CVE-2025-0725
HighAdvisory
Published 5 Feb 2025In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.3
- base score, highest
- EPSS
- 0.013
- 68th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 625
- of 17,781 indexed, latest versions
- Container images
- 628
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 625 of 17,781 indexed charts deploy, on 628 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4, 7.88.1-10+deb12u5+7 more | no fix listed | 408 |
| curlapk | 8.0.1-r2, 8.1.0-r0, 8.1.1-r1, 8.1.2-r0+15 more | 8.12.0-r0 | 220 |
- OSV records
- ALPINE-CVE-2025-0725CGA-jjpm-f2w8-c9gxDEBIAN-CVE-2025-0725
- Also known as
- CGA-v6vj-5785-7c37
Charts affected
625 by stars
Container images carrying it
628 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 76d28575b71c | curl | no fix listed | 7 |
| bitnamilegacy/ | 9e635efba431 | curl | no fix listed | 6 |
| pnnlmiscscripts/ | cfbc9b70cbf8 | curl | 8.12.0-r0 | 6 |
| quay.io/ | 95d6f0e05636 | curl | no fix listed | 6 |
| bitnamilegacy/ | c74b703deed2 | curl | no fix listed | 5 |
| flaresolverr/ | 139dfee1c6f8 | curl | no fix listed | 5 |
| natsio/ | a67913df95f1 | curl | 8.12.0-r0 | 5 |
| ghcr.io/ | b72cf734d85f | curl | 8.12.0-r0 | 5 |
| bitnamilegacy/ | fac502149c40 | curl | no fix listed | 4 |
| library/ | 287ff321f9e3 | curl | no fix listed | 4 |
| apache/ | 16b50bbef664 | curl | no fix listed | 3 |
| bitnamilegacy/ | cd354d5b2556 | curl | no fix listed | 3 |
| bitnamilegacy/ | 77e65e9d633e | curl | no fix listed | 3 |
| dnationcloud/ | 78fed4f3c130 | curl | no fix listed | 3 |
| grafana/ | 0dc5a246ab16 | curl | 8.12.0-r0 | 3 |
| grafana/ | a0f881232a6f | curl | 8.12.0-r0 | 3 |
| library/ | 516475cc129d | curl | 8.12.0-r0 | 3 |
| library/ | a484819eb602 | curl | no fix listed | 3 |
| library/ | be23f54a88d3 | curl | no fix listed | 3 |
| nginxinc/ | be76a26e238d | curl | 8.12.0-r0 | 3 |
| rcdelacruz/ | 38007f358355 | curl | 8.12.0-r0 | 3 |
| rss3/ | d1d2ae6efd05 | curl | 8.12.0-r0 | 3 |
| ghcr.io/ | 6a5594b7b32c | curl | no fix listed | 3 |
| quay.io/ | 6545dac92173 | curl | no fix listed | 3 |
| quay.io/ | 709c7da19c5a | curl | no fix listed | 3 |
| quay.io/ | fd916f75415f | curl | 8.12.0-r0 | 3 |
| registry.k8s.io/ | e5c4824e7375 | curl | 8.12.0-r0 | 3 |
| alpine/ | f0c1b7ca12f6 | curl | 8.12.0-r0 | 2 |
| bitnamilegacy/ | 00176a47afa0 | curl | no fix listed | 2 |
| bitnamilegacy/ | f12387ec882b | curl | no fix listed | 2 |
| cfssl/ | c9018c2ddf0b | curl | no fix listed | 2 |
| chatwoot/ | d530ab8c1753 | curl | 8.12.0-r0 | 2 |
| dtzar/ | 55429449408e | curl | 8.12.0-r0 | 2 |
| ethersphere/ | 0558799ca992 | curl | 8.12.0-r0 | 2 |
| gjeanmart/ | 926264c8f2d1 | curl | no fix listed | 2 |
| grafana/ | 079600c9517b | curl | 8.12.0-r0 | 2 |
| grafana/ | 886b56d5534e | curl | 8.12.0-r0 | 2 |
| grafana/ | d8ea37798ccc | curl | 8.12.0-r0 | 2 |
| hazelcast/ | 5dd5d31c7a06 | curl | 8.12.0-r0 | 2 |
| hoppscotch/ | f1da831950b7 | curl | 8.12.0-r0 | 2 |
| jenkins/ | b470bcdc4ecd | curl | no fix listed | 2 |
| library/ | b8d940ca9376 | curl | no fix listed | 2 |
| library/ | 98f8ec75657d | curl | no fix listed | 2 |
| library/ | 6e75aa8f767c | curl | no fix listed | 2 |
| library/ | eedf63967cdb | curl | no fix listed | 2 |
| lightninglabs/ | f86bbec4dfb3 | curl | 8.12.0-r0 | 2 |
| linuxserver/ | 9932d6759112 | curl | 8.12.0-r0 | 2 |
| louislam/ | 917318f9d7be | curl | no fix listed | 2 |
| louislam/ | 9aeb4e51d038 | curl | no fix listed | 2 |
| louislam/ | a8610b3b4c38 | curl | no fix listed | 2 |