StackRadar

CVE-2025-47273

High

Advisory

Published 17 May 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,086
of 17,787 indexed, latest versions
Container images
1,156
deployed by those charts
Fix available
18 of 19
affected packages

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

Carried by container images the latest versions of 1,086 of 17,787 indexed charts deploy, on 1,156 images.

Affected packageAffected versionsFixed inImages
setuptoolspypi0.9.8, 20.7.0, 20.8.0, 29.0.1.post20161130+124 more78.1.11,083
setuptoolsdeb45.2.0-1, 45.2.0-1ubuntu0.1, 45.2.0-1ubuntu0.2, 52.0.0-4+8 more45.2.0-1ubuntu0.3, 52.0.0-4+deb11u2, 59.6.0-1.2ubuntu0.22.04.3, 66.1.1-1+deb12u2+1 more154
python-setuptoolsdeb3.3-1ubuntu1, 3.3-1ubuntu2, 20.7.0-1, 39.0.1-2+3 more3.3-1ubuntu2+esm3, 20.7.0-1ubuntu0.1~esm3, 39.0.1-2ubuntu0.1+esm2, 44.0.0-2ubuntu0.1+esm239
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+5 more8.1.1-2ubuntu0.6+esm12, 9.0.1-2.3~ubuntu1.18.04.8+esm830
py3-pipapk25.0.1-r0, 25.2-r0, 26.0.1-r1no fix listed3
setuptoolsbitnami70.3.078.1.12
python-setuptoolsrpm0.9.8-7.el7, 39.2.0-5.el8, 39.2.0-6.el8, 39.2.0-6.el8_7.1+6 more0:0.9.8-7.el7_9.2, 0:39.2.0-9.el8_10, 0:53.0.0-13.el9_6.1138
python-chardetrpm3.0.4-7.el80:3.0.4-19.module+el8.4.0+9822+20bf124920
python-idnarpm2.5-5.el80:2.10-3.module+el8.4.0+9822+20bf124920
python-pysocksrpm1.6.8-3.el80:1.7.1-4.module+el8.4.0+9822+20bf124920
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_6, 2.20.0-3.el8_80:2.25.0-2.module+el8.4.0+9822+20bf124920
python-urllib3rpm1.24.2-5.el8, 1.24.2-5.el8_6.10:1.25.10-3.module+el8.4.0+9822+20bf1249, 0:1.25.10-4.module+el8.5.0+11712+ea2d2be120
python3x-setuptoolsrpm41.6.0-4.module+el8.4.0+8888+89bc7e79, 41.6.0-5.module+el8.5.0+12205+a865257a, 50.3.2-3.module+el8.4.0+9822+20bf1249, 50.3.2-4.module+el8.5.0+12204+548604230:50.3.2-3.module+el8.4.0+23445+8885b4ac.3, 0:50.3.2-7.module+el8.8.0+23471+79c1a0709
python-plyrpm3.9-9.el80:3.11-10.module+el8.4.0+9822+20bf12497
python39rpm3.9.2-1.module+el8.4.0+10237+bdc77aac, 3.9.16-1.module+el8.8.0+18968+3d7b19f0.10:3.9.2-2.module+el8.4.0+22379+dcc60181.4, 0:3.9.16-1.module+el8.8.0+22374+62aa8e74.46
python3x-piprpm19.3.1-1.module+el8.4.0+8888+89bc7e79, 19.3.1-6.module+el8.7.0+15823+8950cfa7, 20.2.4-3.module+el8.4.0+9822+20bf12490:20.2.4-3.module+el8.4.0+15042+dc5a279b.1, 0:20.2.4-7.module+el8.6.0+13003+6bb2c4884
python3.11-setuptoolsrpm65.5.1-2.el9, 65.5.1-2.el9_4.10:65.5.1-4.el9_62
python-wheelrpm0.33.6-5.module+el8.4.0+8888+89bc7e791:0.35.1-3.module+el8.4.0+15042+dc5a279b.11
python-3.11deb3.11.15+e43.11.16+e21
OSV records
BIT-setuptools-2025-47273CGA-6rww-wjff-6g99CGA-gfc8-q7jm-4w3vDEBIAN-CVE-2025-47273PYSEC-2025-49RHSA-2025:10407RHSA-2025:11036RHSA-2025:11984RHSA-2025:13578RHSA-2025:15408RHSA-2025:15410RHSA-2025:15411RLSA-2025:10407RLSA-2025:11036UBUNTU-CVE-2025-47273DLA-4183-1ECHO-2d75-a206-3684USN-7544-1
Also known as
CGA-wrp2-2xv2-hfvv, CGA-xqm6-7hq3-gpvg, GHSA-5rjg-fvgr-3xxf, RHSA-2025:11424, RHSA-2025:11425, RHSA-2025:11426, RHSA-2025:11427, RHSA-2025:11868, RHSA-2025:12020, RHSA-2025:13669, USN-8010-1

Charts affected

1,086 by stars
ChartLatestAffected imagesRadar Score
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

11,795
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10
andrianrf/backoffice-be:latest6036614803d4
python-setuptools@53.0.0-12.el9
0:53.0.0-13.el9_6.1
andrianrf/iso-server:latest7da47f525c7d
python-setuptools@53.0.0-12.el9
0:53.0.0-13.el9_6.1

Open the chart page →

34,721
canvas-oamportalopenshift4.0.01 of 1See more

canvas-oamportal openshift 4.0.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/oam:4.0.0ed8fd2062548
setuptools@39.2.0
python-setuptools@39.2.0-8.el8_10
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

7,519
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
setuptools@65.5.1
python-setuptools@53.0.0-12.el9_4.1
python3.11-setuptools@65.5.1-2.el9_4.1
78.1.1
0:53.0.0-13.el9_6.1
0:65.5.1-4.el9_6
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
setuptools@65.5.1
python-setuptools@53.0.0-12.el9
python3.11-setuptools@65.5.1-2.el9
78.1.1
0:53.0.0-13.el9_6.1
0:65.5.1-4.el9_6

Open the chart page →

18,991
exporteropenshift1.0.473 of 3See more

exporter openshift 1.0.47

3 of the 3 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
setuptools@39.2.0
python-setuptools@39.2.0-8.el8_10
78.1.1
0:39.2.0-9.el8_10
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
setuptools@53.0.0
python-setuptools@53.0.0-13.el9
78.1.1
0:53.0.0-13.el9_6.1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
setuptools@53.0.0
python-setuptools@53.0.0-13.el9
78.1.1
0:53.0.0-13.el9_6.1

Open the chart page →

13,034
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

9,968
fsmopenshift0.1.8-ubi.61 of 6See more

fsm openshift 0.1.8-ubi.6

1 of the 6 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

16,554
hamiopenshift2.10.0-r0-openshift.c4e22e881 of 2See more

hami openshift 2.10.0-r0-openshift.c4e22e88

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/dynamia-ai/hami-enterprise:v2.10.0-r0-openshift.c4e22e88745504757300
setuptools@39.2.0
78.1.1

Open the chart page →

4,749
kb-cloud-installeropenshift2.1.351 of 1See more

kb-cloud-installer openshift 2.1.35

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
setuptools@53.0.0
78.1.1

Open the chart page →

4,145
kite-agentopenshift1.0.01 of 1See more

kite-agent openshift 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
setuptools@39.2.0
78.1.1

Open the chart page →

5,863
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
setuptools@39.0.1
78.1.1

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi81 of 7See more

osm-edge openshift 1.2.1-ubi8

1 of the 7 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

19,449
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
setuptools@53.0.0
python-setuptools@53.0.0-12.el9
78.1.1
0:53.0.0-13.el9_6.1

Open the chart page →

8,634
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,608
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

11,740
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,570
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,553
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,457
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,101
openshift-integration-operatoropenshift-integration-operatorVerified publisher0.8.21 of 2See more

openshift-integration-operator openshift-integration-operator 0.8.2

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
python-setuptools@53.0.0-13.el9
0:53.0.0-13.el9_6.1

Open the chart page →

2,063
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
python-setuptools@39.0.1-2
39.0.1-2ubuntu0.1+esm2

Open the chart page →

15,607
open-webconceptopen-webconcept0.1.01 of 3See more

open-webconcept open-webconcept 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
setuptools@58.1.0
78.1.1

Open the chart page →

3,423
openwhiskopenwhisk1.0.02 of 10See more

openwhisk openwhisk 1.0.0

2 of the 10 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
openwhisk/kafkaprovider:2.1.063dc3d2a0904
setuptools@41.4.0
78.1.1
openwhisk/ow-utils:1.0.0c80dba0de3aa
python-pip@9.0.1-2.3~ubuntu1.18.04.4
python-setuptools@39.0.1-2
setuptools@44.1.1
9.0.1-2.3~ubuntu1.18.04.8+esm8
39.0.1-2ubuntu0.1+esm2
78.1.1

Open the chart page →

36,230
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.05 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

5 of the 40 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
yetiplatform/yeti:2.9.09bcbe2650a14
setuptools@78.1.0
78.1.1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
setuptools@68.1.2
78.1.1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
setuptools@68.1.2
78.1.1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
setuptools@68.1.2
78.1.1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
setuptools@68.1.2
78.1.1

Open the chart page →

72,154
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
setuptools@78.1.0
78.1.1

Open the chart page →

6,544
pgaot-container-kit1.0.31 of 6See more

pga ot-container-kit 1.0.3

1 of the 6 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.26.1b8d5067137fe
setuptools@69.0.3
78.1.1

Open the chart page →

5,136
vmot-container-kit0.0.31 of 7See more

vm ot-container-kit 0.0.3

1 of the 7 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
setuptools@70.0.0
78.1.1

Open the chart page →

5,410
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
setuptools@59.4.0
78.1.1

Open the chart page →

1,980
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
mastercloudapps/server:v2.23f3d24dfe2686
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

27,667
plausiblepascaliskeVerified publisher2.0.01 of 1See more

plausible pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
setuptools@70.3.0
78.1.1

Open the chart page →

959
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
setuptools@39.2.0
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-setuptools@39.2.0-6.el8
python-urllib3@1.24.2-5.el8
78.1.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:39.2.0-9.el8_10
0:1.25.10-3.module+el8.4.0+9822+20bf1249

Open the chart page →

15,466
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
setuptools@39.2.0
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-setuptools@39.2.0-6.el8
python-urllib3@1.24.2-5.el8
78.1.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:39.2.0-9.el8_10
0:1.25.10-3.module+el8.4.0+9822+20bf1249

Open the chart page →

15,466
redis-stack-awsphamxuanduong0.1.01 of 1See more

redis-stack-aws phamxuanduong 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.4.0-v0887cf87cc744
setuptools@59.6.0-1.2ubuntu0.22.04.1
59.6.0-1.2ubuntu0.22.04.3

Open the chart page →

3,277
dummy-servicephanVerified publisher0.3.41 of 1See more

dummy-service phan 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phan2410/dummy-service:0.0.89c6ed6de26ca
setuptools@66.1.1-1+deb12u1
setuptools@66.1.1
66.1.1-1+deb12u2
78.1.1

Open the chart page →

5,731
falcon-asgi-serverphanVerified publisher0.1.01 of 1See more

falcon-asgi-server phan 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phan2410/falcon-asgi-server:0.1.04a86d138832d
setuptools@78.1.0
78.1.1

Open the chart page →

8,215
email-managerphntom0.1.221 of 2See more

email-manager phntom 0.1.22

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/email-manager:0.1.22d8e2a9f2f085
setuptools@65.5.1
78.1.1

Open the chart page →

2,565
external-dns-host-networkphntom0.0.121 of 1See more

external-dns-host-network phntom 0.0.12

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/external-dns-host-network:0.0.123adadbac8443
setuptools@58.1.0
78.1.1

Open the chart page →

4,644
npre-essentialsphntom0.1.601 of 22See more

npre-essentials phntom 0.1.60

1 of the 22 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.21.0710e23b489c5
setuptools@65.5.1
78.1.1

Open the chart page →

26,840
postgresql-backupphntom0.1.91 of 1See more

postgresql-backup phntom 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/postgresql-backup-s3:1.0.2249b6488f618b
setuptools@65.6.0
78.1.1

Open the chart page →

2,556
stocks-nasdaq-crawlerphntom0.0.361 of 1See more

stocks-nasdaq-crawler phntom 0.0.36

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/stocks-nasdaq-crawler:0.0.28d2b844700b57
setuptools@50.3.0
78.1.1

Open the chart page →

1,845
phronetisphronetis0.1.271 of 2See more

phronetis phronetis 0.1.27

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
knspar/phronetis-operator:0.1.60c4f0543ee58
setuptools@69.5.1
78.1.1

Open the chart page →

15,077
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
setuptools@45.2.0-1
setuptools@45.2.0
45.2.0-1ubuntu0.3
78.1.1

Open the chart page →

22,146
pingdom-operatorpingdom-operator0.0.201 of 1See more

pingdom-operator pingdom-operator 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
setuptools@71.1.0
78.1.1

Open the chart page →

11,017
planectlplanectlVerified publisher0.7.01 of 10See more

planectl planectl 0.7.0

1 of the 10 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
alpine/k8s:1.30.2cd560fce90f7
setuptools@70.1.1
78.1.1

Open the chart page →

25,626
plausibleplausible0.1.21 of 2See more

plausible plausible 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
setuptools@70.3.0
78.1.1

Open the chart page →

1,337
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
setuptools@46.0.0
python-setuptools@39.2.0-5.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

11,153
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
setuptools@68.2.2
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-3.el8_8
python-setuptools@39.2.0-7.el8
python-urllib3@1.24.2-5.el8
python39@3.9.16-1.module+el8.8.0+18968+3d7b19f0.1
python3x-setuptools@50.3.2-4.module+el8.5.0+12204+54860423
78.1.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:39.2.0-9.el8_10
0:1.25.10-4.module+el8.5.0+11712+ea2d2be1
0:3.9.16-1.module+el8.8.0+22374+62aa8e74.4
0:50.3.2-7.module+el8.8.0+23471+79c1a070

Open the chart page →

12,754
pod-birdspod-birds0.1.01 of 1See more

pod-birds pod-birds 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
teknas09/bird-pod:latest12a1fa85c4aa
setuptools@69.2.0
78.1.1

Open the chart page →

11,680
libretimepodzone-chartsVerified publisher0.4.14 of 9See more

libretime podzone-charts 0.4.1

4 of the 9 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-analyzer:latest3d5e236216ad
setuptools@65.5.1
78.1.1
ghcr.io/libretime/libretime-api:latesteae026cc8909
setuptools@65.5.1
78.1.1
ghcr.io/libretime/libretime-playout:latest71a8706531aa
setuptools@65.5.1
78.1.1
ghcr.io/libretime/libretime-worker:latestd39ff5272b2e
setuptools@65.5.1
78.1.1

Open the chart page →

11,181
port-agentport-labsVerified publisher0.8.161 of 1See more

port-agent port-labs 0.8.16

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/port-labs/port-agent:v0.8.12c92d1e223f5c
python-3.11@3.11.15+e4
3.11.16+e2

Open the chart page →

721

Container images carrying it

1,156 by charts deploying them

A fixed version is listed for 18 of the 19 affected packages.

Container imageDigestPackageFixed inUsed by
kinseii/wazuh-agent:4.14.17160eb143728
setuptools@66.1.1
78.1.1
1
kiwigrid/k8s-sidecar:1.1.03e86186656d3
setuptools@50.3.0
78.1.1
1
kiwigrid/k8s-sidecar:1.3.065095a82d4a1
setuptools@50.3.2
78.1.1
1
kiwigrid/k8s-sidecar:0.0.186eb52513d59e
setuptools@41.0.1
78.1.1
1
kiwigrid/k8s-sidecar:1.12.089739be9ff38
setuptools@56.0.0
78.1.1
1
kiwigrid/k8s-sidecar:0.0.16899ccd0b1f54
setuptools@40.8.0
78.1.1
1
kiwigrid/k8s-sidecar:0.1.20af151f677a63
setuptools@41.0.1
78.1.1
1
kiwigrid/k8s-sidecar:1.27.6db85bd553253
setuptools@74.0.0
78.1.1
1
kiwigrid/k8s-sidecar:1.26.2e271016441af
setuptools@69.2.0
78.1.1
1
knspar/phronetis-operator:0.1.60c4f0543ee58
setuptools@69.5.1
78.1.1
1
kobotoolbox/kobocat:2.022.24ab15679454415
setuptools@63.2.0
setuptools@52.0.0-4
78.1.1
52.0.0-4+deb11u2
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
setuptools@63.2.0
setuptools@52.0.0-4
78.1.1
52.0.0-4+deb11u2
1
kocolosk/couchdb-statefulset-assembler:1.2.06effb982154e
setuptools@38.2.3
78.1.1
1
kodekloud/webapp-color:latest99c3821ea49b
setuptools@40.4.3
78.1.1
1
kong/httpbin:latesta6ac46531193
setuptools@59.6.0-1.2ubuntu0.22.04.2
setuptools@75.6.0
59.6.0-1.2ubuntu0.22.04.3
78.1.1
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
setuptools@57.5.0
78.1.1
1
kserve/models-web-app:v0.8.063ea05e73842
setuptools@57.5.0
78.1.1
1
kserve/models-web-app:v0.13.073486345a602
setuptools@70.3.0
78.1.1
1
kubeaws/kube-spot-termination-notice-handler:1.13.0-1c9cd2ba4373a
setuptools@40.8.0
78.1.1
1
kubeflownotebookswg/jupyter-web-app:v1.9.2afb52057c997
setuptools@65.5.1
78.1.1
1
kubeflownotebookswg/jupyter-web-app:v1.6.1d762690e21c1
setuptools@57.5.0
78.1.1
1
kubeflownotebookswg/tensorboards-web-app:v1.6.10876fef1973b
setuptools@57.5.0
78.1.1
1
kubeflownotebookswg/tensorboards-web-app:v1.9.277f07f52a84a
setuptools@65.5.1
78.1.1
1
kubeflownotebookswg/volumes-web-app:v1.6.17299fa94db15
setuptools@57.5.0
78.1.1
1
kubeflownotebookswg/volumes-web-app:v1.9.2f63c3e550af3
setuptools@65.5.1
78.1.1
1
kubesphere/examples-bookinfo-productpage-v1:1.13.0378f49ec9c44
setuptools@41.0.1
78.1.1
1
kubitodev/traefik-ip-whitelist-sync:1.0.2aa24869319bf
setuptools@58.1.0
78.1.1
1
kunchalavikram/connectedcity:v14a559a47579e
setuptools@40.7.1
78.1.1
1
kunchalavikram/connectedfactory:v152c13fb9b1d9
setuptools@40.7.1
78.1.1
1
kusionstack/kusion:v0.14.0126c8f0b0976
setuptools@59.6.0-1.2ubuntu0.22.04.2
setuptools@59.6.0
59.6.0-1.2ubuntu0.22.04.3
78.1.1
1
kyovint/kyoimgtransactions:1.0.048c19e3ae9a3
setuptools@65.5.1
78.1.1
1
kyovint/kyoimgusers:1.0.080084149156e
setuptools@65.5.1
78.1.1
1
kyso/kyso-nbdime:latest4aa9d38ee81d
setuptools@65.5.1
78.1.1
1
langgenius/dify-api:1.0.0066035f93856
setuptools@75.8.0
78.1.1
1
langgenius/dify-api:0.6.11fca918260dd6
setuptools@65.5.1
78.1.1
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
setuptools@68.1.2
78.1.1
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
setuptools@68.1.2
78.1.1
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
setuptools@68.1.2
78.1.1
1
langgenius/dify-sandbox:0.2.124e65e8a351a2
setuptools@65.5.1
78.1.1
1
leantime/leantime:3.3.3ad4bfb0699d3
setuptools@70.3.0
78.1.1
1
lib42/deluge:20c4d1d326f95
setuptools@65.5.1
78.1.1
1
library/crate:4.7.0c7984a05e15b
setuptools@39.2.0
78.1.1
1
library/mysql:8.4.3106d5197fd8e
setuptools@73.0.1
78.1.1
1
library/mysql:8.0.41bf577825b52a
setuptools@73.0.1
78.1.1
1
library/mysql:8.0.40d58ac93387f6
setuptools@73.0.1
78.1.1
1
library/python:3.8-alpine3d93b1f77efc
setuptools@57.5.0
78.1.1
1
library/python:3.8d41127070014
setuptools@57.5.0
78.1.1
1
librenms/librenms:24.11.00920bc9117a8
setuptools@75.6.0
78.1.1
1
librenms/librenms:22.4.14f1f3d667cc7
setuptools@62.1.0
78.1.1
1
linuxserver/babybuddy:1.10.2f7d7c7704249
setuptools@52.0.0
78.1.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.