StackRadar

CVE-2025-0725

High

Advisory

Published 5 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
627
of 17,787 indexed, latest versions
Container images
630
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 627 of 17,787 indexed charts deploy, on 630 images.

Affected packageAffected versionsFixed inImages
curldeb7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4, 7.88.1-10+deb12u5+7 moreno fix listed409
curlapk8.0.1-r2, 8.1.0-r0, 8.1.1-r1, 8.1.2-r0+15 more8.12.0-r0221
OSV records
ALPINE-CVE-2025-0725CGA-jjpm-f2w8-c9gxDEBIAN-CVE-2025-0725
Also known as
CGA-v6vj-5785-7c37

Charts affected

627 by stars
ChartLatestAffected imagesRadar Score
mychartpythonweb0.1.01 of 1See more

mychart pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

11,400
mypythonpythonweb0.1.01 of 1See more

mypython pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

11,400
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

7,691
nginx-chartrabsnginx0.1.01 of 1See more

nginx-chart rabsnginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
library/nginx:1.276784fb0834aa
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

4,117
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

20,812
app-config-frontendradar-baseVerified publisher2.4.11 of 1See more

app-config-frontend radar-base 2.4.1

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-app-config/radar-app-config-frontend:0.6.2c5f1e2ca5781
curl@8.11.1-r0
8.12.0-r0

Open the chart page →

807
kubecostradar-baseVerified publisher1.0.01 of 7See more

kubecost radar-base 1.0.0

1 of the 7 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
curl@8.11.0-r2
8.12.0-r0

Open the chart page →

9,389
radar-homeradar-baseVerified publisher0.5.51 of 1See more

radar-home radar-base 0.5.5

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-home/radar-home:0.1.71cfe3da9d812
curl@8.11.1-r0
8.12.0-r0

Open the chart page →

807
radar-rest-sources-authorizerradar-baseVerified publisher2.3.41 of 1See more

radar-rest-sources-authorizer radar-base 2.3.4

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-rest-source-auth/radar-rest-source-authorizer:4.4.153e096497f7db
curl@8.11.1-r0
8.12.0-r0

Open the chart page →

807
radar-s3-connectorradar-baseVerified publisher0.7.21 of 2See more

radar-s3-connector radar-base 0.7.2

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
linuxserver/yq:3.2.26f5b9586a93e
curl@8.2.1-r0
8.12.0-r0

Open the chart page →

1,415
esphomeretsamedocVerified publisher2026.2.51 of 1See more

esphome retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
esphome/esphome:2024.3.09ab8cc88b28c
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

6,562
juicepassproxyretsamedocVerified publisher2026.2.41 of 1See more

juicepassproxy retsamedoc 2026.2.4

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

3,753
istio-helloworldrgnu1.0.12 of 2See more

istio-helloworld rgnu 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
istio/examples-helloworld-v1:latest328b237e4fb1
curl@7.88.1-10+deb12u5
no fix listed
istio/examples-helloworld-v2:latest0a7f02b2c7c9
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

8,298
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

15,623
krr-enforcerrobusta0.3.51 of 2See more

krr-enforcer robusta 0.3.5

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
alpine/k8s:1.30.0bd01dae02676
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

4,039
kubewatchrobusta3.5.01 of 1See more

kubewatch robusta 3.5.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
robustadev/kubewatch:v2.9.00457a51e36e8
curl@8.10.1-r0
8.12.0-r0

Open the chart page →

1,821
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

9,275
rocketchat-voiprocketchat-server0.1.01 of 1See more

rocketchat-voip rocketchat-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
rocketchat/freeswitch:stablecfba5c20a5cc
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

5,329
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

9,152
devtron-enterpriseromholdings48.0.02 of 28See more

devtron-enterprise romholdings 48.0.0

2 of the 28 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
curl@7.88.1-10+deb12u4
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

66,542
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
curl@7.88.1-10+deb12u4
no fix listed

Open the chart page →

31,447
chainrss30.1.282 of 8See more

chain rss3 0.1.28

2 of the 8 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
curl@8.5.0-r0
8.12.0-r0
rss3/proxyd:d2c5ced00901227473fc196fda838191f0cb4e028d9a44c650fa
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

8,528
proxydrss30.1.01 of 1See more

proxyd rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
rss3/proxyd:6edce9ddfeee0b00a2d98f24c3ce67885653651b865a0a6bdf4c
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

2,110
vsl-rpcrss30.3.41 of 4See more

vsl-rpc rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

4,611
vsl-sequencerrss30.3.41 of 4See more

vsl-sequencer rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

4,611
flaresolverrrubxkubeVerified publisher0.1.11 of 1See more

flaresolverr rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

27,282
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

29,870
your-spotifyrubxkubeVerified publisher1.0.11 of 3See more

your-spotify rubxkube 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:latestb0652af9c8d0
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

4,966
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
curl@7.88.1-10
no fix listed

Open the chart page →

17,736
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
curl@7.88.1-10
no fix listed

Open the chart page →

14,792
sagawisesagawiseVerified publisher0.1.01 of 3See more

sagawise sagawise 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
venturenox/sagawise:latestc11d32f18718
curl@8.11.0-r2
8.12.0-r0

Open the chart page →

4,104
speedtestsantisbon0.1.02 of 3See more

speedtest santisbon 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
curl@7.88.1-10+deb12u14
no fix listed
santisbon/speedtest:latest8ee3a1697227
curl@7.88.1-10+deb12u1
no fix listed

Open the chart page →

11,314
grocysarab97Verified publisher0.1.11 of 1See more

grocy sarab97 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
linuxserver/grocy:4.0.1f8f5f96b6ea8
curl@8.2.1-r0
8.12.0-r0

Open the chart page →

2,448
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

9,340
jellyfinsb-helm-charts0.4.01 of 1See more

jellyfin sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.317c3a8d9dddb
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

3,864
phpmyadminsb-helm-charts0.3.01 of 1See more

phpmyadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

5,065
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

4,559
vaultwardensb-helm-charts0.4.01 of 1See more

vaultwarden sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
vaultwarden/server:1.34.384fd8a47f58d
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

3,210
wordpresssb-helm-charts0.4.01 of 2See more

wordpress sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
library/wordpress:6.4.3-apache8ae66efb09a2
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

12,009
keycloak-webhook-routerschichtelVerified publisher0.1.01 of 1See more

keycloak-webhook-router schichtel 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/pschichtel/keycloak-webhook-router:main285e226fe7f6
curl@8.11.0-r2
8.12.0-r0

Open the chart page →

704
sponge-vanillaschichtelVerified publisher0.1.21 of 1See more

sponge-vanilla schichtel 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/cubeengine/sponge:1.20.2-11.0.0-RC13755c85f2b82064
curl@8.3.0-r0
8.12.0-r0

Open the chart page →

1,009
otterwikischmitzis0.1.01 of 1See more

otterwiki schmitzis 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
redimp/otterwiki:2778bf30da3da
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

3,019
typo3schoolguys-helmcharts0.4.21 of 1See more

typo3 schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

4,630
sealed-secrets-uisealed-secrets-uiVerified publisher0.0.81 of 1See more

sealed-secrets-ui sealed-secrets-ui 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

4,570
hermitcrabseal-ioVerified publisher0.1.42 of 2See more

hermitcrab seal-io 0.1.4

2 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
sealio/hermitcrab:v0.1.4a326a2f03660
curl@8.5.0-r0
8.12.0-r0
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

4,883
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
curl@8.10.1-r0
8.12.0-r0

Open the chart page →

5,499
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

3,336
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

10,972
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
curl@8.2.1-r0
8.12.0-r0

Open the chart page →

2,863
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
curl@8.8.0-r0
8.12.0-r0

Open the chart page →

2,429

Container images carrying it

630 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/zalando/postgres-operator:v1.12.2d81cda253f5c
curl@8.7.1-r0
8.12.0-r0
1
ghcr.io/zazuko/blueprint:v0.1.092ac2f97978e
curl@8.5.0-r0
8.12.0-r0
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
curl@7.88.1-10+deb12u8
no fix listed
1
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
curl@7.88.1-10+deb12u8
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
curl@7.88.1-10+deb12u8
no fix listed
1
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest5a5d32281374
curl@7.88.1-10+deb12u15
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
curl@7.88.1-10+deb12u7
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
curl@7.88.1-10+deb12u7
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
curl@7.88.1-10+deb12u5
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
curl@7.88.1-10+deb12u5
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
curl@7.88.1-10+deb12u4
no fix listed
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
curl@7.88.1-10+deb12u14
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
curl@7.88.1-10+deb12u8
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
curl@7.88.1-10+deb12u5
no fix listed
1
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
curl@8.9.0-r0
8.12.0-r0
1
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
curl@8.1.0-r0
8.12.0-r0
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
curl@7.88.1-10+deb12u15
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
curl@7.88.1-10+deb12u14
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
curl@7.88.1-10+deb12u14
no fix listed
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
curl@7.88.1-10+deb12u15
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
curl@7.88.1-10+deb12u1
no fix listed
1
quay.io/yushiwho/sys-stats:e1f9d778c8d08b95c0b
curl@8.5.0-r0
8.12.0-r0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
curl@7.88.1-10+deb12u14
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
curl@7.88.1-10+deb12u14
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
curl@7.88.1-10+deb12u4
no fix listed
1
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
curl@8.5.0-r0
8.12.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
curl@8.1.1-r1
8.12.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
curl@8.10.1-r0
8.12.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
curl@8.5.0-r0
8.12.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
curl@8.11.1-r0
8.12.0-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.