StackRadar

CVE-2024-5629

Medium

Advisory

Published 5 Jun 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
47
of 17,781 indexed, latest versions
Container images
58
deployed by those charts
Fix available
4 of 4
affected packages

PyMongo Out-of-bounds Read in the bson module

Carried by container images the latest versions of 47 of 17,781 indexed charts deploy, on 58 images.

Affected packageAffected versionsFixed inImages
pymongopypi3.6.1, 3.8.0, 3.9.0, 3.10.0+11 more4.6.339
python36rpm3.6.8-2.module+el8.1.0+3334+5cb623d7, 3.6.8-2.module+el8.4.0+15040+36b018e7.1, 3.6.8-38.module+el8.5.0+12207+5c5719bc, 3.6.8-38.module+el8.9.0+20976+d3c385250:3.6.8-39.module+el8.10.0+20784+edafcd4319
python-wheelrpm1:0.31.1-2.module+el8.1.0+3724+3c0970901:0.31.1-3.module+el8.10.0+20784+edafcd431
pymongodeb3.11.0-1+b13.11.0-1+deb11u11
OSV records
GHSA-m87m-mmvp-v9qmRHSA-2025:8419DLA-3889-1
Also known as
PYSEC-2026-1826

Charts affected

47 by stars
ChartLatestAffected imagesRadar Score
stackstorm-hastackstormVerified publisher1.1.011 of 17See more

stackstorm-ha stackstorm 1.1.0

11 of the 17 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
pymongo@3.11.3
4.6.3
stackstorm/st2api:3.86f56d239d280
pymongo@3.11.3
4.6.3
stackstorm/st2auth:3.833ecfda16608
pymongo@3.11.3
4.6.3
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
pymongo@3.11.3
4.6.3
stackstorm/st2notifier:3.8f190a6212195
pymongo@3.11.3
4.6.3
stackstorm/st2rulesengine:3.8259503496ff9
pymongo@3.11.3
4.6.3
stackstorm/st2scheduler:3.8b1de2055c362
pymongo@3.11.3
4.6.3
stackstorm/st2sensorcontainer:3.8b1a338f64773
pymongo@3.11.3
4.6.3
stackstorm/st2stream:3.81c8904a3bf67
pymongo@3.11.3
4.6.3
stackstorm/st2timersengine:3.81bf35bfaf00c
pymongo@3.11.3
4.6.3
stackstorm/st2workflowengine:3.819fdfffdbba8
pymongo@3.11.3
4.6.3

Open the chart page →

96,419
alerta-webalerta-webVerified publisher0.1.121 of 2See more

alerta-web alerta-web 0.1.12

1 of the 2 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
hayk96/alerta-web:9.0.486377705e9e3
pymongo@4.4.1
4.6.3

Open the chart page →

3,569
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
pymongo@4.4.1
4.6.3

Open the chart page →

7,960
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

12,042
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

14,546
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

13,874
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
kobotoolbox/kobocat:2.022.24ab15679454415
pymongo@3.12.3
4.6.3
kobotoolbox/kpi:2.022.24dbcacc01bccd4
pymongo@3.12.3
4.6.3

Open the chart page →

18,517
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
apsl/thumbor:6.7.051e2de5c2c70
pymongo@3.10.0
4.6.3

Open the chart page →

38,346
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
pymongo@3.8.0
4.6.3

Open the chart page →

4,568
archerydoubanVerified publisher0.4.31 of 6See more

archery douban 0.4.3

1 of the 6 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
hhyo/archery:v1.9.11aa41843419e
pymongo@3.11.0
4.6.3

Open the chart page →

5,853
enbuildenbuildVerified publisher0.0.501 of 6See more

enbuild enbuild 0.0.50

1 of the 6 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

31,510
mongo-pod-labelerhmdmph1.0.21 of 1See more

mongo-pod-labeler hmdmph 1.0.2

1 of the 1 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
hmdmph/mongo-pod-labeler:1.0.1-alpine79e4a170f3dc
pymongo@3.10.1
4.6.3

Open the chart page →

1,205
alertasomeblackmagic0.2.31 of 2See more

alerta someblackmagic 0.2.3

1 of the 2 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
alerta/alerta-web:8.5.04786b9eaa606
pymongo@3.11.3
4.6.3

Open the chart page →

3,162
fllocaloperationsassist-iot-fl-local-operations1.1.01 of 3See more

fllocaloperations assist-iot-fl-local-operations 1.1.0

1 of the 3 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
assistiot/fl_local_operations_inference:latest0518b63a2e69
pymongo@4.3.3
4.6.3

Open the chart page →

3,786
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
assistiot/fl_repository:latest0fce3ea719a5
pymongo@4.2.0
4.6.3

Open the chart page →

4,367
smartorchestratorassist-iot-smart-orchestrator4.0.02 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

2 of the 14 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
pymongo@4.6.2
4.6.3
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
pymongo@4.6.2
4.6.3

Open the chart page →

45,363
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
pymongo@4.6.1
4.6.3

Open the chart page →

9,412
osba-cosmos-mongodb-demoazure-sample0.1.01 of 1See more

osba-cosmos-mongodb-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
pymongo@3.6.1
4.6.3

Open the chart page →

2,904
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

5,958
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
confluentinc/cp-zookeeper:6.1.078c190f4472c
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

58,857
pritunldysnixVerified publisher0.2.71 of 3See more

pritunl dysnix 0.2.7

1 of the 3 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
dysnix/pritunl:v1.29-r819951e3e7a32
pymongo@3.10.1
4.6.3

Open the chart page →

5,055
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
pymongo@4.3.3
4.6.3

Open the chart page →

4,085
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
pymongo@3.12.1
4.6.3

Open the chart page →

64,489
icinga2g0dscookie0.2.01 of 1See more

icinga2 g0dscookie 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
pymongo@3.11.0
pymongo@3.11.0-1+b1
4.6.3
3.11.0-1+deb11u1

Open the chart page →

4,428
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
pymongo@3.11.0
4.6.3

Open the chart page →

9,077
redashinseefrlab2.1.01 of 3See more

redash inseefrlab 2.1.0

1 of the 3 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
redash/redash:10.0.0.b503639392753c0376
pymongo@3.9.0
4.6.3

Open the chart page →

3,314
jx-app-anchorejenkins-x0.0.41 of 2See more

jx-app-anchore jenkins-x 0.0.4

1 of the 2 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.7.1ed9b3badd17c
python-wheel@1:0.31.1-2.module+el8.1.0+3724+3c097090
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
1:0.31.1-3.module+el8.10.0+20784+edafcd43
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

9,854
pritunlmglants0.1.01 of 1See more

pritunl mglants 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
goofball222/pritunl:1.30.3070.5943c0743701d4
pymongo@3.12.1
4.6.3

Open the chart page →

1,902
pritunl-vpnmoinologics0.0.11 of 1See more

pritunl-vpn moinologics 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
goofball222/pritunl:1.32.3602.807bf26032dfce
pymongo@3.13.0
4.6.3

Open the chart page →

2,470
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-backend:0.11a9ce0b8fbd4
pymongo@3.11.0
4.6.3

Open the chart page →

6,438
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi:x86bacb2ddd8394
pymongo@4.2.0
4.6.3

Open the chart page →

8,556
betydbncsaVerified publisher0.6.11 of 4See more

betydb ncsa 0.6.1

1 of the 4 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
ncsa/checks:1.0.1cc46a03e16ed
pymongo@3.12.3
4.6.3

Open the chart page →

9,542
datawolfncsaVerified publisher1.1.01 of 3See more

datawolf ncsa 1.1.0

1 of the 3 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
ncsa/checks:1.0.1cc46a03e16ed
pymongo@3.12.3
4.6.3

Open the chart page →

4,989
incorencsaVerified publisher1.38.02 of 29See more

incore ncsa 1.38.0

2 of the 29 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
ncsa/checks:1.0.0abf6300b57b7
pymongo@3.11.0
4.6.3
ncsa/checks:1.0.1cc46a03e16ed
pymongo@3.12.3
4.6.3

Open the chart page →

15,369
pecanncsaVerified publisher0.6.21 of 15See more

pecan ncsa 0.6.2

1 of the 15 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
ncsa/checks:1.0.1cc46a03e16ed
pymongo@3.12.3
4.6.3

Open the chart page →

14,154
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
ncsa/checks:1.0.0abf6300b57b7
pymongo@3.11.0
4.6.3

Open the chart page →

55,726
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
python36@3.6.8-38.module+el8.9.0+20976+d3c38525
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

11,796
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

9,968
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
python36@3.6.8-2.module+el8.4.0+15040+36b018e7.1
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

15,466
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
python36@3.6.8-2.module+el8.4.0+15040+36b018e7.1
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

15,466
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

11,151
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
python36@3.6.8-2.module+el8.4.0+15040+36b018e7.1
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

15,291
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
python36@3.6.8-2.module+el8.4.0+15040+36b018e7.1
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

15,291
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

11,437
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

16,047
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
ncsa/checks:main0b738bbc8d70
pymongo@3.13.0
4.6.3

Open the chart page →

66,266
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-5629.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

28,165

Container images carrying it

58 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
stackstorm/st2workflowengine:3.819fdfffdbba8
pymongo@3.11.3
4.6.3
1
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
pymongo@3.11.0
pymongo@3.11.0-1+b1
4.6.3
3.11.0-1+deb11u1
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
quay.io/mongodb/farm-intro-backend:0.11a9ce0b8fbd4
pymongo@3.11.0
4.6.3
1
quay.io/openshift/origin-cli:4.66722d5041b47
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.