StackRadar

CVE-2025-15468

Medium

Advisory

Published 27 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
768
of 17,787 indexed, latest versions
Container images
811
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2025-15468 affecting package openssl for versions less than 3.3.5-3

Carried by container images the latest versions of 768 of 17,787 indexed charts deploy, on 811 images.

Affected packageAffected versionsFixed inImages
opensslapk3.2.0-r0, 3.3.0-r2, 3.3.1-r0, 3.3.1-r1+18 more3.3.6-r0, 3.5.5-r0, 3.6.1-r0731
openssldeb3.5.1-1, 3.5.1-1+deb13u1, 3.5.3-1ubuntu2, 3.5.4-1~deb13u13.5.3-1ubuntu3, 3.5.4-1~deb13u263
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
opensslrpm3.3.5-1.azl33.3.5-31
OSV records
ALPINE-CVE-2025-15468CGA-cfrp-4x8p-ghrrDEBIAN-CVE-2025-15468UBUNTU-CVE-2025-15468AZL-75278
Also known as
CGA-vmpm-7qr6-cwvf, USN-7980-1

Charts affected

768 by stars
ChartLatestAffected imagesRadar Score
clickhousepascaliskeVerified publisher1.0.01 of 1See more

clickhouse pascaliske 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.12.6.70-alpinecd450891db46
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

345
cloudflaredpascaliskeVerified publisher3.0.01 of 1See more

cloudflared pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/cloudflared:2025.9.19b4e856d18f6
openssl@3.5.4-r0
3.5.5-r0

Open the chart page →

2,029
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
openssl@3.5.4-r0
3.5.5-r0

Open the chart page →

4,788
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
openssl@3.5.4-1~deb13u1
3.5.4-1~deb13u2

Open the chart page →

3,866
plausiblepascaliskeVerified publisher2.0.01 of 1See more

plausible pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
openssl@3.3.2-r1
3.3.6-r0

Open the chart page →

959
vaultwardenpascaliskeVerified publisher2.0.01 of 1See more

vaultwarden pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
openssl@3.5.4-1~deb13u1
3.5.4-1~deb13u2

Open the chart page →

3,405
stk-fluent-bit-loki-s3paxtecnologia0.2.02 of 6See more

stk-fluent-bit-loki-s3 paxtecnologia 0.2.0

2 of the 6 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
library/memcached:1.6.39-alpinec8503d4491ed
openssl@3.5.4-r0
3.5.5-r0
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
openssl@3.5.4-r0
3.5.5-r0

Open the chart page →

3,742
everest-db-namespacepercona1.13.01 of 1See more

everest-db-namespace percona 1.13.0

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
percona/everest-helmtools:0.0.1904458d04a18
openssl@3.3.4-r0
3.3.6-r0

Open the chart page →

768
planectlplanectlVerified publisher0.7.03 of 10See more

planectl planectl 0.7.0

3 of the 10 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
alpine/k8s:1.30.2cd560fce90f7
openssl@3.3.1-r0
3.3.6-r0
gitea/act_runner:0.2.11c57233403eff
openssl@3.3.2-r0
3.3.6-r0
library/redis:7.4.2-alpine02419de7eddf
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

25,626
plausibleplausible0.1.21 of 2See more

plausible plausible 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
openssl@3.3.2-r0
3.3.6-r0

Open the chart page →

1,337
k8s-node-image9-1-24pnnl-miscscripts0.2.1492 of 2See more

k8s-node-image9-1-24 pnnl-miscscripts 0.2.149

2 of the 2 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
openssl@3.3.2-r1
3.3.6-r0
pnnlmiscscripts/k8s-node-image9:1.24.17-nginx-882c8dc938b2f9
openssl@3.3.2-r0
3.3.6-r0

Open the chart page →

1,491
k8s-node-image9-1-25pnnl-miscscripts0.2.1052 of 2See more

k8s-node-image9-1-25 pnnl-miscscripts 0.2.105

2 of the 2 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
openssl@3.3.2-r1
3.3.6-r0
pnnlmiscscripts/k8s-node-image9:1.25.16-nginx-772c202c43c0aa
openssl@3.3.2-r0
3.3.6-r0

Open the chart page →

1,491
k8s-node-image9-1-26pnnl-miscscripts0.2.922 of 2See more

k8s-node-image9-1-26 pnnl-miscscripts 0.2.92

2 of the 2 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
openssl@3.3.2-r1
3.3.6-r0
pnnlmiscscripts/k8s-node-image9:1.26.15-nginx-579785e5b82334
openssl@3.3.2-r0
3.3.6-r0

Open the chart page →

1,491
k8s-node-image9-1-27pnnl-miscscripts0.2.902 of 2See more

k8s-node-image9-1-27 pnnl-miscscripts 0.2.90

2 of the 2 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
openssl@3.3.2-r1
3.3.6-r0
pnnlmiscscripts/k8s-node-image9:1.27.16-nginx-306e1a36d646a3
openssl@3.3.2-r0
3.3.6-r0

Open the chart page →

1,491
k8s-node-image9-1-28pnnl-miscscripts0.2.1022 of 2See more

k8s-node-image9-1-28 pnnl-miscscripts 0.2.102

2 of the 2 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
openssl@3.3.2-r1
3.3.6-r0
pnnlmiscscripts/k8s-node-image9:1.28.15-nginx-72b91d6a46e06
openssl@3.3.2-r0
3.3.6-r0

Open the chart page →

1,491
k8s-node-image9-1-29pnnl-miscscripts0.2.642 of 2See more

k8s-node-image9-1-29 pnnl-miscscripts 0.2.64

2 of the 2 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
openssl@3.3.2-r1
3.3.6-r0
pnnlmiscscripts/k8s-node-image9:1.29.10-nginx-7fcd82530bc8b
openssl@3.3.2-r0
3.3.6-r0

Open the chart page →

1,491
k8s-node-image9-1-30pnnl-miscscripts0.2.561 of 2See more

k8s-node-image9-1-30 pnnl-miscscripts 0.2.56

1 of the 2 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
pnnlmiscscripts/k8s-node-image9:1.30.11-nginx-7f9297eea817d
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

619
k8s-node-image9-1-31pnnl-miscscripts0.2.271 of 2See more

k8s-node-image9-1-31 pnnl-miscscripts 0.2.27

1 of the 2 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
pnnlmiscscripts/k8s-node-image9:1.31.7-nginx-7e3e189d9d519
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

619
k8s-oidc-discovery-providerpnnl-miscscripts0.1.21 of 2See more

k8s-oidc-discovery-provider pnnl-miscscripts 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
curlimages/curl:8.17.0935d9100e9ba
openssl@3.5.4-r0
3.5.5-r0

Open the chart page →

4,273
podscopepodscope0.2.31 of 1See more

podscope podscope 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/kadajett/podscope:0.2.3eeedf17112d7
openssl@3.5.4-r0
3.5.5-r0

Open the chart page →

1,485
libretimepodzone-chartsVerified publisher0.4.11 of 9See more

libretime podzone-charts 0.4.1

1 of the 9 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
library/rabbitmq:3.12-alpine97907aceae0a
openssl@3.3.2-r0
3.3.6-r0

Open the chart page →

11,181
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
library/rabbitmq:3-management-alpine606d8c0d6b3c
openssl@3.5.4-r0
3.5.5-r0

Open the chart page →

28,495
trino-loadbalancerpresto-loadbalancer0.3.11 of 1See more

trino-loadbalancer presto-loadbalancer 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
datappeal/trino-loadbalancer:sha-950abbae6b5b9fdb2e6d
openssl@3.5.1-r0
3.5.5-r0

Open the chart page →

2,357
prismeai-appsprismeai0.7.11 of 4See more

prismeai-apps prismeai 0.7.1

1 of the 4 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
openssl@3.5.4-r0
3.5.5-r0

Open the chart page →

2,752
prismeai-coreprismeai1.12.11 of 7See more

prismeai-core prismeai 1.12.1

1 of the 7 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
openssl@3.5.4-r0
3.5.5-r0

Open the chart page →

3,271
prompt-dbprompt-dbVerified publisher1.0.71 of 3See more

prompt-db prompt-db 1.0.7

1 of the 3 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/erlkoenig91/prompt-db-frontend:1.0.7121dc29eb14d
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

3,312
pumperlypumperlyVerified publisher0.1.21 of 3See more

pumperly pumperly 0.1.2

1 of the 3 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
postgis/postgis:17-3.4-alpine5a1dbedac34e
openssl@3.3.2-r0
3.3.6-r0

Open the chart page →

2,853
rabbitpingrabbitping1.3.01 of 1See more

rabbitping rabbitping 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
udhos/rabbitping:1.3.0474c467bbf42
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

889
app-config-frontendradar-baseVerified publisher2.4.11 of 1See more

app-config-frontend radar-base 2.4.1

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-app-config/radar-app-config-frontend:0.6.2c5f1e2ca5781
openssl@3.3.2-r1
3.3.6-r0

Open the chart page →

807
kubecostradar-baseVerified publisher1.0.04 of 7See more

kubecost radar-base 1.0.0

4 of the 7 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
openssl@3.3.2-r0
3.3.6-r0
gcr.io/kubecost1/frontend:prod-2.6.3a535f7de024b
openssl@3.4.1-r0
3.6.1-r0
gcr.io/kubecost1/kubecost-network-costs:v0.17.6ab6a54c53fd8
openssl@3.3.2-r0
3.6.1-r0
ghcr.io/kiwigrid/k8s-sidecar:1.29.142002d66ddb3
openssl@3.3.2-r4
3.3.6-r0

Open the chart page →

9,389
radar-grafanaradar-baseVerified publisher0.1.41 of 2See more

radar-grafana radar-base 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
grafana/grafana:11.6.062d2b9d20a19
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

1,667
radar-homeradar-baseVerified publisher0.5.51 of 1See more

radar-home radar-base 0.5.5

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-home/radar-home:0.1.71cfe3da9d812
openssl@3.3.2-r1
3.3.6-r0

Open the chart page →

807
radar-hydraradar-baseVerified publisher0.3.42 of 2See more

radar-hydra radar-base 0.3.4

2 of the 2 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
curlimages/curl:8.15.04026b29997dc
openssl@3.5.1-r0
3.5.5-r0
oryd/hydra:v2.3.0b94007e19a1f
openssl@3.3.2-r1
3.3.6-r0

Open the chart page →

2,178
radar-kratosradar-baseVerified publisher0.1.51 of 1See more

radar-kratos radar-base 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
oryd/kratos:v1.3.1fe2428f103a6
openssl@3.3.2-r1
3.3.6-r0

Open the chart page →

1,561
radar-rest-sources-authorizerradar-baseVerified publisher2.3.41 of 1See more

radar-rest-sources-authorizer radar-base 2.3.4

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-rest-source-auth/radar-rest-source-authorizer:4.4.153e096497f7db
openssl@3.3.2-r1
3.3.6-r0

Open the chart page →

807
radar-self-enrolment-uiradar-baseVerified publisher0.4.21 of 1See more

radar-self-enrolment-ui radar-base 0.4.2

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
openssl@3.5.4-r0
3.5.5-r0

Open the chart page →

1,506
radar-upload-connect-frontendradar-baseVerified publisher0.8.11 of 1See more

radar-upload-connect-frontend radar-base 0.8.1

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-frontend:0.6.47e27863545fc
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

936
readability-js-serverreadability-js-server0.1.01 of 1See more

readability-js-server readability-js-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
phpdockerio/readability-js-server:1.8.0ea8354b42600
openssl@3.5.4-r0
3.5.5-r0

Open the chart page →

1,859
recipe-apprecipe-app0.1.02 of 2See more

recipe-app recipe-app 0.1.0

2 of the 2 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
openssl@3.3.3-r0
3.3.6-r0
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

3,271
helm-redchefredchef0.1.01 of 3See more

helm-redchef redchef 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
sharanalwar/redchef-frontend:latest5e82950b16b7
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

4,658
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
openssl@3.3.1-r0
3.3.6-r0

Open the chart page →

5,928
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

4,546
memosrm3lVerified publisher0.1.11 of 1See more

memos rm3l 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
neosmemo/memos:0.24c6defc2dfb98
openssl@3.5.0-r0
3.5.5-r0

Open the chart page →

1,614
wallosrm3lVerified publisher0.1.01 of 1See more

wallos rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/ellite/wallos:2.46.09ce55520e7bd
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

1,528
wg-easyrm3lVerified publisher0.2.01 of 1See more

wg-easy rm3l 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
openssl@3.5.0-r0
3.5.5-r0

Open the chart page →

1,158
kubewatchrobusta3.5.01 of 1See more

kubewatch robusta 3.5.0

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
robustadev/kubewatch:v2.9.00457a51e36e8
openssl@3.3.2-r0
3.6.1-r0

Open the chart page →

1,821
fleet-vendoredrock8sVerified publisher6.5.11 of 1See more

fleet-vendored rock8s 6.5.1

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
fleetdm/fleet:v4.66.012e644b7f40e
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

1,581
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
vectorim/element-web:v1.11.9613d0ea68d7ff
openssl@3.3.3-r0
3.3.6-r0

Open the chart page →

9,275
monitoringrocketchat-server0.0.171 of 9See more

monitoring rocketchat-server 0.0.17

1 of the 9 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.30.98c06e1ba643a
openssl@3.5.1-r0
3.5.5-r0

Open the chart page →

6,860
jaegerromanow-helm-chartsVerified publisher1.7.31 of 1See more

jaeger romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2025-15468.

Container imageDigestPackageFixed in
jaegertracing/jaeger:2.9.0e128b9adbb29
openssl@3.5.1-r0
3.5.5-r0

Open the chart page →

1,598

Container images carrying it

811 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/reactiveops/rbac-manager:v1.9.587e3f461446f
openssl@3.5.4-r0
3.5.5-r0
1
quay.io/shivering-isles/dovecot:2.3.214599ada9aa06
openssl@3.3.1-r3
3.3.6-r0
1
quay.io/underndog/samba:1.2.0-not-recyclecca801de9fa5
openssl@3.3.3-r0
3.3.6-r0
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
openssl@3.5.1-r0
3.5.5-r0
1
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
openssl@3.3.3-r0
3.3.6-r0
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssl@3.5.1-1
3.5.4-1~deb13u2
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
openssl@3.5.2-r0
3.5.5-r0
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
openssl@3.5.1-r0
3.5.5-r0
1
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
openssl@3.3.2-r0
3.3.6-r0
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
openssl@3.3.2-r4
3.3.6-r0
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
openssl@3.5.4-r0
3.5.5-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.