StackRadar

CVE-2025-47273

High

Advisory

Published 17 May 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,086
of 17,787 indexed, latest versions
Container images
1,156
deployed by those charts
Fix available
18 of 19
affected packages

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

Carried by container images the latest versions of 1,086 of 17,787 indexed charts deploy, on 1,156 images.

Affected packageAffected versionsFixed inImages
setuptoolspypi0.9.8, 20.7.0, 20.8.0, 29.0.1.post20161130+124 more78.1.11,083
setuptoolsdeb45.2.0-1, 45.2.0-1ubuntu0.1, 45.2.0-1ubuntu0.2, 52.0.0-4+8 more45.2.0-1ubuntu0.3, 52.0.0-4+deb11u2, 59.6.0-1.2ubuntu0.22.04.3, 66.1.1-1+deb12u2+1 more154
python-setuptoolsdeb3.3-1ubuntu1, 3.3-1ubuntu2, 20.7.0-1, 39.0.1-2+3 more3.3-1ubuntu2+esm3, 20.7.0-1ubuntu0.1~esm3, 39.0.1-2ubuntu0.1+esm2, 44.0.0-2ubuntu0.1+esm239
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+5 more8.1.1-2ubuntu0.6+esm12, 9.0.1-2.3~ubuntu1.18.04.8+esm830
py3-pipapk25.0.1-r0, 25.2-r0, 26.0.1-r1no fix listed3
setuptoolsbitnami70.3.078.1.12
python-setuptoolsrpm0.9.8-7.el7, 39.2.0-5.el8, 39.2.0-6.el8, 39.2.0-6.el8_7.1+6 more0:0.9.8-7.el7_9.2, 0:39.2.0-9.el8_10, 0:53.0.0-13.el9_6.1138
python-chardetrpm3.0.4-7.el80:3.0.4-19.module+el8.4.0+9822+20bf124920
python-idnarpm2.5-5.el80:2.10-3.module+el8.4.0+9822+20bf124920
python-pysocksrpm1.6.8-3.el80:1.7.1-4.module+el8.4.0+9822+20bf124920
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_6, 2.20.0-3.el8_80:2.25.0-2.module+el8.4.0+9822+20bf124920
python-urllib3rpm1.24.2-5.el8, 1.24.2-5.el8_6.10:1.25.10-3.module+el8.4.0+9822+20bf1249, 0:1.25.10-4.module+el8.5.0+11712+ea2d2be120
python3x-setuptoolsrpm41.6.0-4.module+el8.4.0+8888+89bc7e79, 41.6.0-5.module+el8.5.0+12205+a865257a, 50.3.2-3.module+el8.4.0+9822+20bf1249, 50.3.2-4.module+el8.5.0+12204+548604230:50.3.2-3.module+el8.4.0+23445+8885b4ac.3, 0:50.3.2-7.module+el8.8.0+23471+79c1a0709
python-plyrpm3.9-9.el80:3.11-10.module+el8.4.0+9822+20bf12497
python39rpm3.9.2-1.module+el8.4.0+10237+bdc77aac, 3.9.16-1.module+el8.8.0+18968+3d7b19f0.10:3.9.2-2.module+el8.4.0+22379+dcc60181.4, 0:3.9.16-1.module+el8.8.0+22374+62aa8e74.46
python3x-piprpm19.3.1-1.module+el8.4.0+8888+89bc7e79, 19.3.1-6.module+el8.7.0+15823+8950cfa7, 20.2.4-3.module+el8.4.0+9822+20bf12490:20.2.4-3.module+el8.4.0+15042+dc5a279b.1, 0:20.2.4-7.module+el8.6.0+13003+6bb2c4884
python3.11-setuptoolsrpm65.5.1-2.el9, 65.5.1-2.el9_4.10:65.5.1-4.el9_62
python-wheelrpm0.33.6-5.module+el8.4.0+8888+89bc7e791:0.35.1-3.module+el8.4.0+15042+dc5a279b.11
python-3.11deb3.11.15+e43.11.16+e21
OSV records
BIT-setuptools-2025-47273CGA-6rww-wjff-6g99CGA-gfc8-q7jm-4w3vDEBIAN-CVE-2025-47273PYSEC-2025-49RHSA-2025:10407RHSA-2025:11036RHSA-2025:11984RHSA-2025:13578RHSA-2025:15408RHSA-2025:15410RHSA-2025:15411RLSA-2025:10407RLSA-2025:11036UBUNTU-CVE-2025-47273DLA-4183-1ECHO-2d75-a206-3684USN-7544-1
Also known as
CGA-wrp2-2xv2-hfvv, CGA-xqm6-7hq3-gpvg, GHSA-5rjg-fvgr-3xxf, RHSA-2025:11424, RHSA-2025:11425, RHSA-2025:11426, RHSA-2025:11427, RHSA-2025:11868, RHSA-2025:12020, RHSA-2025:13669, USN-8010-1

Charts affected

1,086 by stars
ChartLatestAffected imagesRadar Score
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

11,795
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10
andrianrf/backoffice-be:latest6036614803d4
python-setuptools@53.0.0-12.el9
0:53.0.0-13.el9_6.1
andrianrf/iso-server:latest7da47f525c7d
python-setuptools@53.0.0-12.el9
0:53.0.0-13.el9_6.1

Open the chart page →

34,721
canvas-oamportalopenshift4.0.01 of 1See more

canvas-oamportal openshift 4.0.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/oam:4.0.0ed8fd2062548
setuptools@39.2.0
python-setuptools@39.2.0-8.el8_10
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

7,519
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
setuptools@65.5.1
python-setuptools@53.0.0-12.el9_4.1
python3.11-setuptools@65.5.1-2.el9_4.1
78.1.1
0:53.0.0-13.el9_6.1
0:65.5.1-4.el9_6
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
setuptools@65.5.1
python-setuptools@53.0.0-12.el9
python3.11-setuptools@65.5.1-2.el9
78.1.1
0:53.0.0-13.el9_6.1
0:65.5.1-4.el9_6

Open the chart page →

18,991
exporteropenshift1.0.473 of 3See more

exporter openshift 1.0.47

3 of the 3 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
setuptools@39.2.0
python-setuptools@39.2.0-8.el8_10
78.1.1
0:39.2.0-9.el8_10
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
setuptools@53.0.0
python-setuptools@53.0.0-13.el9
78.1.1
0:53.0.0-13.el9_6.1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
setuptools@53.0.0
python-setuptools@53.0.0-13.el9
78.1.1
0:53.0.0-13.el9_6.1

Open the chart page →

13,034
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

9,968
fsmopenshift0.1.8-ubi.61 of 6See more

fsm openshift 0.1.8-ubi.6

1 of the 6 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

16,554
hamiopenshift2.10.0-r0-openshift.c4e22e881 of 2See more

hami openshift 2.10.0-r0-openshift.c4e22e88

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/dynamia-ai/hami-enterprise:v2.10.0-r0-openshift.c4e22e88745504757300
setuptools@39.2.0
78.1.1

Open the chart page →

4,749
kb-cloud-installeropenshift2.1.351 of 1See more

kb-cloud-installer openshift 2.1.35

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
setuptools@53.0.0
78.1.1

Open the chart page →

4,145
kite-agentopenshift1.0.01 of 1See more

kite-agent openshift 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
setuptools@39.2.0
78.1.1

Open the chart page →

5,863
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
setuptools@39.0.1
78.1.1

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi81 of 7See more

osm-edge openshift 1.2.1-ubi8

1 of the 7 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

19,449
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
setuptools@53.0.0
python-setuptools@53.0.0-12.el9
78.1.1
0:53.0.0-13.el9_6.1

Open the chart page →

8,634
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,608
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

11,740
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,570
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,553
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,457
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,101
openshift-integration-operatoropenshift-integration-operatorVerified publisher0.8.21 of 2See more

openshift-integration-operator openshift-integration-operator 0.8.2

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
python-setuptools@53.0.0-13.el9
0:53.0.0-13.el9_6.1

Open the chart page →

2,063
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
python-setuptools@39.0.1-2
39.0.1-2ubuntu0.1+esm2

Open the chart page →

15,607
open-webconceptopen-webconcept0.1.01 of 3See more

open-webconcept open-webconcept 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
setuptools@58.1.0
78.1.1

Open the chart page →

3,423
openwhiskopenwhisk1.0.02 of 10See more

openwhisk openwhisk 1.0.0

2 of the 10 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
openwhisk/kafkaprovider:2.1.063dc3d2a0904
setuptools@41.4.0
78.1.1
openwhisk/ow-utils:1.0.0c80dba0de3aa
python-pip@9.0.1-2.3~ubuntu1.18.04.4
python-setuptools@39.0.1-2
setuptools@44.1.1
9.0.1-2.3~ubuntu1.18.04.8+esm8
39.0.1-2ubuntu0.1+esm2
78.1.1

Open the chart page →

36,230
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.05 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

5 of the 40 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
yetiplatform/yeti:2.9.09bcbe2650a14
setuptools@78.1.0
78.1.1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
setuptools@68.1.2
78.1.1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
setuptools@68.1.2
78.1.1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
setuptools@68.1.2
78.1.1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
setuptools@68.1.2
78.1.1

Open the chart page →

72,154
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
setuptools@78.1.0
78.1.1

Open the chart page →

6,544
pgaot-container-kit1.0.31 of 6See more

pga ot-container-kit 1.0.3

1 of the 6 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.26.1b8d5067137fe
setuptools@69.0.3
78.1.1

Open the chart page →

5,136
vmot-container-kit0.0.31 of 7See more

vm ot-container-kit 0.0.3

1 of the 7 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
setuptools@70.0.0
78.1.1

Open the chart page →

5,410
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
setuptools@59.4.0
78.1.1

Open the chart page →

1,980
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
mastercloudapps/server:v2.23f3d24dfe2686
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

27,667
plausiblepascaliskeVerified publisher2.0.01 of 1See more

plausible pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
setuptools@70.3.0
78.1.1

Open the chart page →

959
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
setuptools@39.2.0
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-setuptools@39.2.0-6.el8
python-urllib3@1.24.2-5.el8
78.1.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:39.2.0-9.el8_10
0:1.25.10-3.module+el8.4.0+9822+20bf1249

Open the chart page →

15,466
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
setuptools@39.2.0
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-setuptools@39.2.0-6.el8
python-urllib3@1.24.2-5.el8
78.1.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:39.2.0-9.el8_10
0:1.25.10-3.module+el8.4.0+9822+20bf1249

Open the chart page →

15,466
redis-stack-awsphamxuanduong0.1.01 of 1See more

redis-stack-aws phamxuanduong 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.4.0-v0887cf87cc744
setuptools@59.6.0-1.2ubuntu0.22.04.1
59.6.0-1.2ubuntu0.22.04.3

Open the chart page →

3,277
dummy-servicephanVerified publisher0.3.41 of 1See more

dummy-service phan 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phan2410/dummy-service:0.0.89c6ed6de26ca
setuptools@66.1.1-1+deb12u1
setuptools@66.1.1
66.1.1-1+deb12u2
78.1.1

Open the chart page →

5,731
falcon-asgi-serverphanVerified publisher0.1.01 of 1See more

falcon-asgi-server phan 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phan2410/falcon-asgi-server:0.1.04a86d138832d
setuptools@78.1.0
78.1.1

Open the chart page →

8,215
email-managerphntom0.1.221 of 2See more

email-manager phntom 0.1.22

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/email-manager:0.1.22d8e2a9f2f085
setuptools@65.5.1
78.1.1

Open the chart page →

2,565
external-dns-host-networkphntom0.0.121 of 1See more

external-dns-host-network phntom 0.0.12

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/external-dns-host-network:0.0.123adadbac8443
setuptools@58.1.0
78.1.1

Open the chart page →

4,644
npre-essentialsphntom0.1.601 of 22See more

npre-essentials phntom 0.1.60

1 of the 22 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.21.0710e23b489c5
setuptools@65.5.1
78.1.1

Open the chart page →

26,840
postgresql-backupphntom0.1.91 of 1See more

postgresql-backup phntom 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/postgresql-backup-s3:1.0.2249b6488f618b
setuptools@65.6.0
78.1.1

Open the chart page →

2,556
stocks-nasdaq-crawlerphntom0.0.361 of 1See more

stocks-nasdaq-crawler phntom 0.0.36

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/stocks-nasdaq-crawler:0.0.28d2b844700b57
setuptools@50.3.0
78.1.1

Open the chart page →

1,845
phronetisphronetis0.1.271 of 2See more

phronetis phronetis 0.1.27

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
knspar/phronetis-operator:0.1.60c4f0543ee58
setuptools@69.5.1
78.1.1

Open the chart page →

15,077
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
setuptools@45.2.0-1
setuptools@45.2.0
45.2.0-1ubuntu0.3
78.1.1

Open the chart page →

22,146
pingdom-operatorpingdom-operator0.0.201 of 1See more

pingdom-operator pingdom-operator 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
setuptools@71.1.0
78.1.1

Open the chart page →

11,017
planectlplanectlVerified publisher0.7.01 of 10See more

planectl planectl 0.7.0

1 of the 10 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
alpine/k8s:1.30.2cd560fce90f7
setuptools@70.1.1
78.1.1

Open the chart page →

25,626
plausibleplausible0.1.21 of 2See more

plausible plausible 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
setuptools@70.3.0
78.1.1

Open the chart page →

1,337
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
setuptools@46.0.0
python-setuptools@39.2.0-5.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

11,153
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
setuptools@68.2.2
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-3.el8_8
python-setuptools@39.2.0-7.el8
python-urllib3@1.24.2-5.el8
python39@3.9.16-1.module+el8.8.0+18968+3d7b19f0.1
python3x-setuptools@50.3.2-4.module+el8.5.0+12204+54860423
78.1.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:39.2.0-9.el8_10
0:1.25.10-4.module+el8.5.0+11712+ea2d2be1
0:3.9.16-1.module+el8.8.0+22374+62aa8e74.4
0:50.3.2-7.module+el8.8.0+23471+79c1a070

Open the chart page →

12,754
pod-birdspod-birds0.1.01 of 1See more

pod-birds pod-birds 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
teknas09/bird-pod:latest12a1fa85c4aa
setuptools@69.2.0
78.1.1

Open the chart page →

11,680
libretimepodzone-chartsVerified publisher0.4.14 of 9See more

libretime podzone-charts 0.4.1

4 of the 9 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-analyzer:latest3d5e236216ad
setuptools@65.5.1
78.1.1
ghcr.io/libretime/libretime-api:latesteae026cc8909
setuptools@65.5.1
78.1.1
ghcr.io/libretime/libretime-playout:latest71a8706531aa
setuptools@65.5.1
78.1.1
ghcr.io/libretime/libretime-worker:latestd39ff5272b2e
setuptools@65.5.1
78.1.1

Open the chart page →

11,181
port-agentport-labsVerified publisher0.8.161 of 1See more

port-agent port-labs 0.8.16

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/port-labs/port-agent:v0.8.12c92d1e223f5c
python-3.11@3.11.15+e4
3.11.16+e2

Open the chart page →

721

Container images carrying it

1,156 by charts deploying them

A fixed version is listed for 18 of the 19 affected packages.

Container imageDigestPackageFixed inUsed by
linuxserver/beets:1.5.0e36d16f7341c
setuptools@56.0.0
78.1.1
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
setuptools@45.2.0-1
45.2.0-1ubuntu0.3
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
setuptools@40.7.2
78.1.1
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
setuptools@42.0.2.post20191202
78.1.1
1
linuxserver/deluge:18.04.10ac871624394
python-setuptools@39.0.1-2
39.0.1-2ubuntu0.1+esm2
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
python-setuptools@39.0.1-2
39.0.1-2ubuntu0.1+esm2
1
linuxserver/healthchecks:version-v1.20.050792a72fc71
setuptools@56.0.0
78.1.1
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
setuptools@65.5.0
78.1.1
1
linuxserver/medusa:v0.3.9-ls340a5f5114128b
setuptools@41.2.0
78.1.1
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
setuptools@42.0.2.post20191202
78.1.1
1
linuxserver/yq:3.2.26f5b9586a93e
setuptools@65.5.0
78.1.1
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
py3-pip@26.0.1-r1
no fix listed
1
lnbitsdocker/lnbits-legend:latest26fae6327477
setuptools@65.5.1
78.1.1
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
setuptools@65.7.0
78.1.1
1
lncm/specter-desktop:v0.10.4bca14d04397d
setuptools@50.3.0
78.1.1
1
localstack/localstack:3.19d278167f2b7
setuptools@69.0.3
78.1.1
1
locustio/locust:2.24.151d866285170
setuptools@65.5.0
78.1.1
1
logiqai/toolbox:2.0.155a574ec5b64
setuptools@42.0.2.post20191202
78.1.1
1
lsstdm/alert-stream-simulator:v1.2.1973df082d006
setuptools@57.5.0
78.1.1
1
lsstdm/lsst_alert_packet:tickets-DM-3274374c97a490940
setuptools@57.5.0
78.1.1
1
lsstsqre/exposurelog:0.8.079b00fb67a65
setuptools@60.8.2
78.1.1
1
lsstsqre/kafkaaggregator:masterbe1b21060854
setuptools@54.1.2
78.1.1
1
lsstsqre/kafkaconnect:0.9.34143c7cd705e
setuptools@57.5.0
78.1.1
1
lsstsqre/narrativelog:0.1.0ce01de04ce21
setuptools@60.9.1
78.1.1
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
setuptools@45.2.0-1
setuptools@60.5.0
python-setuptools@44.0.0-2
45.2.0-1ubuntu0.3
78.1.1
44.0.0-2ubuntu0.1+esm2
1
lsstsqre/prepuller:latest19c2dfc4e4ff
setuptools@56.0.0
78.1.1
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
setuptools@0.9.8
78.1.1
1
lsstsqre/squash-api:0.5.34879415ec6ac
setuptools@51.0.0
78.1.1
1
lsstsqre/strimzi-registry-operator:0.4.1e139fde946d7
setuptools@57.5.0
78.1.1
1
lsstsqre/wfdispatcher:lateste9feb99f524d
setuptools@39.2.0
78.1.1
1
mailserver/docker-mailserver:11.0.0e0809756dc96
setuptools@52.0.0-4
52.0.0-4+deb11u2
1
makersquad/harp-proxy:0.8.1a40dd258c527
setuptools@66.1.1-1+deb12u1
setuptools@66.1.1
66.1.1-1+deb12u2
78.1.1
1
marcinkujawski/flask-app:2.0.1a455017b9d0e
setuptools@57.5.0
78.1.1
1
mariadb/maxscale:23.02.256c5e0908148
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
setuptools@52.0.0-4
52.0.0-4+deb11u2
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
setuptools@72.1.0
78.1.1
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
setuptools@57.5.0
78.1.1
1
matrixdotorg/synapse:v1.78.0def97fd537d8
setuptools@65.5.1
78.1.1
1
mcronce/yadms-ftp:latestf820ef2e3c26
setuptools@41.6.0
78.1.1
1
mcronce/yadms-web:latestc03c1c7f5aa9
setuptools@41.6.0
78.1.1
1
mediagis/nominatim:5.3.27923a8e67197
setuptools@68.1.2
78.1.1
1
mediagis/nominatim:3.7c15e941485ef
setuptools@45.2.0-1
setuptools@45.2.0
45.2.0-1ubuntu0.3
78.1.1
1
mediagis/nominatim:4.2d0eae7b51374
setuptools@59.6.0-1.2ubuntu0.22.04.1
setuptools@59.6.0
59.6.0-1.2ubuntu0.22.04.3
78.1.1
1
mher/flower:2.051c3c3db5be3
setuptools@65.5.1
78.1.1
1
middlewareeng/middleware:0.3.1747d880812f1
setuptools@66.1.1-1+deb12u1
setuptools@58.1.0
66.1.1-1+deb12u2
78.1.1
1
mide/minecraft-overviewer:latest4eee0dcb715f
setuptools@52.0.0-4
52.0.0-4+deb11u2
1
milesmcc/shynet:v0.13.1ba54f7797a6b
setuptools@65.6.3
78.1.1
1
milesmcc/shynet:v0.12.0e821e31140f7
setuptools@57.5.0
78.1.1
1
miltex/python-api:1.0.0dab12a7748d5
setuptools@44.0.0
78.1.1
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.