StackRadar

CVE-2025-0840

High

Advisory

Published 29 Jan 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
309
of 17,781 indexed, latest versions
Container images
286
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 309 of 17,781 indexed charts deploy, on 286 images.

Affected packageAffected versionsFixed inImages
binutilsdeb2.24-5ubuntu3.1, 2.24-5ubuntu14.2, 2.26.1-1ubuntu1~16.04.5, 2.26.1-1ubuntu1~16.04.6+29 more2.24-5ubuntu14.2+esm7, 2.26.1-1ubuntu1~16.04.8+esm11, 2.30-21ubuntu1~18.04.9+esm4, 2.34-6ubuntu1.10+2 more266
binutilsapk2.40-r7, 2.41-r0, 2.42-r02.40-r8, 2.41-r1, 2.42-r120
OSV records
ALPINE-CVE-2025-0840DEBIAN-CVE-2025-0840UBUNTU-CVE-2025-0840
Also known as
USN-7306-1, USN-7423-2, USN-7899-1

Charts affected

309 by stars
ChartLatestAffected imagesRadar Score
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
binutils@2.40-2
no fix listed

Open the chart page →

28,858
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
binutils@2.40-2
no fix listed

Open the chart page →

10,086
node-redthl-chartsVerified publisher0.1.01 of 1See more

node-red thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
nodered/node-red:3.0.2-18e2632a7a35dd
binutils@2.41-r0
2.41-r1

Open the chart page →

2,806
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
binutils@2.40-2
no fix listed

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
binutils@2.40-2
no fix listed

Open the chart page →

14,358
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
binutils@2.38-4ubuntu2.6
2.38-4ubuntu2.7

Open the chart page →

9,347
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
binutils@2.40-2
no fix listed

Open the chart page →

7,085
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
binutils@2.40-2
no fix listed

Open the chart page →

10,001
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
binutils@2.40-r7
2.40-r8

Open the chart page →

1,589

Container images carrying it

286 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
binutils@2.34-6ubuntu1.4
2.34-6ubuntu1.10
1
bitnamilegacy/mysql:8.4.5-debian-12-r07089d796fc9b
binutils@2.40-2
no fix listed
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
binutils@2.40-2
no fix listed
1
bmeares/meerschaum:2.8.48e9c5bacaa82
binutils@2.40-2
no fix listed
1
bnjbvr/kresus:0.22.137e216b182c8
binutils@2.40-2
no fix listed
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
binutils@2.34-6ubuntu1.1
2.34-6ubuntu1.10
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
binutils@2.40-2
no fix listed
1
castlemock/castlemock:latestb7f3f1527ba9
binutils@2.42-4ubuntu2.3
2.42-4ubuntu2.4
1
castopod/castopod:1.12.101fd37280cbb2
binutils@2.40-2
no fix listed
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
binutils@2.24-5ubuntu14.2
2.24-5ubuntu14.2+esm7
1
chetangautamm/repo:sipp.v3e7f7049e1544
binutils@2.34-6ubuntu1
2.34-6ubuntu1.10
1
cheyang/distributed-tf:1.6.046cc34755493
binutils@2.26.1-1ubuntu1~16.04.6
2.26.1-1ubuntu1~16.04.8+esm11
1
cloudve/janis-terminal:latestaf56e77ca587
binutils@2.30-21ubuntu1~18.04.3
2.30-21ubuntu1~18.04.9+esm4
1
codecov/self-hosted-api:24.4.10475cb1c3136
binutils@2.40-r7
2.40-r8
1
codecov/self-hosted-worker:24.4.1837f546b479b
binutils@2.40-r7
2.40-r8
1
commerceexperts/searchhub-smartsuggest-service:1.3.0341eebe7239b
binutils@2.42-r0
2.42-r1
1
countly/countly-server:25.05.4e3c238248f99
binutils@2.34-6ubuntu1.9
2.34-6ubuntu1.10
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
binutils@2.40-2
no fix listed
1
dannyben/madness:latestebdf50556c02
binutils@2.42-r0
2.42-r1
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
binutils@2.40-2
no fix listed
1
ddosify/selfhosted_backend:3.2.93c11e3182652
binutils@2.40-2
no fix listed
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
binutils@2.40-2
no fix listed
1
deconzcommunity/deconz:2.29.2062de2362641
binutils@2.40-2
no fix listed
1
dgtlmoon/sockpuppetbrowser:latestf166a963b550
binutils@2.40-r7
2.40-r8
1
dolibarr/dolibarr:24.0.069ec52e3b7ef
binutils@2.40-2
no fix listed
1
dolibarr/dolibarr:22.0.47ad88fc9b13c
binutils@2.40-2
no fix listed
1
domainmod/domainmod:4.23.04017bfe4c597
binutils@2.40-2
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
binutils@2.40-2
no fix listed
1
drpcorg/dshackle:0.54.08858fae1859d
binutils@2.38-4ubuntu2.3
2.38-4ubuntu2.7
1
elautoestopista/raponchi:0.3.0b6f74db9fc81
binutils@2.42-r0
2.42-r1
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
binutils@2.26.1-1ubuntu1~16.04.5
2.26.1-1ubuntu1~16.04.8+esm11
1
fabioformosa/hello-world-api:latest063873af085c
binutils@2.41-r0
2.41-r1
1
falcosecurity/falco-driver-loader:0.44.17df783d5269a
binutils@2.40-2
no fix listed
1
felipecs8/app-db-connection-test:v129e06c9c6385
binutils@2.40-2
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
binutils@2.40-2
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
binutils@2.40-2
no fix listed
1
flyway/flyway:9.1545b5d7cdc75a
binutils@2.34-6ubuntu1.4
2.34-6ubuntu1.10
1
gethue/hue:4.11.011b649636e68
binutils@2.34-6ubuntu1.4
2.34-6ubuntu1.10
1
gethue/hue:4.10.05702b2c37ff9
binutils@2.30-21ubuntu1~18.04.5
2.30-21ubuntu1~18.04.9+esm4
1
gulacedia/web-dvwa-new:v367b467d961ca
binutils@2.40-2
no fix listed
1
haveagitgat/tdarr:2.00.181256348872ce
binutils@2.34-6ubuntu1.3
2.34-6ubuntu1.10
1
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
binutils@2.34-6ubuntu1.9
2.34-6ubuntu1.10
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
binutils@2.40-2
no fix listed
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
binutils@2.38-4ubuntu2.1
2.38-4ubuntu2.7
1
hmediade/printserver:latest481a552c8e1c
binutils@2.38-4ubuntu2.5
2.38-4ubuntu2.7
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
binutils@2.30-21ubuntu1~18.04.4
2.30-21ubuntu1~18.04.9+esm4
1
hugohg34/toposervice:0.0.2812a03b3f274
binutils@2.34-6ubuntu1.3
2.34-6ubuntu1.10
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
binutils@2.26.1-1ubuntu1~16.04.6
2.26.1-1ubuntu1~16.04.8+esm11
1
i4trust/activation-service:2.2.09f3719176893
binutils@2.40-r7
2.40-r8
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
binutils@2.26.1-1ubuntu1~16.04.6
2.26.1-1ubuntu1~16.04.8+esm11
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.