CVE-2025-0167
LowAdvisory
Published 5 Feb 2025In the index since 5 Sept 2026
- Severity
- Low
- worst across findings
- CVSS
- 3.4
- base score, highest
- EPSS
- 0.007
- 51st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 644
- of 17,787 indexed, latest versions
- Container images
- 643
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 644 of 17,787 indexed charts deploy, on 643 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 7.81.0-1ubuntu1.2, 7.81.0-1ubuntu1.3, 7.81.0-1ubuntu1.4, 7.81.0-1ubuntu1.6+25 more | 7.81.0-1ubuntu1.23, 7.88.1-10+deb12u11, 8.5.0-2ubuntu10.8 | 422 |
| curlapk | 8.0.1-r2, 8.1.0-r0, 8.1.1-r1, 8.1.2-r0+15 more | 8.12.0-r0 | 221 |
- OSV records
- ALPINE-CVE-2025-0167CGA-3rm4-qmc7-26hxDEBIAN-CVE-2025-0167UBUNTU-CVE-2025-0167
- Also known as
- CGA-j39x-f5qx-6xh3, USN-8084-1
Charts affected
644 by stars
Container images carrying it
643 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 9d01bf9c9224 | curl | 8.5.0-2ubuntu10.8 | 1 |
| ghcr.io/ | a56dfe91f5b1 | curl | 7.81.0-1ubuntu1.23 | 1 |
| ghcr.io/ | 916746209ac5 | curl | 7.81.0-1ubuntu1.23 | 1 |
| ghcr.io/ | 63873f3f698e | curl | 7.81.0-1ubuntu1.23 | 1 |
| ghcr.io/ | a3c27ee3fb2f | curl | 7.88.1-10+deb12u11 | 1 |
| ghcr.io/ | dbaa8527bf4c | curl | 7.88.1-10+deb12u11 | 1 |
| ghcr.io/ | d19d886d5090 | curl | 7.88.1-10+deb12u11 | 1 |
| ghcr.io/ | e0f2f8c97598 | curl | 7.81.0-1ubuntu1.23 | 1 |
| ghcr.io/ | 5a6fe78d4d15 | curl | 7.88.1-10+deb12u11 | 1 |
| ghcr.io/ | bf5983d754d7 | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | 4f40cfc2283b | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | d81cda253f5c | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | 92ac2f97978e | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | fbba58ddb1a6 | curl | 7.88.1-10+deb12u11 | 1 |
| ghcr.io/ | 416e980f76a6 | curl | 7.88.1-10+deb12u11 | 1 |
| ghcr.io/ | 7dc0ee57b628 | curl | 7.88.1-10+deb12u11 | 1 |
| public.ecr.aws/ | 1ed844ecab29 | curl | 8.5.0-2ubuntu10.8 | 1 |
| public.ecr.aws/ | ee9d973e3952 | curl | 7.81.0-1ubuntu1.23 | 1 |
| public.ecr.aws/ | b1493760c716 | curl | 7.88.1-10+deb12u11 | 1 |
| public.ecr.aws/ | 34823c8abe00 | curl | 7.88.1-10+deb12u11 | 1 |
| public.ecr.aws/ | 5cd62142d6ed | curl | 7.88.1-10+deb12u11 | 1 |
| public.ecr.aws/ | f8fb4eea4071 | curl | 7.88.1-10+deb12u11 | 1 |
| public.ecr.aws/ | 046ef5c9ed50 | curl | 7.88.1-10+deb12u11 | 1 |
| public.ecr.aws/ | f7567ce3419d | curl | 7.88.1-10+deb12u11 | 1 |
| public.ecr.aws/ | 86380a01587d | curl | 8.5.0-2ubuntu10.8 | 1 |
| public.ecr.aws/ | f74851ce31f5 | curl | 7.88.1-10+deb12u11 | 1 |
| quay.io/ | 578934444f04 | curl | 7.81.0-1ubuntu1.23 | 1 |
| quay.io/ | 5b6701d8fb31 | curl | 7.81.0-1ubuntu1.23 | 1 |
| quay.io/ | 95b5cf7ba6fe | curl | 8.5.0-2ubuntu10.8 | 1 |
| quay.io/ | a36ab0c0860c | curl | 8.5.0-2ubuntu10.8 | 1 |
| quay.io/ | acaf37352569 | curl | 7.81.0-1ubuntu1.23 | 1 |
| quay.io/ | fe2e2e5a2751 | curl | 8.12.0-r0 | 1 |
| quay.io/ | 60950ef63764 | curl | 7.81.0-1ubuntu1.23 | 1 |
| quay.io/ | d53cb940196c | curl | 8.12.0-r0 | 1 |
| quay.io/ | 93889c3d8a34 | curl | 7.81.0-1ubuntu1.23 | 1 |
| quay.io/ | e0d9b93dbf2b | curl | 7.88.1-10+deb12u11 | 1 |
| quay.io/ | 8c8d08b95c0b | curl | 8.12.0-r0 | 1 |
| registry.k8s.io/ | fd9722fd02e3 | curl | 7.88.1-10+deb12u11 | 1 |
| registry.k8s.io/ | 42b3f0e5d084 | curl | 8.12.0-r0 | 1 |
| registry.k8s.io/ | 744ae2afd433 | curl | 8.12.0-r0 | 1 |
| registry.k8s.io/ | d56f135b6462 | curl | 8.12.0-r0 | 1 |
| registry.k8s.io/ | e24f39d3eed6 | curl | 8.12.0-r0 | 1 |
| registry.k8s.io/ | e6b8de175acd | curl | 8.12.0-r0 | 1 |