StackRadar

CVE-2024-47081

Medium

Advisory

Published 9 Jun 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.010
60th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
701
of 17,787 indexed, latest versions
Container images
757
deployed by those charts
Fix available
5 of 5
affected packages

Requests vulnerable to .netrc credentials leak via malicious URLs

Carried by container images the latest versions of 701 of 17,787 indexed charts deploy, on 757 images.

Affected packageAffected versionsFixed inImages
requestspypi2.2.1, 2.6.0, 2.9.1, 2.10.0+25 more2.32.4745
requestsdeb2.2.1-1, 2.2.1-1ubuntu0.3, 2.9.1-3, 2.9.1-3ubuntu0.1+6 more2.2.1-1ubuntu0.4+esm1, 2.9.1-3ubuntu0.1+esm2, 2.18.4-2ubuntu0.1+esm2, 2.22.0-2ubuntu1.1+esm1+1 more62
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_6, 2.20.0-3.el8_8, 2.25.1-7.el9_2+2 more0:2.20.0-6.el8_10, 0:2.25.1-10.el9_643
python-pipdeb22.0.2+dfsg-1, 22.0.2+dfsg-1ubuntu0.2, 22.0.2+dfsg-1ubuntu0.3, 22.0.2+dfsg-1ubuntu0.4+5 more22.0.2+dfsg-1ubuntu0.7, 24.0+dfsg-1ubuntu1.321
py3-requestsapk2.32.3-r02.32.4-r03
OSV records
ALPINE-CVE-2024-47081DEBIAN-CVE-2024-47081GHSA-9hjg-9r4m-mvj7RHSA-2025:12519RHSA-2025:13234UBUNTU-CVE-2024-47081
Also known as
PYSEC-2026-1872, RHSA-2025:15121, RHSA-2025:15122, RHSA-2025:15691, USN-7568-1, USN-7762-1

Charts affected

701 by stars
ChartLatestAffected imagesRadar Score
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-47081.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
requests@2.32.3
2.32.4

Open the chart page →

569

Container images carrying it

757 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
requests@2.27.1
2.32.4
1
taigaio/taiga-back:6.4.29f97323cc150
requests@2.21.0
2.32.4
1
teknas09/bird-pod:latest12a1fa85c4aa
requests@2.31.0
2.32.4
1
tenableofficial/nessus:latestc88e43fe1a8c
requests@2.27.1
2.32.4
1
th0th/node-red:4.0.3-debiand06fa39f7406
requests@2.25.1
2.32.4
1
thongngo3301/stakefish:latesta341af5976e3
requests@2.32.2
2.32.4
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
requests@2.25.1+dfsg-2
requests@2.25.1
2.25.1+dfsg-2ubuntu0.3
2.32.4
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
requests@2.25.1+dfsg-2
requests@2.25.1
2.25.1+dfsg-2ubuntu0.3
2.32.4
1
timescale/timescaledb-ha:pg16d7db8f1085a3
requests@2.25.1
2.32.4
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
python-pip@22.0.2+dfsg-1ubuntu0.5
requests@2.25.1+dfsg-2ubuntu0.1
requests@2.25.1
22.0.2+dfsg-1ubuntu0.7
2.25.1+dfsg-2ubuntu0.3
2.32.4
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
requests@2.25.1+dfsg-2
requests@2.25.1
2.25.1+dfsg-2ubuntu0.3
2.32.4
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
requests@2.18.4
2.32.4
1
tomsajan/netio-exporter:0.0.5fb61907707b8
requests@2.31.0
2.32.4
1
tomsquest/docker-radicale:3.1.1.04759cc353a1d
requests@2.25.1
2.32.4
1
trungkien210493/icinga2-report:v1.7.12cc8c3763c4c
requests@2.21.0
2.32.4
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
requests@2.25.1+dfsg-2ubuntu0.1
requests@2.25.1
2.25.1+dfsg-2ubuntu0.3
2.32.4
1
ubcctlt/barman:v2.19cbbbbc8ae16b
requests@2.23.0
2.32.4
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
requests@2.27.0
2.32.4
1
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
requests@2.25.1
2.32.4
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
python-requests@2.20.0-3.el8_8
requests@2.20.0
0:2.20.0-6.el8_10
2.32.4
1
voltha/voltha-cli:1.6.0c4e41e92f046
requests@2.9.1-3ubuntu0.1
requests@2.9.1
2.9.1-3ubuntu0.1+esm2
2.32.4
1
voltha/voltha-netconf:1.6.037f80524c207
requests@2.18.4
2.32.4
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
requests@2.18.4
2.32.4
1
voltha/voltha-tester:1.7.0655c3048a602
requests@2.18.4
2.32.4
1
voltha/voltha-voltha:1.6.0ff596b62de59
requests@2.18.4
2.32.4
1
wallarm/ingress-python:4.6.0-15cb2ae08b40f
requests@2.21.0
2.32.4
1
wallarm/node-helpers:5.0.2-1097cadc42336
requests@2.32.3
2.32.4
1
wazuh/wazuh-manager:4.11.11da5c38c6a78
requests@2.32.2
2.32.4
1
wazuh/wazuh-manager:4.4.121994f40e0da
requests@2.25.1
2.32.4
1
weblate/weblate:3.11.3-182848df56ecd
requests@2.23.0
2.32.4
1
wiremind/pghoard:12-2019-11-264dea42c8166c
requests@2.22.0
2.32.4
1
xeladock/mysql_dns:latest4baf531453f1
python-pip@22.0.2+dfsg-1
22.0.2+dfsg-1ubuntu0.7
1
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
requests@2.32.3
2.32.4
1
yetiplatform/yeti:2.9.09bcbe2650a14
requests@2.32.3
2.32.4
1
yetiplatform/yeti:latest9c3006cedcca
requests@2.32.3
2.32.4
1
youssef11gaber10/deployment-weather-flask:latest96bce8b8b5a7
requests@2.26.0
2.32.4
1
zohardocker12/weather_app_flask:latestb86d60dbb68d
requests@2.27.1
2.32.4
1
zurdi15/romm:2.3.12db88fe44c89
requests@2.31.0
2.32.4
1
gcr.io/getindata-images-public/mlflow:latest25d6975951f1
requests@2.31.0
2.32.4
1
gcr.io/google-samples/microservices-demo/loadgenerator:v0.2.3360130ab5850
requests@2.24.0
2.32.4
1
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
requests@2.24.0
2.32.4
1
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
requests@2.32.3
2.32.4
1
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
python-requests@2.25.1-8.el9
requests@2.32.3
0:2.25.1-10.el9_6
2.32.4
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
requests@2.31.0
2.32.4
1
gcr.io/ml-pipeline/metadata-writer:2.0.0-alpha.5ec3ae9f6df47
requests@2.27.1
2.32.4
1
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
requests@2.32.3
2.32.4
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
requests@2.32.3
2.32.4
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
requests@2.28.1+dfsg-1
requests@2.28.1
no fix listed
2.32.4
1
ghcr.io/aws-exporters/prometheus-ecr-exporter:0.1.442b0c87470d6
requests@2.26.0
2.32.4
1
ghcr.io/aws-exporters/prometheus-inspector-exporter:0.0.29c7c11293b3c
requests@2.26.0
2.32.4
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.