StackRadar

CVE-2025-1149

Low

Advisory

Published 10 Feb 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.1
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
406
of 17,787 indexed, latest versions
Container images
390
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 406 of 17,787 indexed charts deploy, on 390 images.

Affected packageAffected versionsFixed inImages
binutilsdeb2.24-5ubuntu3.1, 2.24-5ubuntu14.2, 2.26.1-1ubuntu1~16.04.5, 2.26.1-1ubuntu1~16.04.6+39 moreno fix listed390
OSV records
DEBIAN-CVE-2025-1149UBUNTU-CVE-2025-1149

Charts affected

406 by stars
ChartLatestAffected imagesRadar Score
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-1149.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
binutils@2.38-4ubuntu2.6
no fix listed

Open the chart page →

9,347
aih-scannerwallarmVerified publisher2.7.111 of 2See more

aih-scanner wallarm 2.7.11

1 of the 2 container images this version deploys carry CVE-2025-1149.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.7.11f1cb26db1f5b
binutils@2.44-3
no fix listed

Open the chart page →

3,911
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-1149.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
binutils@2.40-2
no fix listed

Open the chart page →

7,085
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-1149.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
binutils@2.40-2
no fix listed

Open the chart page →

10,001
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2025-1149.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
binutils@2.44-3
no fix listed

Open the chart page →

5,560
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2025-1149.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
binutils@2.38-4ubuntu2.12
no fix listed

Open the chart page →

7,849

Container images carrying it

390 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/monicahq/monica-next:main8be69156acbb
binutils@2.44-3
no fix listed
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
binutils@2.40-2
no fix listed
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
binutils@2.40-2
no fix listed
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
binutils@2.42-4ubuntu2.10
no fix listed
1
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
binutils@2.42-4ubuntu2.10
no fix listed
1
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
binutils@2.42-4ubuntu2.10
no fix listed
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
binutils@2.42-4ubuntu2.10
no fix listed
1
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
binutils@2.42-4ubuntu2.10
no fix listed
1
ghcr.io/open-telemetry/demo:3.0.0-mcp654f860148ba
binutils@2.44-3
no fix listed
1
ghcr.io/open-telemetry/demo:3.0.0-chatbot66ba53497f1f
binutils@2.44-3
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
binutils@2.40-2
no fix listed
1
ghcr.io/open-telemetry/demo:3.0.0-agentdf5ee05e23e3
binutils@2.44-3
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
binutils@2.34-6ubuntu1.3
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
binutils@2.40-2
no fix listed
1
ghcr.io/securo-finance/securo-backend:0.15.162e030110745
binutils@2.44-3
no fix listed
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
binutils@2.34-6ubuntu1.3
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
binutils@2.34-6ubuntu1.3
no fix listed
1
ghcr.io/stac-utils/stac-fastapi-pgstac:6.4.0fa35b9519abb
binutils@2.44-3
no fix listed
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
binutils@2.34-6ubuntu1.9
no fix listed
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
binutils@2.34-6ubuntu1.9
no fix listed
1
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
binutils@2.40-2
no fix listed
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
binutils@2.40-2
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
binutils@2.40-2
no fix listed
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
binutils@2.40-2
no fix listed
1
ghcr.io/yourls/yourls:1.10.69b220ea83329
binutils@2.44-3
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
binutils@2.40-2
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
binutils@2.40-2
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
binutils@2.40-2
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
binutils@2.40-2
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
binutils@2.40-2
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
binutils@2.40-2
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
binutils@2.40-2
no fix listed
1
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
binutils@2.44-3
no fix listed
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
binutils@2.38-4ubuntu2
no fix listed
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
binutils@2.40-2
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
binutils@2.40-2
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
binutils@2.42-4ubuntu2.10
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
binutils@2.40-2
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
binutils@2.34-6ubuntu1.1
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
binutils@2.40-2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.