CVE-2026-25645
MediumAdvisory
Published 25 Mar 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.002
- 8th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 870
- of 17,787 indexed, latest versions
- Container images
- 920
- deployed by those charts
- Fix available
- 3 of 5
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 870 of 17,787 indexed charts deploy, on 920 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| requestspypi | 2.2.1, 2.6.0, 2.9.1, 2.10.0+27 more | 2.33.0 | 882 |
| requestsdeb | 2.2.1-1, 2.2.1-1ubuntu0.3, 2.9.1-3, 2.9.1-3ubuntu0.1+8 more | no fix listed | 72 |
| py3-requestsapk | 2.32.3-r0, 2.32.4-r0, 2.32.5-r0 | 2.33.1-r0 | 7 |
| python-pipdeb | 1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+23 more | no fix listed | 108 |
| py3-pipapk | 25.0.1-r0, 25.2-r0, 26.0.1-r1 | 26.1.1-r0 | 3 |
- OSV records
- ALPINE-CVE-2026-25645CGA-8rh8-wj4q-c4fxCGA-p6r3-cg4x-wxcmDEBIAN-CVE-2026-25645PYSEC-2026-2275UBUNTU-CVE-2026-25645
- Also known as
- CGA-hq6f-pr48-q7w8, CGA-wfp2-2xhv-mx6w, GHSA-gc5v-m9x4-r6x2
Charts affected
870 by stars
Container images carrying it
920 by charts deploying them
A fixed version is listed for 3 of the 5 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| langgenius/ | 066035f93856 | requests | 2.33.0 | 1 |
| langgenius/ | fca918260dd6 | requests | 2.33.0 | 1 |
| langgenius/ | 3c694329357b | python-pip | no fix listed | 1 |
| langgenius/ | 8269050f192e | requests python-pip | 2.33.0 no fix listed | 1 |
| langgenius/ | da995c129e2f | python-pip | no fix listed | 1 |
| langgenius/ | 4e65e8a351a2 | requests | 2.33.0 | 1 |
| langgenius/ | 750e1111426e | requests | 2.33.0 | 1 |
| library/ | ee75c9a737e7 | requests | 2.33.0 | 1 |
| librenms/ | 4f1f3d667cc7 | requests | 2.33.0 | 1 |
| libretranslate/ | 1de2d7056bb8 | requests | 2.33.0 | 1 |
| linuxserver/ | f7d7c7704249 | requests | 2.33.0 | 1 |
| linuxserver/ | e36d16f7341c | requests | 2.33.0 | 1 |
| linuxserver/ | 241009026e6f | requests python-pip | 2.33.0 no fix listed | 1 |
| linuxserver/ | 938810eca3d3 | requests | 2.33.0 | 1 |
| linuxserver/ | 89cd8d5fb1ac | requests | 2.33.0 | 1 |
| linuxserver/ | c4d2766b9eb7 | requests | 2.33.0 | 1 |
| linuxserver/ | 0ac871624394 | requests requests | 2.33.0 no fix listed | 1 |
| linuxserver/ | 2ce561a95e7b | requests requests | 2.33.0 no fix listed | 1 |
| linuxserver/ | 50792a72fc71 | requests | 2.33.0 | 1 |
| linuxserver/ | 94696dab3c50 | requests | 2.33.0 | 1 |
| linuxserver/ | f93d2560e233 | requests | 2.33.0 | 1 |
| linuxserver/ | 4477fb1ce3ca | requests | 2.33.0 | 1 |
| linuxserver/ | e48b479c1891 | requests | 2.33.0 | 1 |
| litellm/ | 09b217802ded | requests py3-pip | 2.33.0 26.1.1-r0 | 1 |
| lnbitsdocker/ | 26fae6327477 | requests | 2.33.0 | 1 |
| lnbitsdocker/ | a11aaa6d2b21 | requests | 2.33.0 | 1 |
| lncm/ | bca14d04397d | requests | 2.33.0 | 1 |
| localstack/ | 9d278167f2b7 | requests | 2.33.0 | 1 |
| locustio/ | 51d866285170 | requests | 2.33.0 | 1 |
| logiqai/ | 55a574ec5b64 | requests | 2.33.0 | 1 |
| louislam/ | 059b49d64739 | requests requests | no fix listed 2.33.0 | 1 |
| louislam/ | 0b55bcb83a1c | requests | 2.33.0 | 1 |
| louislam/ | 3d632903e6af | requests | 2.33.0 | 1 |
| louislam/ | 3e24e96c89ef | requests requests | no fix listed 2.33.0 | 1 |
| louislam/ | 4c364ef96aad | requests requests | no fix listed 2.33.0 | 1 |
| louislam/ | 91e963bfda56 | requests requests | no fix listed 2.33.0 | 1 |
| louislam/ | 96510915e6be | requests | 2.33.0 | 1 |
| louislam/ | 9865163f92c1 | requests requests | no fix listed 2.33.0 | 1 |
| louislam/ | a4eab252e5a2 | requests | 2.33.0 | 1 |
| louislam/ | a84767d7934f | requests | 2.33.0 | 1 |
| louislam/ | bc6f244ecf27 | requests | 2.33.0 | 1 |
| lsstdm/ | 74c97a490940 | requests | 2.33.0 | 1 |
| lsstsqre/ | 4143c7cd705e | requests | 2.33.0 | 1 |
| lsstsqre/ | b75bf8aaafa4 | requests python-pip | 2.33.0 no fix listed | 1 |
| lsstsqre/ | 19c2dfc4e4ff | requests | 2.33.0 | 1 |
| lsstsqre/ | 5e0ade6bed1c | requests | 2.33.0 | 1 |
| lsstsqre/ | 4879415ec6ac | requests | 2.33.0 | 1 |
| lsstsqre/ | e139fde946d7 | requests | 2.33.0 | 1 |
| lsstsqre/ | e9feb99f524d | requests | 2.33.0 | 1 |
| makersquad/ | a40dd258c527 | requests requests | no fix listed 2.33.0 | 1 |