix listed
2.32.0
1
opendatacube/restcube:latest91870111837c
python-pip@9.0.1-2.3~ubuntu1
requests@2.18.4-2ubuntu0.1
requests@2.18.4
no fix listed
no fix listed
2.32.0
1
opendatacube/wms:latest1b90cdf68831
python-pip@9.0.1-2.3~ubuntu1
requests@2.18.4-2ubuntu0.1
requests@2.20.1
no fix listed
no fix listed
2.32.0
1
openelevation/open-elevation:latest82fb21612e86
python-pip@20.0.2-5ubuntu1.6
no fix listed
1
openemr/openemr:6.1.089eaa6d9a4e3
requests@2.26.0
2.32.0
1
openspeedtest/latest:v2.0.0d4d62f4b7d85
requests@2.28.1
2.32.0
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
requests@2.25.1
2.32.0
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
requests@2.25.1
2.32.0
1
openvpn/openvpn-as:latest2253c10ec652
requests@2.31.0+dfsg-1ubuntu1.1
requests@2.31.0
no fix listed
2.32.0
1
openwhisk/kafkaprovider:2.1.063dc3d2a0904
requests@2.10.0
2.32.0
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
python-pip@9.0.1-2.3~ubuntu1.18.04.4
requests@2.24.0
no fix listed
2.32.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.