StackRadar

CVE-2025-14819

Medium

Advisory

Published 6 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
656
of 17,787 indexed, latest versions
Container images
651
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 656 of 17,787 indexed charts deploy, on 651 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4+16 more1:8.14.1-2+deb13u3+e2, 7.88.1-10+deb12u15, 8.5.0-2ubuntu10.7, 8.14.1-2+deb13u4+1 more546
curlapk8.12.1-r0, 8.17.0-r18.18.0-r0105
OSV records
ALPINE-CVE-2025-14819DEBIAN-CVE-2025-14819UBUNTU-CVE-2025-14819ECHO-2c28-953d-b5a0
Also known as
USN-8062-1

Charts affected

656 by stars
ChartLatestAffected imagesRadar Score
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2025-14819.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15

Open the chart page →

7,643
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-14819.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15

Open the chart page →

5,548
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2025-14819.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15

Open the chart page →

2,383
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-14819.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-14819.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
curl@7.88.1-10+deb12u7
7.88.1-10+deb12u15

Open the chart page →

13,197
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2025-14819.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.18.0-r0

Open the chart page →

1,571

Container images carrying it

651 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.7
1
ghcr.io/sudo-kraken/3d-printing-cost-calculators:v1.1.1220c5e4e1a3d
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
ghcr.io/sudo-kraken/authentik-webfinger-proxy:v1.1.1e1351a977607
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
ghcr.io/sudo-kraken/fantasy-dice-chamber:v1.3.299fd4cb0f4fe
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
ghcr.io/sudo-kraken/finances-tracker:v1.1.1c73527cde81c
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
ghcr.io/sudo-kraken/jf-pushover-webhook:v1.1.0ee9cf22a39ab
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
curl@8.17.0-r1
8.18.0-r0
1
ghcr.io/thoroslives/zilean:v3.10.1bce6aca0f6ca
curl@8.12.1-r0
8.18.0-r0
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
curl@8.5.0-2ubuntu10.5
8.5.0-2ubuntu10.7
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
curl@8.17.0-r1
8.18.0-r0
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
curl@8.17.0-r1
8.18.0-r0
1
ghcr.io/umami-software/umami:3.1.0e3f80c0625aa
curl@8.17.0-r1
8.18.0-r0
1
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u15
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u15
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
curl@7.88.1-10+deb12u6
7.88.1-10+deb12u15
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
1
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.7
1
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
curl@1:8.14.1-2+deb13u3+e1
1:8.14.1-2+deb13u3+e2
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
curl@7.88.1-10+deb12u7
7.88.1-10+deb12u15
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
curl@7.88.1-10+deb12u7
7.88.1-10+deb12u15
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u15
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.7
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.7
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.7
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
curl@8.17.0-r1
8.18.0-r0
1
quay.io/groundcover/tools:20260719b705e0cbe171
curl@1:8.14.1-2+deb13u3+e1
1:8.14.1-2+deb13u3+e2
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u15
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
curl@8.17.0-r1
8.18.0-r0
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
curl@8.17.0-r1
8.18.0-r0
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
curl@8.17.0-r1
8.18.0-r0
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
curl@8.14.1-2
8.14.1-2+deb13u4
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u15
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.