StackRadar

CVE-2025-13327

Medium

Advisory

Published 29 Oct 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
12
deployed by those charts
Fix available
2 of 2
affected packages

uv allows ZIP payload obfuscation through parsing differentials

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 12 images.

Affected packageAffected versionsFixed inImages
uvpypi0.4.1, 0.4.29, 0.5.27, 0.6.1+5 more0.9.611
uvcargo0.8.110.9.61
OSV records
GHSA-pqhf-p39g-3x64GHSA-v653-r55g-hcmg
Also known as
PYSEC-2026-2295

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
difydify-helmVerified publisher0.38.03 of 11See more

dify dify-helm 0.38.0

3 of the 11 container images this version deploys carry CVE-2025-13327.

Container imageDigestPackageFixed in
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
uv@0.8.9
0.9.6
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
uv@0.8.9
0.9.6
langgenius/dify-api:1.16.1dcefa5f7c47c
uv@0.8.9
0.9.6

Open the chart page →

22,002
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2025-13327.

Container imageDigestPackageFixed in
grafana/oncall:v1.16.5499851658393
uv@0.8.13
0.9.6

Open the chart page →

16,251
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-13327.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
uv@0.8.11
0.9.6

Open the chart page →

4,292
colosseumbook-k8sinfra-v21.0.181 of 5See more

colosseum book-k8sinfra-v2 1.0.18

1 of the 5 container images this version deploys carry CVE-2025-13327.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-rwd:log74ded2d92f07
uv@0.6.14
0.9.6

Open the chart page →

26,996
opencvecfi20170.1.21 of 7See more

opencve cfi2017 0.1.2

1 of the 7 container images this version deploys carry CVE-2025-13327.

Container imageDigestPackageFixed in
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
uv@0.4.29
0.9.6

Open the chart page →

15,371
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2025-13327.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
uv@0.6.3
0.9.6

Open the chart page →

20,900
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2025-13327.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
uv@0.7.20
0.9.6

Open the chart page →

58,897
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2025-13327.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
uv@0.6.1
0.9.6

Open the chart page →

4,647
meerschaummeerschaumVerified publisher0.2.01 of 1See more

meerschaum meerschaum 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-13327.

Container imageDigestPackageFixed in
bmeares/meerschaum:2.8.48e9c5bacaa82
uv@0.5.27
0.9.6

Open the chart page →

5,823
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-13327.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
uv@0.4.1
0.9.6

Open the chart page →

21,211

Container images carrying it

12 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apache/airflow:2.10.2-python3.9ce90bdc3d2af
uv@0.4.1
0.9.6
1
bmeares/meerschaum:2.8.48e9c5bacaa82
uv@0.5.27
0.9.6
1
grafana/oncall:v1.16.5499851658393
uv@0.8.13
0.9.6
1
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
uv@0.8.9
0.9.6
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
uv@0.8.9
0.9.6
1
langgenius/dify-api:1.16.1dcefa5f7c47c
uv@0.8.9
0.9.6
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
uv@0.7.20
0.9.6
1
sysnet4admin/colosseum-rwd:log74ded2d92f07
uv@0.6.14
0.9.6
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
uv@0.6.3
0.9.6
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
uv@0.8.11
0.9.6
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
uv@0.4.29
0.9.6
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
uv@0.6.1
0.9.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.