/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-xwfv-5pq7-9cgg

Published

Last updated

https://images.chainguard.dev/security/CGA-xwfv-5pq7-9cgg
Package

kserve

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2024-47874
  • GHSA-f96h-pmfr-66vw

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-47874

Updates

Status

Not affected

Justification

Vulnerable code not in execute path

Impact

vulnerable version of Starlette python package used (v0.36.3, fixed is v0.40.0), but no vulnerable functions are used in kserve. The vulnerable DoS attack vector involves a very specific case of functions in the starlette.applications and starlette.routing subpackages, but those are never used in kserve. We cannot simply upgrade to the fixed version because kserve enforces starlette version >=0.37.2,<0.39.0. Waiting on upstream to migrate to fixed versions, but in the meantime, false-positive-determination."

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing