StackRadar

CVE-2025-0725

High

Advisory

Published 5 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
622
of 17,787 indexed, latest versions
Container images
623
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 622 of 17,787 indexed charts deploy, on 623 images.

Affected packageAffected versionsFixed inImages
curldeb7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4, 7.88.1-10+deb12u5+7 moreno fix listed403
curlapk8.0.1-r2, 8.1.0-r0, 8.1.1-r1, 8.1.2-r0+15 more8.12.0-r0220
OSV records
ALPINE-CVE-2025-0725CGA-jjpm-f2w8-c9gxDEBIAN-CVE-2025-0725
Also known as
CGA-v6vj-5785-7c37

Charts affected

622 by stars
ChartLatestAffected imagesRadar Score
stable-hacalltelemetry0.11.41 of 7See more

stable-ha calltelemetry 0.11.4

1 of the 7 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.2e808e0644ce1
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

4,705
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

8,001
httpd-ldapauth-proxycamptocamp31.0.21 of 1See more

httpd-ldapauth-proxy camptocamp3 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
library/httpd:2.4.631ae8051591a5
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

3,311
nginx-s3-gatewaycamptocamp31.0.01 of 1See more

nginx-s3-gateway camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss-202503313db8145349a3
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

5,039
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

10,776
caninecanine0.1.101 of 7See more

canine canine 0.1.10

1 of the 7 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/caninehq/canine:latesta058034ca006
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

14,130
stigatroncarbide-charts0.4.11 of 10See more

stigatron carbide-charts 0.4.1

1 of the 10 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
curl@8.4.0-r0
8.12.0-r0

Open the chart page →

4,423
temporalcastaiVerified publisher0.54.24 of 14See more

temporal castai 0.54.2

4 of the 14 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
curl@8.5.0-r0
8.12.0-r0
temporalio/admin-tools:1.26.237e2e33dbd7b
curl@8.9.1-r2
8.12.0-r0
temporalio/server:1.26.21e2626efcbc1
curl@8.9.1-r2
8.12.0-r0
temporalio/ui:2.33.05c586a3c8ec5
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

16,198
opencvecfi20170.1.21 of 7See more

opencve cfi2017 0.1.2

1 of the 7 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

15,371
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

5,778
arbitrumchronicleVerified publisher0.3.41 of 1See more

arbitrum chronicle 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

6,998
zksyncchronicleVerified publisher0.1.01 of 2See more

zksync chronicle 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
matterlabs/external-node:v24.0.06cbfea4c694a
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

5,982
kamaji-etcdclastixVerified publisher0.17.01 of 4See more

kamaji-etcd clastix 0.17.0

1 of the 4 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
cfssl/cfssl:latestc9018c2ddf0b
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

11,995
galaxy-depscloudve1.1.11 of 7See more

galaxy-deps cloudve 1.1.1

1 of the 7 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

10,531
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

6,162
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

8,009
pbcore-utilcluster-deploy0.0.11 of 1See more

pbcore-util cluster-deploy 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

9,128
cluster-octopuscluster-octopus1.0.01 of 1See more

cluster-octopus cluster-octopus 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
cgtysylr/cluster-octopus:1.0.0aec0f8a38a77
curl@8.11.1-r0
8.12.0-r0

Open the chart page →

1,038
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

3,868
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

13,220
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

5,141
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

5,141
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

5,141
commonground-gatewaycommonground-gateway-frontend0.1.51 of 4See more

commonground-gateway commonground-gateway-frontend 0.1.5

1 of the 4 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-nginx:latestb72cf734d85f
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

2,825
cortezacorteza1.1.01See more

corteza corteza 1.1.0

1 container image this version deploys carries CVE-2025-0725.

Container imageDigestPackageFixed in
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

14,559
mongodbcowboysysopVerified publisher15.1.51 of 1See more

mongodb cowboysysop 15.1.5

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

6,161
piwigocronce0.0.61 of 1See more

piwigo cronce 0.0.6

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
mathieuruellan/piwigo:latest04572c8a1b04
curl@8.11.0-r2
8.12.0-r0

Open the chart page →

1,084
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
cryptexlabs/authf:0.12.11189c07411d7c
curl@8.9.1-r1
8.12.0-r0

Open the chart page →

3,769
iam-zencryptexlabsVerified publisher0.12.231 of 4See more

iam-zen cryptexlabs 0.12.23

1 of the 4 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

3,860
csghubcsghubVerified publisher2.4.36 of 34See more

csghub csghub 2.4.3

6 of the 34 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
curl@7.88.1-10+deb12u14
no fix listed
opencsghq/csghub-server:v2.4.0-ee302c9d45d8a8
curl@7.88.1-10+deb12u14
no fix listed
opencsghq/csghub-xnet:v2.4.0-ee04121fd19ef9
curl@7.88.1-10+deb12u14
no fix listed
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
curl@7.88.1-10+deb12u7
no fix listed
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
curl@7.88.1-10+deb12u7
no fix listed
opencsghq/kubectl:latestb6d87e1048c2
curl@7.88.1-10+deb12u12
no fix listed

Open the chart page →

58,897
rtcsic-charts0.1.11 of 5See more

rt csic-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
firefart/requesttracker:5.0.40d6249906d8c
curl@7.88.1-10+deb12u4
no fix listed

Open the chart page →

15,380
cspconsolecspconsole1.3.113 of 5See more

cspconsole cspconsole 1.3.11

3 of the 5 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
cspconsole/config-provider:1.0.365524a26a6c23
curl@7.88.1-10+deb12u14
no fix listed
cspconsole/csp-control-center:1.0.1046dda4a31bd6
curl@7.88.1-10+deb12u14
no fix listed
cspconsole/report-collector:1.0.15839750248193b
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

12,274
cypikcypik-app0.1.01 of 2See more

cypik cypik-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
curl@7.88.1-10+deb12u5
no fix listed

Open the chart page →

7,503
jupyterhubd4nVerified publisher3.3.72 of 7See more

jupyterhub d4n 3.3.7

2 of the 7 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
curl@7.88.1-10+deb12u6
no fix listed
quay.io/jupyterhub/configurable-http-proxy:4.6.1fd916f75415f
curl@8.4.0-r0
8.12.0-r0

Open the chart page →

16,604
daejeon_2-3daejeon2-30.1.01 of 2See more

daejeon_2-3 daejeon2-3 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
clsen2024/daejeon_2-3:latest1156cd87c8fb
curl@8.9.0-r0
8.12.0-r0

Open the chart page →

1,141
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
curl@8.4.0-r0
8.12.0-r0

Open the chart page →

6,179
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

5,062
sentry-relaydasmeta0.1.21 of 1See more

sentry-relay dasmeta 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
getsentry/relay:24.10.0ba7bf9163219
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

3,571
giphy-appdavidy-helm-charts-repository0.1.21 of 1See more

giphy-app davidy-helm-charts-repository 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
davidy/giphy-app:1.0.2-arm41b2355cc23a
curl@8.11.0-r2
8.12.0-r0

Open the chart page →

704
db-connection-testdb-connection-testVerified publisher0.1.01 of 1See more

db-connection-test db-connection-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
felipecs8/app-db-connection-test:v129e06c9c6385
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

10,090
defactopsdefactops1.0.91 of 2See more

defactops defactops 1.0.9

1 of the 2 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
defactops/defactops-ui:1.0.16825cdf9ba706
curl@8.5.0-r0
8.12.0-r0

Open the chart page →

4,509
linkdingdeimosfr-charts1.0.31 of 1See more

linkding deimosfr-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.35.00c5dddf0b37c
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

6,075
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
curl@7.88.1-10+deb12u15
no fix listed

Open the chart page →

2,305
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

9,607
devtron-enterprisedevtron48.0.02 of 28See more

devtron-enterprise devtron 48.0.0

2 of the 28 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
curl@7.88.1-10+deb12u4
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

68,240
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
curl@7.88.1-10+deb12u7
no fix listed

Open the chart page →

9,607
devtron-enterprisedevtron-labs48.0.02 of 28See more

devtron-enterprise devtron-labs 48.0.0

2 of the 28 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
curl@7.88.1-10+deb12u4
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
curl@7.88.1-10+deb12u14
no fix listed

Open the chart page →

68,240
devtron-operatordevtron-labs0.23.31 of 11See more

devtron-operator devtron-labs 0.23.3

1 of the 11 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
curl@7.88.1-10+deb12u4
no fix listed

Open the chart page →

32,902
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-0725.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
curl@7.88.1-10+deb12u8
no fix listed

Open the chart page →

19,224

Container images carrying it

623 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
curl@7.88.1-10+deb12u7
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
curl@7.88.1-10+deb12u5
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
curl@7.88.1-10+deb12u5
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
curl@7.88.1-10+deb12u4
no fix listed
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
curl@7.88.1-10+deb12u14
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
curl@7.88.1-10+deb12u8
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
curl@7.88.1-10+deb12u5
no fix listed
1
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
curl@8.9.0-r0
8.12.0-r0
1
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
curl@8.1.0-r0
8.12.0-r0
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
curl@7.88.1-10+deb12u15
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
curl@7.88.1-10+deb12u14
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
curl@7.88.1-10+deb12u14
no fix listed
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
curl@7.88.1-10+deb12u15
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
curl@7.88.1-10+deb12u1
no fix listed
1
quay.io/yushiwho/sys-stats:e1f9d778c8d08b95c0b
curl@8.5.0-r0
8.12.0-r0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
curl@7.88.1-10+deb12u14
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
curl@7.88.1-10+deb12u14
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
curl@7.88.1-10+deb12u4
no fix listed
1
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
curl@8.5.0-r0
8.12.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
curl@8.1.1-r1
8.12.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
curl@8.10.1-r0
8.12.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
curl@8.5.0-r0
8.12.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
curl@8.11.1-r0
8.12.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.