StackRadar

CVE-2025-15469

Medium

Advisory

Published 27 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
356
of 17,787 indexed, latest versions
Container images
362
deployed by those charts
Fix available
2 of 3
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 356 of 17,787 indexed charts deploy, on 362 images.

Affected packageAffected versionsFixed inImages
opensslapk3.2.0-r0, 3.3.1-r4, 3.3.2-r0, 3.3.2-r2+8 more3.5.5-r0, 3.6.1-r0283
openssldeb3.5.1-1, 3.5.1-1+deb13u1, 3.5.3-1ubuntu2, 3.5.4-1~deb13u13.5.3-1ubuntu3, 3.5.4-1~deb13u263
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
OSV records
ALPINE-CVE-2025-15469CGA-cxqr-wch6-w4mpDEBIAN-CVE-2025-15469UBUNTU-CVE-2025-15469
Also known as
CGA-h6xg-wcqx-j6v6, USN-7980-1

Charts affected

356 by stars
ChartLatestAffected imagesRadar Score
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2025-15469.

Container imageDigestPackageFixed in
vcnngr/pnfrontend:latest4e4979ab8c41
openssl@3.5.1-r0
3.5.5-r0

Open the chart page →

4,768
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-15469.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
nodejs@20.11.1-1nodesource1
no fix listed

Open the chart page →

9,347
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2025-15469.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
openssl@3.5.2-r0
3.5.5-r0

Open the chart page →

athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2025-15469.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:latestab6f1a1f0fb4
openssl@3.5.4-r0
3.5.5-r0

Open the chart page →

4,984
wexa-studiowexa-studio1.2.03 of 15See more

wexa-studio wexa-studio 1.2.0

3 of the 15 container images this version deploys carry CVE-2025-15469.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
openssl@3.5.0-r0
3.5.5-r0
temporalio/server:1.29.1c1e3326b2ce1
openssl@3.5.0-r0
3.5.5-r0
temporalio/ui:2.44.00b36e00aad30
openssl@3.5.4-r0
3.5.5-r0

Open the chart page →

14,983
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-15469.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
nodejs@20.15.0-1nodesource1
no fix listed

Open the chart page →

14,100

Container images carrying it

362 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/appscode/scanner:v0.0.2116907aae5de1
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/appscode/taskqueue:v0.0.36877c958a3c6
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/appscode/trickster:v2.0.0cdbbed831f28
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/bensoer/external-secrets-reloader:v0.1.38e31b5a81853
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/bensoer/sibyl:v0.2.06dca4455fde3
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
openssl@3.5.2-r0
3.6.1-r0
1
ghcr.io/b-it-projects-gmbh/nvme_exporter:lateste70307b193c6
openssl@3.5.0-r0
3.5.5-r0
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/browsersec/kubebrowse-frontend:chore-improve-backbd6bea5e487c
openssl@3.5.1-r0
3.5.5-r0
1
ghcr.io/bryopsida/patchwork:mainc01e018bced4
openssl@3.5.0-r0
3.5.5-r0
1
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
openssl@3.5.1-r0
3.5.5-r0
1
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
openssl@3.5.0-r0
3.5.5-r0
1
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
openssl@3.5.1-r0
3.5.5-r0
1
ghcr.io/cloudscript-technology/k8s-monitoring-app:v0.0.25cab66a6b3574
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/cloudtty/cloudshell:v0.8.900984ba0f0eb
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/cncf/clowarden/dbmigrator:v0.2.3c022fd42de45
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/cncf/clowarden/server:v0.2.3f9379427b917
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/cncf/gitvote/dbmigrator:v1.5.0f1e7efe440da
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/cncf/gitvote/server:v1.5.026167f01c898
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/cndoit18/lxcfs-agent:latest9853bb613cd0
openssl@3.5.0-r0
3.5.5-r0
1
ghcr.io/cndoit18/lxcfs-manager:latest6bb61ded2625
openssl@3.5.0-r0
3.5.5-r0
1
ghcr.io/cosanet/cosanet:1.0.098cb5d9fa215
openssl@3.5.1-1
3.5.4-1~deb13u2
1
ghcr.io/crazygit/cert-manager-alidns-webhook:0.1.4976be6506eb6
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/crazy-max/cloudflared:2025.9.19b4e856d18f6
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
openssl@3.5.4-1~deb13u1
3.5.4-1~deb13u2
1
ghcr.io/dexidp/dex:v2.44.05d0656fce7d4
openssl@3.5.1-r0
3.5.5-r0
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
openssl@3.5.1-1+deb13u1
3.5.4-1~deb13u2
1
ghcr.io/eminaktas/oom-tracer:v0.1.0c90ca8389c87
openssl@3.5.1-r0
3.5.5-r0
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
openssl@3.5.1-r0
3.5.5-r0
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
openssl@3.5.1-r0
3.5.5-r0
1
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
openssl@3.5.4-1~deb13u1
3.5.4-1~deb13u2
1
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
openssl@3.5.4-1~deb13u1
3.5.4-1~deb13u2
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
openssl@3.5.1-1+deb13u1
3.5.4-1~deb13u2
1
ghcr.io/gochain/rpc-proxy/rpc-proxy:latestca01f5ab95f7
openssl@3.5.1-r0
3.5.5-r0
1
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.2c7adcc4db378
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
openssl@3.5.1-r0
3.5.5-r0
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
openssl@3.5.0-r0
3.5.5-r0
1
ghcr.io/home-operations/lidarr:3.1.2.4902dab0e07502a3
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/home-operations/prowlarr:2.3.01a8a4b11972b
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/huseyinbabal/kubetag:lateste161eddc59a0
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
openssl@3.5.1-1+deb13u1
3.5.4-1~deb13u2
1
ghcr.io/innago-property-management/innago-vault-k8s-role-operator:2.0.0ed1c3fd04057
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/interplex-ai/interplex:v1.1.041b0dd0d55b2
openssl@3.5.0-r0
3.5.5-r0
1
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
openssl@3.5.1-r0
3.5.5-r0
1
ghcr.io/kadajett/podscope:0.2.3eeedf17112d7
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/kagent-dev/doc2vec/mcp:1.1.14ace1de323f4a
openssl@3.6.0-r4
3.6.1-r0
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
openssl@3.5.1-r0
3.5.5-r0
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
openssl@3.5.1-r0
3.5.5-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.