StackRadar

CVE-2025-12781

Medium

Advisory

Published 21 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
651
of 17,787 indexed, latest versions
Container images
645
deployed by those charts
Fix available
3 of 15
affected packages

base64.b64decode() always accepts "+/" characters, despite setting altchars

Carried by container images the latest versions of 651 of 17,787 indexed charts deploy, on 645 images.

Affected packageAffected versionsFixed inImages
python-3.12apk3.12.0-r1, 3.12.9-r1, 3.12.14-r2, 3.12.14-r6no fix listed8
python-3.14apk3.14.2-r2, 3.14.4-r2, 3.14.6-r03.14.6-r16
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-13.15.03
python-3.13apk3.13.7-r0, 3.13.10-r0, 3.13.12-r23.13.14-r03
python-3.11apk3.11.16-r5no fix listed1
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 moreno fix listed180
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 moreno fix listed100
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+11 moreno fix listed87
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+16 moreno fix listed80
python3.13deb3.13.5-2, 3.13.5-2+deb13u2, 3.13.5-2+deb13u4, 3.13.7-1ubuntu0.1no fix listed74
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 moreno fix listed54
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 moreno fix listed44
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9no fix listed25
python3.14deb3.14.4-1, 3.14.4-1ubuntu0.1, 3.14.4-1ubuntu0.2no fix listed9
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7no fix listed7
OSV records
BIT-python-2025-12781CGA-3mjq-5c23-prmpCGA-4mf7-96v4-52mjCGA-8w6w-j788-x97qCGA-p288-9mv5-m48fDEBIAN-CVE-2025-12781UBUNTU-CVE-2025-12781
Also known as
BIT-libpython-2025-12781, BIT-python-min-2025-12781, CGA-m2h9-8f76-h5pw, CGA-qm9w-v5cx-mm74, CGA-x4f5-663c-vj94, CGA-xp35-jg4m-v7xg, PSF-2026-7

Charts affected

651 by stars
ChartLatestAffected imagesRadar Score
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2025-12781.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
python3.10@3.10.12-1~22.04.16
no fix listed

Open the chart page →

7,849

Container images carrying it

645 by charts deploying them

A fixed version is listed for 3 of the 15 affected packages.

Container imageDigestPackageFixed inUsed by
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
python3.10@3.10.6-1~22.04.2ubuntu1
no fix listed
2
uffizzi/controller:latest0344805f267b
python3.11@3.11.2-6
no fix listed
2
vdiogov/glpi-conteiner:latest6945f84f0058
python3.11@3.11.2-6+deb12u2
no fix listed
2
wurstmeister/zookeeper:latest7a7fd44a7210
python2.7@2.7.6-8
python3.4@3.4.0-2ubuntu1
no fix listed
no fix listed
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
python3.12@3.12.3-1ubuntu0.17
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
python3.12@3.12.3-1ubuntu0.5
no fix listed
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
python2.7@2.7.18-13ubuntu1.1
python3.10@3.10.6-1~22.04
no fix listed
no fix listed
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
python3.8@3.8.10-0ubuntu1~20.04
no fix listed
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
python3.11@3.11.2-6+deb12u2
no fix listed
2
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
python2.7@2.7.17-1~18.04ubuntu1.2
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
python3.11@3.11.2-6+deb12u6
no fix listed
2
ghcr.io/xeor/karb:1.0.6:main647a3c938d31
python-3.14@3.14.6-r0
3.14.6-r1
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
python3.8@3.8.10-0ubuntu1~20.04.8
no fix listed
2
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
python3.11@3.11.2-6+deb12u7
no fix listed
2
a10networks/acos-prometheus-exporter:latest8dc58d434d71
python3.6@3.6.9-1~18.04ubuntu1
no fix listed
1
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
python3.13@3.13.5-2+deb13u2
no fix listed
1
aboogie/login_test_backend:new9c41a4483ac8
python3.11@3.11.2-6+deb12u2
no fix listed
1
acryldata/datahub-actions:v1.7.0.1c5fd70130157
python-3.11@3.11.16-r5
no fix listed
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
python3.8@3.8.5-1~20.04
no fix listed
1
agentarea/agentarea-mcp-runner:latestd3c209a5d531
python3.11@3.11.2-6+deb12u8
no fix listed
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
python3.8@3.8.5-1~20.04.3
no fix listed
1
akeyless/base:latest759e4289fae8
python3.12@3.12.3-1ubuntu0.13
no fix listed
1
akeyless/gateway:5.3.13d2e7dce5eb9
python3.12@3.12.3-1ubuntu0.16
no fix listed
1
allegroai/clearml:2.0.0-613713ae38f7daf
python3.11@3.11.2-6+deb12u4
no fix listed
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
python3.6@3.6.9-1~18.04ubuntu1.7
no fix listed
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
python3.12@3.12.3-1ubuntu0.15
no fix listed
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
python3.10@3.10.12-1~22.04.2
no fix listed
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
python3.10@3.10.12-1~22.04.11
no fix listed
1
antiantiops/vscode-browser-docker:1.137.0eeff80a99d92
python3.12@3.12.3-1ubuntu0.16
no fix listed
1
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
python3.12@3.12.3-1ubuntu0.15
no fix listed
1
anujdatar/cups:25.07.01685df04a643b
python3.11@3.11.2-6+deb12u6
no fix listed
1
apache/airflow:2.8.4-python3.964e58748b6b9
python3.11@3.11.2-6
no fix listed
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
python3.11@3.11.2-6+deb12u3
no fix listed
1
apache/airflow:2.8.1e5560ad0b86e
python3.11@3.11.2-6
no fix listed
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
python3.10@3.10.12-1~22.04.15
no fix listed
1
apache/hertzbeat:1.8.075d48a62748f
python3.12@3.12.3-1ubuntu0.11
no fix listed
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
python3.12@3.12.3-1ubuntu0.11
no fix listed
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
python3.10@3.10.12-1~22.04.2
no fix listed
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
python3.8@3.8.10-0ubuntu1~20.04.2
no fix listed
1
apachepulsar/pulsar:3.0.79c9947de139d
python3.10@3.10.12-1~22.04.6
no fix listed
1
apachepulsar/pulsar:2.9.0d056c89b7131
python3.8@3.8.10-0ubuntu1~20.04.1
no fix listed
1
apachepulsar/pulsar:2.8.2d538416d5afe
python3.8@3.8.10-0ubuntu1~20.04.2
no fix listed
1
apache/ranger:2.7.076c176e8a0e4
python3.10@3.10.12-1~22.04.10
no fix listed
1
apache/tika:latest-full80072bb73dd3
python3.14@3.14.4-1ubuntu0.1
no fix listed
1
archivebox/archivebox:0.7.41a5a37331091
python3.11@3.11.2-6+deb12u7
no fix listed
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
python3.11@3.11.2-6
no fix listed
1
arunvelsriram/utils:latest655ad18fd8d6
python3.12@3.12.3-1ubuntu0.7
no fix listed
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
python2.7@2.7.18-1~20.04.3
no fix listed
1
assistiot/open_api_backend:1.1.230812ba93555
python3.10@3.10.12-1~22.04.3
no fix listed
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
python3.11@3.11.2-6
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.