StackRadar

CVE-2025-13878

High

Advisory

Published 21 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.085
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
22
of 17,781 indexed, latest versions
Container images
25
deployed by those charts
Fix available
3 of 3
affected packages

Security update for bind

Carried by container images the latest versions of 22 of 17,781 indexed charts deploy, on 25 images.

Affected packageAffected versionsFixed inImages
bindapk9.18.19-r1, 9.18.24-r1, 9.18.31-r0, 9.18.33-r0+6 more9.18.44-r0, 9.20.18-r015
bind9deb1:9.18.19-1~deb12u1, 1:9.18.24-1, 1:9.18.33-1~deb12u2, 1:9.18.41-1~deb12u1+2 more1:9.18.44-1~deb12u1, 1:9.20.18-1~deb13u19
bindrpm9.20.11-150700.3.6.19.20.18-150700.3.15.11
OSV records
ALPINE-CVE-2025-13878DEBIAN-CVE-2025-13878SUSE-SU-2026:0348-1
Also known as
DSA-6107-1

Charts affected

22 by stars
ChartLatestAffected imagesRadar Score
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
bind9@1:9.20.15-1~deb13u1
1:9.20.18-1~deb13u1

Open the chart page →

5,366
servarrservarr1.0.24 of 10See more

servarr servarr 1.0.2

4 of the 10 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
ghcr.io/onedr0p/prowlarr-develop:1.14.0.4286c77d84ebf7a6
bind@9.18.19-r1
9.18.44-r0
ghcr.io/onedr0p/qbittorrent:4.6.3a4ad890e8c4a
bind@9.18.19-r1
9.18.44-r0
ghcr.io/onedr0p/radarr:5.3.6.86128d299e59fce7
bind@9.18.19-r1
9.18.44-r0
ghcr.io/onedr0p/sonarr:4.0.2.118327ffdcc8a937
bind@9.18.19-r1
9.18.44-r0

Open the chart page →

14,238
pod-gatewayangelnu7.1.11 of 2See more

pod-gateway angelnu 7.1.1

1 of the 2 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
ghcr.io/angelnu/pod-gateway:v1.13.0a5b032e15f75
bind@9.18.35-r0
9.18.44-r0

Open the chart page →

1,133
certscertsVerified publisher2.1.31 of 1See more

certs certs 2.1.3

1 of the 1 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
mathnao/certs:2.1.3b900e6b64684
bind@9.18.39-r0
9.18.44-r0

Open the chart page →

695
bscdysnixVerified publisher0.6.591 of 4See more

bsc dysnix 0.6.59

1 of the 4 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
bind@9.18.41-r0
9.18.44-r0

Open the chart page →

2,012
dragonfly-stackdragonflyVerified publisher0.1.21 of 7See more

dragonfly-stack dragonfly 0.1.2

1 of the 7 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
dragonflyoss/client:v0.1.82edf3e921f4e0
bind9@1:9.18.24-1
1:9.18.44-1~deb12u1

Open the chart page →

18,376
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
bind@9.20.11-150700.3.6.1
9.20.18-150700.3.15.1

Open the chart page →

13,479
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
bind9@1:9.18.41-1~deb12u1
1:9.18.44-1~deb12u1

Open the chart page →

7,740
dnsbl-exporterchristianhuthVerified publisher1.4.01 of 2See more

dnsbl-exporter christianhuth 1.4.0

1 of the 2 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
ghcr.io/luzilla/unbound:v0.7.0-rc3252613692e5e
bind@9.18.24-r1
9.18.44-r0

Open the chart page →

1,459
arbitrumchronicleVerified publisher0.3.41 of 1See more

arbitrum chronicle 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
bind9@1:9.18.33-1~deb12u2
1:9.18.44-1~deb12u1

Open the chart page →

6,998
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
bind9@1:9.18.33-1~deb12u2
1:9.18.44-1~deb12u1

Open the chart page →

14,559
smokepingdjjudas21Verified publisher0.1.31 of 1See more

smokeping djjudas21 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
linuxserver/smokeping:2.8.2b7f906899cd3
bind@9.18.37-r0
9.18.44-r0

Open the chart page →

2,053
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
bind9@1:9.20.11-4
1:9.20.18-1~deb13u1

Open the chart page →

5,174
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
bind9@1:9.18.24-1
1:9.18.44-1~deb12u1

Open the chart page →

9,244
ejabberdejabberdVerified publisher0.1.01 of 1See more

ejabberd ejabberd 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
indevlab/ejabberd:24.12-k8s8bc689d093a7
bind@9.18.33-r0
9.18.44-r0

Open the chart page →

903
rospoferama0.4.31 of 1See more

rospo ferama 0.4.3

1 of the 1 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
bind9@1:9.18.19-1~deb12u1
1:9.18.44-1~deb12u1

Open the chart page →

6,026
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
bind@9.18.33-r0
9.18.44-r0

Open the chart page →

4,647
librenmsnimbolus0.5.11 of 3See more

librenms nimbolus 0.5.1

1 of the 3 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
librenms/librenms:24.11.00920bc9117a8
bind@9.18.31-r0
9.18.44-r0

Open the chart page →

2,293
cloudflaredpascaliskeVerified publisher3.0.01 of 1See more

cloudflared pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/cloudflared:2025.9.19b4e856d18f6
bind@9.20.13-r0
9.20.18-r0

Open the chart page →

2,028
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
bind@9.20.16-r0
9.20.18-r0

Open the chart page →

4,749
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
bind9@1:9.18.33-1~deb12u2
1:9.18.44-1~deb12u1

Open the chart page →

6,779
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-13878.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
bind@9.18.19-r1
9.18.44-r0

Open the chart page →

2,336

Container images carrying it

25 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
bind9@1:9.18.33-1~deb12u2
1:9.18.44-1~deb12u1
1
boky/postfix:5.1.0aafc77238423
bind9@1:9.20.15-1~deb13u1
1:9.20.18-1~deb13u1
1
dragonflyoss/client:v0.1.82edf3e921f4e0
bind9@1:9.18.24-1
1:9.18.44-1~deb12u1
1
fluent/fluent-bit:4.0-debuge76397ef3983
bind9@1:9.18.41-1~deb12u1
1:9.18.44-1~deb12u1
1
indevlab/ejabberd:24.12-k8s8bc689d093a7
bind@9.18.33-r0
9.18.44-r0
1
ixsystems/truecommand:3.2.019c218455cd2
bind9@1:9.20.11-4
1:9.20.18-1~deb13u1
1
librenms/librenms:24.11.00920bc9117a8
bind@9.18.31-r0
9.18.44-r0
1
linuxserver/smokeping:2.8.2b7f906899cd3
bind@9.18.37-r0
9.18.44-r0
1
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
bind@9.20.11-150700.3.6.1
9.20.18-150700.3.15.1
1
mathnao/certs:2.1.3b900e6b64684
bind@9.18.39-r0
9.18.44-r0
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
bind9@1:9.18.33-1~deb12u2
1:9.18.44-1~deb12u1
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
bind9@1:9.18.24-1
1:9.18.44-1~deb12u1
1
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
bind@9.18.19-r1
9.18.44-r0
1
ghcr.io/angelnu/pod-gateway:v1.13.0a5b032e15f75
bind@9.18.35-r0
9.18.44-r0
1
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
bind@9.18.41-r0
9.18.44-r0
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
bind9@1:9.18.33-1~deb12u2
1:9.18.44-1~deb12u1
1
ghcr.io/crazy-max/cloudflared:2025.9.19b4e856d18f6
bind@9.20.13-r0
9.20.18-r0
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
bind9@1:9.18.19-1~deb12u1
1:9.18.44-1~deb12u1
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
bind@9.18.33-r0
9.18.44-r0
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
bind@9.20.16-r0
9.20.18-r0
1
ghcr.io/luzilla/unbound:v0.7.0-rc3252613692e5e
bind@9.18.24-r1
9.18.44-r0
1
ghcr.io/onedr0p/prowlarr-develop:1.14.0.4286c77d84ebf7a6
bind@9.18.19-r1
9.18.44-r0
1
ghcr.io/onedr0p/qbittorrent:4.6.3a4ad890e8c4a
bind@9.18.19-r1
9.18.44-r0
1
ghcr.io/onedr0p/radarr:5.3.6.86128d299e59fce7
bind@9.18.19-r1
9.18.44-r0
1
ghcr.io/onedr0p/sonarr:4.0.2.118327ffdcc8a937
bind@9.18.19-r1
9.18.44-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.