StackRadar

CVE-2025-14523

High

Advisory

Published 11 Dec 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
54
of 17,781 indexed, latest versions
Container images
58
deployed by those charts
Fix available
1 of 3
affected packages

Red Hat Security Advisory: libsoup security update

Carried by container images the latest versions of 54 of 17,781 indexed charts deploy, on 58 images.

Affected packageAffected versionsFixed inImages
libsoup2.4deb2.52.2-1ubuntu0.2, 2.52.2-1ubuntu0.3, 2.62.1-1ubuntu0.1, 2.62.1-1ubuntu0.4+8 moreno fix listed43
libsouprpm2.62.3-2.el8, 2.62.3-3.el8, 2.62.3-4.el8, 2.62.3-5.el8+1 more0:2.62.3-11.el8_10, 0:2.72.0-12.el9_7.311
libsoup3deb3.0.7-0ubuntu1, 3.2.2-2, 3.4.4-5ubuntu0.5, 3.4.4-5ubuntu0.7+1 moreno fix listed6
OSV records
DEBIAN-CVE-2025-14523RHSA-2026:0421RHSA-2026:0422UBUNTU-CVE-2025-14523
Also known as
RHSA-2026:0867, RHSA-2026:0908, RHSA-2026:0909

Charts affected

54 by stars
ChartLatestAffected imagesRadar Score
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-14523.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libsoup3@3.4.4-5ubuntu0.5
no fix listed

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-14523.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
libsoup3@3.4.4-5ubuntu0.5
no fix listed

Open the chart page →

12,460
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-14523.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
libsoup2.4@2.70.0-1
no fix listed

Open the chart page →

18,756
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-14523.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libsoup2.4@2.74.2-3
libsoup3@3.0.7-0ubuntu1
no fix listed
no fix listed

Open the chart page →

14,100

Container images carrying it

58 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
libsoup2.4@2.52.2-1ubuntu0.3
no fix listed
3
kurento/kurento-media-server:latest03c0d34d0828
libsoup3@3.4.4-5ubuntu0.5
no fix listed
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
libsoup2.4@2.70.0-1
no fix listed
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libsoup2.4@2.70.0-1
no fix listed
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
libsoup2.4@2.70.0-1
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
libsoup2.4@2.74.3-1+deb12u1
no fix listed
2
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
libsoup2.4@2.70.0-1
no fix listed
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libsoup2.4@2.70.0-1
no fix listed
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
libsoup2.4@2.74.2-3ubuntu0.5
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
libsoup2.4@2.70.0-1
no fix listed
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libsoup2.4@2.70.0-1
no fix listed
1
codetogether/codetogether:latest4348c8a38752
libsoup@2.72.0-8.el9
0:2.72.0-12.el9_7.3
1
countly/countly-server:25.05.4e3c238248f99
libsoup2.4@2.70.0-1
no fix listed
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
libsoup2.4@2.70.0-1ubuntu0.5
no fix listed
1
gurolakman/oam:4.0.0ed8fd2062548
libsoup@2.62.3-5.el8
0:2.62.3-11.el8_10
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
libsoup@2.62.3-4.el8
0:2.62.3-11.el8_10
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
libsoup@2.62.3-4.el8
0:2.62.3-11.el8_10
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
libsoup@2.62.3-4.el8
0:2.62.3-11.el8_10
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
libsoup@2.62.3-4.el8
0:2.62.3-11.el8_10
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
libsoup@2.62.3-4.el8
0:2.62.3-11.el8_10
1
gurolakman/ussigw-core:1.0.48739565c3ea2
libsoup@2.62.3-4.el8
0:2.62.3-11.el8_10
1
haveagitgat/tdarr:2.00.181256348872ce
libsoup2.4@2.70.0-1
no fix listed
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
libsoup2.4@2.70.0-1
no fix listed
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
libsoup2.4@2.70.0-1
no fix listed
1
hazelcast/management-center:5.3.2f9d34300d330
libsoup@2.62.3-3.el8
0:2.62.3-11.el8_10
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libsoup2.4@2.70.0-1
no fix listed
1
jaedb/iris:latest048cfbf58d57
libsoup2.4@2.74.3-1+deb12u1
libsoup3@3.2.2-2
no fix listed
no fix listed
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
libsoup2.4@2.62.1-1ubuntu0.4
no fix listed
1
livekit/ingress:v1.2.21ab01641b366
libsoup2.4@2.74.2-3
no fix listed
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libsoup2.4@2.62.1-1ubuntu0.1
no fix listed
1
openkm/openkm-ce:6.3.113bc465a7461b
libsoup2.4@2.70.0-1
no fix listed
1
photoprism/photoprism:220629-jammy2954334adbda
libsoup2.4@2.74.2-3
no fix listed
1
photoprism/photoprism:251130db16ee6b1ba3
libsoup3@3.6.5-4
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
libsoup2.4@2.74.3-6ubuntu1
no fix listed
1
project2team4/react:latest3ff031a08887
libsoup2.4@2.70.0-1
no fix listed
1
scrapinghub/splash:3.4.1a5f89bc84606
libsoup2.4@2.62.1-1ubuntu0.4
no fix listed
1
seafileltd/seafile-mc:9.0.106693911bcc40
libsoup2.4@2.70.0-1
no fix listed
1
seafileltd/seafile-mc:10.0.170628f29c663
libsoup2.4@2.70.0-1
no fix listed
1
seafileltd/seafile-mc:9.0.97ac833196f60
libsoup2.4@2.70.0-1
no fix listed
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
libsoup2.4@2.70.0-1
no fix listed
1
selenium/node-chrome:4.48.0-202609055ac71fd8dd1e
libsoup3@3.4.4-5ubuntu0.7
no fix listed
1
selenium/node-firefox:4.48.0-2026090574a5c1c90f95
libsoup3@3.4.4-5ubuntu0.7
no fix listed
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libsoup2.4@2.70.0-1
no fix listed
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
libsoup2.4@2.70.0-1
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libsoup2.4@2.52.2-1ubuntu0.2
no fix listed
1
trueosiris/vrising:latest9356f98ad561
libsoup2.4@2.74.2-3ubuntu0.6
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libsoup2.4@2.74.2-3
libsoup3@3.0.7-0ubuntu1
no fix listed
no fix listed
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
libsoup2.4@2.72.0-2
no fix listed
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
libsoup2.4@2.70.0-1
no fix listed
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libsoup2.4@2.70.0-1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.