StackRadar

CVE-2025-15367

Medium

Advisory

Published 20 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
666
of 17,787 indexed, latest versions
Container images
646
deployed by those charts
Fix available
9 of 15
affected packages

POP3 command injection in user-controlled commands

Carried by container images the latest versions of 666 of 17,787 indexed charts deploy, on 646 images.

Affected packageAffected versionsFixed inImages
python3.11deb3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more3.11.0~rc1-1~22.04.1~esm9180
python3.8deb3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more3.8.10-0ubuntu1~20.04.18+esm6100
python3.12deb3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+11 more3.12.3-1ubuntu0.1287
python3.10deb3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+16 more3.10.12-1~22.04.1580
python3.13deb3.13.5-2, 3.13.5-2+deb13u2, 3.13.5-2+deb13u4, 3.13.7-1ubuntu0.13.13.7-1ubuntu0.474
python2.7deb2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 moreno fix listed54
python3.6deb3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more3.6.9-1~18.04ubuntu1.13+esm944
python3.5deb3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.93.5.2-2ubuntu0~16.04.13+esm2225
python-3.13apk3.13.7-r0, 3.13.10-r0, 3.13.12-r2, 3.13.15-r1+3 moreno fix listed10
python-3.14apk3.14.2-r2, 3.14.4-r2, 3.14.6-r0, 3.14.7-r1+2 moreno fix listed9
python-3.12apk3.12.0-r1, 3.12.9-r1, 3.12.14-r2, 3.12.14-r6no fix listed8
python3.4deb3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.73.4.3-1ubuntu1~14.04.7+esm207
pythonbitnami3.11.11-0, 3.12.8-0, 3.13.5-13.15.03
python-3.11apk3.11.16-r5no fix listed1
python3rpm3.12.9-13.azl3no fix listed1
OSV records
BIT-python-2025-15367CGA-3h86-qrh3-64w8CGA-5336-j8mr-r6g4CGA-8fx3-25f8-fh5xCGA-c39r-w42m-w4vjDEBIAN-CVE-2025-15367UBUNTU-CVE-2025-15367AZL-75038
Also known as
BIT-libpython-2025-15367, BIT-python-min-2025-15367, CGA-ch3p-52mr-p765, CGA-ffmr-pm2v-8xqw, CGA-fhp9-r9rg-wpv2, CGA-wx55-qrwh-xc7r, PSF-2026-4, USN-8018-1, USN-8018-2

Charts affected

666 by stars
ChartLatestAffected imagesRadar Score
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
python3.10@3.10.12-1~22.04.11
3.10.12-1~22.04.15

Open the chart page →

27,267
geonode-k8sgeonode-k8sVerified publisher2.0.02 of 10See more

geonode-k8s geonode-k8s 2.0.0

2 of the 10 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
python3.10@3.10.12-1~22.04.15
no fix listed
geopython/pycsw:3.0.0-beta284662ea6b78b
python3.11@3.11.2-6+deb12u6
no fix listed

Open the chart page →

13,953
gitops-promotergitops-promoterOfficialVerified publisher0.17.01 of 2See more

gitops-promoter gitops-promoter 0.17.0

1 of the 2 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
python3.13@3.13.5-2+deb13u4
no fix listed

Open the chart page →

2,814
glpiglpi-conteiner0.1.01 of 3See more

glpi glpi-conteiner 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
python3.11@3.11.2-6+deb12u2
no fix listed

Open the chart page →

12,170
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
python3.12@3.12.3-1ubuntu0.15
no fix listed

Open the chart page →

9,460
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
python3.12@3.12.3-1ubuntu0.11
3.12.3-1ubuntu0.12
apache/hertzbeat-collector:1.8.0a2bab1be574c
python3.12@3.12.3-1ubuntu0.11
3.12.3-1ubuntu0.12

Open the chart page →

14,000
kamu-api-serverkamuVerified publisher0.89.01 of 1See more

kamu-api-server kamu 0.89.0

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
python3.8@3.8.10-0ubuntu1~20.04.18
3.8.10-0ubuntu1~20.04.18+esm6

Open the chart page →

6,307
kubeflowkubeflow1.6.22 of 45See more

kubeflow kubeflow 1.6.2

2 of the 45 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
python3.6@3.6.9-1~18.04ubuntu1.4
3.6.9-1~18.04ubuntu1.13+esm9
library/python:3.7eedf63967cdb
python3.11@3.11.2-6
no fix listed

Open the chart page →

96,941
testkubekubeshop2.13.21See more

testkube kubeshop 2.13.2

1 container image this version deploys carries CVE-2025-15367.

Container imageDigestPackageFixed in
kubeshop/bitnami-mongodb:8.3.8d48b172d99d8
python3.12@3.12.3-1ubuntu0.15
no fix listed

Open the chart page →

topolvmtopolvmVerified publisher17.2.01 of 1See more

topolvm topolvm 17.2.0

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
python3.10@3.10.12-1~22.04.17
no fix listed

Open the chart page →

2,316
uffizzi-appuffizzi-app1.3.01 of 14See more

uffizzi-app uffizzi-app 1.3.0

1 of the 14 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
python3.11@3.11.2-6
no fix listed

Open the chart page →

19,337
grafana-pdf-exporterwiremindVerified publisher2.1.11 of 1See more

grafana-pdf-exporter wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
python3.11@3.11.2-6
no fix listed

Open the chart page →

9,746
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
python3.8@3.8.10-0ubuntu1~20.04.8
3.8.10-0ubuntu1~20.04.18+esm6

Open the chart page →

7,960
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
python3.11@3.11.2-6+deb12u4
no fix listed

Open the chart page →

17,404
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
python3.11@3.11.2-6+deb12u5
no fix listed

Open the chart page →

28,839
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
python3.13@3.13.5-2
no fix listed

Open the chart page →

9,316
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
python3.12@3.12.3-1ubuntu0.3
3.12.3-1ubuntu0.12

Open the chart page →

4,147
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
python2.7@2.7.17-1~18.04ubuntu1.6
python3.6@3.6.9-1~18.04ubuntu1.4
no fix listed
3.6.9-1~18.04ubuntu1.13+esm9

Open the chart page →

22,773
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm6

Open the chart page →

10,598
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
python3.8@3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm6

Open the chart page →

10,154
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
python3.8@3.8.10-0ubuntu1~20.04.1
3.8.10-0ubuntu1~20.04.18+esm6

Open the chart page →

10,628
coreinstill-aiOfficialVerified publisher0.1.753 of 15See more

core instill-ai 0.1.75

3 of the 15 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
instill/artifact-backend:b28766ac4a393e601ed
python3.13@3.13.5-2
no fix listed
instill/mgmt-backend:d0933d4ebe12f77a3f9
python3.13@3.13.5-2
no fix listed
instill/model-backend:611f0f2e980125e5ba5
python3.13@3.13.5-2
no fix listed

Open the chart page →

30,816
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
python3.12@3.12.3-1ubuntu0.2
3.12.3-1ubuntu0.12

Open the chart page →

4,309
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
python3.12@3.12.3-1ubuntu0.15
no fix listed

Open the chart page →

4,477
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
python3.8@3.8.10-0ubuntu1~20.04.18
3.8.10-0ubuntu1~20.04.18+esm6

Open the chart page →

11,582
lightsteplightstepsatellite1.2.41 of 1See more

lightstep lightstepsatellite 1.2.4

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
python3.5@3.5.2-2ubuntu0~16.04.5
3.5.2-2ubuntu0~16.04.13+esm22

Open the chart page →

15,330
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
python3.11@3.11.2-6+deb12u7
no fix listed

Open the chart page →

5,218
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
python3.12@3.12.3-1ubuntu0.9
3.12.3-1ubuntu0.12

Open the chart page →

107,811
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.48.10f6c1c4b957d2
python3.10@3.10.12-1~22.04.11
3.10.12-1~22.04.15

Open the chart page →

13,521
nominatimrobjuz6.4.11 of 4See more

nominatim robjuz 6.4.1

1 of the 4 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
mediagis/nominatim:5.3.27923a8e67197
python3.12@3.12.3-1ubuntu0.13
no fix listed

Open the chart page →

8,690
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm6

Open the chart page →

24,488
freeradiusstartechnicaVerified publisher1.2.01 of 1See more

freeradius startechnica 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.2.8af6fd34a5b78
python2.7@2.7.18-13ubuntu1.5
python3.10@3.10.12-1~22.04.10
no fix listed
3.10.12-1~22.04.15

Open the chart page →

5,751
sn-platformstreamnative1.11.441 of 9See more

sn-platform streamnative 1.11.44

1 of the 9 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
python3.8@3.8.10-0ubuntu1~20.04.9
3.8.10-0ubuntu1~20.04.18+esm6

Open the chart page →

15,477
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
pretix/standalone:2026.7.05df3b7aa852e
python3.13@3.13.5-2+deb13u4
no fix listed

Open the chart page →

9,770
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
wger/server:2.6997ead43aabd
python3.12@3.12.3-1ubuntu0.13
no fix listed

Open the chart page →

8,491
paperless-ngxadnoctemVerified publisher0.4.21 of 5See more

paperless-ngx adnoctem 0.4.2

1 of the 5 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
python3.13@3.13.5-2+deb13u4
no fix listed

Open the chart page →

19,691
github-actions-runneradwerx0.10.31 of 1See more

github-actions-runner adwerx 0.10.3

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
python3.8@3.8.5-1~20.04
3.8.10-0ubuntu1~20.04.18+esm6

Open the chart page →

13,635
agentareaagentareaVerified publisher0.0.181 of 16See more

agentarea agentarea 0.0.18

1 of the 16 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
agentarea/agentarea-mcp-runner:latestd3c209a5d531
python3.11@3.11.2-6+deb12u8
no fix listed

Open the chart page →

14,914
akeyless-api-gatewayakeyless-services-helmVerified publisher1.62.221 of 1See more

akeyless-api-gateway akeyless-services-helm 1.62.22

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
akeyless/base:latest759e4289fae8
python3.12@3.12.3-1ubuntu0.13
no fix listed

Open the chart page →

2,358
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
python3.6@3.6.9-1~18.04ubuntu1.7
3.6.9-1~18.04ubuntu1.13+esm9

Open the chart page →

12,046
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
python3.13@3.13.5-2+deb13u4
no fix listed

Open the chart page →

5,880
antreaantreaVerified publisher2.7.01 of 2See more

antrea antrea 2.7.0

1 of the 2 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
python3.12@3.12.3-1ubuntu0.15
no fix listed

Open the chart page →

3,231
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
python3.10@3.10.12-1~22.04.10
3.10.12-1~22.04.15

Open the chart page →

7,740
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
python2.7@2.7.18-1~20.04.3
no fix listed

Open the chart page →

17,896
dltbrokerassist-iot-distributed-broker0.2.02 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

2 of the 9 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
python2.7@2.7.12-1ubuntu0~16.04.3
python3.5@3.5.2-2ubuntu0~16.04.4
no fix listed
3.5.2-2ubuntu0~16.04.13+esm22
hyperledger/fabric-couchdb:0.4.15f6c724592abf
python2.7@2.7.12-1ubuntu0~16.04.4
python3.5@3.5.2-2ubuntu0~16.04.5
no fix listed
3.5.2-2ubuntu0~16.04.13+esm22

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.02 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

2 of the 9 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
python2.7@2.7.12-1ubuntu0~16.04.3
python3.5@3.5.2-2ubuntu0~16.04.4
no fix listed
3.5.2-2ubuntu0~16.04.13+esm22
hyperledger/fabric-couchdb:0.4.15f6c724592abf
python2.7@2.7.12-1ubuntu0~16.04.4
python3.5@3.5.2-2ubuntu0~16.04.5
no fix listed
3.5.2-2ubuntu0~16.04.13+esm22

Open the chart page →

77,687
autonomous-plant-opsautonomous-plant-opsOfficialVerified publisher0.3.04 of 5See more

autonomous-plant-ops autonomous-plant-ops 0.3.0

4 of the 5 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
ghcr.io/thotischner/autonomous-plant-ops/dashboard-api:1.1.0af663f4ba6e4
python-3.12@3.12.14-r6
no fix listed
ghcr.io/thotischner/autonomous-plant-ops/llm-agent:1.1.059e362c2b669
python-3.12@3.12.14-r6
no fix listed
ghcr.io/thotischner/autonomous-plant-ops/orchestrator:1.1.01beb0658f9e3
python-3.12@3.12.14-r6
no fix listed
ghcr.io/thotischner/autonomous-plant-ops/sensor-simulator:1.1.0f02bb7b28e8a
python-3.12@3.12.14-r6
no fix listed

Open the chart page →

470
music-assistantbdclark-helm-chartsVerified publisher0.4.131 of 1See more

music-assistant bdclark-helm-charts 0.4.13

1 of the 1 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.10.3885872224fa5
python3.13@3.13.5-2+deb13u4
no fix listed

Open the chart page →

3,657
open-elevationbeeinventor0.1.01 of 2See more

open-elevation beeinventor 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
openelevation/open-elevation:latest82fb21612e86
python3.8@3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.18+esm6

Open the chart page →

13,145
aramid-indexerbiatec-repoVerified publisher3.9.01 of 5See more

aramid-indexer biatec-repo 3.9.0

1 of the 5 container images this version deploys carry CVE-2025-15367.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
python3.12@3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.12

Open the chart page →

13,357

Container images carrying it

646 by charts deploying them

A fixed version is listed for 9 of the 15 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
python3.12@3.12.3-1ubuntu0.10
3.12.3-1ubuntu0.12
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
python3.8@3.8.10-0ubuntu1~20.04.13
3.8.10-0ubuntu1~20.04.18+esm6
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
python3.8@3.8.10-0ubuntu1~20.04.13
3.8.10-0ubuntu1~20.04.18+esm6
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
python3.12@3.12.3-1ubuntu0.13
no fix listed
1
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
python3.13@3.13.5-2+deb13u4
no fix listed
1
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
python-3.14@3.14.4-r2
no fix listed
1
ghcr.io/thotischner/autonomous-plant-ops/dashboard-api:1.1.0af663f4ba6e4
python-3.12@3.12.14-r6
no fix listed
1
ghcr.io/thotischner/autonomous-plant-ops/llm-agent:1.1.059e362c2b669
python-3.12@3.12.14-r6
no fix listed
1
ghcr.io/thotischner/autonomous-plant-ops/orchestrator:1.1.01beb0658f9e3
python-3.12@3.12.14-r6
no fix listed
1
ghcr.io/thotischner/autonomous-plant-ops/sensor-simulator:1.1.0f02bb7b28e8a
python-3.12@3.12.14-r6
no fix listed
1
ghcr.io/topolvm/pie:0.18.0aa467443e407
python3.10@3.10.12-1~22.04.17
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
python3.10@3.10.12-1~22.04.17
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
python3.10@3.10.12-1~22.04.6
3.10.12-1~22.04.15
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
python3.11@3.11.2-6+deb12u6
no fix listed
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
python3.11@3.11.2-6
no fix listed
1
ghcr.io/wittdennis/homeassistant-otbr:4.2.31b53b0b3488e
python3.13@3.13.5-2+deb13u4
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
python3.11@3.11.2-6
no fix listed
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
python3.11@3.11.2-6+deb12u5
no fix listed
1
ghcr.io/zazukoians/qlever-server:v0.10.0f10fd24b2290
python3.12@3.12.3-1ubuntu0.15
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
python3.11@3.11.2-6+deb12u4
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
python3.11@3.11.2-6+deb12u4
no fix listed
1
mcr.microsoft.com/acstor/local-csi-driver:v0.3.0f9af53a79fd1
python3@3.12.9-13.azl3
no fix listed
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
python2.7@2.7.17-1~18.04ubuntu1.11
python3.6@3.6.9-1~18.04ubuntu1.12
no fix listed
3.6.9-1~18.04ubuntu1.13+esm9
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
python3.8@3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.18+esm6
1
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
python3.12@3.12.3-1ubuntu0.15
no fix listed
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
python3.10@3.10.12-1~22.04.16
no fix listed
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
python3.12@3.12.3-1ubuntu0.13
no fix listed
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
python2.7@2.7.17-1~18.04ubuntu1.11
python3.6@3.6.9-1~18.04ubuntu1.12
no fix listed
3.6.9-1~18.04ubuntu1.13+esm9
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
python3.11@3.11.2-6+deb12u3
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
python3.11@3.11.2-6
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
python3.11@3.11.2-6
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
python3.8@3.8.5-1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm6
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
python3.11@3.11.2-6
no fix listed
1
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
python3.13@3.13.5-2+deb13u4
no fix listed
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
python3.6@3.6.9-1~18.04ubuntu1.8
3.6.9-1~18.04ubuntu1.13+esm9
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
python3.12@3.12.3-1ubuntu0.9
3.12.3-1ubuntu0.12
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
python-3.14@3.14.2-r2
no fix listed
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
python-3.14@3.14.2-r2
no fix listed
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
python-3.14@3.14.2-r2
no fix listed
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
python-3.14@3.14.2-r2
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
python3.11@3.11.2-6
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
python3.12@3.12.3-1ubuntu0.15
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
python3.11@3.11.2-6+deb12u7
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
python3.8@3.8.5-1~20.04.2
3.8.10-0ubuntu1~20.04.18+esm6
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
python3.11@3.11.2-6+deb12u7
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
python3.11@3.11.2-6+deb12u5
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.