CVE-2026-25645
MediumAdvisory
Published 25 Mar 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.002
- 8th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 860
- of 17,787 indexed, latest versions
- Container images
- 911
- deployed by those charts
- Fix available
- 3 of 5
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 860 of 17,787 indexed charts deploy, on 911 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| requestspypi | 2.2.1, 2.6.0, 2.9.1, 2.10.0+27 more | 2.33.0 | 875 |
| requestsdeb | 2.2.1-1, 2.2.1-1ubuntu0.3, 2.9.1-3, 2.9.1-3ubuntu0.1+8 more | no fix listed | 72 |
| py3-requestsapk | 2.32.3-r0, 2.32.4-r0, 2.32.5-r0 | 2.33.1-r0 | 7 |
| python-pipdeb | 1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+22 more | no fix listed | 106 |
| py3-pipapk | 25.0.1-r0, 25.2-r0, 26.0.1-r1 | 26.1.1-r0 | 3 |
- OSV records
- ALPINE-CVE-2026-25645CGA-8rh8-wj4q-c4fxCGA-p6r3-cg4x-wxcmDEBIAN-CVE-2026-25645PYSEC-2026-2275UBUNTU-CVE-2026-25645
- Also known as
- CGA-hq6f-pr48-q7w8, CGA-wfp2-2xhv-mx6w, GHSA-gc5v-m9x4-r6x2
Charts affected
860 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| emissary-ingresswenerme | 8.12.2 | 1 of 2See more | 10,843 |
| juicefs-csi-driverwenerme | 0.32.5 | 1 of 5See more | 9,117 |
| ceph-csi-cephfswikimedia | 0.1.8 | 1 of 5See more | 10,285 |
| ceph-csi-rbdwikimedia | 0.1.13 | 1 of 6See more | 11,784 |
| docker-hub-rate-limit-exporterwiremindVerified publisher | 0.3.0 | 1 of 1See more | 1,843 |
| marge-botwiremindVerified publisher | 1.4.4 | 1 of 1See more | 5,542 |
| powerdnsadminwitcom-gmbh | 0.3.4 | 1 of 1See more | 2,643 |
| xkopsxkops | 0.1.0 | 2 of 5See more | 13,677 |
| enterprise-gatewayzeet | 3.2.2 | 1 of 2See more | 1,838 |
| zerossl-cert-managerzerossl-cert-manager | 0.1.0 | 1 of 2See more | 570 |
Container images carrying it
911 by charts deploying them
A fixed version is listed for 3 of the 5 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | a6b3f707f883 | requests | 2.33.0 | 13 |
| oomk8s/ | 875814cc853d | requests python-pip | 2.33.0 no fix listed | 11 |
| quay.io/ | 605eaa5d469c | requests | 2.33.0 | 7 |
| oomk8s/ | 7daa08b81954 | requests python-pip | 2.33.0 no fix listed | 6 |
| flaresolverr/ | 139dfee1c6f8 | requests | 2.33.0 | 5 |
| opea/ | 0c25aab3f106 | requests | 2.33.0 | 4 |
| shashkist/ | 581de1fd6084 | requests | 2.33.0 | 4 |
| apache/ | 16b50bbef664 | requests | 2.33.0 | 3 |
| cloudve/ | 4a3d7fae90bb | requests python-pip | 2.33.0 no fix listed | 3 |
| dnationcloud/ | 78fed4f3c130 | requests | 2.33.0 | 3 |
| dpage/ | 781369df9994 | requests | 2.33.0 | 3 |
| kiwigrid/ | 170069ff0976 | requests | 2.33.0 | 3 |
| kiwigrid/ | 4166a019eeaf | requests | 2.33.0 | 3 |
| kiwigrid/ | 7b98eecdf6d1 | requests | 2.33.0 | 3 |
| kiwigrid/ | cdb361e67b1b | requests | 2.33.0 | 3 |
| quay.io/ | 6545dac92173 | requests | 2.33.0 | 3 |
| quay.io/ | 35654389f8a9 | requests | 2.33.0 | 3 |
| quay.io/ | a7dff785d821 | requests | 2.33.0 | 3 |
| amancevice/ | 12a0a9e66550 | requests | 2.33.0 | 2 |
| aquasec/ | e64fe49f059f | requests | 2.33.0 | 2 |
| blakeblackshear/ | 8330b0a265b8 | requests | 2.33.0 | 2 |
| confluentinc/ | ac776fad95a5 | requests | 2.33.0 | 2 |
| confluentinc/ | 7610a50b13e7 | requests | 2.33.0 | 2 |
| confluentinc/ | cae577096489 | requests | 2.33.0 | 2 |
| cs3org/ | 02a9e78757b4 | requests | 2.33.0 | 2 |
| datawire/ | 8588eafe6862 | requests | 2.33.0 | 2 |
| gisaia/ | 98213fa403ae | requests | 2.33.0 | 2 |
| gisaia/ | 5abfe00317bf | requests | 2.33.0 | 2 |
| gisaia/ | ac6564921994 | requests | 2.33.0 | 2 |
| gisaia/ | ae525930b4b6 | requests | 2.33.0 | 2 |
| hjacobs/ | 4b2147f47425 | requests | 2.33.0 | 2 |
| hjacobs/ | 58221b57d4d2 | requests | 2.33.0 | 2 |
| homebridge/ | 77c685a40911 | python-pip | no fix listed | 2 |
| istio/ | 0a5eb4795952 | requests | 2.33.0 | 2 |
| istio/ | 22a0410f35a8 | requests | 2.33.0 | 2 |
| kiwigrid/ | 4138bea678f0 | requests | 2.33.0 | 2 |
| kiwigrid/ | 5af76eebbba7 | requests | 2.33.0 | 2 |
| kiwigrid/ | 8c06e1ba643a | requests | 2.33.0 | 2 |
| langgenius/ | 09b7e8705673 | requests | 2.33.0 | 2 |
| larribas/ | 05ccb0b46bfb | requests | 2.33.0 | 2 |
| lncm/ | 36eaa06f99f4 | requests | 2.33.0 | 2 |
| locustio/ | a0d4b88e42c1 | requests | 2.33.0 | 2 |
| louislam/ | 917318f9d7be | requests requests | no fix listed 2.33.0 | 2 |
| louislam/ | 9aeb4e51d038 | requests requests | no fix listed 2.33.0 | 2 |
| louislam/ | a8610b3b4c38 | requests requests | no fix listed 2.33.0 | 2 |
| neuvector/ | f1b7d666eae0 | requests | 2.33.0 | 2 |
| ngoduykhanh/ | ba36ab196d3d | requests | 2.33.0 | 2 |
| omecproject/ | 7c17a7b1d1ef | requests | 2.33.0 | 2 |
| omecproject/ | cfdb566dd949 | requests python-pip | 2.33.0 no fix listed | 2 |
| opea/ | 5c9639de61c1 | requests | 2.33.0 | 2 |