CVE-2025-0725
HighAdvisory
Published 5 Feb 2025In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.3
- base score, highest
- EPSS
- 0.013
- 68th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 617
- of 17,787 indexed, latest versions
- Container images
- 620
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 617 of 17,787 indexed charts deploy, on 620 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4, 7.88.1-10+deb12u5+7 more | no fix listed | 401 |
| curlapk | 8.0.1-r2, 8.1.0-r0, 8.1.1-r1, 8.1.2-r0+15 more | 8.12.0-r0 | 219 |
- OSV records
- ALPINE-CVE-2025-0725CGA-jjpm-f2w8-c9gxDEBIAN-CVE-2025-0725
- Also known as
- CGA-v6vj-5785-7c37
Charts affected
617 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| consulwarjiang | 1.3.0 | 1 of 2See more | 4,060 |
| sirenwateim | 1.0.2 | 1 of 1See more | 5,984 |
| supersetwbstack | 0.1.0 | 1 of 1See more | 7,085 |
| web-dvwaweb-dvwa | 1.16.0 | 1 of 2See more | 10,001 |
| emissary-ingresswenerme | 8.12.2 | 1 of 2See more | 10,843 |
| giteawenerme | 12.7.0 | 1 of 4See more | 8,811 |
| juicefs-csi-driverwenerme | 0.32.5 | 1 of 5See more | 9,117 |
| keycloakwiremindVerified publisher | 25.3.1 | 1 of 2See more | 7,624 |
| kibanawiremindVerified publisher | 8.5.23 | 1 of 2See more | 6,285 |
| marge-botwiremindVerified publisher | 1.4.4 | 1 of 1See more | 5,542 |
| postgres-operatorwiremindVerified publisher | 1.14.0-wiremind0 | 1 of 1See more | 1,286 |
| rabbitmqwiremindVerified publisher | 16.0.17 | 1 of 1See more | 2,473 |
| tabbyxdVerified publisher | 1.0.6 | 1 of 2See more | 7,673 |
| xkopsxkops | 0.1.0 | 2 of 5See more | 13,677 |
| ygdrassil-monitoringygdrassilVerified publisher | 0.4.0 | 1 of 10See more | 9,381 |
| prometheusalertygqygq2Verified publisher | 1.0.0 | 1 of 1See more | 1,611 |
| sockpuppetbrowserzekker6Verified publisher | 0.1.0 | 1 of 1See more | 1,589 |
Container images carrying it
620 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ckan/ | 87ecf3f27ad6 | curl | no fix listed | 1 |
| ckulka/ | 434bdd162247 | curl | no fix listed | 1 |
| cloudtooling/ | f4f04e0fc401 | curl | no fix listed | 1 |
| clsen2024/ | 1156cd87c8fb | curl | 8.12.0-r0 | 1 |
| clsen2024/ | 0ba9eff852c5 | curl | 8.12.0-r0 | 1 |
| clsen2024/ | 51b1d45961cd | curl | 8.12.0-r0 | 1 |
| clsen2024/ | efb1586c8299 | curl | 8.12.0-r0 | 1 |
| codecov/ | 0475cb1c3136 | curl | 8.12.0-r0 | 1 |
| codecov/ | 837f546b479b | curl | 8.12.0-r0 | 1 |
| collabora/ | 01dc4ab83977 | curl | no fix listed | 1 |
| collabora/ | 05299b452f7f | curl | no fix listed | 1 |
| cometbft/ | 22c2ac018f40 | curl | 8.12.0-r0 | 1 |
| contentsquareplatform/ | 24555f22d4be | curl | no fix listed | 1 |
| cryptexlabs/ | 189c07411d7c | curl | 8.12.0-r0 | 1 |
| cspconsole/ | 5524a26a6c23 | curl | no fix listed | 1 |
| cspconsole/ | 46dda4a31bd6 | curl | no fix listed | 1 |
| cspconsole/ | 39750248193b | curl | no fix listed | 1 |
| dachichang/ | 7ccac90a935e | curl | no fix listed | 1 |
| daledavies/ | 0a0c8ad93902 | curl | 8.12.0-r0 | 1 |
| dannielkil/ | 937993927694 | curl | no fix listed | 1 |
| dannyben/ | ebdf50556c02 | curl | 8.12.0-r0 | 1 |
| datawire/ | 95ec30b3c732 | curl | 8.12.0-r0 | 1 |
| datawire/ | 1f67a1292d2a | curl | 8.12.0-r0 | 1 |
| davidy/ | 41b2355cc23a | curl | 8.12.0-r0 | 1 |
| ddosify/ | 56dbd7cf0776 | curl | 8.12.0-r0 | 1 |
| ddosify/ | bf454ab99d89 | curl | 8.12.0-r0 | 1 |
| deconzcommunity/ | 062de2362641 | curl | no fix listed | 1 |
| defactops/ | 825cdf9ba706 | curl | 8.12.0-r0 | 1 |
| dessalines/ | 79e9f02c286c | curl | no fix listed | 1 |
| dgtlmoon/ | f166a963b550 | curl | 8.12.0-r0 | 1 |
| diygod/ | 7a6312cac0d5 | curl | no fix listed | 1 |
| djjudas21/ | 4fa898a52d97 | curl | 8.12.0-r0 | 1 |
| dobtc/ | a870f7cb1105 | curl | no fix listed | 1 |
| docmost/ | 41c8d777cf23 | curl | no fix listed | 1 |
| dolibarr/ | 69ec52e3b7ef | curl | no fix listed | 1 |
| dolibarr/ | 7ad88fc9b13c | curl | no fix listed | 1 |
| domainmod/ | 4017bfe4c597 | curl | no fix listed | 1 |
| dragonflyoss/ | a1b52779c4dd | curl | no fix listed | 1 |
| dragonflyoss/ | edf3e921f4e0 | curl | no fix listed | 1 |
| drumsergio/ | 28244054e1bf | curl | no fix listed | 1 |
| dserio83/ | 6b3d9115fee2 | curl | no fix listed | 1 |
| dserio83/ | d5deae589229 | curl | no fix listed | 1 |
| dwdraju/ | 83bd9be2b14b | curl | 8.12.0-r0 | 1 |
| emqx/ | e33e9816f147 | curl | no fix listed | 1 |
| epamedp/ | 28ef56bc0ca3 | curl | 8.12.0-r0 | 1 |
| eqalpha/ | f1d60f12cb3c | curl | 8.12.0-r0 | 1 |
| esphome/ | 9ab8cc88b28c | curl | no fix listed | 1 |
| esphome/ | b2c6322700ac | curl | no fix listed | 1 |
| esphome/ | def8b6e4f517 | curl | no fix listed | 1 |
| falcosecurity/ | 932956d86c99 | curl | no fix listed | 1 |