StackRadar

CVE-2025-47273

High

Advisory

Published 17 May 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,086
of 17,787 indexed, latest versions
Container images
1,156
deployed by those charts
Fix available
18 of 19
affected packages

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

Carried by container images the latest versions of 1,086 of 17,787 indexed charts deploy, on 1,156 images.

Affected packageAffected versionsFixed inImages
setuptoolspypi0.9.8, 20.7.0, 20.8.0, 29.0.1.post20161130+124 more78.1.11,083
setuptoolsdeb45.2.0-1, 45.2.0-1ubuntu0.1, 45.2.0-1ubuntu0.2, 52.0.0-4+8 more45.2.0-1ubuntu0.3, 52.0.0-4+deb11u2, 59.6.0-1.2ubuntu0.22.04.3, 66.1.1-1+deb12u2+1 more154
python-setuptoolsdeb3.3-1ubuntu1, 3.3-1ubuntu2, 20.7.0-1, 39.0.1-2+3 more3.3-1ubuntu2+esm3, 20.7.0-1ubuntu0.1~esm3, 39.0.1-2ubuntu0.1+esm2, 44.0.0-2ubuntu0.1+esm239
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+5 more8.1.1-2ubuntu0.6+esm12, 9.0.1-2.3~ubuntu1.18.04.8+esm830
py3-pipapk25.0.1-r0, 25.2-r0, 26.0.1-r1no fix listed3
setuptoolsbitnami70.3.078.1.12
python-setuptoolsrpm0.9.8-7.el7, 39.2.0-5.el8, 39.2.0-6.el8, 39.2.0-6.el8_7.1+6 more0:0.9.8-7.el7_9.2, 0:39.2.0-9.el8_10, 0:53.0.0-13.el9_6.1138
python-chardetrpm3.0.4-7.el80:3.0.4-19.module+el8.4.0+9822+20bf124920
python-idnarpm2.5-5.el80:2.10-3.module+el8.4.0+9822+20bf124920
python-pysocksrpm1.6.8-3.el80:1.7.1-4.module+el8.4.0+9822+20bf124920
python-requestsrpm2.20.0-2.1.el8_1, 2.20.0-3.el8_6, 2.20.0-3.el8_80:2.25.0-2.module+el8.4.0+9822+20bf124920
python-urllib3rpm1.24.2-5.el8, 1.24.2-5.el8_6.10:1.25.10-3.module+el8.4.0+9822+20bf1249, 0:1.25.10-4.module+el8.5.0+11712+ea2d2be120
python3x-setuptoolsrpm41.6.0-4.module+el8.4.0+8888+89bc7e79, 41.6.0-5.module+el8.5.0+12205+a865257a, 50.3.2-3.module+el8.4.0+9822+20bf1249, 50.3.2-4.module+el8.5.0+12204+548604230:50.3.2-3.module+el8.4.0+23445+8885b4ac.3, 0:50.3.2-7.module+el8.8.0+23471+79c1a0709
python-plyrpm3.9-9.el80:3.11-10.module+el8.4.0+9822+20bf12497
python39rpm3.9.2-1.module+el8.4.0+10237+bdc77aac, 3.9.16-1.module+el8.8.0+18968+3d7b19f0.10:3.9.2-2.module+el8.4.0+22379+dcc60181.4, 0:3.9.16-1.module+el8.8.0+22374+62aa8e74.46
python3x-piprpm19.3.1-1.module+el8.4.0+8888+89bc7e79, 19.3.1-6.module+el8.7.0+15823+8950cfa7, 20.2.4-3.module+el8.4.0+9822+20bf12490:20.2.4-3.module+el8.4.0+15042+dc5a279b.1, 0:20.2.4-7.module+el8.6.0+13003+6bb2c4884
python3.11-setuptoolsrpm65.5.1-2.el9, 65.5.1-2.el9_4.10:65.5.1-4.el9_62
python-wheelrpm0.33.6-5.module+el8.4.0+8888+89bc7e791:0.35.1-3.module+el8.4.0+15042+dc5a279b.11
python-3.11deb3.11.15+e43.11.16+e21
OSV records
BIT-setuptools-2025-47273CGA-6rww-wjff-6g99CGA-gfc8-q7jm-4w3vDEBIAN-CVE-2025-47273PYSEC-2025-49RHSA-2025:10407RHSA-2025:11036RHSA-2025:11984RHSA-2025:13578RHSA-2025:15408RHSA-2025:15410RHSA-2025:15411RLSA-2025:10407RLSA-2025:11036UBUNTU-CVE-2025-47273DLA-4183-1ECHO-2d75-a206-3684USN-7544-1
Also known as
CGA-wrp2-2xv2-hfvv, CGA-xqm6-7hq3-gpvg, GHSA-5rjg-fvgr-3xxf, RHSA-2025:11424, RHSA-2025:11425, RHSA-2025:11426, RHSA-2025:11427, RHSA-2025:11868, RHSA-2025:12020, RHSA-2025:13669, USN-8010-1

Charts affected

1,086 by stars
ChartLatestAffected imagesRadar Score
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

11,795
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10
andrianrf/backoffice-be:latest6036614803d4
python-setuptools@53.0.0-12.el9
0:53.0.0-13.el9_6.1
andrianrf/iso-server:latest7da47f525c7d
python-setuptools@53.0.0-12.el9
0:53.0.0-13.el9_6.1

Open the chart page →

34,721
canvas-oamportalopenshift4.0.01 of 1See more

canvas-oamportal openshift 4.0.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/oam:4.0.0ed8fd2062548
setuptools@39.2.0
python-setuptools@39.2.0-8.el8_10
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

7,519
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
setuptools@65.5.1
python-setuptools@53.0.0-12.el9_4.1
python3.11-setuptools@65.5.1-2.el9_4.1
78.1.1
0:53.0.0-13.el9_6.1
0:65.5.1-4.el9_6
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
setuptools@65.5.1
python-setuptools@53.0.0-12.el9
python3.11-setuptools@65.5.1-2.el9
78.1.1
0:53.0.0-13.el9_6.1
0:65.5.1-4.el9_6

Open the chart page →

18,991
exporteropenshift1.0.473 of 3See more

exporter openshift 1.0.47

3 of the 3 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
setuptools@39.2.0
python-setuptools@39.2.0-8.el8_10
78.1.1
0:39.2.0-9.el8_10
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
setuptools@53.0.0
python-setuptools@53.0.0-13.el9
78.1.1
0:53.0.0-13.el9_6.1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
setuptools@53.0.0
python-setuptools@53.0.0-13.el9
78.1.1
0:53.0.0-13.el9_6.1

Open the chart page →

13,034
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

9,968
fsmopenshift0.1.8-ubi.61 of 6See more

fsm openshift 0.1.8-ubi.6

1 of the 6 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

16,554
hamiopenshift2.10.0-r0-openshift.c4e22e881 of 2See more

hami openshift 2.10.0-r0-openshift.c4e22e88

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/dynamia-ai/hami-enterprise:v2.10.0-r0-openshift.c4e22e88745504757300
setuptools@39.2.0
78.1.1

Open the chart page →

4,749
kb-cloud-installeropenshift2.1.351 of 1See more

kb-cloud-installer openshift 2.1.35

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
setuptools@53.0.0
78.1.1

Open the chart page →

4,145
kite-agentopenshift1.0.01 of 1See more

kite-agent openshift 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
setuptools@39.2.0
78.1.1

Open the chart page →

5,863
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
setuptools@39.0.1
78.1.1

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi81 of 7See more

osm-edge openshift 1.2.1-ubi8

1 of the 7 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

19,449
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
setuptools@53.0.0
python-setuptools@53.0.0-12.el9
78.1.1
0:53.0.0-13.el9_6.1

Open the chart page →

8,634
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,608
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

11,740
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,570
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,553
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,457
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

13,101
openshift-integration-operatoropenshift-integration-operatorVerified publisher0.8.21 of 2See more

openshift-integration-operator openshift-integration-operator 0.8.2

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
python-setuptools@53.0.0-13.el9
0:53.0.0-13.el9_6.1

Open the chart page →

2,063
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
python-setuptools@39.0.1-2
39.0.1-2ubuntu0.1+esm2

Open the chart page →

15,607
open-webconceptopen-webconcept0.1.01 of 3See more

open-webconcept open-webconcept 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
setuptools@58.1.0
78.1.1

Open the chart page →

3,423
openwhiskopenwhisk1.0.02 of 10See more

openwhisk openwhisk 1.0.0

2 of the 10 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
openwhisk/kafkaprovider:2.1.063dc3d2a0904
setuptools@41.4.0
78.1.1
openwhisk/ow-utils:1.0.0c80dba0de3aa
python-pip@9.0.1-2.3~ubuntu1.18.04.4
python-setuptools@39.0.1-2
setuptools@44.1.1
9.0.1-2.3~ubuntu1.18.04.8+esm8
39.0.1-2ubuntu0.1+esm2
78.1.1

Open the chart page →

36,230
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.05 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

5 of the 40 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
yetiplatform/yeti:2.9.09bcbe2650a14
setuptools@78.1.0
78.1.1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
setuptools@68.1.2
78.1.1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
setuptools@68.1.2
78.1.1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
setuptools@68.1.2
78.1.1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
setuptools@68.1.2
78.1.1

Open the chart page →

72,154
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
setuptools@78.1.0
78.1.1

Open the chart page →

6,544
pgaot-container-kit1.0.31 of 6See more

pga ot-container-kit 1.0.3

1 of the 6 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.26.1b8d5067137fe
setuptools@69.0.3
78.1.1

Open the chart page →

5,136
vmot-container-kit0.0.31 of 7See more

vm ot-container-kit 0.0.3

1 of the 7 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
setuptools@70.0.0
78.1.1

Open the chart page →

5,410
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
setuptools@59.4.0
78.1.1

Open the chart page →

1,980
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
mastercloudapps/server:v2.23f3d24dfe2686
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

27,667
plausiblepascaliskeVerified publisher2.0.01 of 1See more

plausible pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
setuptools@70.3.0
78.1.1

Open the chart page →

959
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
setuptools@39.2.0
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-setuptools@39.2.0-6.el8
python-urllib3@1.24.2-5.el8
78.1.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:39.2.0-9.el8_10
0:1.25.10-3.module+el8.4.0+9822+20bf1249

Open the chart page →

15,466
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
setuptools@39.2.0
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-setuptools@39.2.0-6.el8
python-urllib3@1.24.2-5.el8
78.1.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:39.2.0-9.el8_10
0:1.25.10-3.module+el8.4.0+9822+20bf1249

Open the chart page →

15,466
redis-stack-awsphamxuanduong0.1.01 of 1See more

redis-stack-aws phamxuanduong 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.4.0-v0887cf87cc744
setuptools@59.6.0-1.2ubuntu0.22.04.1
59.6.0-1.2ubuntu0.22.04.3

Open the chart page →

3,277
dummy-servicephanVerified publisher0.3.41 of 1See more

dummy-service phan 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phan2410/dummy-service:0.0.89c6ed6de26ca
setuptools@66.1.1-1+deb12u1
setuptools@66.1.1
66.1.1-1+deb12u2
78.1.1

Open the chart page →

5,731
falcon-asgi-serverphanVerified publisher0.1.01 of 1See more

falcon-asgi-server phan 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phan2410/falcon-asgi-server:0.1.04a86d138832d
setuptools@78.1.0
78.1.1

Open the chart page →

8,215
email-managerphntom0.1.221 of 2See more

email-manager phntom 0.1.22

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/email-manager:0.1.22d8e2a9f2f085
setuptools@65.5.1
78.1.1

Open the chart page →

2,565
external-dns-host-networkphntom0.0.121 of 1See more

external-dns-host-network phntom 0.0.12

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/external-dns-host-network:0.0.123adadbac8443
setuptools@58.1.0
78.1.1

Open the chart page →

4,644
npre-essentialsphntom0.1.601 of 22See more

npre-essentials phntom 0.1.60

1 of the 22 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.21.0710e23b489c5
setuptools@65.5.1
78.1.1

Open the chart page →

26,840
postgresql-backupphntom0.1.91 of 1See more

postgresql-backup phntom 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/postgresql-backup-s3:1.0.2249b6488f618b
setuptools@65.6.0
78.1.1

Open the chart page →

2,556
stocks-nasdaq-crawlerphntom0.0.361 of 1See more

stocks-nasdaq-crawler phntom 0.0.36

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
phntom/stocks-nasdaq-crawler:0.0.28d2b844700b57
setuptools@50.3.0
78.1.1

Open the chart page →

1,845
phronetisphronetis0.1.271 of 2See more

phronetis phronetis 0.1.27

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
knspar/phronetis-operator:0.1.60c4f0543ee58
setuptools@69.5.1
78.1.1

Open the chart page →

15,077
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
setuptools@45.2.0-1
setuptools@45.2.0
45.2.0-1ubuntu0.3
78.1.1

Open the chart page →

22,146
pingdom-operatorpingdom-operator0.0.201 of 1See more

pingdom-operator pingdom-operator 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
setuptools@71.1.0
78.1.1

Open the chart page →

11,017
planectlplanectlVerified publisher0.7.01 of 10See more

planectl planectl 0.7.0

1 of the 10 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
alpine/k8s:1.30.2cd560fce90f7
setuptools@70.1.1
78.1.1

Open the chart page →

25,626
plausibleplausible0.1.21 of 2See more

plausible plausible 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
setuptools@70.3.0
78.1.1

Open the chart page →

1,337
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
setuptools@46.0.0
python-setuptools@39.2.0-5.el8
78.1.1
0:39.2.0-9.el8_10

Open the chart page →

11,153
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
setuptools@68.2.2
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-3.el8_8
python-setuptools@39.2.0-7.el8
python-urllib3@1.24.2-5.el8
python39@3.9.16-1.module+el8.8.0+18968+3d7b19f0.1
python3x-setuptools@50.3.2-4.module+el8.5.0+12204+54860423
78.1.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:39.2.0-9.el8_10
0:1.25.10-4.module+el8.5.0+11712+ea2d2be1
0:3.9.16-1.module+el8.8.0+22374+62aa8e74.4
0:50.3.2-7.module+el8.8.0+23471+79c1a070

Open the chart page →

12,754
pod-birdspod-birds0.1.01 of 1See more

pod-birds pod-birds 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
teknas09/bird-pod:latest12a1fa85c4aa
setuptools@69.2.0
78.1.1

Open the chart page →

11,680
libretimepodzone-chartsVerified publisher0.4.14 of 9See more

libretime podzone-charts 0.4.1

4 of the 9 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-analyzer:latest3d5e236216ad
setuptools@65.5.1
78.1.1
ghcr.io/libretime/libretime-api:latesteae026cc8909
setuptools@65.5.1
78.1.1
ghcr.io/libretime/libretime-playout:latest71a8706531aa
setuptools@65.5.1
78.1.1
ghcr.io/libretime/libretime-worker:latestd39ff5272b2e
setuptools@65.5.1
78.1.1

Open the chart page →

11,181
port-agentport-labsVerified publisher0.8.161 of 1See more

port-agent port-labs 0.8.16

1 of the 1 container images this version deploys carry CVE-2025-47273.

Container imageDigestPackageFixed in
ghcr.io/port-labs/port-agent:v0.8.12c92d1e223f5c
python-3.11@3.11.15+e4
3.11.16+e2

Open the chart page →

721

Container images carrying it

1,156 by charts deploying them

A fixed version is listed for 18 of the 19 affected packages.

Container imageDigestPackageFixed inUsed by
library/mysql:5.74bc6bc963e6d
setuptools@58.1.0
78.1.1
22
oomk8s/readiness-check:2.0.2875814cc853d
python-pip@8.1.1-2ubuntu0.4
python-setuptools@20.7.0-1
setuptools@40.8.0
8.1.1-2ubuntu0.6+esm12
20.7.0-1ubuntu0.1~esm3
78.1.1
11
codeurjc/server:v1.0310bea5b1ee7
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
8
oomk8s/readiness-check:2.0.07daa08b81954
python-pip@8.1.1-2ubuntu0.4
python-setuptools@20.7.0-1
setuptools@39.0.1
8.1.1-2ubuntu0.6+esm12
20.7.0-1ubuntu0.1~esm3
78.1.1
6
cachethq/docker:2.3.15a61ff0f67ea7
setuptools@33.1.1.post20171031
78.1.1
4
mastercloudapps/server:v2.23f3d24dfe2686
setuptools@39.2.0
python-setuptools@39.2.0-6.el8
78.1.1
0:39.2.0-9.el8_10
4
ncsa/checks:1.0.1cc46a03e16ed
setuptools@57.5.0
78.1.1
4
opea/llm-tgi:1.00c25aab3f106
setuptools@65.5.1
78.1.1
4
quay.io/strimzi/operator:0.37.052f376e64b9b
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
78.1.1
0:39.2.0-9.el8_10
4
argoproj/argocd:v1.8.1830e86cacefd
setuptools@40.8.0
78.1.1
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
setuptools@45.2.0-1
setuptools@45.2.0
45.2.0-1ubuntu0.3
78.1.1
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
setuptools@57.5.0
78.1.1
3
dpage/pgadmin4:6.12781369df9994
setuptools@52.0.0
78.1.1
3
kiwigrid/k8s-sidecar:0.1.193170069ff0976
setuptools@49.6.0
78.1.1
3
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
setuptools@75.1.0
78.1.1
3
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
setuptools@46.1.3
78.1.1
3
kiwigrid/k8s-sidecar:1.30.2cdb361e67b1b
setuptools@76.0.0
78.1.1
3
paulkellerman/resultserver-app:1.0381eeccb0618
setuptools@65.5.0
78.1.1
3
paulkellerman/webserver-app:latest5a37b74f61b9
setuptools@65.5.0
78.1.1
3
selenium/hub:3.141.5902f251d48d5f
setuptools@45.2.0-1
45.2.0-1ubuntu0.3
3
quay.io/devtron/ai-agent:0.0.16545dac92173
setuptools@72.2.0
78.1.1
3
quay.io/kiwigrid/k8s-sidecar:1.14.235654389f8a9
setuptools@57.5.0
78.1.1
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
setuptools@40.8.0
78.1.1
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
setuptools@39.2.0
python-chardet@3.0.4-7.el8
python-idna@2.5-5.el8
python-ply@3.9-9.el8
python-pysocks@1.6.8-3.el8
python-requests@2.20.0-2.1.el8_1
python-setuptools@39.2.0-6.el8
python-urllib3@1.24.2-5.el8
78.1.1
0:3.0.4-19.module+el8.4.0+9822+20bf1249
0:2.10-3.module+el8.4.0+9822+20bf1249
0:3.11-10.module+el8.4.0+9822+20bf1249
0:1.7.1-4.module+el8.4.0+9822+20bf1249
0:2.25.0-2.module+el8.4.0+9822+20bf1249
0:39.2.0-9.el8_10
0:1.25.10-4.module+el8.5.0+11712+ea2d2be1
3
amancevice/superset:0.35.212a0a9e66550
setuptools@44.0.0
78.1.1
2
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
setuptools@0.9.8
78.1.1
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
setuptools@40.6.3.post20190116
78.1.1
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
setuptools@68.1.2-2ubuntu1
68.1.2-2ubuntu1.2
2
aquasec/kube-hunter:0.6.8e64fe49f059f
setuptools@57.5.0
78.1.1
2
architectminds/aws-kubectl:1.19735e59a1085
setuptools@41.0.1
78.1.1
2
blakeblackshear/frigate:0.11.18330b0a265b8
setuptools@52.0.0
setuptools@52.0.0-4
78.1.1
52.0.0-4+deb11u2
2
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
setuptools@50.3.2
python-setuptools@39.2.0-7.el8
python39@3.9.16-1.module+el8.8.0+18968+3d7b19f0.1
python3x-setuptools@50.3.2-4.module+el8.5.0+12204+54860423
78.1.1
0:39.2.0-9.el8_10
0:3.9.16-1.module+el8.8.0+22374+62aa8e74.4
0:50.3.2-7.module+el8.8.0+23471+79c1a070
2
confluentinc/cp-zookeeper:latest7610a50b13e7
setuptools@71.1.0
python-setuptools@39.2.0-8.el8_10
78.1.1
0:39.2.0-9.el8_10
2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
setuptools@39.2.0
python-setuptools@39.2.0-7.el8
python39@3.9.16-1.module+el8.8.0+18968+3d7b19f0.1
python3x-setuptools@50.3.2-4.module+el8.5.0+12204+54860423
78.1.1
0:39.2.0-9.el8_10
0:3.9.16-1.module+el8.8.0+22374+62aa8e74.4
0:50.3.2-7.module+el8.8.0+23471+79c1a070
2
cs3org/wopiserver:v9.4.202a9e78757b4
setuptools@67.4.0
78.1.1
2
datawire/aes:1.14.48588eafe6862
setuptools@50.3.2
78.1.1
2
devopsjourney1/mywebapp:latestbd1ec6838570
setuptools@57.5.0
78.1.1
2
gradiant/spark:2.4.4-python-alpine97657d56e927
setuptools@41.6.0
78.1.1
2
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
setuptools@65.5.1
78.1.1
2
hjacobs/kube-ops-view:20.4.058221b57d4d2
setuptools@46.1.3
78.1.1
2
homebridge/homebridge:latest77c685a40911
setuptools@68.1.2
78.1.1
2
hookiesolutions/webhookie:latest0629694246ba
setuptools@45.2.0-1
45.2.0-1ubuntu0.3
2
istio/examples-bookinfo-productpage-v1:1.15.00a5eb4795952
setuptools@41.0.1
78.1.1
2
istio/examples-bookinfo-productpage-v1:1.14.022a0410f35a8
setuptools@41.0.1
78.1.1
2
jvstein/bitcoin-prometheus-exporter:v0.6.07645ba790ea8
setuptools@57.0.0
78.1.1
2
kiwigrid/k8s-sidecar:1.24.44138bea678f0
setuptools@68.0.0
78.1.1
2
kiwigrid/k8s-sidecar:1.24.35af76eebbba7
setuptools@65.5.1
78.1.1
2
kodekloud/examplevotingapp_vote:v13a856afb02a3
setuptools@58.1.0
78.1.1
2
langgenius/dify-sandbox:0.2.009b7e8705673
setuptools@65.5.1
78.1.1
2
larribas/mlflow:1.9.105ccb0b46bfb
setuptools@46.1.3
78.1.1
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.