CVE-2025-0665
HighAdvisory
Published 5 Feb 2025In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.0
- base score, highest
- EPSS
- 0.013
- 69th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 233
- of 17,781 indexed, latest versions
- Container images
- 222
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
curl-8.12.1-1.1 on GA media
Carried by container images the latest versions of 233 of 17,781 indexed charts deploy, on 222 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curlapk | 8.0.1-r2, 8.1.0-r0, 8.1.1-r1, 8.1.2-r0+15 more | 8.12.0-r0 | 220 |
| curlrpm | 7.60.0-lp151.5.6.1 | 8.12.1-1.1 | 2 |
- OSV records
- ALPINE-CVE-2025-0665CGA-fr6q-jchj-fq9ropenSUSE-SU-2025:14809-1
- Also known as
- CGA-mcvh-pjq3-m6h6
Charts affected
233 by stars
Container images carrying it
222 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| pnnlmiscscripts/ | cfbc9b70cbf8 | curl | 8.12.0-r0 | 6 |
| natsio/ | a67913df95f1 | curl | 8.12.0-r0 | 5 |
| ghcr.io/ | b72cf734d85f | curl | 8.12.0-r0 | 5 |
| grafana/ | 0dc5a246ab16 | curl | 8.12.0-r0 | 3 |
| grafana/ | a0f881232a6f | curl | 8.12.0-r0 | 3 |
| library/ | 516475cc129d | curl | 8.12.0-r0 | 3 |
| nginxinc/ | be76a26e238d | curl | 8.12.0-r0 | 3 |
| rcdelacruz/ | 38007f358355 | curl | 8.12.0-r0 | 3 |
| rss3/ | d1d2ae6efd05 | curl | 8.12.0-r0 | 3 |
| quay.io/ | fd916f75415f | curl | 8.12.0-r0 | 3 |
| registry.k8s.io/ | e5c4824e7375 | curl | 8.12.0-r0 | 3 |
| alpine/ | f0c1b7ca12f6 | curl | 8.12.0-r0 | 2 |
| chatwoot/ | d530ab8c1753 | curl | 8.12.0-r0 | 2 |
| dtzar/ | 55429449408e | curl | 8.12.0-r0 | 2 |
| ethersphere/ | 0558799ca992 | curl | 8.12.0-r0 | 2 |
| grafana/ | 079600c9517b | curl | 8.12.0-r0 | 2 |
| grafana/ | 886b56d5534e | curl | 8.12.0-r0 | 2 |
| grafana/ | d8ea37798ccc | curl | 8.12.0-r0 | 2 |
| hazelcast/ | 5dd5d31c7a06 | curl | 8.12.0-r0 | 2 |
| hoppscotch/ | f1da831950b7 | curl | 8.12.0-r0 | 2 |
| lightninglabs/ | f86bbec4dfb3 | curl | 8.12.0-r0 | 2 |
| linuxserver/ | 9932d6759112 | curl | 8.12.0-r0 | 2 |
| opea/ | 02d5674ca863 | curl | 8.12.0-r0 | 2 |
| organizr/ | 1ce319d73cdf | curl | 8.12.0-r0 | 2 |
| temporalio/ | c0a44c26397b | curl | 8.12.0-r0 | 2 |
| temporalio/ | af9c9349708f | curl | 8.12.0-r0 | 2 |
| registry.k8s.io/ | 5b161f051d01 | curl | 8.12.0-r0 | 2 |
| registry.k8s.io/ | b3aba22b1da8 | curl | 8.12.0-r0 | 2 |
| alpine/ | 513c4f0d7123 | curl | 8.12.0-r0 | 1 |
| alpine/ | 105741fa6621 | curl | 8.12.0-r0 | 1 |
| alpine/ | 21b24e6bf801 | curl | 8.12.0-r0 | 1 |
| alpine/ | 9c4976d47656 | curl | 8.12.0-r0 | 1 |
| alpine/ | bd01dae02676 | curl | 8.12.0-r0 | 1 |
| alpine/ | cd560fce90f7 | curl | 8.12.0-r0 | 1 |
| alpine/ | e5c0b053fed7 | curl | 8.12.0-r0 | 1 |
| alpine/ | fc059f056ad0 | curl | 8.12.0-r0 | 1 |
| andrcuns/ | b4a8eb20581a | curl | 8.12.0-r0 | 1 |
| aquasec/ | 6e790e233872 | curl | 8.12.0-r0 | 1 |
| aquasec/ | 0795cba777e7 | curl | 8.12.0-r0 | 1 |
| aquasec/ | 944a04445179 | curl | 8.12.0-r0 | 1 |
| carlosmz87/ | 79f4b528f42a | curl | 8.12.0-r0 | 1 |
| casbin/ | 770ad9ec3190 | curl | 8.12.0-r0 | 1 |
| cfcontainerization/ | 82fa261c18a8 | curl | 8.12.1-1.1 | 1 |
| cfcontainerization/ | 58fb1c173a46 | curl | 8.12.1-1.1 | 1 |
| cgtysylr/ | aec0f8a38a77 | curl | 8.12.0-r0 | 1 |
| clsen2024/ | 1156cd87c8fb | curl | 8.12.0-r0 | 1 |
| clsen2024/ | 0ba9eff852c5 | curl | 8.12.0-r0 | 1 |
| clsen2024/ | 51b1d45961cd | curl | 8.12.0-r0 | 1 |
| clsen2024/ | efb1586c8299 | curl | 8.12.0-r0 | 1 |
| codecov/ | 0475cb1c3136 | curl | 8.12.0-r0 | 1 |