StackRadar

CVE-2025-11411

High

Advisory

Published 22 Oct 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
22
of 17,781 indexed, latest versions
Container images
31
deployed by those charts
Fix available
2 of 2
affected packages

unbound - security update

Carried by container images the latest versions of 22 of 17,781 indexed charts deploy, on 31 images.

Affected packageAffected versionsFixed inImages
unbounddeb1.9.4-2ubuntu1.1, 1.9.4-2ubuntu1.2, 1.13.1-1, 1.13.1-1+deb11u1+8 more1.13.1-1+deb11u6, 1.13.1-1ubuntu5.14, 1.17.1-2+deb12u4, 1.19.2-1ubuntu3.7+2 more30
unboundapk1.19.3-r01.20.0-r21
OSV records
ALPINE-CVE-2025-11411DEBIAN-CVE-2025-11411UBUNTU-CVE-2025-11411DLA-4365-1
Also known as
DLA-4365-2, DSA-6071-1, USN-7855-1, USN-7855-2

Charts affected

22 by stars
ChartLatestAffected imagesRadar Score
docker-mailserverdocker-mailserver0.4.01 of 2See more

docker-mailserver docker-mailserver 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
mailserver/docker-mailserver:11.0.0e0809756dc96
unbound@1.13.1-1
1.13.1-1+deb11u6

Open the chart page →

1,382
kobotoolboxone-acre-fundVerified publisher0.7.41 of 9See more

kobotoolbox one-acre-fund 0.7.4

1 of the 9 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
kobotoolbox/kobocat:2.022.24ab15679454415
unbound@1.13.1-1
1.13.1-1+deb11u6

Open the chart page →

18,517
freeradiusstartechnicaVerified publisher1.2.01 of 1See more

freeradius startechnica 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.2.8af6fd34a5b78
unbound@1.13.1-1ubuntu5.11
1.13.1-1ubuntu5.14

Open the chart page →

5,751
anteonanteonVerified publisher2.6.42 of 13See more

anteon anteon 2.6.4

2 of the 13 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
unbound@1.13.1-1+deb11u2
1.13.1-1+deb11u6
ddosify/selfhosted_backend:3.2.93c11e3182652
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u4

Open the chart page →

22,202
iris-webappiris-webapp0.2.41 of 2See more

iris-webapp iris-webapp 0.2.4

1 of the 2 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
unbound@1.22.0-2
1.22.0-2+deb13u1

Open the chart page →

11,764
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
unbound@1.22.0-2ubuntu2.1
1.22.0-2ubuntu2.2

Open the chart page →

11,103
napcatredish101Verified publisher0.1.31 of 1See more

napcat redish101 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
mlikiowa/napcat-docker:latest1336a777f9a4
unbound@1.13.1-1ubuntu5.8
1.13.1-1ubuntu5.14

Open the chart page →

7,405
varnishsoftonic0.18.91 of 1See more

varnish softonic 0.18.9

1 of the 1 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
library/varnish:7.2.14e7b912086b6
unbound@1.13.1-1+deb11u1
1.13.1-1+deb11u6

Open the chart page →

467
varnish-cachevarnishVerified publisher1.1.11 of 1See more

varnish-cache varnish 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
library/varnish:7.5.04d0bb287d87b
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u4

Open the chart page →

4,249
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
unbound@1.9.4-2ubuntu1.1
no fix listed

Open the chart page →

25,443
ddosifyanteonVerified publisher1.7.52 of 13See more

ddosify anteon 1.7.5

2 of the 13 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u4
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u4

Open the chart page →

25,669
dnsbl-exporterchristianhuthVerified publisher1.4.01 of 2See more

dnsbl-exporter christianhuth 1.4.0

1 of the 2 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
ghcr.io/luzilla/unbound:v0.7.0-rc3252613692e5e
unbound@1.19.3-r0
1.20.0-r2

Open the chart page →

1,459
wordpressdevops0.12.01 of 4See more

wordpress devops 0.12.0

1 of the 4 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/wordpress:6.0.23113c0960507
unbound@1.13.1-1
1.13.1-1+deb11u6

Open the chart page →

12,992
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u4

Open the chart page →

7,141
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
unbound@1.22.0-2
1.22.0-2+deb13u1

Open the chart page →

13,391
icinga2g0dscookie0.2.01 of 1See more

icinga2 g0dscookie 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
unbound@1.13.1-1
1.13.1-1+deb11u6

Open the chart page →

4,428
ibexaibexaVerified publisher3.11.11 of 10See more

ibexa ibexa 3.11.1

1 of the 10 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
boky/postfix:4.4.0f3f247fd4252
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u4

Open the chart page →

5,959
kube-ovnkube-ovn-test1.14.01 of 1See more

kube-ovn kube-ovn-test 1.14.0

1 of the 1 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
kubeovn/kube-ovn:v1.14.06722b54eb5c0
unbound@1.19.2-1ubuntu3.4
1.19.2-1ubuntu3.7

Open the chart page →

4,940
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
unbound@1.9.4-2ubuntu1.2
no fix listed

Open the chart page →

43,341
smilencsaVerified publisher1.1.08 of 23See more

smile ncsa 1.1.0

8 of the 23 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
unbound@1.13.1-1
1.13.1-1+deb11u6
socialmediamacroscope/classification_split:0.1.24bfda60829fe
unbound@1.13.1-1
1.13.1-1+deb11u6
socialmediamacroscope/classification_train:0.1.207477060bba8
unbound@1.13.1-1
1.13.1-1+deb11u6
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
unbound@1.13.1-1+deb11u1
1.13.1-1+deb11u6
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
unbound@1.17.1-2
1.17.1-2+deb12u4
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
unbound@1.17.1-2
1.17.1-2+deb12u4
socialmediamacroscope/preprocessing:0.1.3ca863306314b
unbound@1.17.1-2
1.17.1-2+deb12u4
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
unbound@1.17.1-2
1.17.1-2+deb12u4

Open the chart page →

109,294
liquidsoapnorth141.0.01 of 1See more

liquidsoap north14 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
ghcr.io/savonet/liquidsoap:v2.0.19e08148e1055
unbound@1.13.1-1
1.13.1-1+deb11u6

Open the chart page →

2,954
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2025-11411.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
unbound@1.22.0-2
1.22.0-2+deb13u1

Open the chart page →

9,534

Container images carrying it

31 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
boky/postfix:4.4.0f3f247fd4252
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u4
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u4
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
unbound@1.13.1-1+deb11u2
1.13.1-1+deb11u6
1
ddosify/selfhosted_backend:3.2.93c11e3182652
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u4
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u4
1
domainmod/domainmod:4.23.04017bfe4c597
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u4
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
unbound@1.22.0-2
1.22.0-2+deb13u1
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
unbound@1.13.1-1ubuntu5.11
1.13.1-1ubuntu5.14
1
kobotoolbox/kobocat:2.022.24ab15679454415
unbound@1.13.1-1
1.13.1-1+deb11u6
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
unbound@1.19.2-1ubuntu3.4
1.19.2-1ubuntu3.7
1
library/python:3.9da5aee29682d
unbound@1.22.0-2
1.22.0-2+deb13u1
1
library/varnish:7.5.04d0bb287d87b
unbound@1.17.1-2+deb12u2
1.17.1-2+deb12u4
1
library/varnish:7.2.14e7b912086b6
unbound@1.13.1-1+deb11u1
1.13.1-1+deb11u6
1
mailserver/docker-mailserver:11.0.0e0809756dc96
unbound@1.13.1-1
1.13.1-1+deb11u6
1
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
unbound@1.9.4-2ubuntu1.2
no fix listed
1
mlikiowa/napcat-docker:latest1336a777f9a4
unbound@1.13.1-1ubuntu5.8
1.13.1-1ubuntu5.14
1
photoprism/photoprism:251130db16ee6b1ba3
unbound@1.22.0-2ubuntu2.1
1.22.0-2ubuntu2.2
1
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
unbound@1.13.1-1
1.13.1-1+deb11u6
1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
unbound@1.13.1-1
1.13.1-1+deb11u6
1
socialmediamacroscope/classification_train:0.1.207477060bba8
unbound@1.13.1-1
1.13.1-1+deb11u6
1
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
unbound@1.13.1-1+deb11u1
1.13.1-1+deb11u6
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
unbound@1.17.1-2
1.17.1-2+deb12u4
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
unbound@1.17.1-2
1.17.1-2+deb12u4
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
unbound@1.17.1-2
1.17.1-2+deb12u4
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
unbound@1.17.1-2
1.17.1-2+deb12u4
1
ghcr.io/codingducksrl/wordpress:6.0.23113c0960507
unbound@1.13.1-1
1.13.1-1+deb11u6
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
unbound@1.22.0-2
1.22.0-2+deb13u1
1
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
unbound@1.13.1-1
1.13.1-1+deb11u6
1
ghcr.io/luzilla/unbound:v0.7.0-rc3252613692e5e
unbound@1.19.3-r0
1.20.0-r2
1
ghcr.io/savonet/liquidsoap:v2.0.19e08148e1055
unbound@1.13.1-1
1.13.1-1+deb11u6
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
unbound@1.9.4-2ubuntu1.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.