StackRadar

CVE-2025-13601

High

Advisory

Published 26 Nov 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
555
of 17,787 indexed, latest versions
Container images
646
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: glib2 security update

Carried by container images the latest versions of 555 of 17,787 indexed charts deploy, on 646 images.

Affected packageAffected versionsFixed inImages
glib2rpm2.56.1-2.el7, 2.56.1-4.el7_6, 2.56.1-5.el7, 2.56.1-7.el7+27 more0:2.56.1-11.el7_9, 0:2.56.4-168.el8_10, 0:2.68.4-18.el9_7.1329
glib2.0deb2.40.2-0ubuntu1, 2.48.2-0ubuntu1, 2.48.2-0ubuntu4.1, 2.48.2-0ubuntu4.4+37 more2.40.2-0ubuntu1.1+esm7, 2.48.2-0ubuntu4.8+esm5, 2.56.4-0ubuntu0.18.04.9+esm5, 2.64.6-1~ubuntu20.04.9+esm1+5 more317
OSV records
DEBIAN-CVE-2025-13601RHSA-2026:0936RHSA-2026:0991RHSA-2026:1608RLSA-2026:0936RLSA-2026:0991UBUNTU-CVE-2025-13601
Also known as
RHSA-2026:1324, RHSA-2026:1326, RHSA-2026:1465, RHSA-2026:1624, RHSA-2026:1625, RHSA-2026:1626, RHSA-2026:1627, USN-7942-1, USN-7942-2

Charts affected

555 by stars
ChartLatestAffected imagesRadar Score
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2025-13601.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
glib2@2.56.4-166.el8_10
0:2.56.4-168.el8_10

Open the chart page →

14,618
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-13601.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
glib2.0@2.72.4-0ubuntu2.3
2.72.4-0ubuntu2.7

Open the chart page →

14,172
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-13601.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
glib2@2.56.4-156.el8
0:2.56.4-168.el8_10

Open the chart page →

11,592
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-13601.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
glib2@2.56.4-159.el8
0:2.56.4-168.el8_10

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-13601.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
glib2@2.56.4-159.el8
0:2.56.4-168.el8_10

Open the chart page →

3,697

Container images carrying it

646 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
glib2@2.68.4-16.el9
0:2.68.4-18.el9_7.1
1
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
glib2@2.68.4-16.el9_6.2
0:2.68.4-18.el9_7.1
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
glib2.0@2.74.6-2+deb12u3
2.74.6-2+deb12u8
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
glib2.0@2.64.6-1~ubuntu20.04.4
2.64.6-1~ubuntu20.04.9+esm1
1
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
glib2.0@2.74.6-2+deb12u7
2.74.6-2+deb12u8
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
glib2.0@2.84.4-3~deb13u1
2.84.4-3~deb13u2
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
glib2@2.68.4-18.el9_7
0:2.68.4-18.el9_7.1
1
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
glib2@2.68.4-16.el9_6.2
0:2.68.4-18.el9_7.1
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
glib2@2.68.4-11.el9
0:2.68.4-18.el9_7.1
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
glib2@2.56.4-8.el8
0:2.56.4-168.el8_10
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
glib2.0@2.56.4-0ubuntu0.18.04.9
2.56.4-0ubuntu0.18.04.9+esm5
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
glib2.0@2.80.0-6ubuntu3.2
2.80.0-6ubuntu3.6
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
glib2.0@2.80.0-6ubuntu3.2
2.80.0-6ubuntu3.6
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
glib2.0@2.64.6-1~ubuntu20.04.4
2.64.6-1~ubuntu20.04.9+esm1
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
glib2.0@2.64.6-1~ubuntu20.04.4
2.64.6-1~ubuntu20.04.9+esm1
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
glib2.0@2.64.6-1~ubuntu20.04.4
2.64.6-1~ubuntu20.04.9+esm1
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
glib2.0@2.64.6-1~ubuntu20.04.3
2.64.6-1~ubuntu20.04.9+esm1
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
glib2.0@2.72.1-1
2.72.4-0ubuntu2.7
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
glib2.0@2.64.6-1~ubuntu20.04.4
2.64.6-1~ubuntu20.04.9+esm1
1
ghcr.io/k8snetworkplumbingwg/multus-dynamic-networks-controller:v0.3.72a2bb32c0ea8
glib2@2.56.4-165.el8_10
0:2.56.4-168.el8_10
1
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
glib2.0@2.64.6-1~ubuntu20.04.9
2.64.6-1~ubuntu20.04.9+esm1
1
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
glib2@2.56.4-161.el8
0:2.56.4-168.el8_10
1
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
glib2@2.56.4-161.el8
0:2.56.4-168.el8_10
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
glib2.0@2.64.6-1~ubuntu20.04.4
2.64.6-1~ubuntu20.04.9+esm1
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
glib2.0@2.64.6-1~ubuntu20.04.4
2.64.6-1~ubuntu20.04.9+esm1
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
glib2.0@2.64.6-1~ubuntu20.04.3
2.64.6-1~ubuntu20.04.9+esm1
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
glib2.0@2.64.6-1~ubuntu20.04.4
2.64.6-1~ubuntu20.04.9+esm1
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
glib2.0@2.64.6-1~ubuntu20.04.4
2.64.6-1~ubuntu20.04.9+esm1
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
glib2.0@2.64.6-1~ubuntu20.04.4
2.64.6-1~ubuntu20.04.9+esm1
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
glib2.0@2.74.6-2+deb12u3
2.74.6-2+deb12u8
1
ghcr.io/linuxforhealth/fhir-schematool:5.1.1f62cefee6ef6
glib2@2.56.4-165.el8_10
0:2.56.4-168.el8_10
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
glib2.0@2.56.4-0ubuntu0.18.04.8
2.56.4-0ubuntu0.18.04.9+esm5
1
ghcr.io/llm-d/llm-d-model-service:v0.0.158b99a8104a2f
glib2@2.68.4-16.el9
0:2.68.4-18.el9_7.1
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
glib2.0@2.80.0-6ubuntu3.2
2.80.0-6ubuntu3.6
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
glib2.0@2.74.6-2+deb12u5
2.74.6-2+deb12u8
1
ghcr.io/microboxlabs/miot-calendar:latest-jvm7157cdc0bf5b
glib2@2.68.4-18.el9_7
0:2.68.4-18.el9_7.1
1
ghcr.io/microboxlabs/miot-srv:latest4ec11d229028
glib2@2.68.4-18.el9_7
0:2.68.4-18.el9_7.1
1
ghcr.io/microboxlabs/miot-srv:latest5796553b41ae
glib2@2.68.4-18.el9_7
0:2.68.4-18.el9_7.1
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
glib2.0@2.80.0-6ubuntu3.2
2.80.0-6ubuntu3.6
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
glib2.0@2.74.6-2+deb12u3
2.74.6-2+deb12u8
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
glib2.0@2.74.6-2+deb12u5
2.74.6-2+deb12u8
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
glib2.0@2.74.6-2+deb12u3
2.74.6-2+deb12u8
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
glib2.0@2.64.6-1~ubuntu20.04.4
2.64.6-1~ubuntu20.04.9+esm1
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
glib2.0@2.74.6-2+deb12u3
2.74.6-2+deb12u8
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
glib2.0@2.84.4-3~deb13u1
2.84.4-3~deb13u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
glib2.0@2.84.4-3~deb13u1
2.84.4-3~deb13u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
glib2.0@2.74.6-2
2.74.6-2+deb12u8
1
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
glib2@2.68.4-14.el9
0:2.68.4-18.el9_7.1
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
glib2.0@2.74.6-2+deb12u5
2.74.6-2+deb12u8
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
glib2.0@2.64.6-1~ubuntu20.04.4
2.64.6-1~ubuntu20.04.9+esm1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.