StackRadar

CVE-2025-14819

Medium

Advisory

Published 6 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
656
of 17,787 indexed, latest versions
Container images
651
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 656 of 17,787 indexed charts deploy, on 651 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4+16 more1:8.14.1-2+deb13u3+e2, 7.88.1-10+deb12u15, 8.5.0-2ubuntu10.7, 8.14.1-2+deb13u4+1 more546
curlapk8.12.1-r0, 8.17.0-r18.18.0-r0105
OSV records
ALPINE-CVE-2025-14819DEBIAN-CVE-2025-14819UBUNTU-CVE-2025-14819ECHO-2c28-953d-b5a0
Also known as
USN-8062-1

Charts affected

656 by stars
ChartLatestAffected imagesRadar Score
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2025-14819.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15

Open the chart page →

7,643
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-14819.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15

Open the chart page →

5,548
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2025-14819.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15

Open the chart page →

2,383
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-14819.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-14819.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
curl@7.88.1-10+deb12u7
7.88.1-10+deb12u15

Open the chart page →

13,197
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2025-14819.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.18.0-r0

Open the chart page →

1,571

Container images carrying it

651 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
boky/postfix:5.1.0aafc77238423
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
boky/postfix:4.4.0f3f247fd4252
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
1
budibase/database:2.1.0d90f656261c9
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
1
cars10/elasticvue:1.15.0efddf4fa0fd8
curl@8.17.0-r1
8.18.0-r0
1
castlemock/castlemock:latestb7f3f1527ba9
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.7
1
castopod/castopod:1.12.101fd37280cbb2
curl@7.88.1-10+deb12u7
7.88.1-10+deb12u15
1
castopod/castopod:1.15.54e4f0440520f
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.7
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
chocobozzz/peertube:v8.1.5052712130691
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
1
ckulka/baikal:0.10.1-nginx434bdd162247
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
cm2network/squad:latest8cba47f53df5
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
collabora/code:24.04.13.2.101dc4ab83977
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
1
collabora/code:23.05.10.1.105299b452f7f
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15
1
conductoross/conductor:3.31.09fba127693e6
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
1
consensys/teku:25.4.1bf6ecd2ea716
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.7
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
curl@7.88.1-10+deb12u7
7.88.1-10+deb12u15
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
cspconsole/config-provider:1.0.365524a26a6c23
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
cspconsole/report-collector:1.0.15839750248193b
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u15
1
dannielkil/book-frontend:latest937993927694
curl@7.88.1-10+deb12u7
7.88.1-10+deb12u15
1
deconzcommunity/deconz:2.29.2062de2362641
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
dependencytrack/frontend:4.14.200560b57a6cf
curl@8.17.0-r1
8.18.0-r0
1
dgraph/dgraph:v24.1.4b57fa31f9b7f
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.7
1
diygod/rsshub:2025-11-097a6312cac0d5
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
dobtc/bitcoin:25.1a870f7cb1105
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u15
1
docmost/docmost:0.95.041c8d777cf23
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
docuseal/docuseal:2.4.17493fd7f6728
curl@8.17.0-r1
8.18.0-r0
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
curl@8.14.1-2
8.14.1-2+deb13u4
1
dolibarr/dolibarr:22.0.47ad88fc9b13c
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
domainmod/domainmod:4.23.04017bfe4c597
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
1
dragonflyoss/client:v0.1.82edf3e921f4e0
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u15
1
drumsergio/genieacs:1.2.16.028244054e1bf
curl@7.88.1-10+deb12u14
7.88.1-10+deb12u15
1
dserio83/velero-api:0.3.16b3d9115fee2
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
dserio83/velero-watchdog:0.1.8d5deae589229
curl@7.88.1-10+deb12u12
7.88.1-10+deb12u15
1
dunglas/mercure:v0.24.080fcb704a741
curl@8.17.0-r1
8.18.0-r0
1
dzikoysk/reposilite:3.5.264128c2d7a6ba
curl@8.5.0-2ubuntu10.6
8.5.0-2ubuntu10.7
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
elautoestopista/aeneabot:4.2.1125ba620d528
curl@8.17.0-r1
8.18.0-r0
1
emqx/ecp-ui:2.5.1e33e9816f147
curl@7.88.1-10+deb12u8
7.88.1-10+deb12u15
1
emqx/emqx:5.8.935b46f7aa7a0
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
curl@8.17.0-r1
8.18.0-r0
1
escaping/core-keeper-dedicated:latest87fa79255962
curl@8.14.1-2+deb13u2
8.14.1-2+deb13u4
1
esphome/esphome:2026.7.44866347cb5b4
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
1
esphome/esphome:2026.8.285abea33854b
curl@8.14.1-2+deb13u3
8.14.1-2+deb13u4
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.