StackRadar

CVE-2025-1632

Medium

Advisory

Published 24 Feb 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.003
27th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
13
of 17,781 indexed, latest versions
Container images
12
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 13 of 17,781 indexed charts deploy, on 12 images.

Affected packageAffected versionsFixed inImages
libarchivedeb3.6.2-1, 3.6.2-1+deb12u1, 3.6.2-1+deb12u3, 3.6.2-1+deb12u4+2 more3.7.2-2ubuntu0.410
libarchiveapk3.7.6-r0, 3.7.7-r03.7.9-r02
OSV records
ALPINE-CVE-2025-1632DEBIAN-CVE-2025-1632UBUNTU-CVE-2025-1632
Also known as
USN-7454-1

Charts affected

13 by stars
ChartLatestAffected imagesRadar Score
paperless-ngxcrystalnetVerified publisher0.2.221 of 3See more

paperless-ngx crystalnet 0.2.22

1 of the 3 container images this version deploys carry CVE-2025-1632.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
libarchive@3.6.2-1+deb12u1
no fix listed

Open the chart page →

13,761
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2025-1632.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
libarchive@3.6.2-1+deb12u1
no fix listed

Open the chart page →

11,458
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2025-1632.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
libarchive@3.6.2-1+deb12u3
no fix listed

Open the chart page →

7,740
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2025-1632.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
libarchive@3.6.2-1
no fix listed

Open the chart page →

9,412
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2025-1632.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
libarchive@3.7.2-2ubuntu0.1
3.7.2-2ubuntu0.4

Open the chart page →

16,954
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2025-1632.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
libarchive@3.6.2-1
no fix listed

Open the chart page →

13,241
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2025-1632.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
libarchive@3.6.2-1+deb12u4
no fix listed

Open the chart page →

9,077
medikeephelmforgeVerified publisher2.0.01 of 3See more

medikeep helmforge 2.0.0

1 of the 3 container images this version deploys carry CVE-2025-1632.

Container imageDigestPackageFixed in
ghcr.io/afairgiant/medikeep:v0.69.0766699daa9ac
libarchive@3.6.2-1+deb12u4
no fix listed

Open the chart page →

6,022
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2025-1632.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libarchive@3.6.2-1
no fix listed

Open the chart page →

16,384
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2025-1632.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
libarchive@3.7.2-2
3.7.2-2ubuntu0.4

Open the chart page →

45,239
pumperlypumperlyVerified publisher0.1.21 of 3See more

pumperly pumperly 0.1.2

1 of the 3 container images this version deploys carry CVE-2025-1632.

Container imageDigestPackageFixed in
postgis/postgis:17-3.4-alpine5a1dbedac34e
libarchive@3.7.6-r0
3.7.9-r0

Open the chart page →

2,854
scapyscapy-containerised0.3.41 of 2See more

scapy scapy-containerised 0.3.4

1 of the 2 container images this version deploys carry CVE-2025-1632.

Container imageDigestPackageFixed in
saidsef/scapy-containerised:v2025.02f17f7c435891
libarchive@3.7.7-r0
3.7.9-r0

Open the chart page →

2,817
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2025-1632.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
libarchive@3.7.2-2
3.7.2-2ubuntu0.4

Open the chart page →

45,239

Container images carrying it

12 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apache/tika:2.9.2.1-fullae0b86d3c4d0
libarchive@3.7.2-2
3.7.2-2ubuntu0.4
2
fluent/fluent-bit:4.0-debuge76397ef3983
libarchive@3.6.2-1+deb12u3
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
libarchive@3.6.2-1+deb12u4
no fix listed
1
localstack/localstack:3.19d278167f2b7
libarchive@3.6.2-1
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
libarchive@3.7.2-2ubuntu0.1
3.7.2-2ubuntu0.4
1
postgis/postgis:17-3.4-alpine5a1dbedac34e
libarchive@3.7.6-r0
3.7.9-r0
1
saidsef/scapy-containerised:v2025.02f17f7c435891
libarchive@3.7.7-r0
3.7.9-r0
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
libarchive@3.6.2-1
no fix listed
1
ghcr.io/afairgiant/medikeep:v0.69.0766699daa9ac
libarchive@3.6.2-1+deb12u4
no fix listed
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
libarchive@3.6.2-1+deb12u1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
libarchive@3.6.2-1+deb12u1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libarchive@3.6.2-1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.