StackRadar

CVE-2025-21614

High

Advisory

Published 6 Jan 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
113
of 17,781 indexed, latest versions
Container images
110
deployed by those charts
Fix available
1 of 2
affected packages

go-git clients vulnerable to DoS via maliciously crafted Git server replies

Carried by container images the latest versions of 113 of 17,781 indexed charts deploy, on 110 images.

Affected packageAffected versionsFixed inImages
github.com/go-git/go-git/v5golangv5.0.0, v5.1.0, v5.2.0, v5.3.0+9 more5.13.097
gopkg.in/src-d/go-git.v4golangv4.10.0, v4.13.1no fix listed16
OSV records
GHSA-r9px-m959-cxf4
Also known as
GO-2025-3367

Charts affected

113 by stars
ChartLatestAffected imagesRadar Score
codebase-operatorepmdedp-devVerified publisher2.12.0-MDTU-DDM-SNAPSHOT.101 of 1See more

codebase-operator epmdedp-dev 2.12.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
github.com/go-git/go-git/v5@v5.4.3-0.20210630082519-b4368b2a2ca4
5.13.0

Open the chart page →

2,825
gerrit-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.21 of 1See more

gerrit-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.2

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

2,811
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

13,450
apm-hubflanksourceVerified publisher0.0.471 of 2See more

apm-hub flanksource 0.0.47

1 of the 2 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
flanksource/apm-hub:v0.0.471dacc3195bf9
github.com/go-git/go-git/v5@v5.6.1
5.13.0

Open the chart page →

6,078
owncloud-ocisgeek-cookbookVerified publisher2.4.21 of 1See more

owncloud-ocis geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
owncloud/ocis:1.7.0d2efcae92c84
github.com/go-git/go-git/v5@v5.1.0
5.13.0

Open the chart page →

3,236
gitanagitana1.4.01 of 1See more

gitana gitana 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
ntakashi/gitana:1.4.04171ec641120
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

3,478
apid-helpergkarthiks0.1.41 of 1See more

apid-helper gkarthiks 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
github.com/go-git/go-git/v5@v5.6.1
5.13.0

Open the chart page →

2,607
act-runnergringolitoVerified publisher0.2.01 of 1See more

act-runner gringolito 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
github.com/go-git/go-git/v5@v5.12.0
5.13.0

Open the chart page →

2,590
goshimmerhiveroad0.2.141 of 1See more

goshimmer hiveroad 0.2.14

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
iotaledger/goshimmer:v0.8.6b02a8f77474f
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

2,544
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

10,494
gravity-initinvisiblVerified publisher1.0.91 of 1See more

gravity-init invisibl 1.0.9

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
invisibl/gravity-init:v1.0.91a970f84178b
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

2,006
deploydefenderk8s-custom-controllerVerified publisher0.1.31 of 1See more

deploydefender k8s-custom-controller 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/go-git/go-git/v5@v5.12.0
5.13.0

Open the chart page →

1,893
kiaekiae0.1.61 of 9See more

kiae kiae 0.1.6

1 of the 9 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.35.313964b29d63e
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

19,168
u4a-componentkubebb0.2.101 of 8See more

u4a-component kubebb 0.2.10

1 of the 8 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
kubebb/oidc-server:v0.2.02b5894ef1e2f
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

13,819
argo-workflowskubeblocksVerified publisher0.40.141 of 2See more

argo-workflows kubeblocks 0.40.14

1 of the 2 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
quay.io/argoproj/argocli:v3.5.591b9825f09a8
github.com/go-git/go-git/v5@v5.11.0
5.13.0

Open the chart page →

2,871
casdoor-helm-chartskubeblocksVerified publisher1.753.01 of 1See more

casdoor-helm-charts kubeblocks 1.753.0

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
casbin/casdoor:v1.753.0770ad9ec3190
github.com/go-git/go-git/v5@v5.11.0
5.13.0

Open the chart page →

2,299
grafanakubeblocksVerified publisher6.59.41 of 1See more

grafana kubeblocks 6.59.4

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
grafana/grafana:10.1.11b9ca4bbc4a2
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

3,561
kubeclaritykubeclarity2.23.31 of 5See more

kubeclarity kubeclarity 2.23.3

1 of the 5 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
ghcr.io/openclarity/grype-server:v0.6.079412399f301
github.com/go-git/go-git/v5@v5.8.1
5.13.0

Open the chart page →

5,496
harborkubesphereVerified publisher1.9.31 of 11See more

harbor kubesphere 1.9.3

1 of the 11 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

17,798
deepflowkubesphere-stable6.2.6061 of 8See more

deepflow kubesphere-stable 6.2.606

1 of the 8 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
grafana/grafana:9.5.239c849cebccc
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

18,316
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.41 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

1 of the 9 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
grafana/alloy:v1.5.101a63f4e032c
github.com/go-git/go-git/v5@v5.11.0
5.13.0

Open the chart page →

20,204
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
github.com/go-git/go-git/v5@v5.12.0
5.13.0

Open the chart page →

6,824
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

4,271
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

9,880
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
github.com/go-git/go-git/v5@v5.11.0
5.13.0

Open the chart page →

9,774
kubeaddons-catalogmesosphere0.1.161 of 2See more

kubeaddons-catalog mesosphere 0.1.16

1 of the 2 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
github.com/go-git/go-git/v5@v5.1.0
5.13.0

Open the chart page →

12,010
dexmesosphere-stable2.14.11 of 5See more

dex mesosphere-stable 2.14.1

1 of the 5 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

19,214
kommandermesosphere-stable0.39.22 of 29See more

kommander mesosphere-stable 0.39.2

2 of the 29 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
github.com/go-git/go-git/v5@v5.2.0
gopkg.in/src-d/go-git.v4@v4.13.1
5.13.0
no fix listed
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
github.com/go-git/go-git/v5@v5.1.0
5.13.0

Open the chart page →

68,284
argocd-extra-app-info-exportermikejohVerified publisher0.1.121 of 1See more

argocd-extra-app-info-exporter mikejoh 0.1.12

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
github.com/go-git/go-git/v5@v5.12.0
5.13.0

Open the chart page →

1,334
giteamyaVerified publisher23.12.51 of 1See more

gitea mya 23.12.5

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
gitea/gitea:1.21.6ac73e0da341f
github.com/go-git/go-git/v5@v5.11.0
5.13.0

Open the chart page →

3,430
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
github.com/go-git/go-git/v5@v5.1.0
5.13.0

Open the chart page →

4,861
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

8,540
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/go-git/go-git/v5@v5.3.0
5.13.0

Open the chart page →

8,599
npre-essentialsphntom0.1.601 of 22See more

npre-essentials phntom 0.1.60

1 of the 22 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
quay.io/groundcover/grafana:9.3.18c65b333a3d3
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

26,840
planectlplanectlVerified publisher0.7.01 of 10See more

planectl planectl 0.7.0

1 of the 10 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11c57233403eff
github.com/go-git/go-git/v5@v5.12.0
5.13.0

Open the chart page →

25,934
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

9,606
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/go-git/go-git/v5@v5.11.0
5.13.0

Open the chart page →

16,047
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

29,227
argocdromholdings1.8.11 of 3See more

argocd romholdings 1.8.1

1 of the 3 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

10,466
devtron-enterpriseromholdings48.0.03 of 28See more

devtron-enterprise romholdings 48.0.0

3 of the 28 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
quay.io/devtron/dex:v2.30.22e4c14d1b444
github.com/go-git/go-git/v5@v5.2.0
5.13.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/go-git/go-git/v5@v5.7.0
5.13.0
quay.io/devtron/kubectl:latest2ad610626658
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

68,240
devtron-in-clustercdromholdings0.10.21 of 2See more

devtron-in-clustercd romholdings 0.10.2

1 of the 2 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/go-git/go-git/v5@v5.6.1
5.13.0

Open the chart page →

5,039
devtron-operatorromholdings0.23.32 of 11See more

devtron-operator romholdings 0.23.3

2 of the 11 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
quay.io/devtron/dex:v2.30.22e4c14d1b444
github.com/go-git/go-git/v5@v5.2.0
5.13.0
quay.io/devtron/kubectl:latest2ad610626658
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

32,902
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
github.com/go-git/go-git/v5@v5.11.0
5.13.0

Open the chart page →

3,337
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
github.com/go-git/go-git/v5@v5.8.1
5.13.0

Open the chart page →

2,314
metrics-generatorsikalabs0.2.01 of 1See more

metrics-generator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
sikalabs/slu:v0.34.0fdc0c6711add
github.com/go-git/go-git/v5@v5.4.2
5.13.0

Open the chart page →

2,381
harborsoftonic1.13.01 of 8See more

harbor softonic 1.13.0

1 of the 8 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/go-git/go-git/v5@v5.7.0
5.13.0

Open the chart page →

7,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/go-git/go-git/v5@v5.7.0
5.13.0

Open the chart page →

2,505
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
github.com/go-git/go-git/v5@v5.12.0
5.13.0

Open the chart page →

2,416
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

2,564
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2025-21614.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed

Open the chart page →

6,671

Container images carrying it

110 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/go-git/go-git/v5@v5.7.0
5.13.0
1
quay.io/argoproj/argocli:v3.5.591b9825f09a8
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
github.com/go-git/go-git/v5@v5.3.0
5.13.0
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/go-git/go-git/v5@v5.3.0
gopkg.in/src-d/go-git.v4@v4.13.1
5.13.0
no fix listed
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
github.com/go-git/go-git/v5@v5.6.1
5.13.0
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/go-git/go-git/v5@v5.11.0
5.13.0
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/go-git/go-git/v5@v5.3.0
5.13.0
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
gopkg.in/src-d/go-git.v4@v4.13.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.