StackRadar

CVE-2025-0665

High

Advisory

Published 5 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.0
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
233
of 17,781 indexed, latest versions
Container images
222
deployed by those charts
Fix available
2 of 2
affected packages

curl-8.12.1-1.1 on GA media

Carried by container images the latest versions of 233 of 17,781 indexed charts deploy, on 222 images.

Affected packageAffected versionsFixed inImages
curlapk8.0.1-r2, 8.1.0-r0, 8.1.1-r1, 8.1.2-r0+15 more8.12.0-r0220
curlrpm7.60.0-lp151.5.6.18.12.1-1.12
OSV records
ALPINE-CVE-2025-0665CGA-fr6q-jchj-fq9ropenSUSE-SU-2025:14809-1
Also known as
CGA-mcvh-pjq3-m6h6

Charts affected

233 by stars
ChartLatestAffected imagesRadar Score
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
curl@8.8.0-r0
8.12.0-r0

Open the chart page →

2,429
commonground-gatewayskeleton-pip0.1.71 of 5See more

commonground-gateway skeleton-pip 0.1.7

1 of the 5 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-nginx:latestb72cf734d85f
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

2,825
mimirskyloud-helm-chartsVerified publisher5.5.11 of 5See more

mimir skyloud-helm-charts 5.5.1

1 of the 5 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.25-alpine8265b1df5a89
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

10,651
snspingsnsping1.2.91 of 1See more

snsping snsping 1.2.9

1 of the 1 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
udhos/snsping:1.2.96ae70677b6a3
curl@8.11.1-r0
8.12.0-r0

Open the chart page →

1,326
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

2,416
flowssqream-chartsVerified publisher0.6.21 of 3See more

flows sqream-charts 0.6.2

1 of the 3 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
alpine/curl:8.7.1f0c1b7ca12f6
curl@8.7.1-r0
8.12.0-r0

Open the chart page →

655
umbrellasqream-chartsVerified publisher0.1.811 of 18See more

umbrella sqream-charts 0.1.81

1 of the 18 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
alpine/curl:8.7.1f0c1b7ca12f6
curl@8.7.1-r0
8.12.0-r0

Open the chart page →

655
ingress-nginx-external-lbsuminhong1.0.01 of 2See more

ingress-nginx-external-lb suminhong 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

2,094
ingress-nginxsvtech-public-helm-charts1.0.01 of 1See more

ingress-nginx svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
curl@8.4.0-r0
8.12.0-r0

Open the chart page →

1,480
snmp-managersvtech-public-helm-charts1.1.01 of 1See more

snmp-manager svtech-public-helm-charts 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
svtechnmaa/svtech_snmp_manager:v1.0.18e8abe71a46d
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

761
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

2,336
synadia-serversynadiaVerified publisher1.1.101 of 2See more

synadia-server synadia 1.1.10

1 of the 2 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
curl@8.4.0-r0
8.12.0-r0

Open the chart page →

1,970
temporaltemporal0.28.93 of 13See more

temporal temporal 0.28.9

3 of the 13 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
curl@8.2.0-r1
8.12.0-r0
temporalio/server:1.22.0ddeebf8bad8f
curl@8.2.0-r1
8.12.0-r0
temporalio/ui:2.16.2af9c9349708f
curl@8.1.2-r0
8.12.0-r0

Open the chart page →

21,005
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
carlosmz87/test_helm_frontend:latest79f4b528f42a
curl@8.11.0-r2
8.12.0-r0

Open the chart page →

11,648
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
opea/chatqna-conversation-ui:1.002d5674ca863
curl@8.9.1-r1
8.12.0-r0

Open the chart page →

39,090
chatqna-uitest-opea0.9.01 of 1See more

chatqna-ui test-opea 0.9.0

1 of the 1 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
opea/chatqna-conversation-ui:v0.9bdb9ec215872
curl@8.9.0-r0
8.12.0-r0

Open the chart page →

921
uitest-opea1.0.01 of 1See more

ui test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
opea/chatqna-conversation-ui:1.002d5674ca863
curl@8.9.1-r1
8.12.0-r0

Open the chart page →

755
node-redthl-chartsVerified publisher0.1.01 of 1See more

node-red thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
nodered/node-red:3.0.2-18e2632a7a35dd
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

2,806
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

2,477
posteetrivy-operator2.14.01 of 3See more

postee trivy-operator 2.14.0

1 of the 3 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
curl@8.1.2-r0
8.12.0-r0

Open the chart page →

4,815
demo-frontendv2flyVerified publisher0.0.31 of 1See more

demo-frontend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
quay.io/yushiwho/sys-stats:e1f9d778c8d08b95c0b
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

753
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
curl@8.9.0-r0
8.12.0-r0

Open the chart page →

4,303
vote-appvote-appVerified publisher1.0.72 of 6See more

vote-app vote-app 1.0.7

2 of the 6 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
curl@8.7.1-r0
8.12.0-r0
thecloudspark/app-vote:1.0c7da7417a86a
curl@8.7.1-r0
8.12.0-r0

Open the chart page →

3,031
wallarm-ingress-rcwallarmVerified publisher4.8.41 of 2See more

wallarm-ingress-rc wallarm 4.8.4

1 of the 2 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
wallarm/ingress-controller:4.8.0-1a591b9c91570
curl@8.4.0-r0
8.12.0-r0

Open the chart page →

2,635
consulwarjiang1.3.01 of 2See more

consul warjiang 1.3.0

1 of the 2 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
hashicorp/consul:1.17.0712fe02d2f84
curl@8.4.0-r0
8.12.0-r0

Open the chart page →

4,060
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
datawire/emissary:3.12.21f67a1292d2a
curl@8.9.1-r1
8.12.0-r0

Open the chart page →

10,843
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
curl@8.9.0-r0
8.12.0-r0

Open the chart page →

2,634
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
dwdraju/alpine-curl-jq:latest83bd9be2b14b
curl@8.9.1-r1
8.12.0-r0

Open the chart page →

6,285
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
curl@8.11.1-r0
8.12.0-r0

Open the chart page →

1,286
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
curl@8.10.1-r0
8.12.0-r0

Open the chart page →

13,677
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
curl@8.11.1-r0
8.12.0-r0

Open the chart page →

9,381
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

1,611
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0665.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

1,589

Container images carrying it

222 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
curl@8.5.0-r0
8.12.0-r0
1
kfirfer/mysql-client:0.0.4d23d173f333f
curl@8.5.0-r0
8.12.0-r0
1
kubeshop/testkube-dashboard:1.16.748958b4126a4
curl@8.5.0-r0
8.12.0-r0
1
kubesphere/kubectl:v1.27.1649b445b1b732
curl@8.9.0-r0
8.12.0-r0
1
kubestar/event-exporter:latest656606941255
curl@8.5.0-r0
8.12.0-r0
1
kubevirtmanager/kubevirt-manager:1.3.3df3ea27d4a9e
curl@8.5.0-r0
8.12.0-r0
1
leantime/leantime:3.3.3ad4bfb0699d3
curl@8.11.0-r2
8.12.0-r0
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
curl@8.10.1-r0
8.12.0-r0
1
library/docker:26.1-dinddd43b430341a
curl@8.8.0-r0
8.12.0-r0
1
library/influxdb:2.7.4-alpinea10d46445d68
curl@8.4.0-r0
8.12.0-r0
1
library/nginx:1.25.4-alpine31bad00311cb
curl@8.5.0-r0
8.12.0-r0
1
librenms/librenms:24.11.00920bc9117a8
curl@8.9.1-r1
8.12.0-r0
1
linuxserver/grocy:4.0.1f8f5f96b6ea8
curl@8.2.1-r0
8.12.0-r0
1
linuxserver/openssh-server:9.7_p1-r4-ls17153ea39d2485c
curl@8.9.1-r2
8.12.0-r0
1
linuxserver/yq:3.2.26f5b9586a93e
curl@8.2.1-r0
8.12.0-r0
1
mathieuruellan/piwigo:latest04572c8a1b04
curl@8.11.0-r2
8.12.0-r0
1
natsio/nats-box:0.14.31cc420186664
curl@8.5.0-r0
8.12.0-r0
1
natsio/nats-box:0.14.2e808e0644ce1
curl@8.5.0-r0
8.12.0-r0
1
nginxinc/nginx-unprivileged:1.25-alpine8265b1df5a89
curl@8.5.0-r0
8.12.0-r0
1
nginxinc/nginx-unprivileged8f14986c54fa
curl@8.5.0-r0
8.12.0-r0
1
nodered/node-red:3.0.2-18e2632a7a35dd
curl@8.5.0-r0
8.12.0-r0
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
curl@8.10.1-r0
8.12.0-r0
1
opea/chatqna-conversation-ui:v0.9bdb9ec215872
curl@8.9.0-r0
8.12.0-r0
1
openmined/syft-seaweedfs:0.9.53a4144c0bb82
curl@8.5.0-r0
8.12.0-r0
1
openruntimes/executor:0.11.42228f186dcbb
curl@8.9.1-r0
8.12.0-r0
1
phntom/chartmuseum:v0.16.053883b65d9b7
curl@8.2.0-r1
8.12.0-r0
1
phpipam/phpipam-cron:v1.7.354468713454e
curl@8.11.0-r2
8.12.0-r0
1
phpipam/phpipam-www:v1.7.3ace0efd24830
curl@8.11.0-r2
8.12.0-r0
1
pnnlmiscscripts/k8s-node-image:1.22.17-nginx-362b3ae9b5ec25
curl@8.5.0-r0
8.12.0-r0
1
pnnlmiscscripts/k8s-node-image:1.24.17-nginx-23952d87cca3d2
curl@8.5.0-r0
8.12.0-r0
1
pnnlmiscscripts/k8s-node-image:1.23.17-nginx-36a5ee1dea30e4
curl@8.5.0-r0
8.12.0-r0
1
pnnlmiscscripts/k8s-node-image:1.21.14-nginx-36c19a40d7435d
curl@8.5.0-r0
8.12.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.28.15-nginx-72b91d6a46e06
curl@8.9.1-r1
8.12.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.25.16-nginx-772c202c43c0aa
curl@8.9.1-r1
8.12.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.24.17-nginx-882c8dc938b2f9
curl@8.9.1-r1
8.12.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.27.16-nginx-306e1a36d646a3
curl@8.9.1-r1
8.12.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.26.15-nginx-579785e5b82334
curl@8.9.1-r1
8.12.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.29.10-nginx-7fcd82530bc8b
curl@8.9.1-r1
8.12.0-r0
1
postgis/postgis:15-3.3-alpine4738bee21eb6
curl@8.2.1-r0
8.12.0-r0
1
postgis/postgis:17-3.4-alpine5a1dbedac34e
curl@8.10.1-r0
8.12.0-r0
1
psono/psono-server:5.0.03b974b43ea03
curl@8.10.1-r0
8.12.0-r0
1
qbittorrentofficial/qbittorrent-nox:4.6.3-12b86d9c356ae
curl@8.5.0-r0
8.12.0-r0
1
replicated/replicated-sdk:1.0.0-beta.318751b4963250
curl@8.10.1-r1
8.12.0-r0
1
robustadev/kubewatch:v2.9.00457a51e36e8
curl@8.10.1-r0
8.12.0-r0
1
rss3/proxyd:6edce9ddfeee0b00a2d98f24c3ce67885653651b865a0a6bdf4c
curl@8.5.0-r0
8.12.0-r0
1
rss3/proxyd:d2c5ced00901227473fc196fda838191f0cb4e028d9a44c650fa
curl@8.5.0-r0
8.12.0-r0
1
sealio/hermitcrab:v0.1.4a326a2f03660
curl@8.5.0-r0
8.12.0-r0
1
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
curl@8.5.0-r0
8.12.0-r0
1
semaphoreui/semaphore:v2.9.645b50bc11833f
curl@8.5.0-r0
8.12.0-r0
1
sky5367/locust-plugins-grafana:latestd51bf68d4b26
curl@8.5.0-r0
8.12.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.