StackRadar

CVE-2025-0840

High

Advisory

Published 29 Jan 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
309
of 17,781 indexed, latest versions
Container images
286
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 309 of 17,781 indexed charts deploy, on 286 images.

Affected packageAffected versionsFixed inImages
binutilsdeb2.24-5ubuntu3.1, 2.24-5ubuntu14.2, 2.26.1-1ubuntu1~16.04.5, 2.26.1-1ubuntu1~16.04.6+29 more2.24-5ubuntu14.2+esm7, 2.26.1-1ubuntu1~16.04.8+esm11, 2.30-21ubuntu1~18.04.9+esm4, 2.34-6ubuntu1.10+2 more266
binutilsapk2.40-r7, 2.41-r0, 2.42-r02.40-r8, 2.41-r1, 2.42-r120
OSV records
ALPINE-CVE-2025-0840DEBIAN-CVE-2025-0840UBUNTU-CVE-2025-0840
Also known as
USN-7306-1, USN-7423-2, USN-7899-1

Charts affected

309 by stars
ChartLatestAffected imagesRadar Score
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
binutils@2.40-2
no fix listed

Open the chart page →

28,858
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
binutils@2.40-2
no fix listed

Open the chart page →

10,086
node-redthl-chartsVerified publisher0.1.01 of 1See more

node-red thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
nodered/node-red:3.0.2-18e2632a7a35dd
binutils@2.41-r0
2.41-r1

Open the chart page →

2,806
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
binutils@2.40-2
no fix listed

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
binutils@2.40-2
no fix listed

Open the chart page →

14,358
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
binutils@2.38-4ubuntu2.6
2.38-4ubuntu2.7

Open the chart page →

9,347
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
binutils@2.40-2
no fix listed

Open the chart page →

7,085
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
binutils@2.40-2
no fix listed

Open the chart page →

10,001
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-0840.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
binutils@2.40-r7
2.40-r8

Open the chart page →

1,589

Container images carrying it

286 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
oomk8s/readiness-check:2.0.2875814cc853d
binutils@2.26.1-1ubuntu1~16.04.8
2.26.1-1ubuntu1~16.04.8+esm11
11
oomk8s/readiness-check:2.0.07daa08b81954
binutils@2.26.1-1ubuntu1~16.04.6
2.26.1-1ubuntu1~16.04.8+esm11
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
binutils@2.40-2
no fix listed
6
solsson/kafka:latest41e5d8f6f290
binutils@2.34-6ubuntu1.3
2.34-6ubuntu1.10
5
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
binutils@2.40-2
no fix listed
4
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
binutils@2.26.1-1ubuntu1~16.04.6
2.26.1-1ubuntu1~16.04.8+esm11
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
binutils@2.26.1-1ubuntu1~16.04.8
2.26.1-1ubuntu1~16.04.8+esm11
4
mastercloudapps/planner:v1.2340a950b311b2
binutils@2.38-4ubuntu2.1
2.38-4ubuntu2.7
4
codeurjc/planner:v1.0800cf520c245
binutils@2.38-4ubuntu2.1
2.38-4ubuntu2.7
3
library/node:ltsbe23f54a88d3
binutils@2.40-2
no fix listed
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
binutils@2.40-r7
2.40-r8
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
binutils@2.40-2
no fix listed
3
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
binutils@2.40-2
no fix listed
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
binutils@2.40-r7
2.40-r8
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
binutils@2.40-2
no fix listed
2
library/phpmyadmin:5.2.16e75aa8f767c
binutils@2.40-2
no fix listed
2
library/python:3.7eedf63967cdb
binutils@2.40-2
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
binutils@2.40-2
no fix listed
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
binutils@2.26.1-1ubuntu1~16.04.8
2.26.1-1ubuntu1~16.04.8+esm11
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
binutils@2.40-2
no fix listed
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
binutils@2.34-6ubuntu1.3
2.34-6ubuntu1.10
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
binutils@2.34-6ubuntu1.9
2.34-6ubuntu1.10
2
uffizzi/controller:latest0344805f267b
binutils@2.40-2
no fix listed
2
vdiogov/glpi-conteiner:latest6945f84f0058
binutils@2.40-2
no fix listed
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
binutils@2.38-4ubuntu2
2.38-4ubuntu2.7
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
binutils@2.40-2
no fix listed
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
binutils@2.40-2
no fix listed
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
binutils@2.38-3ubuntu1
2.38-4ubuntu2.7
2
a10networks/acos-prometheus-exporter:latest8dc58d434d71
binutils@2.30-21ubuntu1~18.04.3
2.30-21ubuntu1~18.04.9+esm4
1
aboogie/login_test_backend:new9c41a4483ac8
binutils@2.40-2
no fix listed
1
akaunting/akaunting:3.0.1552811b36ec3a
binutils@2.40-2
no fix listed
1
allegroai/clearml:2.0.0-613713ae38f7daf
binutils@2.40-2
no fix listed
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
binutils@2.30-21ubuntu1~18.04.7
2.30-21ubuntu1~18.04.9+esm4
1
apachepulsar/pulsar:2.9.0d056c89b7131
binutils@2.34-6ubuntu1.3
2.34-6ubuntu1.10
1
apachepulsar/pulsar:2.8.2d538416d5afe
binutils@2.34-6ubuntu1.3
2.34-6ubuntu1.10
1
apache/superset:4.0.1ab9467fd712c
binutils@2.40-2
no fix listed
1
aristidetm/basic-notebook:3.6.5469dbc951224
binutils@2.40-2
no fix listed
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
binutils@2.40-2
no fix listed
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
binutils@2.40-2
no fix listed
1
assistiot/location_processing:lateste9bae124095f
binutils@2.38-4ubuntu2
2.38-4ubuntu2.7
1
assistiot/open_api_backend:1.1.230812ba93555
binutils@2.38-4ubuntu2.4
2.38-4ubuntu2.7
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
binutils@2.40-2
no fix listed
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
binutils@2.40-2
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
binutils@2.40-2
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
binutils@2.34-6ubuntu1.4
2.34-6ubuntu1.10
1
avinash263/pyredis263:latestaa2b8727f1a6
binutils@2.40-2
no fix listed
1
baserow/backend:1.31.1e0b3c8130b91
binutils@2.40-2
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
binutils@2.40-2
no fix listed
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
binutils@2.34-6ubuntu1.3
2.34-6ubuntu1.10
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
binutils@2.40-2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.