StackRadar

CVE-2025-13151

High

Advisory

Published 7 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
65th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,959
of 17,805 indexed, latest versions
Container images
2,127
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libtasn1 security update

Carried by container images the latest versions of 1,959 of 17,805 indexed charts deploy, on 2,127 images.

Affected packageAffected versionsFixed inImages
libtasn1-6deb3.4-3ubuntu0.1, 3.4-3ubuntu0.5, 3.4-3ubuntu0.6, 4.7-3ubuntu0.16.04.2+12 more3.4-3ubuntu0.6+esm1, 4.7-3ubuntu0.16.04.3+esm4, 4.13-2ubuntu0.1~esm1, 4.16.0-2ubuntu0.1+esm1+4 more1,732
libtasn1apk4.19.0-r2, 4.20.0-r04.21.0-r046
libtasn1rpm4.13-3.el8, 4.13-3.el8_6.1, 4.13-4.el8_7, 4.13-5.el8_10+7 more0:4.13-6.el8_10, 0:4.16.0-10.el9_8, 0:4.20.0-5.el10_2, 4.13-150000.4.14.1+2 more349
OSV records
ALPINE-CVE-2025-13151DEBIAN-CVE-2025-13151UBUNTU-CVE-2025-13151RHSA-2026:28235RHSA-2026:28253RHSA-2026:36728RLSA-2026:28253RLSA-2026:36728openSUSE-SU-2026:10033-1SUSE-SU-2026:0224-1SUSE-SU-2026:21142-1
Also known as
USN-7954-1, USN-7954-2

Charts affected

1,959 by stars
ChartLatestAffected imagesRadar Score
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-13151.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libtasn1-6@4.19.0-2
no fix listed

Open the chart page →

7,672
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-13151.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
libtasn1-6@4.19.0-2
no fix listed
hamzaarshad10/querypodpy:1.7154f38e8668e
libtasn1-6@4.19.0-2
no fix listed
murtazashah46/helmfile:latest4d11726cf803
libtasn1-6@4.19.0-2
no fix listed

Open the chart page →

13,875
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-13151.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
libtasn1-6@4.19.0-3build1
4.19.0-3ubuntu0.24.04.2

Open the chart page →

2,156
pgcatxxl-job-adminVerified publisher0.3.31See more

pgcat xxl-job-admin 0.3.3

1 container image this version deploys carries CVE-2025-13151.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
libtasn1-6@4.19.0-2
no fix listed

Open the chart page →

api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-13151.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
libtasn1-6@4.19.0-2
no fix listed

Open the chart page →

2,710
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-13151.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libtasn1@4.13-4.el8_7
0:4.13-6.el8_10

Open the chart page →

6,021
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-13151.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libtasn1@4.13-4.el8_7
0:4.13-6.el8_10

Open the chart page →

3,700
changedetection-iozekker6Verified publisher1.102.01See more

changedetection-io zekker6 1.102.0

1 container image this version deploys carries CVE-2025-13151.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
libtasn1-6@4.19.0-2+deb12u1
no fix listed

Open the chart page →

clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2025-13151.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
libtasn1-6@4.13-2
4.13-2ubuntu0.1~esm1
yandex/clickhouse-server:21.3.204eccfffb01d7
libtasn1-6@4.16.0-2
4.16.0-2ubuntu0.1+esm1

Open the chart page →

9,280

Container images carrying it

2,127 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/strimzi/operator:0.36.1e9e03b31007c
libtasn1@4.13-4.el8_7
0:4.13-6.el8_10
1
quay.io/underndog/samba:1.2.0-not-recyclecca801de9fa5
libtasn1@4.20.0-r0
4.21.0-r0
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
libtasn1-6@4.19.0-2+deb12u1
no fix listed
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
libtasn1@4.13-4.el8_7
0:4.13-6.el8_10
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libtasn1-6@4.19.0-2
no fix listed
1
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
libtasn1-6@4.19.0-2+deb12u1
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
libtasn1-6@4.19.0-2+deb12u1
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
libtasn1-6@4.19.0-2+deb12u1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
libtasn1-6@4.20.0-2
4.20.0-2+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
libtasn1-6@4.19.0-2+deb12u1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
libtasn1@4.13-3.el8
0:4.13-6.el8_10
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
libtasn1-6@4.19.0-2
no fix listed
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
libtasn1@4.13-3.el8
0:4.13-6.el8_10
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
libtasn1-6@4.16.0-2
4.16.0-2ubuntu0.1+esm1
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
libtasn1@4.13-3.el8
0:4.13-6.el8_10
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
libtasn1-6@4.19.0-2+deb12u1
no fix listed
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
libtasn1@4.16.0-9.el9
0:4.16.0-10.el9_8
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
libtasn1@4.16.0-9.el9
0:4.16.0-10.el9_8
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
libtasn1-6@4.19.0-2+deb12u1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
libtasn1-6@4.20.0-2
4.20.0-2+deb13u1
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
libtasn1-6@4.19.0-2
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
libtasn1-6@4.19.0-2
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
libtasn1-6@4.19.0-2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
libtasn1-6@4.19.0-2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
libtasn1-6@4.19.0-2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
libtasn1-6@4.19.0-2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
libtasn1-6@4.19.0-2+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.