StackRadar

CVE-2025-0725

High

Advisory

Published 5 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
627
of 17,787 indexed, latest versions
Container images
630
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 627 of 17,787 indexed charts deploy, on 630 images.

Affected packageAffected versionsFixed inImages
curldeb7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4, 7.88.1-10+deb12u5+7 moreno fix listed409
curlapk8.0.1-r2, 8.1.0-r0, 8.1.1-r1, 8.1.2-r0+15 more8.12.0-r0221
OSV records
ALPINE-CVE-2025-0725CGA-jjpm-f2w8-c9gxDEBIAN-CVE-2025-0725
Also known as
CGA-v6vj-5785-7c37

Charts affected

627 by stars
ChartLatestAffected imagesRadar Score
opencloudunxwaresVerified publisher0.2.36 of 13See more

opencloud unxwares 0.2.3

6 of the 13 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
curl@7.88.1-10+deb12u8
no fix listed
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
curl@7.88.1-10+deb12u8
no fix listed
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
curl@7.88.1-10+deb12u8
no fix listed
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
curl@7.88.1-10+deb12u8
no fix listed
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
curl@7.88.1-10+deb12u8
no fix listed
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

45,392
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
curl@7.88.1-10+deb12u1
no fix listed

Open the chart page →

14,383
demo-frontendv2flyVerified publisher0.0.31 of 1See more

demo-frontend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
quay.io/yushiwho/sys-stats:e1f9d778c8d08b95c0b
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

753
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

4,394
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
curl@8.9.0-r0
8.12.0-r0

Open the chart page →

4,302
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

10,801
vote-appvote-appVerified publisher1.0.72 of 6See more

vote-app vote-app 1.0.7

2 of the 6 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
curl@8.7.1-r0
8.12.0-r0
thecloudspark/app-vote:1.0c7da7417a86a
curl@8.7.1-r0
8.12.0-r0

Open the chart page →

3,030
api-gatewaywallarmVerified publisher0.2.01 of 1See more

api-gateway wallarm 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
wallarm/api-gateway:0.2.0a3d4d2f780e8
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

2,300
wallarm-ingress-rcwallarmVerified publisher4.8.41 of 2See more

wallarm-ingress-rc wallarm 4.8.4

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
wallarm/ingress-controller:4.8.0-1a591b9c91570
curl@8.4.0-r0
8.12.0-r0

Open the chart page →

2,635
consulwarjiang1.3.01 of 2See more

consul warjiang 1.3.0

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
hashicorp/consul:1.17.0712fe02d2f84
curl@8.4.0-r0
8.12.0-r0

Open the chart page →

4,059
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

5,774
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

6,540
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
curl@7.88.1-10
no fix listed

Open the chart page →

8,858
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
datawire/emissary:3.12.21f67a1292d2a
curl@8.9.1-r1
8.12.0-r0

Open the chart page →

10,857
giteawenerme12.7.01 of 4See more

gitea wenerme 12.7.0

1 of the 4 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

8,842
hazelcastwenerme5.10.31 of 2See more

hazelcast wenerme 5.10.3

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
curl@8.9.0-r0
8.12.0-r0

Open the chart page →

2,623
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

8,824
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

7,643
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
dwdraju/alpine-curl-jq:latest83bd9be2b14b
curl@8.9.1-r1
8.12.0-r0

Open the chart page →

6,323
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

5,548
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
curl@8.11.1-r0
8.12.0-r0

Open the chart page →

1,286
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

2,383
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

7,685
xkopsxkops0.1.02 of 5See more

xkops xkops 0.1.0

2 of the 5 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
curl@8.10.1-r0
8.12.0-r0
murtazashah46/helmfile:latest4d11726cf803
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

13,197
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
curl@8.11.1-r0
8.12.0-r0

Open the chart page →

9,381
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

1,610
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

1,588

Container images carrying it

630 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
supabase/studio:latest94a2a9d2906e
curl@7.88.1-10+deb12u15
no fix listed
1
supermq/vernemq:latest944a0be3563e
curl@8.5.0-r0
8.12.0-r0
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
curl@7.88.1-10+deb12u5
no fix listed
1
svtechnmaa/svtech_snmp_manager:v1.0.18e8abe71a46d
curl@8.5.0-r0
8.12.0-r0
1
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
curl@8.5.0-r0
8.12.0-r0
1
swaggerapi/swagger-ui:v5.6.2342808e22de4
curl@8.2.1-r0
8.12.0-r0
1
sysnet4admin/colosseum-cms:loge74b43c7f492
curl@7.88.1-10+deb12u12
no fix listed
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
curl@7.88.1-10+deb12u12
no fix listed
1
teknas09/bird-pod:latest12a1fa85c4aa
curl@7.88.1-10+deb12u5
no fix listed
1
temporalio/admin-tools:1.22.4258958fe2ff2
curl@8.4.0-r0
8.12.0-r0
1
temporalio/admin-tools:1.26.237e2e33dbd7b
curl@8.9.1-r2
8.12.0-r0
1
temporalio/admin-tools:1.22.0836af062af30
curl@8.2.0-r1
8.12.0-r0
1
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
curl@8.5.0-r0
8.12.0-r0
1
temporalio/server:1.26.21e2626efcbc1
curl@8.9.1-r2
8.12.0-r0
1
temporalio/server:1.25.08a5798191dea
curl@8.5.0-r0
8.12.0-r0
1
temporalio/server:1.22.0ddeebf8bad8f
curl@8.2.0-r1
8.12.0-r0
1
temporalio/ui:2.30.25c2a3645d09c
curl@8.5.0-r0
8.12.0-r0
1
temporalio/ui:2.33.05c586a3c8ec5
curl@8.5.0-r0
8.12.0-r0
1
thecloudspark/app-result:1.09a5302cb8312
curl@8.7.1-r0
8.12.0-r0
1
thecloudspark/app-vote:1.0c7da7417a86a
curl@8.7.1-r0
8.12.0-r0
1
theradius/loggia:0.463ba348546ec
curl@7.88.1-10+deb12u5
no fix listed
1
thesisrobot/lnd:v0.16.4-beta-c287129953689
curl@8.3.0-r0
8.12.0-r0
1
thingsboard/toolbox:1.13.01bd61a0da6d3
curl@8.9.1-r1
8.12.0-r0
1
thongngo3301/stakefish:latesta341af5976e3
curl@7.88.1-10+deb12u1
no fix listed
1
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
curl@8.5.0-r0
8.12.0-r0
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
curl@7.88.1-10+deb12u8
no fix listed
1
udhos/forward:1.1.312e120d39fdb
curl@8.1.2-r0
8.12.0-r0
1
udhos/lambdaping:1.0.46bd2cf2ac732
curl@8.11.1-r0
8.12.0-r0
1
udhos/miniapi:1.3.28a7042db82ce
curl@8.10.1-r0
8.12.0-r0
1
udhos/snsping:1.2.96ae70677b6a3
curl@8.11.1-r0
8.12.0-r0
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
curl@7.88.1-10+deb12u12
no fix listed
1
vaultwarden/server:1.34.384fd8a47f58d
curl@7.88.1-10+deb12u12
no fix listed
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
curl@7.88.1-10+deb12u12
no fix listed
1
venturenox/sagawise:latestc11d32f18718
curl@8.11.0-r2
8.12.0-r0
1
vlebediantsev/notes-admin-front:latest007c6670ff48
curl@7.88.1-10+deb12u1
no fix listed
1
vlebediantsev/notes-project-front:latest945675fd2636
curl@7.88.1-10+deb12u1
no fix listed
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
curl@7.88.1-10+deb12u1
no fix listed
1
wallarm/api-gateway:0.2.0a3d4d2f780e8
curl@7.88.1-10+deb12u14
no fix listed
1
wallarm/ingress-controller:4.8.0-1a591b9c91570
curl@8.4.0-r0
8.12.0-r0
1
wiktorn/overpass-api:latest9bb5f4a9b54c
curl@7.88.1-10+deb12u15
no fix listed
1
wmbusmeters/wmbusmeters:release-1.18.0d82715d9ae22
curl@8.11.0-r2
8.12.0-r0
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
curl@7.88.1-10+deb12u6
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
curl@7.88.1-10+deb12u6
no fix listed
1
zepai/knowledge-graph-mcp:v0.2.16ab0ee79926b
curl@7.88.1-10+deb12u12
no fix listed
1
gcr.io/kubecost1/frontend:prod-1.108.14c6df805bbf2
curl@8.5.0-r0
8.12.0-r0
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
curl@7.88.1-10+deb12u7
no fix listed
1
ghcr.io/afairgiant/medikeep:v0.69.0766699daa9ac
curl@7.88.1-10+deb12u15
no fix listed
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
curl@7.88.1-10+deb12u14
no fix listed
1
ghcr.io/appscode/deploy-ui:0.3.6f3e07eff3997
curl@8.11.0-r2
8.12.0-r0
1
ghcr.io/appscode/marketplace-ui:0.3.1d52177072013
curl@8.11.0-r2
8.12.0-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.