StackRadar

CVE-2025-2175

Medium

Advisory

Published 11 Mar 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
55
of 17,781 indexed, latest versions
Container images
55
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 55 of 17,781 indexed charts deploy, on 55 images.

Affected packageAffected versionsFixed inImages
zvbideb0.2.35-10, 0.2.35-13, 0.2.35-17, 0.2.35-19+2 more0.2.35-10ubuntu0.1~esm1, 0.2.35-13ubuntu0.1~esm1, 0.2.35-17ubuntu0.1~esm1, 0.2.35-19ubuntu0.1~esm1+2 more55
OSV records
DEBIAN-CVE-2025-2175UBUNTU-CVE-2025-2175
Also known as
USN-7367-1

Charts affected

55 by stars
ChartLatestAffected imagesRadar Score
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-2175.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
zvbi@0.2.42-2
0.2.42-2ubuntu0.24.04.1~esm1

Open the chart page →

12,460
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-2175.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
zvbi@0.2.41-1
0.2.41-1+deb12u1

Open the chart page →

9,616
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-2175.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
zvbi@0.2.41-1
0.2.41-1+deb12u1

Open the chart page →

3,958
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-2175.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
zvbi@0.2.35-19
0.2.35-19ubuntu0.1~esm1

Open the chart page →

9,347
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-2175.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
zvbi@0.2.35-19
0.2.35-19ubuntu0.1~esm1

Open the chart page →

14,100

Container images carrying it

55 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ciscolabs/rtsp-client:latesta7b60ec88285
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
3
ciscolabs/rtsp-server:latestb59fc10bb821
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
zvbi@0.2.35-10
0.2.35-10ubuntu0.1~esm1
3
kurento/kurento-media-server:latest03c0d34d0828
zvbi@0.2.42-2
0.2.42-2ubuntu0.24.04.1~esm1
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
zvbi@0.2.41-1
0.2.41-1+deb12u1
2
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
zvbi@0.2.35-19
0.2.35-19ubuntu0.1~esm1
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
1
castopod/castopod:1.12.101fd37280cbb2
zvbi@0.2.41-1
0.2.41-1+deb12u1
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
zvbi@0.2.35-13
0.2.35-13ubuntu0.1~esm1
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
zvbi@0.2.35-13
0.2.35-13ubuntu0.1~esm1
1
haveagitgat/tdarr:2.00.181256348872ce
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
1
jaedb/iris:latest048cfbf58d57
zvbi@0.2.41-1
0.2.41-1+deb12u1
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
zvbi@0.2.41-1
0.2.41-1+deb12u1
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
zvbi@0.2.41-1
0.2.41-1+deb12u1
1
jellyfin/jellyfin:10.10.77ae36aab93ef
zvbi@0.2.41-1
0.2.41-1+deb12u1
1
jellyfin/jellyfin:10.10.696b09723b22f
zvbi@0.2.41-1
0.2.41-1+deb12u1
1
josh5/unmanic:0.2.64d49c4816260
zvbi@0.2.35-19
0.2.35-19ubuntu0.1~esm1
1
langgenius/dify-api:0.6.11fca918260dd6
zvbi@0.2.41-1
0.2.41-1+deb12u1
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
zvbi@0.2.42-2
0.2.42-2ubuntu0.24.04.1~esm1
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
zvbi@0.2.42-2
0.2.42-2ubuntu0.24.04.1~esm1
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
zvbi@0.2.42-2
0.2.42-2ubuntu0.24.04.1~esm1
1
linuxserver/jellyfin:10.7.72427dde159a2
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
1
livekit/ingress:v1.2.21ab01641b366
zvbi@0.2.35-19
0.2.35-19ubuntu0.1~esm1
1
mlikiowa/napcat-docker:latest1336a777f9a4
zvbi@0.2.35-19
0.2.35-19ubuntu0.1~esm1
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
zvbi@0.2.35-13
0.2.35-13ubuntu0.1~esm1
1
opea/speecht5:1.0249afad3d268
zvbi@0.2.41-1
0.2.41-1+deb12u1
1
photoprism/photoprism:220629-jammy2954334adbda
zvbi@0.2.35-19
0.2.35-19ubuntu0.1~esm1
1
photoprism/photoprism:240711-cefc6fd632ca74
zvbi@0.2.42-2
0.2.42-2ubuntu0.24.04.1~esm1
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
zvbi@0.2.35-19
0.2.35-19ubuntu0.1~esm1
1
scrapinghub/splash:3.4.1a5f89bc84606
zvbi@0.2.35-13
0.2.35-13ubuntu0.1~esm1
1
selenium/node-chrome:4.48.0-202609055ac71fd8dd1e
zvbi@0.2.42-2
0.2.42-2ubuntu0.24.04.1~esm1
1
selenium/node-firefox:4.48.0-2026090574a5c1c90f95
zvbi@0.2.42-2
0.2.42-2ubuntu0.24.04.1~esm1
1
sismics/docs:v1.10f4b0ef019cf1
zvbi@0.2.35-13
0.2.35-13ubuntu0.1~esm1
1
stashapp/stash:latest24dbd7607174
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
zvbi@0.2.35-10
0.2.35-10ubuntu0.1~esm1
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
zvbi@0.2.35-19
0.2.35-19ubuntu0.1~esm1
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
zvbi@0.2.35-19
0.2.35-19ubuntu0.1~esm1
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
zvbi@0.2.35-17
0.2.35-17ubuntu0.1~esm1
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
zvbi@0.2.35-13
0.2.35-13ubuntu0.1~esm1
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
zvbi@0.2.41-1
0.2.41-1+deb12u1
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
zvbi@0.2.41-1
0.2.41-1+deb12u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
zvbi@0.2.41-1
0.2.41-1+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.