StackRadar

CVE-2025-24528

High

Advisory

Published 31 Jan 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,461
of 17,790 indexed, latest versions
Container images
1,616
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: krb5 security update

Carried by container images the latest versions of 1,461 of 17,790 indexed charts deploy, on 1,616 images.

Affected packageAffected versionsFixed inImages
krb5deb1.12+dfsg-2ubuntu5, 1.12+dfsg-2ubuntu5.1, 1.12+dfsg-2ubuntu5.3, 1.12+dfsg-2ubuntu5.4+35 more1.17-6ubuntu4.9, 1.18.3-6+deb11u6, 1.19.2-2ubuntu0.6, 1.20.1-2+deb12u3+1 more1,350
krb5rpm1.15.1-37.el7_6, 1.15.1-37.el7_7.2, 1.15.1-46.el7, 1.15.1-50.el7+29 more0:1.15.1-55.el7_9.4, 0:1.18.2-31.el8_10, 0:1.21.1-6.el9, 1.21.3-2.1266
OSV records
DEBIAN-CVE-2025-24528UBUNTU-CVE-2025-24528RHSA-2025:1352RHSA-2025:2722RHSA-2025:7067RLSA-2025:2722RLSA-2025:7067DLA-4065-1openSUSE-SU-2025:14736-1
Also known as
USN-7314-1

Charts affected

1,461 by stars
ChartLatestAffected imagesRadar Score
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u3

Open the chart page →

5,559
vaultwardenwitcom-gmbh0.2.01 of 2See more

vaultwarden witcom-gmbh 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
vaultwarden/server:1.25.239f34c5159a2
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6

Open the chart page →

1,586
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6

Open the chart page →

2,021
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.6

Open the chart page →

14,173
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
krb5@1.18.2-14.el8
0:1.18.2-31.el8_10

Open the chart page →

11,603
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u3

Open the chart page →

7,697
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
hamzaarshad10/querypodpy:1.7154f38e8668e
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
murtazashah46/helmfile:latest4d11726cf803
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3

Open the chart page →

13,783
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
krb5@1.20.1-6ubuntu2
1.20.1-6ubuntu2.5

Open the chart page →

2,142
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
krb5@1.18.2-22.el8_7
0:1.18.2-31.el8_10

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u6

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
krb5@1.18.2-22.el8_7
0:1.18.2-31.el8_10

Open the chart page →

3,697

Container images carrying it

1,616 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
andrianrf/iso-client:latestba560086ce15
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
andrianrf/iso-server:latest7da47f525c7d
krb5@1.20.1-8.el9
0:1.21.1-6.el9
1
anguda/ant-media:2.5c435285fc241
krb5@1.17-6ubuntu4.3
1.17-6ubuntu4.9
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
krb5@1.20.1-2
1.20.1-2+deb12u3
1
apache/activemq-artemis:2.37.0bae523439ee3
krb5@1.20.1-6ubuntu2.1
1.20.1-6ubuntu2.5
1
apache/airflow:2.8.4-python3.964e58748b6b9
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u3
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
1
apache/airflow:2.8.1e5560ad0b86e
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u3
1
apache/camel-k:1.10.43bb13d14f64a
krb5@1.18.2-14.el8
0:1.18.2-31.el8_10
1
apache/drill:1.21.11f96558fd292
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
apache/iotdb:0.13.3-nodeafa47bf1692a
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.9
1
apache/nifi-registry:1.27.063b8e3e40742
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.6
1
apachepinot/pinot:latest-jdk110018bb04ced7
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.6
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.9
1
apachepulsar/pulsar:3.0.79c9947de139d
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.6
1
apachepulsar/pulsar:2.9.0d056c89b7131
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.9
1
apachepulsar/pulsar:2.8.2d538416d5afe
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.9
1
apache/rocketmq:5.3.0434d8398f996
krb5@1.20.1-6ubuntu2
1.20.1-6ubuntu2.5
1
apache/rocketmq-exporter:0.0.2c8fb51195444
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.6
1
apache/skywalking-oap-server:9.2.0133d35d2c263
krb5@1.19.2-2
1.19.2-2ubuntu0.6
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.9
1
apache/skywalking-ui:9.2.0295f1dc87d98
krb5@1.19.2-2
1.19.2-2ubuntu0.6
1
apache/skywalking-ui:8.9.180530f0308a5
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.9
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
apache/superset:4.0.1ab9467fd712c
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u3
1
apache/tika:2.9.0.092d055a84e9e
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.6
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
krb5@1.18.2-25.el8_8
0:1.18.2-31.el8_10
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
krb5@1.18.2-8.el8
0:1.18.2-31.el8_10
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
krb5@1.18.2-25.el8_8
0:1.18.2-31.el8_10
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
krb5@1.18.2-25.el8_8
0:1.18.2-31.el8_10
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
krb5@1.18.2-25.el8_8
0:1.18.2-31.el8_10
1
apimap/api:v1.8.11ae2b3ab00177
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u6
1
apimap/developer:v1.3.1406d3858e20c
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u6
1
apimap/portal:v2.4.0041a4790c65c
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u6
1
archish27/python-fastapi-postgres:latest6610071a2101
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
aristidetm/basic-notebook:3.6.5469dbc951224
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
1
aristidetm/k8s-hub:3.3.7ccb516cb8474
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u6
1
aroralalit/student-producer:1.0.02a094f597b36
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
1
artifacthub/tracker:v1.19.06596c8c4d955
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u6
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u3
1
arturisimo/planner:v1.0fff9de644941
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
krb5@1.17-6ubuntu4.3
1.17-6ubuntu4.9
1
assistiot/cybersecurity-monitoring_ir-ctx:latestae8b3d72eb5d
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u6
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u6
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.9
1
assistiot/identity-manager_db:latest0d3e6d35f168
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u3
1
assistiot/identity-manager_kc:latest0df4b4fa899a
krb5@1.18.2-14.el8
0:1.18.2-31.el8_10
1
assistiot/location_processing:lateste9bae124095f
krb5@1.19.2-2
1.19.2-2ubuntu0.6
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.