StackRadar

CVE-2024-37891

Medium

Advisory

Published 17 Jun 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.011
65th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
608
of 17,787 indexed, latest versions
Container images
651
deployed by those charts
Fix available
4 of 4
affected packages

urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects

Carried by container images the latest versions of 608 of 17,787 indexed charts deploy, on 651 images.

Affected packageAffected versionsFixed inImages
python-urllib3deb1.7.1-1build1, 1.7.1-1ubuntu4, 1.13.1-2ubuntu0.16.04.1, 1.13.1-2ubuntu0.16.04.2+8 more1.13.1-2ubuntu0.16.04.4+esm2, 1.22-1ubuntu0.18.04.2+esm2, 1.25.8-2ubuntu0.4, 1.26.5-1~exp1ubuntu0.2+1 more46
urllib3pypi1.7.1, 1.10.2, 1.13.1, 1.19.1+42 more1.26.19, 2.2.2630
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+16 more8.1.1-2ubuntu0.6+esm10, 9.0.1-2.3~ubuntu1.18.04.8+esm6, 20.0.2-5ubuntu1.11, 22.0.2+dfsg-1ubuntu0.5+1 more70
python-urllib3rpm1.24.2-4.el8, 1.24.2-5.el8, 1.24.2-5.el8_6.1, 1.24.2-5.el8_9.2+3 more0:1.24.2-5.el8_6.3, 0:1.24.2-8.el8_10, 0:1.26.5-5.el9_4.134
OSV records
DEBIAN-CVE-2024-37891GHSA-34jh-p97f-mpxfRHSA-2024:5041RHSA-2024:5309RHSA-2024:6162UBUNTU-CVE-2024-37891
Also known as
PYSEC-2026-1995, RHSA-2024:5526, RHSA-2024:6240, USN-7084-1, USN-7084-2

Charts affected

608 by stars
ChartLatestAffected imagesRadar Score
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
urllib3@1.26.9
1.26.19

Open the chart page →

7,579
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
urllib3@1.26.7
1.26.19

Open the chart page →

10,676
mlflowgetindataVerified publisher0.1.21 of 1See more

mlflow getindata 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
gcr.io/getindata-images-public/mlflow:latest25d6975951f1
urllib3@2.2.1
2.2.2

Open the chart page →

2,452
netbirdhelmforgeVerified publisher1.0.101 of 4See more

netbird helmforge 1.0.10

1 of the 4 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
netbirdio/dashboard:v2.90.101b59e1c905c9
urllib3@1.26.5
1.26.19

Open the chart page →

3,012
redis-pod-labelerhmdmph1.0.21 of 1See more

redis-pod-labeler hmdmph 1.0.2

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
hmdmph/redis-pod-labeler:1.0.0-alpine7f1381fe0f3b
urllib3@1.25.9
1.26.19

Open the chart page →

2,985
kiali-operatorkiali2.32.01 of 1See more

kiali-operator kiali 2.32.0

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
quay.io/kiali/kiali-operator:v2.32.096c5264d54ab
urllib3@1.26.5
1.26.19

Open the chart page →

1,079
mysqldumpkokuwa7.0.31 of 1See more

mysqldump kokuwa 7.0.3

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
ghcr.io/kokuwaio/gcloud-mysql:v3.2.1963098135c550
urllib3@1.26.18
1.26.19

Open the chart page →

847
kubeviouskubevious1.2.21 of 7See more

kubevious kubevious 1.2.2

1 of the 7 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
redislabs/redisearch:2.4.1433561794c5c8
urllib3@1.26.11
1.26.19

Open the chart page →

14,204
karporkusionstackVerified publisher0.7.61 of 3See more

karpor kusionstack 0.7.6

1 of the 3 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
kusionstack/karpor:v0.6.4b707d3bf0abd
urllib3@1.26.18
1.26.19

Open the chart page →

3,297
kea-dhcpmglants0.7.11 of 1See more

kea-dhcp mglants 0.7.1

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
ghcr.io/mglants/kea-dhcp:2.5.8e1b6eb9e37f9
urllib3@2.2.1
2.2.2

Open the chart page →

1,132
flagsmithone-acre-fundVerified publisher0.1.52 of 6See more

flagsmith one-acre-fund 0.1.5

2 of the 6 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
blacktop/httpie:latestfc5e68e2f5ab
urllib3@1.22
1.26.19
flagsmith/flagsmith-api:v2.6.0fd58556339a4
urllib3@1.25.11
1.26.19

Open the chart page →

6,868
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
kobotoolbox/kobocat:2.022.24ab15679454415
urllib3@1.26.9
1.26.19
kobotoolbox/kpi:2.022.24dbcacc01bccd4
urllib3@1.26.9
1.26.19

Open the chart page →

18,518
open-zaakopen-zaak0.8.01 of 3See more

open-zaak open-zaak 0.8.0

1 of the 3 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
openzaak/open-zaak:1.6.02ca2ea6e0ae9
urllib3@1.26.9
1.26.19

Open the chart page →

4,045
oesopsmxVerified publisher4.0.328 of 25See more

oes opsmx 4.0.32

8 of the 25 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
urllib3@1.26.7
1.26.19
quay.io/opsmxpublic/awsgit:v3-js15a6faada3d4
urllib3@1.26.5
1.26.19
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
urllib3@1.24.2
1.26.19
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
urllib3@1.24.2
1.26.19
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
urllib3@1.24.2
1.26.19
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
python-urllib3@1.24.2-5.el8
urllib3@1.24.2
0:1.24.2-8.el8_10
1.26.19
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
urllib3@1.24.2
1.26.19
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
urllib3@1.24.2
1.26.19

Open the chart page →

107,899
fritzbox-exporterpascaliskeVerified publisher3.0.01 of 1See more

fritzbox-exporter pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
sealife/fritzbox-exporter:1.0f5cc2f0f4c9b
urllib3@1.26.2
1.26.19

Open the chart page →

2,094
kube-prometheus-stackprometheus-worawutchan12.8.01 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

1 of the 6 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.1.03e86186656d3
urllib3@1.25.10
1.26.19

Open the chart page →

12,125
nominatimrobjuz6.4.11 of 4See more

nominatim robjuz 6.4.1

1 of the 4 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
mediagis/nominatim:5.3.27923a8e67197
urllib3@2.0.7
2.2.2

Open the chart page →

8,760
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
python-urllib3@1.25.8-2ubuntu0.1
urllib3@1.25.8
1.25.8-2ubuntu0.4
1.26.19

Open the chart page →

24,549
sn-platformstreamnative1.11.441 of 9See more

sn-platform streamnative 1.11.44

1 of the 9 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python-pip@20.0.2-5ubuntu1.10
20.0.2-5ubuntu1.11

Open the chart page →

15,525
wombatwombatOfficialVerified publisher4.1.281 of 1See more

wombat wombat 4.1.28

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
erlangsolutions/wombatoam:4.1.284680c990147a
urllib3@1.26.5
1.26.19

Open the chart page →

3,697
github-actions-runneradwerx0.10.31 of 1See more

github-actions-runner adwerx 0.10.3

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
python-urllib3@1.25.8-2ubuntu0.1
urllib3@1.25.8
1.25.8-2ubuntu0.4
1.26.19

Open the chart page →

13,683
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
python-pip@9.0.1-2.3~ubuntu1.18.04.5
urllib3@1.26.9
9.0.1-2.3~ubuntu1.18.04.8+esm6
1.26.19

Open the chart page →

12,061
clearml-servingallegroaiVerified publisher1.6.22 of 9See more

clearml-serving allegroai 1.6.2

2 of the 9 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
urllib3@1.26.15
1.26.19
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
urllib3@1.26.15
1.26.19

Open the chart page →

17,879
anteonanteonVerified publisher2.6.41 of 13See more

anteon anteon 2.6.4

1 of the 13 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
ddosify/selfhosted_backend:3.2.93c11e3182652
urllib3@2.2.1
2.2.2

Open the chart page →

22,233
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
urllib3@1.26.5
1.26.19

Open the chart page →

10,731
open-elevationbeeinventor0.1.01 of 2See more

open-elevation beeinventor 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
openelevation/open-elevation:latest82fb21612e86
python-pip@20.0.2-5ubuntu1.6
20.0.2-5ubuntu1.11

Open the chart page →

13,199
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
urllib3@1.24.3
1.26.19

Open the chart page →

2,663
finops-stackcert-managerVerified publisher0.0.51 of 12See more

finops-stack cert-manager 0.0.5

1 of the 12 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
urllib3@2.2.1
2.2.2

Open the chart page →

12,561
cnpg-sandboxcloudnative-pgVerified publisher0.6.11 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

1 of the 6 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.15.1a25886092fa4
urllib3@1.26.8
1.26.19

Open the chart page →

7,583
pgbenchcloudnative-pgVerified publisher0.1.01 of 1See more

pgbench cloudnative-pg 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
urllib3@1.26.12
1.26.19

Open the chart page →

2,713
cosmotech-copilot-apicosmotech-apiVerified publisher0.1.11 of 1See more

cosmotech-copilot-api cosmotech-api 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
urllib3@1.26.18
1.26.19

Open the chart page →

11,236
rommcrystalnetVerified publisher0.2.201 of 3See more

romm crystalnet 0.2.20

1 of the 3 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
zurdi15/romm:2.3.12db88fe44c89
urllib3@2.0.7
2.2.2

Open the chart page →

1,944
cubefscubefs3.2.02 of 10See more

cubefs cubefs 3.2.0

2 of the 10 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
chubaofs/cfs-client:3.2.015ff74209ce7
urllib3@1.26.8
1.26.19
chubaofs/cfs-server:3.2.0205030e045f2
urllib3@1.26.8
1.26.19

Open the chart page →

15,891
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
apsl/thumbor:6.7.051e2de5c2c70
urllib3@1.25.7
1.26.19

Open the chart page →

38,424
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
urllib3@1.25.10
1.26.19

Open the chart page →

4,570
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
urllib3@1.25.10
1.26.19

Open the chart page →

7,987
trivy-operatordevopstalesVerified publisher2.5.01 of 1See more

trivy-operator devopstales 2.5.0

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
devopstales/trivy-operator:2.575136aa7a26e
urllib3@1.26.14
1.26.19

Open the chart page →

5,599
dominodominoVerified publisher0.1.111 of 3See more

domino domino 0.1.11

1 of the 3 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
urllib3@2.2.1
2.2.2

Open the chart page →

8,842
archerydoubanVerified publisher0.4.31 of 6See more

archery douban 0.4.3

1 of the 6 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
hhyo/archery:v1.9.11aa41843419e
urllib3@1.26.12
1.26.19

Open the chart page →

5,854
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
python-pip@22.0.2+dfsg-1ubuntu0.4
22.0.2+dfsg-1ubuntu0.5

Open the chart page →

10,884
spinnakerdwardu-helm-charts2.2.61 of 2See more

spinnaker dwardu-helm-charts 2.2.6

1 of the 2 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
urllib3@1.25.8
1.26.19

Open the chart page →

8,752
jenkinsedu2.7.11 of 2See more

jenkins edu 2.7.1

1 of the 2 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.193170069ff0976
urllib3@1.25.10
1.26.19

Open the chart page →

4,434
enbuildenbuildVerified publisher0.0.501 of 6See more

enbuild enbuild 0.0.50

1 of the 6 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
python-urllib3@1.24.2-5.el8
urllib3@1.24.2
0:1.24.2-8.el8_10
1.26.19

Open the chart page →

31,572
genesis-generatorethereum-helm-chartsVerified publisher0.2.31 of 2See more

genesis-generator ethereum-helm-charts 0.2.3

1 of the 2 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
skylenet/ethereum-genesis-generator:latest210353ce7c89
urllib3@1.26.12
1.26.19

Open the chart page →

3,135
appdaemongeek-cookbookVerified publisher8.4.21 of 1See more

appdaemon geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
acockburn/appdaemon:4.0.83a93281d7e94
urllib3@1.26.4
1.26.19

Open the chart page →

3,461
deepstackgeek-cookbookVerified publisher1.5.21 of 2See more

deepstack geek-cookbook 1.5.2

1 of the 2 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
robmarkcole/deepstack-ui:latest410275726459
urllib3@1.26.6
1.26.19

Open the chart page →

5,305
healthchecksgeek-cookbookVerified publisher4.4.21 of 1See more

healthchecks geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
linuxserver/healthchecks:version-v1.20.050792a72fc71
urllib3@1.26.6
1.26.19

Open the chart page →

1,667
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
python-pip@20.0.2-5ubuntu1.6
20.0.2-5ubuntu1.11

Open the chart page →

15,717
kube-ops-viewgeek-cookbookVerified publisher1.2.21 of 1See more

kube-ops-view geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:20.4.058221b57d4d2
urllib3@1.22
1.26.19

Open the chart page →

1,848
lazylibrariangeek-cookbookVerified publisher7.4.21 of 1See more

lazylibrarian geek-cookbook 7.4.2

1 of the 1 container images this version deploys carry CVE-2024-37891.

Container imageDigestPackageFixed in
linuxserver/lazylibrarian:version-1152df82f93d2560e233
urllib3@1.26.5
1.26.19

Open the chart page →

11,684

Container images carrying it

651 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
urllib3@1.26.5
1.26.19
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.