StackRadar

CVE-2024-49768

Critical

Advisory

Published 29 Oct 2024In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
24
deployed by those charts
Fix available
1 of 1
affected package

Waitress has request processing race condition in HTTP pipelining with invalid first request

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 24 images.

Affected packageAffected versionsFixed inImages
waitresspypi2.0.0, 2.1.1, 2.1.2, 3.0.03.0.124
OSV records
GHSA-9298-4cf8-g4wj
Also known as
PYSEC-2024-210

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.3.21f104ee51e512
waitress@2.1.2
3.0.1

Open the chart page →

3,004
stackstorm-hastackstormVerified publisher1.1.011 of 17See more

stackstorm-ha stackstorm 1.1.0

11 of the 17 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
waitress@2.1.2
3.0.1
stackstorm/st2api:3.86f56d239d280
waitress@2.1.2
3.0.1
stackstorm/st2auth:3.833ecfda16608
waitress@2.1.2
3.0.1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
waitress@2.1.2
3.0.1
stackstorm/st2notifier:3.8f190a6212195
waitress@2.1.2
3.0.1
stackstorm/st2rulesengine:3.8259503496ff9
waitress@2.1.2
3.0.1
stackstorm/st2scheduler:3.8b1de2055c362
waitress@2.1.2
3.0.1
stackstorm/st2sensorcontainer:3.8b1a338f64773
waitress@2.1.2
3.0.1
stackstorm/st2stream:3.81c8904a3bf67
waitress@2.1.2
3.0.1
stackstorm/st2timersengine:3.81bf35bfaf00c
waitress@2.1.2
3.0.1
stackstorm/st2workflowengine:3.819fdfffdbba8
waitress@2.1.2
3.0.1

Open the chart page →

96,419
servarrservarr1.0.21 of 10See more

servarr servarr 1.0.2

1 of the 10 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.3.16088412db1051
waitress@2.1.2
3.0.1

Open the chart page →

14,238
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
redislabs/redisinsight:1.14.0b03ab1426d0d
waitress@2.1.2
3.0.1

Open the chart page →

13,874
iopsciencemeshVerified publisher0.4.01 of 2See more

iop sciencemesh 0.4.0

1 of the 2 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
cs3org/wopiserver:v9.4.202a9e78757b4
waitress@2.1.2
3.0.1

Open the chart page →

4,052
speedtest-exporteralekcVerified publisher0.2.01 of 1See more

speedtest-exporter alekc 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.5.4f1064d49124c
waitress@2.1.2
3.0.1

Open the chart page →

741
keystonearzu0.2.291 of 4See more

keystone arzu 0.2.29

1 of the 4 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
waitress@2.0.0
3.0.1

Open the chart page →

22,568
wopiservercs3orgOfficialVerified publisher0.9.21 of 1See more

wopiserver cs3org 0.9.2

1 of the 1 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
cs3org/wopiserver:v9.4.202a9e78757b4
waitress@2.1.2
3.0.1

Open the chart page →

2,348
speedtest-exportergeek-cookbookVerified publisher5.4.21 of 1See more

speedtest-exporter geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.2.29e36964bce26
waitress@2.0.0
3.0.1

Open the chart page →

1,772
bazarrk8s-home-lab-repo11.3.21 of 1See more

bazarr k8s-home-lab-repo 11.3.2

1 of the 1 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
ghcr.io/home-operations/bazarr:1.5.680cb090162b4
waitress@3.0.0
3.0.1

Open the chart page →

1,794
slackgptkfirfer0.0.61 of 1See more

slackgpt kfirfer 0.0.6

1 of the 1 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
kfirfer/slackgpt:0.0.15461331bd838e
waitress@2.1.2
3.0.1

Open the chart page →

1,126
errbotmidokura-communityVerified publisher0.0.51 of 1See more

errbot midokura-community 0.0.5

1 of the 1 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
errbotio/errbot:6.1.900ee4e0953ab
waitress@2.1.2
3.0.1

Open the chart page →

2,233
libretranslateobeoneVerified publisher1.0.71 of 1See more

libretranslate obeone 1.0.7

1 of the 1 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
libretranslate/libretranslate:v1.9.61de2d7056bb8
waitress@2.1.2
3.0.1

Open the chart page →

1,990
reportportalreportportal5.7.21 of 8See more

reportportal reportportal 5.7.2

1 of the 8 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
reportportal/service-auto-analyzer:5.7.295ada4a216ce
waitress@2.1.1
3.0.1

Open the chart page →

25,737
syncstorageschichtelVerified publisher0.1.11 of 1See more

syncstorage schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
mozilla/syncstorage-rs:0.15.893752877dced
waitress@3.0.0
3.0.1

Open the chart page →

1,318
speedtest-exporterspeedtest-exporter0.2.21 of 1See more

speedtest-exporter speedtest-exporter 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-49768.

Container imageDigestPackageFixed in
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.5.4f1064d49124c
waitress@2.1.2
3.0.1

Open the chart page →

741

Container images carrying it

24 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
cs3org/wopiserver:v9.4.202a9e78757b4
waitress@2.1.2
3.0.1
2
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.5.4f1064d49124c
waitress@2.1.2
3.0.1
2
errbotio/errbot:6.1.900ee4e0953ab
waitress@2.1.2
3.0.1
1
kfirfer/slackgpt:0.0.15461331bd838e
waitress@2.1.2
3.0.1
1
libretranslate/libretranslate:v1.9.61de2d7056bb8
waitress@2.1.2
3.0.1
1
mozilla/syncstorage-rs:0.15.893752877dced
waitress@3.0.0
3.0.1
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
waitress@2.0.0
3.0.1
1
redislabs/redisinsight:1.14.0b03ab1426d0d
waitress@2.1.2
3.0.1
1
reportportal/service-auto-analyzer:5.7.295ada4a216ce
waitress@2.1.1
3.0.1
1
stackstorm/st2actionrunner:3.888235ba70cad
waitress@2.1.2
3.0.1
1
stackstorm/st2api:3.86f56d239d280
waitress@2.1.2
3.0.1
1
stackstorm/st2auth:3.833ecfda16608
waitress@2.1.2
3.0.1
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
waitress@2.1.2
3.0.1
1
stackstorm/st2notifier:3.8f190a6212195
waitress@2.1.2
3.0.1
1
stackstorm/st2rulesengine:3.8259503496ff9
waitress@2.1.2
3.0.1
1
stackstorm/st2scheduler:3.8b1de2055c362
waitress@2.1.2
3.0.1
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
waitress@2.1.2
3.0.1
1
stackstorm/st2stream:3.81c8904a3bf67
waitress@2.1.2
3.0.1
1
stackstorm/st2timersengine:3.81bf35bfaf00c
waitress@2.1.2
3.0.1
1
stackstorm/st2workflowengine:3.819fdfffdbba8
waitress@2.1.2
3.0.1
1
ghcr.io/flaresolverr/flaresolverr:v3.3.16088412db1051
waitress@2.1.2
3.0.1
1
ghcr.io/flaresolverr/flaresolverr:v3.3.21f104ee51e512
waitress@2.1.2
3.0.1
1
ghcr.io/home-operations/bazarr:1.5.680cb090162b4
waitress@3.0.0
3.0.1
1
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.2.29e36964bce26
waitress@2.0.0
3.0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.