CVE-2026-25645
MediumAdvisory
Published 25 Mar 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.002
- 8th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 860
- of 17,787 indexed, latest versions
- Container images
- 911
- deployed by those charts
- Fix available
- 3 of 5
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 860 of 17,787 indexed charts deploy, on 911 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| requestspypi | 2.2.1, 2.6.0, 2.9.1, 2.10.0+27 more | 2.33.0 | 875 |
| requestsdeb | 2.2.1-1, 2.2.1-1ubuntu0.3, 2.9.1-3, 2.9.1-3ubuntu0.1+8 more | no fix listed | 72 |
| py3-requestsapk | 2.32.3-r0, 2.32.4-r0, 2.32.5-r0 | 2.33.1-r0 | 7 |
| python-pipdeb | 1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+22 more | no fix listed | 106 |
| py3-pipapk | 25.0.1-r0, 25.2-r0, 26.0.1-r1 | 26.1.1-r0 | 3 |
- OSV records
- ALPINE-CVE-2026-25645CGA-8rh8-wj4q-c4fxCGA-p6r3-cg4x-wxcmDEBIAN-CVE-2026-25645PYSEC-2026-2275UBUNTU-CVE-2026-25645
- Also known as
- CGA-hq6f-pr48-q7w8, CGA-wfp2-2xhv-mx6w, GHSA-gc5v-m9x4-r6x2
Charts affected
860 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| emissary-ingresswenerme | 8.12.2 | 1 of 2See more | 10,843 |
| juicefs-csi-driverwenerme | 0.32.5 | 1 of 5See more | 9,117 |
| ceph-csi-cephfswikimedia | 0.1.8 | 1 of 5See more | 10,285 |
| ceph-csi-rbdwikimedia | 0.1.13 | 1 of 6See more | 11,784 |
| docker-hub-rate-limit-exporterwiremindVerified publisher | 0.3.0 | 1 of 1See more | 1,843 |
| marge-botwiremindVerified publisher | 1.4.4 | 1 of 1See more | 5,542 |
| powerdnsadminwitcom-gmbh | 0.3.4 | 1 of 1See more | 2,643 |
| xkopsxkops | 0.1.0 | 2 of 5See more | 13,677 |
| enterprise-gatewayzeet | 3.2.2 | 1 of 2See more | 1,838 |
| zerossl-cert-managerzerossl-cert-manager | 0.1.0 | 1 of 2See more | 570 |
Container images carrying it
911 by charts deploying them
A fixed version is listed for 3 of the 5 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| bnjbvr/ | 37e216b182c8 | requests | 2.33.0 | 1 |
| boky/ | aafc77238423 | requests | 2.33.0 | 1 |
| bootc/ | f1383295e7be | requests | 2.33.0 | 1 |
| browserless/ | c81ae5585b47 | requests requests | 2.33.0 no fix listed | 1 |
| buildkite/ | aec38cfaae0e | requests | 2.33.0 | 1 |
| buntha/ | 154542cc3083 | requests | 2.33.0 | 1 |
| camerahub/ | a5af37dd6e1b | requests | 2.33.0 | 1 |
| camptocamp/ | acfafc308d88 | requests | 2.33.0 | 1 |
| camptocamp/ | 35c91d5fda04 | requests | 2.33.0 | 1 |
| camptocamp/ | bff736b15623 | requests | 2.33.0 | 1 |
| camptocamp/ | 2924b43dbf40 | requests | 2.33.0 | 1 |
| castai/ | da62858c8381 | requests | 2.33.0 | 1 |
| cdignam/ | 5a6a55b39cee | requests | 2.33.0 | 1 |
| ceph/ | 90f30824a96e | requests | 2.33.0 | 1 |
| checkmk/ | c11b422210c4 | requests | 2.33.0 | 1 |
| chetangautamm/ | e7f7049e1544 | requests requests | 2.33.0 no fix listed | 1 |
| chiefonboarding/ | 59bc7aa60fe7 | requests | 2.33.0 | 1 |
| chubaofs/ | 15ff74209ce7 | requests | 2.33.0 | 1 |
| chubaofs/ | 205030e045f2 | requests | 2.33.0 | 1 |
| citizenstig/ | b81c818ccb86 | python-pip | no fix listed | 1 |
| ciuse99/ | d72768245ef5 | requests | 2.33.0 | 1 |
| ckan/ | 84d11924549f | requests | 2.33.0 | 1 |
| cleveritcz/ | c75c1636e0b7 | requests | 2.33.0 | 1 |
| cloudve/ | af56e77ca587 | requests python-pip | 2.33.0 no fix listed | 1 |
| cloudve/ | d79c1c5881c0 | requests | 2.33.0 | 1 |
| clowder/ | 11f3d844e4c0 | requests | 2.33.0 | 1 |
| clowder/ | 14155326c7b9 | requests | 2.33.0 | 1 |
| clowder/ | bf146f1ca24f | requests | 2.33.0 | 1 |
| codaprotocol/ | 37c68e67a401 | requests | 2.33.0 | 1 |
| codaprotocol/ | 4ba4dd3a041f | requests | 2.33.0 | 1 |
| codecov/ | 0475cb1c3136 | requests | 2.33.0 | 1 |
| codecov/ | 837f546b479b | requests | 2.33.0 | 1 |
| confluentinc/ | f2975d507a2a | requests | 2.33.0 | 1 |
| confluentinc/ | 8f1544df1f48 | requests | 2.33.0 | 1 |
| confluentinc/ | 1bbda887bc53 | requests | 2.33.0 | 1 |
| confluentinc/ | 3bf359d5e340 | requests | 2.33.0 | 1 |
| confluentinc/ | 83dbca3efd2a | requests | 2.33.0 | 1 |
| confluentinc/ | adc392d28a1e | requests | 2.33.0 | 1 |
| confluentinc/ | c0224a1adf7a | requests | 2.33.0 | 1 |
| confluentinc/ | c87b1c07fb53 | requests | 2.33.0 | 1 |
| confluentinc/ | dc9b972db002 | requests | 2.33.0 | 1 |
| confluentinc/ | 4bc70a83ca6f | requests | 2.33.0 | 1 |
| confluentinc/ | b0b7aa26254a | requests | 2.33.0 | 1 |
| confluentinc/ | 8ec46c27982f | requests | 2.33.0 | 1 |
| confluentinc/ | ee403d5b9090 | requests | 2.33.0 | 1 |
| confluentinc/ | b651d4b6185a | requests | 2.33.0 | 1 |
| confluentinc/ | 0bec03c1f3ce | requests | 2.33.0 | 1 |
| confluentinc/ | 5ca5f3269814 | requests | 2.33.0 | 1 |
| confluentinc/ | 78c190f4472c | requests | 2.33.0 | 1 |
| countly/ | e3c238248f99 | requests requests | 2.33.0 no fix listed | 1 |