StackRadar

CVE-2025-2174

High

Advisory

Published 11 Mar 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
55
of 17,781 indexed, latest versions
Container images
55
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 55 of 17,781 indexed charts deploy, on 55 images.

Affected packageAffected versionsFixed inImages
zvbideb0.2.35-10, 0.2.35-13, 0.2.35-17, 0.2.35-19+2 more0.2.35-10ubuntu0.1~esm1, 0.2.35-13ubuntu0.1~esm1, 0.2.35-17ubuntu0.1~esm1, 0.2.35-19ubuntu0.1~esm1+2 more55
OSV records
DEBIAN-CVE-2025-2174UBUNTU-CVE-2025-2174
Also known as
USN-7367-1

Charts affected

55 by stars
ChartLatestAffected imagesRadar Score
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-2174.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
zvbi@0.2.42-2
0.2.42-2ubuntu0.24.04.1~esm1

Open the chart page →

12,460
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-2174.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
zvbi@0.2.41-1
0.2.41-1+deb12u1

Open the chart page →

9,616
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-2174.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
zvbi@0.2.41-1
0.2.41-1+deb12u1

Open the chart page →

3,958
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-2174.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
zvbi@0.2.35-19
0.2.35-19ubuntu0.1~esm1

Open the chart page →

9,347
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-2174.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
zvbi@0.2.35-19
0.2.35-19ubuntu0.1~esm1

Open the chart page →

14,100

Container images carrying it

55 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
zvbi@0.2.41-1
0.2.41-1+deb12u1
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
zvbi@0.2.42-2
0.2.42-2ubuntu0.24.04.1~esm1
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
zvbi@0.2.42-2
0.2.42-2ubuntu0.24.04.1~esm1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.