/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-fff7-969w-wcq5

Published

Last updated

https://images.chainguard.dev/security/CGA-fff7-969w-wcq5
Package

apache-beam-python-3.11-sdk

Repository

Chainguard

Latest Update
Fixed
Fixed Version

2.59.0-r0

Aliases
  • CVE-2024-35195
  • GHSA-9wx4-h78v-vm56

Severity

5.6

Medium

CVSS CVSS_V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-35195

Updates

Status

Fixed

Fixed version

2.59.0-r0

Status

Pending upstream fix

Impact

Bumping the requests package to the fixed version (v2.32.0) was attempted upstream (https://github.com/apache/beam/pull/31355) and checks are failing. According to sdks/python/setup.py#L388 (which references https://github.com/docker/docker-py/pull/3257), this is because requests@v2.32.0 breaks compatibility with docker.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing