CVE-2025-0725
HighAdvisory
Published 5 Feb 2025In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.3
- base score, highest
- EPSS
- 0.013
- 68th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 627
- of 17,787 indexed, latest versions
- Container images
- 630
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 627 of 17,787 indexed charts deploy, on 630 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4, 7.88.1-10+deb12u5+7 more | no fix listed | 409 |
| curlapk | 8.0.1-r2, 8.1.0-r0, 8.1.1-r1, 8.1.2-r0+15 more | 8.12.0-r0 | 221 |
- OSV records
- ALPINE-CVE-2025-0725CGA-jjpm-f2w8-c9gxDEBIAN-CVE-2025-0725
- Also known as
- CGA-v6vj-5785-7c37
Charts affected
627 by stars
Container images carrying it
630 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 5889bea38e56 | curl | no fix listed | 1 |
| ghcr.io/ | 8766ba08bf1a | curl | no fix listed | 1 |
| ghcr.io/ | aa7831e207cd | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | 72f35584026d | curl | no fix listed | 1 |
| ghcr.io/ | 835b72878606 | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | ca7dc7362968 | curl | no fix listed | 1 |
| ghcr.io/ | 0e99f12bb040 | curl | no fix listed | 1 |
| ghcr.io/ | a058034ca006 | curl | no fix listed | 1 |
| ghcr.io/ | 41177982c584 | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | 8d943799621b | curl | no fix listed | 1 |
| ghcr.io/ | 726a947bb65b | curl | no fix listed | 1 |
| ghcr.io/ | 16fda01ae58a | curl | no fix listed | 1 |
| ghcr.io/ | 5c85f2b82064 | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | cc9498b64b5b | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | a8d40779eeae | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | 5a9216989707 | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | 5c47ef99443a | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | 8ac53eb38393 | curl | no fix listed | 1 |
| ghcr.io/ | 96c25035cb02 | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | a982103d91d3 | curl | no fix listed | 1 |
| ghcr.io/ | 6e82914e1051 | curl | no fix listed | 1 |
| ghcr.io/ | 2d15d14b201a | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | 22ae556e0de4 | curl | no fix listed | 1 |
| ghcr.io/ | 78a82d810709 | curl | no fix listed | 1 |
| ghcr.io/ | ab40c1745534 | curl | no fix listed | 1 |
| ghcr.io/ | 70453d7102cc | curl | no fix listed | 1 |
| ghcr.io/ | ebcf66281fc1 | curl | no fix listed | 1 |
| ghcr.io/ | ab535d1fef5d | curl | no fix listed | 1 |
| ghcr.io/ | 1fd90a9e4d04 | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | a5c1daef46c0 | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | 472a25038957 | curl | no fix listed | 1 |
| ghcr.io/ | feffc0b8227d | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | 66db77d7856c | curl | no fix listed | 1 |
| ghcr.io/ | ad950d30878e | curl | no fix listed | 1 |
| ghcr.io/ | a752b6aee537 | curl | no fix listed | 1 |
| ghcr.io/ | 8e53861be292 | curl | no fix listed | 1 |
| ghcr.io/ | 984dc4f19162 | curl | no fix listed | 1 |
| ghcr.io/ | b069e4307dec | curl | no fix listed | 1 |
| ghcr.io/ | c6fe64c7bfcd | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | b5ade0d9cc6b | curl | no fix listed | 1 |
| ghcr.io/ | ca51b6bb15dd | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | ed86db9f0efe | curl | no fix listed | 1 |
| ghcr.io/ | 0664c28a039b | curl | no fix listed | 1 |
| ghcr.io/ | 5dfa86b6451f | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | b69bcdaa8492 | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | 45e744fc623f | curl | 8.12.0-r0 | 1 |
| ghcr.io/ | c6ab95ca9130 | curl | no fix listed | 1 |
| ghcr.io/ | 3522e8a7a8f0 | curl | no fix listed | 1 |
| ghcr.io/ | 50666a6f8d7f | curl | no fix listed | 1 |
| ghcr.io/ | eef3ee7810d0 | curl | no fix listed | 1 |