StackRadar

CVE-2025-47273

High

Advisory

Published 17 May 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,086
of 17,787 indexed, latest versions
Container images
1,156
deployed by those charts
Fix available
18 of 19
affected packages

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

Carried by container images the latest versions of 1,086 of 17,787 indexed charts deploy, on 1,156 images.

Affected packageAffected versionsFixed inImages
setuptoolspypi0.9.8, 20.7.0, 20.8.0, 29.0.1.post20161130+124 more78.1.11,083
setuptoolsdeb45.2.0-1, 45.2.0-1ubuntu0.1, 45.2.0-1ubuntu0.2, 52.0.0-4+8 more45.2.0-1ubuntu0.3, 52.0.0-4+deb11u2, 59.6.0-1.2ubuntu0.22.04.3, 66.1.1-1+deb12u2+1 more154
python-setuptoolsdeb3.3-1ubuntu1, 3.3-1ubuntu2, 20.7.0-1, 39.0.1-2+3 more3.3-1ubuntu2+esm3, 20.7.0-1ubuntu0.1~esm3, 39.0.1-2ubuntu0.1+esm2, 44.0.0-2ubuntu0.1+esm239
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+5 more8.1.1-2ubuntu0.6+esm12, 9.0.1-2.3~ubuntu1.18.04.8+esm830
py3-pipapk25.0.1-r0, 25.2-r0, 26.0.1-r1no fix listed3
setuptoolsbitnami70.3.078.1.12
python-setuptoolsrpm0.9.8-7.el7, 39.2.0-5.el8, 39.2.0-6.el8, 39.2.0-6.el8_7.1+6 more0:0.9.8-7.el7_9.2, 0:39.2.0-9.el8_10, 0:53.0.0-13.el9_6.1138
python-chardetrpm3.0.4-7.el80:3.0.4-19.module+el8.4.0+9822+20bf124920
python-idnarpm2.5-5.el80:2.10-3.module+el8.4.0+9822+20bf124920
python-pysocksrpm1.6.8-3.el80:1.7.1-4.module+el8.4.0+9822+20bf124920
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_6, 2.20.0-3.el8_80:2.25.0-2.module+el8.4.0+9822+20bf124920
python-urllib3rpm1.24.2-5.el8, 1.24.2-5.el8_6.10:1.25.10-3.module+el8.4.0+9822+20bf1249, 0:1.25.10-4.module+el8.5.0+11712+ea2d2be120
python3x-setuptoolsrpm41.6.0-4.module+el8.4.0+8888+89bc7e79, 41.6.0-5.module+el8.5.0+12205+a865257a, 50.3.2-3.module+el8.4.0+9822+20bf1249, 50.3.2-4.module+el8.5.0+12204+548604230:50.3.2-3.module+el8.4.0+23445+8885b4ac.3, 0:50.3.2-7.module+el8.8.0+23471+79c1a0709
python-plyrpm3.9-9.el80:3.11-10.module+el8.4.0+9822+20bf12497
python39rpm3.9.2-1.module+el8.4.0+10237+bdc77aac, 3.9.16-1.module+el8.8.0+18968+3d7b19f0.10:3.9.2-2.module+el8.4.0+22379+dcc60181.4, 0:3.9.16-1.module+el8.8.0+22374+62aa8e74.46
python3x-piprpm19.3.1-1.module+el8.4.0+8888+89bc7e79, 19.3.1-6.module+el8.7.0+15823+8950cfa7, 20.2.4-3.module+el8.4.0+9822+20bf12490:20.2.4-3.module+el8.4.0+15042+dc5a279b.1, 0:20.2.4-7.module+el8.6.0+13003+6bb2c4884
python3.11-setuptoolsrpm65.5.1-2.el9, 65.5.1-2.el9_4.10:65.5.1-4.el9_62
python-wheelrpm0.33.6-5.module+el8.4.0+8888+89bc7e791:0.35.1-3.module+el8.4.0+15042+dc5a279b.11
python-3.11deb3.11.15+e43.11.16+e21
OSV records
BIT-setuptools-2025-47273CGA-6rww-wjff-6g99CGA-gfc8-q7jm-4w3vDEBIAN-CVE-2025-47273PYSEC-2025-49RHSA-2025:10407RHSA-2025:11036RHSA-2025:11984RHSA-2025:13578RHSA-2025:15408RHSA-2025:15410RHSA-2025:15411RLSA-2025:10407RLSA-2025:11036UBUNTU-CVE-2025-47273DLA-4183-1ECHO-2d75-a206-3684USN-7544-1
Also known as
CGA-wrp2-2xv2-hfvv, CGA-xqm6-7hq3-gpvg, GHSA-5rjg-fvgr-3xxf, RHSA-2025:11424, RHSA-2025:11425, RHSA-2025:11426, RHSA-2025:11427, RHSA-2025:11868, RHSA-2025:12020, RHSA-2025:13669, USN-8010-1

Charts affected

1,086 by stars
ChartLatestAffected imagesRadar Score
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

11,795
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10
andrianrf/backoffice-be:latest6036614803d4
python-setuptools@53.0.0-12.el9
0:53.0.0-13.el9_6.1
andrianrf/iso-server:latest7da47f525c7d
python-setuptools@53.0.0-12.el9
0:53.0.0-13.el9_6.1

Open the chart page →

34,721
canvas-oamportalopenshift4.0.01 of 1See more

canvas-oamportal openshift 4.0.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/oam:4.0.0ed8fd2062548
setuptools@39.2.0
python-setuptools@39.2.0-8.el8_10
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

7,519
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
setuptools@65.5.1
python-setuptools@53.0.0-12.el9_4.1
python3.11-setuptools@65.5.1-2.el9_4.1
78.1.1
0:53.0.0-13.el9_6.1
0:65.5.1-4.el9_6
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
setuptools@65.5.1
python-setuptools@53.0.0-12.el9
python3.11-setuptools@65.5.1-2.el9
78.1.1
0:53.0.0-13.el9_6.1
0:65.5.1-4.el9_6

Open the chart page →

18,991
exporteropenshift1.0.473 of 3See more

exporter openshift 1.0.47

3 of the 3 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
setuptools@39.2.0
python-setuptools@39.2.0-8.el8_10
78.1.1
0:39.2.0-9.el8_10
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
setuptools@53.0.0
python-setuptools@53.0.0-13.el9
78.1.1
0:53.0.0-13.el9_6.1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
setuptools@53.0.0
python-setuptools@53.0.0-13.el9
78.1.1
0:53.0.0-13.el9_6.1

Open the chart page →

13,034
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

9,968
fsmopenshift0.1.8-ubi.61 of 6See more

fsm openshift 0.1.8-ubi.6

1 of the 6 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

16,554
hamiopenshift2.10.0-r0-openshift.c4e22e881 of 2See more

hami openshift 2.10.0-r0-openshift.c4e22e88

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/dynamia-ai/hami-enterprise:v2.10.0-r0-openshift.c4e22e88745504757300
setuptools@39.2.0
78.1.1

Open the chart page →

4,749
kb-cloud-installeropenshift2.1.351 of 1See more

kb-cloud-installer openshift 2.1.35

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
setuptools@53.0.0
78.1.1

Open the chart page →

4,145
kite-agentopenshift1.0.01 of 1See more

kite-agent openshift 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
setuptools@39.2.0
78.1.1

Open the chart page →

5,863
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
setuptools@39.0.1
78.1.1

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi81 of 7See more

osm-edge openshift 1.2.1-ubi8

1 of the 7 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

19,449
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
setuptools@53.0.0
python-setuptools@53.0.0-12.el9
78.1.1
0:53.0.0-13.el9_6.1

Open the chart page →

8,634
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,608
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

11,740
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,570
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,553
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,457
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,101
openshift-integration-operatoropenshift-integration-operatorVerified publisher0.8.21 of 2See more

openshift-integration-operator openshift-integration-operator 0.8.2

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
python-setuptools@53.0.0-13.el9
0:53.0.0-13.el9_6.1

Open the chart page →

2,063
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
python-setuptools@39.0.1-2
39.0.1-2ubuntu0.1+esm2

Open the chart page →

15,607
open-webconceptopen-webconcept0.1.01 of 3See more

open-webconcept open-webconcept 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
setuptools@58.1.0
78.1.1

Open the chart page →

3,423
openwhiskopenwhisk1.0.02 of 10See more

openwhisk openwhisk 1.0.0

2 of the 10 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
openwhisk/kafkaprovider:2.1.063dc3d2a0904
setuptools@41.4.0
78.1.1
openwhisk/ow-utils:1.0.0c80dba0de3aa
python-pip@9.0.1-2.3~ubuntu1.18.04.4
python-setuptools@39.0.1-2
setuptools@44.1.1
9.0.1-2.3~ubuntu1.18.04.8+esm8
39.0.1-2ubuntu0.1+esm2
78.1.1

Open the chart page →

36,230
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.05 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

5 of the 40 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
yetiplatform/yeti:2.9.09bcbe2650a14
setuptools@78.1.0
78.1.1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
setuptools@68.1.2
78.1.1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
setuptools@68.1.2
78.1.1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
setuptools@68.1.2
78.1.1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
setuptools@68.1.2
78.1.1

Open the chart page →

72,154
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
setuptools@78.1.0
78.1.1

Open the chart page →

6,544
pgaot-container-kit1.0.31 of 6See more

pga ot-container-kit 1.0.3

1 of the 6 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.26.1b8d5067137fe
setuptools@69.0.3
78.1.1

Open the chart page →

5,136
vmot-container-kit0.0.31 of 7See more

vm ot-container-kit 0.0.3

1 of the 7 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
setuptools@70.0.0
78.1.1

Open the chart page →

5,410
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
setuptools@59.4.0
78.1.1

Open the chart page →

1,980
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
mastercloudapps/server:v2.23f3d24dfe2686
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

27,667
plausiblepascaliskeVerified publisher2.0.01 of 1See more

plausible pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
setuptools@70.3.0
78.1.1

Open the chart page →

959
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
setuptools@39.2.0
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-setuptools@39.2.0-6.el8
python-urllib3@1.24.2-5.el8
78.1.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:39.2.0-9.el8_10
0:1.25.10-3.module+el8.4.0+9822+20bf1249

Open the chart page →

15,466
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
setuptools@39.2.0
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-setuptools@39.2.0-6.el8
python-urllib3@1.24.2-5.el8
78.1.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:39.2.0-9.el8_10
0:1.25.10-3.module+el8.4.0+9822+20bf1249

Open the chart page →

15,466
redis-stack-awsphamxuanduong0.1.01 of 1See more

redis-stack-aws phamxuanduong 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.4.0-v0887cf87cc744
setuptools@59.6.0-1.2ubuntu0.22.04.1
59.6.0-1.2ubuntu0.22.04.3

Open the chart page →

3,277
dummy-servicephanVerified publisher0.3.41 of 1See more

dummy-service phan 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phan2410/dummy-service:0.0.89c6ed6de26ca
setuptools@66.1.1-1+deb12u1
setuptools@66.1.1
66.1.1-1+deb12u2
78.1.1

Open the chart page →

5,731
falcon-asgi-serverphanVerified publisher0.1.01 of 1See more

falcon-asgi-server phan 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phan2410/falcon-asgi-server:0.1.04a86d138832d
setuptools@78.1.0
78.1.1

Open the chart page →

8,215
email-managerphntom0.1.221 of 2See more

email-manager phntom 0.1.22

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/email-manager:0.1.22d8e2a9f2f085
setuptools@65.5.1
78.1.1

Open the chart page →

2,565
external-dns-host-networkphntom0.0.121 of 1See more

external-dns-host-network phntom 0.0.12

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/external-dns-host-network:0.0.123adadbac8443
setuptools@58.1.0
78.1.1

Open the chart page →

4,644
npre-essentialsphntom0.1.601 of 22See more

npre-essentials phntom 0.1.60

1 of the 22 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.21.0710e23b489c5
setuptools@65.5.1
78.1.1

Open the chart page →

26,840
postgresql-backupphntom0.1.91 of 1See more

postgresql-backup phntom 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/postgresql-backup-s3:1.0.2249b6488f618b
setuptools@65.6.0
78.1.1

Open the chart page →

2,556
stocks-nasdaq-crawlerphntom0.0.361 of 1See more

stocks-nasdaq-crawler phntom 0.0.36

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/stocks-nasdaq-crawler:0.0.28d2b844700b57
setuptools@50.3.0
78.1.1

Open the chart page →

1,845
phronetisphronetis0.1.271 of 2See more

phronetis phronetis 0.1.27

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
knspar/phronetis-operator:0.1.60c4f0543ee58
setuptools@69.5.1
78.1.1

Open the chart page →

15,077
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
setuptools@45.2.0-1
setuptools@45.2.0
45.2.0-1ubuntu0.3
78.1.1

Open the chart page →

22,146
pingdom-operatorpingdom-operator0.0.201 of 1See more

pingdom-operator pingdom-operator 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
setuptools@71.1.0
78.1.1

Open the chart page →

11,017
planectlplanectlVerified publisher0.7.01 of 10See more

planectl planectl 0.7.0

1 of the 10 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
alpine/k8s:1.30.2cd560fce90f7
setuptools@70.1.1
78.1.1

Open the chart page →

25,626
plausibleplausible0.1.21 of 2See more

plausible plausible 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
setuptools@70.3.0
78.1.1

Open the chart page →

1,337
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
setuptools@46.0.0
python-setuptools@39.2.0-5.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

11,153
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
setuptools@68.2.2
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-3.el8_8
python-setuptools@39.2.0-7.el8
python-urllib3@1.24.2-5.el8
python39@3.9.16-1.module+el8.8.0+18968+3d7b19f0.1
python3x-setuptools@50.3.2-4.module+el8.5.0+12204+54860423
78.1.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:39.2.0-9.el8_10
0:1.25.10-4.module+el8.5.0+11712+ea2d2be1
0:3.9.16-1.module+el8.8.0+22374+62aa8e74.4
0:50.3.2-7.module+el8.8.0+23471+79c1a070

Open the chart page →

12,754
pod-birdspod-birds0.1.01 of 1See more

pod-birds pod-birds 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
teknas09/bird-pod:latest12a1fa85c4aa
setuptools@69.2.0
78.1.1

Open the chart page →

11,680
libretimepodzone-chartsVerified publisher0.4.14 of 9See more

libretime podzone-charts 0.4.1

4 of the 9 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-analyzer:latest3d5e236216ad
setuptools@65.5.1
78.1.1
ghcr.io/libretime/libretime-api:latesteae026cc8909
setuptools@65.5.1
78.1.1
ghcr.io/libretime/libretime-playout:latest71a8706531aa
setuptools@65.5.1
78.1.1
ghcr.io/libretime/libretime-worker:latestd39ff5272b2e
setuptools@65.5.1
78.1.1

Open the chart page →

11,181
port-agentport-labsVerified publisher0.8.161 of 1See more

port-agent port-labs 0.8.16

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/port-labs/port-agent:v0.8.12c92d1e223f5c
python-3.11@3.11.15+e4
3.11.16+e2

Open the chart page →

721

Container images carrying it

1,156 by charts deploying them

A fixed version is listed for 18 of the 19 affected packages.

Container imageDigestPackageFixed inUsed by
cloudve/janis-terminal:latestaf56e77ca587
python-pip@9.0.1-2.3~ubuntu1.18.04.1
python-setuptools@39.0.1-2
setuptools@39.0.1
9.0.1-2.3~ubuntu1.18.04.8+esm8
39.0.1-2ubuntu0.1+esm2
78.1.1
1
cloudve/ttyd:latestd79c1c5881c0
setuptools@46.4.0.post20200518
78.1.1
1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
setuptools@75.6.0
78.1.1
1
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
setuptools@75.6.0
78.1.1
1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
setuptools@75.6.0
78.1.1
1
clsen2024/daejeon_2-3:latest1156cd87c8fb
setuptools@58.1.0
78.1.1
1
clsen2024/gwangju_2-3:service-b-10ba9eff852c5
setuptools@58.1.0
78.1.1
1
clsen2024/gwangju_2-3:service-a-151b1d45961cd
setuptools@58.1.0
78.1.1
1
clsen2024/gwangju_2-3:service-c-1efb1586c8299
setuptools@58.1.0
78.1.1
1
cockroachdb/cockroach-operator:v2.1.0983312754620
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
1
codaprotocol/buildkite-exporter:0.2.137c68e67a401
setuptools@52.0.0
78.1.1
1
codaprotocol/coda-user-agent:0.1.54ba4dd3a041f
setuptools@45.2.0
78.1.1
1
codecov/self-hosted-api:24.4.10475cb1c3136
setuptools@59.6.0
78.1.1
1
codecov/self-hosted-worker:24.4.1837f546b479b
setuptools@69.2.0
78.1.1
1
codekoala/pypi:1.2.14a999b2cfff2
setuptools@29.0.1.post20161130
78.1.1
1
coderenvs/coder-service:1.44.61deffc4670e6
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10
1
coderenvs/timescale:1.44.676fd37fe6830
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10
1
codetogether/codetogether:latest4348c8a38752
python-setuptools@53.0.0-12.el9
0:53.0.0-13.el9_6.1
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
1
confluentinc/cp-kafka:5.4.01bbda887bc53
setuptools@44.0.0
78.1.1
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
setuptools@71.1.0
python-setuptools@39.2.0-8.el8_10
78.1.1
0:39.2.0-9.el8_10
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
setuptools@39.2.0
python-setuptools@39.2.0-8.el8_10
78.1.1
0:39.2.0-9.el8_10
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
setuptools@67.8.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
setuptools@40.5.0
78.1.1
1
confluentinc/cp-kafka:7.5.1dc9b972db002
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
python39@3.9.16-1.module+el8.8.0+18968+3d7b19f0.1
python3x-setuptools@50.3.2-4.module+el8.5.0+12204+54860423
78.1.1
0:39.2.0-9.el8_10
0:3.9.16-1.module+el8.8.0+22374+62aa8e74.4
0:50.3.2-7.module+el8.8.0+23471+79c1a070
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
setuptools@53.0.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
setuptools@53.0.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
setuptools@53.0.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
setuptools@53.0.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
setuptools@67.8.0
python-setuptools@39.2.0-7.el8
python39@3.9.16-1.module+el8.8.0+18968+3d7b19f0.1
python3x-setuptools@50.3.2-4.module+el8.5.0+12204+54860423
78.1.1
0:39.2.0-9.el8_10
0:3.9.16-1.module+el8.8.0+22374+62aa8e74.4
0:50.3.2-7.module+el8.8.0+23471+79c1a070
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
setuptools@39.2.0
python-setuptools@39.2.0-8.el8_10
78.1.1
0:39.2.0-9.el8_10
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
setuptools@53.0.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
1
countly/api:25.05.4f4cc7447c4f5
setuptools@56.0.0
78.1.1
1
countly/countly-server:25.05.4e3c238248f99
setuptools@45.2.0-1
45.2.0-1ubuntu0.3
1
countly/frontend:25.05.42acbc11499b6
setuptools@56.0.0
78.1.1
1
craigwillis/c2metadata-bd:latestae317d7e4724
setuptools@50.3.0
78.1.1
1
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
setuptools@65.6.0
78.1.1
1
ctron/hawkbit-operator:0.1.48fdea8f76499
setuptools@39.2.0
python-setuptools@39.2.0-5.el8
78.1.1
0:39.2.0-9.el8_10
1
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
setuptools@75.8.0
78.1.1
1
danuk/telegram-sender:0.0.1026560388070
setuptools@58.1.0
78.1.1
1
daskdev/dask:1.1.04ecd7bc35500
setuptools@40.2.0
78.1.1
1
daskdev/dask-notebook:1.1.0052630f5ca04
setuptools@40.6.3
78.1.1
1
datadog/agent:7.22.08f20e56b5311
setuptools@47.1.0
78.1.1
1
datamate/seafile-professional:11.0.202dd66b722464
setuptools@75.3.2
78.1.1
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
setuptools@50.3.2
78.1.1
1
datawire/aes:1.13.62beb65062c8b
setuptools@50.3.2
78.1.1
1
datawire/aes:3.11.195ec30b3c732
setuptools@69.5.1
78.1.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.