StackRadar

CVE-2025-24358

Medium

Advisory

Published 14 Apr 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.0
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
21
of 17,781 indexed, latest versions
Container images
19
deployed by those charts
Fix available
1 of 1
affected package

gorilla/csrf CSRF vulnerability due to broken Referer validation

Carried by container images the latest versions of 21 of 17,781 indexed charts deploy, on 19 images.

Affected packageAffected versionsFixed inImages
github.com/gorilla/csrfgolangv1.6.2, v1.7.0, v1.7.1, v1.7.2+1 more1.7.319
OSV records
GHSA-rq77-p4h8-4crw
Also known as
GO-2025-3607

Charts affected

21 by stars
ChartLatestAffected imagesRadar Score
harborharborOfficialVerified publisher1.19.21 of 8See more

harbor harbor 1.19.2

1 of the 8 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.15.2d7b780d23721
github.com/gorilla/csrf@v1.7.2
1.7.3

Open the chart page →

1,650
headscalegabe565Verified publisher0.16.01 of 2See more

headscale gabe565 0.16.0

1 of the 2 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
github.com/gorilla/csrf@v1.7.3-0.20250123201450-9dd6af1f6d30
1.7.3

Open the chart page →

1,979
tailscale-relaymvisonneau0.2.71 of 1See more

tailscale-relay mvisonneau 0.2.7

1 of the 1 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
mvisonneau/tailscale:v1.68.1fc45ad8abf10
github.com/gorilla/csrf@v1.7.2
1.7.3

Open the chart page →

1,356
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
headscale/headscale:0.25.1a7a8ae9616bb
github.com/gorilla/csrf@v1.7.3-0.20250123201450-9dd6af1f6d30
1.7.3

Open the chart page →

7,949
beaconchain-explorerethereum-helm-chartsVerified publisher0.1.61 of 2See more

beaconchain-explorer ethereum-helm-charts 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
github.com/gorilla/csrf@v1.7.0
1.7.3

Open the chart page →

3,048
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
artifacthub/hub:v1.19.0111918d8c399
github.com/gorilla/csrf@v1.7.2
1.7.3

Open the chart page →

14,491
cortezacorteza1.0.121 of 3See more

corteza corteza 1.0.12

1 of the 3 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.4cb9f200de5d2
github.com/gorilla/csrf@v1.7.1
1.7.3

Open the chart page →

8,368
corteza-all-in-onecorteza0.1.01 of 2See more

corteza-all-in-one corteza 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.08eb7a26605c9
github.com/gorilla/csrf@v1.7.1
1.7.3

Open the chart page →

4,644
admin-console-operatorepmdedpVerified publisher2.14.01 of 2See more

admin-console-operator epmdedp 2.14.0

1 of the 2 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
epamedp/edp-admin-console:2.14.0616c678ba3e7
github.com/gorilla/csrf@v1.7.1
1.7.3

Open the chart page →

4,308
harborgpg-dev1.18.31 of 8See more

harbor gpg-dev 1.18.3

1 of the 8 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.14.3a30e5a8be3d9
github.com/gorilla/csrf@v1.7.2
1.7.3

Open the chart page →

3,376
gophishhelmforgeVerified publisher0.1.51 of 1See more

gophish helmforge 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
gophish/gophish:0.12.18a57cd171999
github.com/gorilla/csrf@v1.6.2
1.7.3

Open the chart page →

2,819
harborhelm-harborVerified publisher2.3.51 of 8See more

harbor helm-harbor 2.3.5

1 of the 8 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.15.2d7b780d23721
github.com/gorilla/csrf@v1.7.2
1.7.3

Open the chart page →

1,650
sing-boxhuscker-chartsVerified publisher1.0.71 of 1See more

sing-box huscker-charts 1.0.7

1 of the 1 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
ghcr.io/sagernet/sing-box:v1.12.03c1ee82d450d
github.com/gorilla/csrf@v1.7.3-0.20250123201450-9dd6af1f6d30
1.7.3

Open the chart page →

1,443
harborkubesphereVerified publisher1.9.31 of 11See more

harbor kubesphere 1.9.3

1 of the 11 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.5.386bf3031f4a7
github.com/gorilla/csrf@v1.6.2
1.7.3

Open the chart page →

17,798
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
github.com/gorilla/csrf@v1.7.2
1.7.3

Open the chart page →

3,225
vcluster-control-planeloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

vcluster-control-plane loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
github.com/gorilla/csrf@v1.7.2
1.7.3

Open the chart page →

3,225
harborsb-helm-charts0.3.01 of 2See more

harbor sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.11.1c017dd84ee96
github.com/gorilla/csrf@v1.7.2
1.7.3

Open the chart page →

1,680
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
github.com/gorilla/csrf@v1.7.1
1.7.3

Open the chart page →

3,286
tailscale-operatorskyloud-helm-chartsVerified publisher1.70.31 of 1See more

tailscale-operator skyloud-helm-charts 1.70.3

1 of the 1 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
tailscale/k8s-operator:v1.70.08edd06cf5bac
github.com/gorilla/csrf@v1.7.2
1.7.3

Open the chart page →

1,045
harborsoftonic1.13.01 of 8See more

harbor softonic 1.13.0

1 of the 8 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
github.com/gorilla/csrf@v1.6.2
1.7.3

Open the chart page →

7,672
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2025-24358.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.15.2d7b780d23721
github.com/gorilla/csrf@v1.7.2
1.7.3

Open the chart page →

1,650

Container images carrying it

19 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
goharbor/harbor-core:v2.15.2d7b780d23721
github.com/gorilla/csrf@v1.7.2
1.7.3
3
artifacthub/hub:v1.19.0111918d8c399
github.com/gorilla/csrf@v1.7.2
1.7.3
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
github.com/gorilla/csrf@v1.7.1
1.7.3
1
cortezaproject/corteza:2024.9.08eb7a26605c9
github.com/gorilla/csrf@v1.7.1
1.7.3
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
github.com/gorilla/csrf@v1.7.1
1.7.3
1
epamedp/edp-admin-console:2.14.0616c678ba3e7
github.com/gorilla/csrf@v1.7.1
1.7.3
1
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
github.com/gorilla/csrf@v1.7.0
1.7.3
1
goharbor/harbor-core:v2.9.06412d679fdc3
github.com/gorilla/csrf@v1.6.2
1.7.3
1
goharbor/harbor-core:v2.5.386bf3031f4a7
github.com/gorilla/csrf@v1.6.2
1.7.3
1
goharbor/harbor-core:v2.14.3a30e5a8be3d9
github.com/gorilla/csrf@v1.7.2
1.7.3
1
goharbor/harbor-core:v2.11.1c017dd84ee96
github.com/gorilla/csrf@v1.7.2
1.7.3
1
gophish/gophish:0.12.18a57cd171999
github.com/gorilla/csrf@v1.6.2
1.7.3
1
headscale/headscale:0.25.1a7a8ae9616bb
github.com/gorilla/csrf@v1.7.3-0.20250123201450-9dd6af1f6d30
1.7.3
1
mvisonneau/tailscale:v1.68.1fc45ad8abf10
github.com/gorilla/csrf@v1.7.2
1.7.3
1
tailscale/k8s-operator:v1.70.08edd06cf5bac
github.com/gorilla/csrf@v1.7.2
1.7.3
1
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
github.com/gorilla/csrf@v1.7.3-0.20250123201450-9dd6af1f6d30
1.7.3
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
github.com/gorilla/csrf@v1.7.2
1.7.3
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
github.com/gorilla/csrf@v1.7.2
1.7.3
1
ghcr.io/sagernet/sing-box:v1.12.03c1ee82d450d
github.com/gorilla/csrf@v1.7.3-0.20250123201450-9dd6af1f6d30
1.7.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.