StackRadar

CVE-2025-2361

Medium

Advisory

Published 17 Mar 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
121
of 17,781 indexed, latest versions
Container images
130
deployed by those charts
Fix available
1 of 1
affected package

mercurial - security update

Carried by container images the latest versions of 121 of 17,781 indexed charts deploy, on 130 images.

Affected packageAffected versionsFixed inImages
mercurialdeb5.6.1-4, 6.3.2-1, 6.7.2-1ubuntu2.25.6.1-4+deb11u1, 6.3.2-1+deb12u1130
OSV records
DEBIAN-CVE-2025-2361UBUNTU-CVE-2025-2361DLA-4094-1
Also known as
DSA-5883-1

Charts affected

121 by stars
ChartLatestAffected imagesRadar Score
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
mercurial@6.3.2-1
6.3.2-1+deb12u1

Open the chart page →

68,240
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
mercurial@6.3.2-1
6.3.2-1+deb12u1

Open the chart page →

32,902
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
mercurial@6.3.2-1
6.3.2-1+deb12u1

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
mercurial@6.3.2-1
6.3.2-1+deb12u1

Open the chart page →

16,620
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
mercurial@5.6.1-4
5.6.1-4+deb11u1

Open the chart page →

4,245
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
mercurial@5.6.1-4
5.6.1-4+deb11u1

Open the chart page →

7,574
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
sashafefler/spacecapybara_app:latestf96d7804c0ca
mercurial@6.3.2-1
6.3.2-1+deb12u1

Open the chart page →

11,888
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
mercurial@6.3.2-1
6.3.2-1+deb12u1

Open the chart page →

20,223
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
mercurial@6.3.2-1
6.3.2-1+deb12u1

Open the chart page →

6,779
student-producerstudentproducerVerified publisher2.0.01 of 1See more

student-producer studentproducer 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
aroralalit/student-producer:1.0.02a094f597b36
mercurial@5.6.1-4
5.6.1-4+deb11u1

Open the chart page →

3,018
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
mercurial@6.3.2-1
6.3.2-1+deb12u1

Open the chart page →

13,390
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
mercurial@6.3.2-1
6.3.2-1+deb12u1

Open the chart page →

11,199
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
mercurial@6.3.2-1
6.3.2-1+deb12u1

Open the chart page →

11,648
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
mercurial@6.3.2-1
6.3.2-1+deb12u1

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
mercurial@6.3.2-1
6.3.2-1+deb12u1

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
mercurial@6.3.2-1
6.3.2-1+deb12u1

Open the chart page →

28,858
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
mercurial@6.3.2-1
6.3.2-1+deb12u1

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
mercurial@6.3.2-1
6.3.2-1+deb12u1

Open the chart page →

14,358
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
mercurial@5.6.1-4
5.6.1-4+deb11u1

Open the chart page →

3,392
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
mercurial@5.6.1-4
5.6.1-4+deb11u1

Open the chart page →

9,397
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-2361.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
mercurial@5.6.1-4
5.6.1-4+deb11u1

Open the chart page →

1,838

Container images carrying it

130 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
mercurial@6.3.2-1
6.3.2-1+deb12u1
6
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
mercurial@6.3.2-1
6.3.2-1+deb12u1
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
mercurial@6.3.2-1
6.3.2-1+deb12u1
2
library/python:3.7eedf63967cdb
mercurial@6.3.2-1
6.3.2-1+deb12u1
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
mercurial@6.3.2-1
6.3.2-1+deb12u1
2
pecan/bety:5.4.1f825d480cd62
mercurial@5.6.1-4
5.6.1-4+deb11u1
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
mercurial@6.3.2-1
6.3.2-1+deb12u1
2
uffizzi/controller:latest0344805f267b
mercurial@6.3.2-1
6.3.2-1+deb12u1
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
mercurial@6.3.2-1
6.3.2-1+deb12u1
2
aboogie/login_test_backend:new9c41a4483ac8
mercurial@6.3.2-1
6.3.2-1+deb12u1
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
mercurial@6.7.2-1ubuntu2.2
no fix listed
1
andreacioni/kube-workload-restarter:0.0.242938b310090a
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
apache/drill:1.21.11f96558fd292
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
archish27/python-fastapi-postgres:latest6610071a2101
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
aroralalit/student-producer:1.0.02a094f597b36
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
mercurial@6.3.2-1
6.3.2-1+deb12u1
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
mercurial@6.3.2-1
6.3.2-1+deb12u1
1
atomix/atomix:3.1.127738ff4f5c63
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
avinash263/pyredis263:latestaa2b8727f1a6
mercurial@6.3.2-1
6.3.2-1+deb12u1
1
azhar008/flaskapplication:latesta1e827b0adea
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
mercurial@6.3.2-1
6.3.2-1+deb12u1
1
bnjbvr/kresus:0.22.137e216b182c8
mercurial@6.3.2-1
6.3.2-1+deb12u1
1
buntha/mlflow:2.1.1154542cc3083
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
mercurial@6.3.2-1
6.3.2-1+deb12u1
1
chubaofs/cfs-client:3.2.015ff74209ce7
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
chubaofs/cfs-server:3.2.0205030e045f2
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
danuk/telegram-sender:0.0.1026560388070
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
darkobas/ethexporter:latest62e6464491ba
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
darkobas/tokenexporter:latesta0349a0eedf0
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
douz/helpdesk:latest4384103d0219
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
duck1123/me.untethr.nostr-relay:0.2.1119fc5d4cbfb
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
elyra/kernel-image-puller:3.2.2c922f1f1646a
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
erlangsolutions/wombatoam:4.1.284680c990147a
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
fanzynoodle/smeejas:0.0.15f9916c1a287
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
golenski/db-init:1.0.086ca17cd3063
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
ha33ona/python:test6affdfc644d0
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
mercurial@6.3.2-1
6.3.2-1+deb12u1
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
mercurial@6.3.2-1
6.3.2-1+deb12u1
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
mercurial@6.3.2-1
6.3.2-1+deb12u1
1
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
knspar/phronetis-operator:0.1.60c4f0543ee58
mercurial@6.3.2-1
6.3.2-1+deb12u1
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
mercurial@5.6.1-4
5.6.1-4+deb11u1
1
library/python:3.8d41127070014
mercurial@6.3.2-1
6.3.2-1+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.