StackRadar

CVE-2024-35195

Medium

Advisory

Published 20 May 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.6
base score, highest
EPSS
0.003
27th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
605
of 17,787 indexed, latest versions
Container images
658
deployed by those charts
Fix available
3 of 4
affected packages

Requests `Session` object does not verify requests after making first request with verify=False

Carried by container images the latest versions of 605 of 17,787 indexed charts deploy, on 658 images.

Affected packageAffected versionsFixed inImages
requestspypi2.2.1, 2.6.0, 2.9.1, 2.10.0+22 more2.32.0612
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+23 more22.0.2+dfsg-1ubuntu0.7+esm1, 24.0+dfsg-1ubuntu1.3+esm1108
requestsdeb2.2.1-1, 2.2.1-1ubuntu0.3, 2.9.1-3, 2.9.1-3ubuntu0.1+8 moreno fix listed72
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_6, 2.20.0-3.el8_8, 2.25.1-7.el9_2+1 more0:2.20.0-5.el8_10, 0:2.25.1-9.el942
OSV records
DEBIAN-CVE-2024-35195GHSA-9wx4-h78v-vm56RHSA-2025:0012RHSA-2025:7049UBUNTU-CVE-2024-35195
Also known as
PYSEC-2026-1873, USN-8344-1

Charts affected

605 by stars
ChartLatestAffected imagesRadar Score
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
requests@2.20.0
2.32.0

Open the chart page →

11,785
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
requests@2.25.1
2.32.0

Open the chart page →

1,843
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
requests@2.31.0
2.32.0

Open the chart page →

5,548
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
requests@2.24.0
2.32.0

Open the chart page →

2,643
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2024-35195.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
requests@2.28.2
2.32.0

Open the chart page →

1,838

Container images carrying it

658 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
openzaak/open-notificaties:1.3.02e65313b9b10
requests@2.27.1
2.32.0
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
requests@2.27.1
2.32.0
1
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
requests@2.26.0
2.32.0
1
pangeo/base-notebook:2024.01.155fbe688a4f80
requests@2.31.0
2.32.0
1
pecan/monitor:1.7.273b2074f3fec
requests@2.21.0
2.32.0
1
phntom/email-manager:0.1.22d8e2a9f2f085
requests@2.28.2
2.32.0
1
phntom/external-dns-host-network:0.0.123adadbac8443
requests@2.28.1
2.32.0
1
phntom/stocks-nasdaq-crawler:0.0.28d2b844700b57
requests@2.24.0
2.32.0
1
phsmith/rundeck-exporter:2.6.10265a7616ae8
requests@2.31.0
2.32.0
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
requests@2.23.0
2.32.0
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
python-requests@2.20.0-3.el8_8
requests@2.31.0
0:2.20.0-5.el8_10
2.32.0
1
prompve/prometheus-pve-exporter:2.0.1ff6749eb03b0
requests@2.23.0
2.32.0
1
pryorda/vmware_exporter:v0.18.479925e63e59f
requests@2.28.1
2.32.0
1
pryorda/vmware_exporter:v0.18.3e0f5ba8b7856
requests@2.27.1
2.32.0
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
requests@2.28.2
2.32.0
1
rdavidoff/twitch-channel-points-miner-v2:1.8.67ae4c5135771
requests@2.31.0
2.32.0
1
redash/redash:10.0.0.b503639392753c0376
requests@2.21.0
2.32.0
1
redislabs/redisearch:2.4.1433561794c5c8
requests@2.28.1
2.32.0
1
redislabs/redisinsight:1.14.0b03ab1426d0d
requests@2.28.0
2.32.0
1
reportportal/service-auto-analyzer:5.7.295ada4a216ce
requests@2.22.0
2.32.0
1
reportportal/service-metrics-gatherer:1.1.202a0e6dc11161
requests@2.22.0
2.32.0
1
rezachalak/bzen-mongo:1.0.034f694325191
python-pip@20.0.2-5ubuntu1.9
requests@2.31.0
no fix listed
2.32.0
1
roadiehq/community-backstage-image:latestef355bf5b639
requests@2.26.0
2.32.0
1
robmarkcole/deepstack-ui:latest410275726459
requests@2.26.0
2.32.0
1
robotshop/rs-payment:latest774b52c6180d
requests@2.26.0
2.32.0
1
rook/ceph:v1.20.72f970c425617
requests@2.25.1
2.32.0
1
rook/ceph:v1.19.2944a1dd70496
requests@2.25.1
2.32.0
1
saltstack/salt:3006.3e9c7906b7a5c
requests@2.31.0
2.32.0
1
santisbon/evwatcher:latestc4e994ca4540
requests@2.31.0
2.32.0
1
scrapinghub/splash:3.4.1a5f89bc84606
python-pip@9.0.1-2.3~ubuntu1.18.04.1
no fix listed
1
seafileltd/seafile-mc:9.0.106693911bcc40
python-pip@20.0.2-5ubuntu1.6
requests@2.22.0-2ubuntu1
requests@2.22.0
no fix listed
no fix listed
2.32.0
1
seafileltd/seafile-mc:10.0.170628f29c663
python-pip@20.0.2-5ubuntu1.9
requests@2.22.0-2ubuntu1.1
requests@2.22.0
no fix listed
no fix listed
2.32.0
1
seafileltd/seafile-mc:9.0.97ac833196f60
python-pip@20.0.2-5ubuntu1.6
requests@2.22.0-2ubuntu1
requests@2.22.0
no fix listed
no fix listed
2.32.0
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
python-pip@22.0.2+dfsg-1ubuntu0.4
requests@2.31.0
22.0.2+dfsg-1ubuntu0.7+esm1
2.32.0
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
python-pip@20.0.2-5ubuntu1.6
requests@2.22.0-2ubuntu1
requests@2.22.0
no fix listed
no fix listed
2.32.0
1
searx/searx:1.0.0-211-968b28993dbb3a6d9419
requests@2.23.0
2.32.0
1
seldonio/locust-core:0.81d0da98a2d76
python-pip@8.1.1-2ubuntu0.4
requests@2.22.0
no fix listed
2.32.0
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
python-requests@2.20.0-2.1.el8_1
requests@2.26.0
0:2.20.0-5.el8_10
2.32.0
1
shaowenchen/ops-controller-manager:latest26da43bb5b66
python-pip@22.0.2+dfsg-1ubuntu0.7
22.0.2+dfsg-1ubuntu0.7+esm1
1
shaowenchen/ops-server:latest315444f703f4
python-pip@22.0.2+dfsg-1ubuntu0.6
22.0.2+dfsg-1ubuntu0.7+esm1
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
requests@2.31.0
2.32.0
1
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
requests@2.31.0
2.32.0
1
sirrend/helmup-notifications-service:0.1.3997866417011
requests@2.31.0
2.32.0
1
skylenet/ethereum-genesis-generator:latest210353ce7c89
requests@2.28.1
2.32.0
1
smarketshq/marge-bot:0.9.2cfc765b27e64
requests@2.21.0
2.32.0
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
python-pip@20.0.2-5ubuntu1.9
requests@2.31.0
no fix listed
2.32.0
1
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
requests@2.29.0
2.32.0
1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
requests@2.29.0
2.32.0
1
socialmediamacroscope/classification_train:0.1.207477060bba8
requests@2.29.0
2.32.0
1
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
requests@2.29.0
2.32.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.