StackRadar

CVE-2025-47278

Low

Advisory

Published 13 May 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
1.8
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
18
of 17,957 indexed, latest versions
Container images
17
deployed by those charts
Fix available
1 of 1
affected package

Flask uses fallback key instead of current signing key

Carried by container images the latest versions of 18 of 17,957 indexed charts deploy, on 17 images.

Affected packageAffected versionsFixed inImages
flaskpypi3.1.03.1.117
OSV records
GHSA-4grg-w6v8-c28g
Also known as
PYSEC-2026-1377

Charts affected

18 by stars
ChartLatestAffected imagesRadar Score
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
flask@3.1.0
3.1.1

Open the chart page →

11,045
alerta-webalerta-webVerified publisher0.1.121 of 2See more

alerta-web alerta-web 0.1.12

1 of the 2 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
hayk96/alerta-web:9.0.486377705e9e3
flask@3.1.0
3.1.1

Open the chart page →

3,696
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
flask@3.1.0
3.1.1

Open the chart page →

103,437
hasher-matcher-actionerhasher-matcher-actioner1.0.01 of 1See more

hasher-matcher-actioner hasher-matcher-actioner 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
ghcr.io/facebook/threatexchange/hma:1.0.1784d09c6b75a7
flask@3.1.0
3.1.1

Open the chart page →

1,070
locustlocustVerified publisher0.1.41 of 1See more

locust locust 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
hansehe/locust:1.1.0bc8e45262bc4
flask@3.1.0
3.1.1

Open the chart page →

2,958
opikopikOfficialVerified publisher2.2.851 of 13See more

opik opik 2.2.85

1 of the 13 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
ghcr.io/comet-ml/opik/opik-python-backend:2.2.85bd3cc22d1bdb
flask@3.1.0
3.1.1

Open the chart page →

14,244
snappasssnappassVerified publisher0.4.31 of 3See more

snappass snappass 0.4.3

1 of the 3 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
flask@3.1.0
3.1.1

Open the chart page →

3,443
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
flask@3.1.0
3.1.1

Open the chart page →

11,543
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
flask@3.1.0
3.1.1

Open the chart page →

6,368
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
flask@3.1.0
3.1.1

Open the chart page →

6,368
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
flask@3.1.0
3.1.1

Open the chart page →

6,662
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
flask@3.1.0
3.1.1

Open the chart page →

56,519
hawk-envoy-pluginhawk0.1.01 of 4See more

hawk-envoy-plugin hawk 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
kong/httpbin:latesta6ac46531193
flask@3.1.0
3.1.1

Open the chart page →

71,218
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
flask@3.1.0
3.1.1

Open the chart page →

5,113
kubecostradar-baseVerified publisher1.0.01 of 7See more

kubecost radar-base 1.0.0

1 of the 7 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
flask@3.1.0
3.1.1

Open the chart page →

9,791
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
flask@3.1.0
3.1.1

Open the chart page →

8,290
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
flask@3.1.0
3.1.1

Open the chart page →

5,256
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-47278.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
flask@3.1.0
3.1.1

Open the chart page →

597

Container images carrying it

17 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
opendatacube/ows:latest668cbb41473c
flask@3.1.0
3.1.1
2
allegroai/clearml:2.0.0-613713ae38f7daf
flask@3.1.0
3.1.1
1
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
flask@3.1.0
3.1.1
1
dpage/pgadmin4:9.252cb72a9e3da
flask@3.1.0
3.1.1
1
hansehe/locust:1.1.0bc8e45262bc4
flask@3.1.0
3.1.1
1
hayk96/alerta-web:9.0.486377705e9e3
flask@3.1.0
3.1.1
1
kong/httpbin:latesta6ac46531193
flask@3.1.0
3.1.1
1
langgenius/dify-api:1.0.0066035f93856
flask@3.1.0
3.1.1
1
lmacka/snappass:2.1.293f5c048b7d4
flask@3.1.0
3.1.1
1
opendatacube/wps:latest80df355a660b
flask@3.1.0
3.1.1
1
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
flask@3.1.0
3.1.1
1
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
flask@3.1.0
3.1.1
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
flask@3.1.0
3.1.1
1
ghcr.io/comet-ml/opik/opik-python-backend:2.2.85bd3cc22d1bdb
flask@3.1.0
3.1.1
1
ghcr.io/facebook/threatexchange/hma:1.0.1784d09c6b75a7
flask@3.1.0
3.1.1
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
flask@3.1.0
3.1.1
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
flask@3.1.0
3.1.1
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.