StackRadar

CVE-2025-24528

High

Advisory

Published 31 Jan 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,461
of 17,790 indexed, latest versions
Container images
1,616
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: krb5 security update

Carried by container images the latest versions of 1,461 of 17,790 indexed charts deploy, on 1,616 images.

Affected packageAffected versionsFixed inImages
krb5deb1.12+dfsg-2ubuntu5, 1.12+dfsg-2ubuntu5.1, 1.12+dfsg-2ubuntu5.3, 1.12+dfsg-2ubuntu5.4+35 more1.17-6ubuntu4.9, 1.18.3-6+deb11u6, 1.19.2-2ubuntu0.6, 1.20.1-2+deb12u3+1 more1,350
krb5rpm1.15.1-37.el7_6, 1.15.1-37.el7_7.2, 1.15.1-46.el7, 1.15.1-50.el7+29 more0:1.15.1-55.el7_9.4, 0:1.18.2-31.el8_10, 0:1.21.1-6.el9, 1.21.3-2.1266
OSV records
DEBIAN-CVE-2025-24528UBUNTU-CVE-2025-24528RHSA-2025:1352RHSA-2025:2722RHSA-2025:7067RLSA-2025:2722RLSA-2025:7067DLA-4065-1openSUSE-SU-2025:14736-1
Also known as
USN-7314-1

Charts affected

1,461 by stars
ChartLatestAffected imagesRadar Score
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u3

Open the chart page →

5,559
vaultwardenwitcom-gmbh0.2.01 of 2See more

vaultwarden witcom-gmbh 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
vaultwarden/server:1.25.239f34c5159a2
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6

Open the chart page →

1,586
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6

Open the chart page →

2,021
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.6

Open the chart page →

14,173
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
krb5@1.18.2-14.el8
0:1.18.2-31.el8_10

Open the chart page →

11,603
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u3

Open the chart page →

7,697
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
hamzaarshad10/querypodpy:1.7154f38e8668e
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
murtazashah46/helmfile:latest4d11726cf803
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3

Open the chart page →

13,783
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
krb5@1.20.1-6ubuntu2
1.20.1-6ubuntu2.5

Open the chart page →

2,142
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
krb5@1.18.2-22.el8_7
0:1.18.2-31.el8_10

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u6

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
krb5@1.18.2-22.el8_7
0:1.18.2-31.el8_10

Open the chart page →

3,697

Container images carrying it

1,616 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
duck1123/me.untethr.nostr-relay:0.2.1119fc5d4cbfb
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
easypi/openrefine:3.7.0d2950a36a576
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
easysoft/quickon-zentao:18.5592ad5df1f8b
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u6
1
eclipseaerios/openldap:2.6.30208743f315e
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u6
1
elastic/apm-server:7.17.6c7a1c63257d0
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.9
1
elastictranscoder/media:627e21dc963ab3858c6b
krb5@1.16-2ubuntu0.1
no fix listed
1
elastictranscoder/media-storage:f6d861a026208b8c2359
krb5@1.16-2ubuntu0.1
no fix listed
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
krb5@1.16-2ubuntu0.1
no fix listed
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
krb5@1.16-2ubuntu0.1
no fix listed
1
elyra/kernel-image-puller:3.2.2c922f1f1646a
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u6
1
emberstack/sftp:5.1.711d81a5df909b
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u6
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.9
1
emqx/ecp-ui:2.5.1e33e9816f147
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
1
engrmth/bnkr:2.1.06d8464e6f0e8
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.9
1
envoyproxy/envoy:v1.30.92956bd9de830
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.6
1
envoyproxy/envoy:v1.33.056da5afd7df3
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.6
1
envoyproxy/envoy:v1.30.1e596fda6a0ce
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.6
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
krb5@1.16-2ubuntu0.3
no fix listed
1
erlangsolutions/wombatoam:4.1.284680c990147a
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u6
1
errbotio/errbot:6.1.900ee4e0953ab
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
esphome/esphome:2024.3.09ab8cc88b28c
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u3
1
esphome/esphome:2024.12.2b2c6322700ac
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
1
esphome/esphome:2025.3.0def8b6e4f517
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
krb5@1.13.2+dfsg-5ubuntu2
no fix listed
1
ethersphere/ethproxy:latest3a8a3926caa2
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u6
1
evk02/mlflow:2.2.1ef6ff257ef35
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
expediagroup/pitchfork:1.314f2cf61e7de9
krb5@1.18.3-6
1.18.3-6+deb11u6
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u6
1
fanzynoodle/smeejas:0.0.15f9916c1a287
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
farberg/apache-knox-docker:1.6.14b4a22487394
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
felipecs8/app-db-connection-test:v129e06c9c6385
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
1
firefart/requesttracker:5.0.40d6249906d8c
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u3
1
fiware/mintaka:0.7.092a3c5cf43c0
krb5@1.18.2-14.el8
0:1.18.2-31.el8_10
1
fiware/mintaka:latestefc6793388cc
krb5@1.18.2-14.el8
0:1.18.2-31.el8_10
1
flag5/clustersecret:0.0.94ad5748bfcc6
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
flanksource/apm-hub:v0.0.471dacc3195bf9
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.6
1
flofree/base-project:2.1.16b6486c5f81e
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
fluent/fluent-bit:2.2.00fa18c71d821
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u6
1
fluent/fluent-bit:2.15766d881ddb1
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u6
1
fluent/fluent-bit:2.1.96a1d0c693dfa
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u6
1
flyway/flyway:9.1545b5d7cdc75a
krb5@1.17-6ubuntu4.2
1.17-6ubuntu4.9
1
fnzv/dump1090:latestb3079b95c336
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.6
1
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
krb5@1.21.1-4.el9_5
0:1.21.1-6.el9
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
krb5@1.16-2ubuntu0.1
no fix listed
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
krb5@1.16-2ubuntu0.1
no fix listed
1
free5gmano/nextepc-mongodb:latest36f806935519
krb5@1.13.2+dfsg-5ubuntu2.1
no fix listed
1
freedom98/flask:k3.0d7ce1533f297
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
1
galaxy/cloudman-server:lateste5c265fe9fcd
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.9
1
galaxy/galaxy-init:v18.010267bad550e6
krb5@1.12+dfsg-2ubuntu5.3
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
krb5@1.12+dfsg-2ubuntu5.3
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.