StackRadar

CVE-2025-24528

High

Advisory

Published 31 Jan 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,461
of 17,790 indexed, latest versions
Container images
1,616
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: krb5 security update

Carried by container images the latest versions of 1,461 of 17,790 indexed charts deploy, on 1,616 images.

Affected packageAffected versionsFixed inImages
krb5deb1.12+dfsg-2ubuntu5, 1.12+dfsg-2ubuntu5.1, 1.12+dfsg-2ubuntu5.3, 1.12+dfsg-2ubuntu5.4+35 more1.17-6ubuntu4.9, 1.18.3-6+deb11u6, 1.19.2-2ubuntu0.6, 1.20.1-2+deb12u3+1 more1,350
krb5rpm1.15.1-37.el7_6, 1.15.1-37.el7_7.2, 1.15.1-46.el7, 1.15.1-50.el7+29 more0:1.15.1-55.el7_9.4, 0:1.18.2-31.el8_10, 0:1.21.1-6.el9, 1.21.3-2.1266
OSV records
DEBIAN-CVE-2025-24528UBUNTU-CVE-2025-24528RHSA-2025:1352RHSA-2025:2722RHSA-2025:7067RLSA-2025:2722RLSA-2025:7067DLA-4065-1openSUSE-SU-2025:14736-1
Also known as
USN-7314-1

Charts affected

1,461 by stars
ChartLatestAffected imagesRadar Score
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u3

Open the chart page →

5,559
vaultwardenwitcom-gmbh0.2.01 of 2See more

vaultwarden witcom-gmbh 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
vaultwarden/server:1.25.239f34c5159a2
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6

Open the chart page →

1,586
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6

Open the chart page →

2,021
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.6

Open the chart page →

14,173
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
krb5@1.18.2-14.el8
0:1.18.2-31.el8_10

Open the chart page →

11,603
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u3

Open the chart page →

7,697
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
hamzaarshad10/querypodpy:1.7154f38e8668e
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
murtazashah46/helmfile:latest4d11726cf803
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3

Open the chart page →

13,783
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
krb5@1.20.1-6ubuntu2
1.20.1-6ubuntu2.5

Open the chart page →

2,142
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
krb5@1.18.2-22.el8_7
0:1.18.2-31.el8_10

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u6

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-24528.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
krb5@1.18.2-22.el8_7
0:1.18.2-31.el8_10

Open the chart page →

3,697

Container images carrying it

1,616 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
camunda/zeebe:8.4.5ab5abc09e407
krb5@1.19.2-2ubuntu0.3
1.19.2-2ubuntu0.6
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
1
castlemock/castlemock:latestb7f3f1527ba9
krb5@1.20.1-6ubuntu2.2
1.20.1-6ubuntu2.5
1
castopod/castopod:1.12.101fd37280cbb2
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
krb5@1.16.3-lp151.2.6.1
1.21.3-2.1
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
krb5@1.16.3-lp151.2.6.1
1.21.3-2.1
1
chandanteekinavar/findery-market-order-service:1.00cf52bf5ee9a
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
chandanteekinavar/findery-market-product-service:1.0c49ff7c141c0
krb5@1.18.3-6+deb11u5
1.18.3-6+deb11u6
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
krb5@1.12+dfsg-2ubuntu5.4
no fix listed
1
chetangautamm/repo:sipp.v3e7f7049e1544
krb5@1.17-6ubuntu4.1
1.17-6ubuntu4.9
1
cheyang/distributed-tf:1.6.046cc34755493
krb5@1.13.2+dfsg-5ubuntu2
no fix listed
1
chubaofs/cfs-client:3.2.015ff74209ce7
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
chubaofs/cfs-server:3.2.0205030e045f2
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
circleci/runner:launch-agent9bdc62f02162
krb5@1.17-6ubuntu4.7
1.17-6ubuntu4.9
1
ciscolabs/msm-nc:0710202336d02faad958
krb5@1.19.2-2ubuntu0.2
1.19.2-2ubuntu0.6
1
cleveritcz/opencve:1.5.0c75c1636e0b7
krb5@1.21.1-1.el9
0:1.21.1-6.el9
1
clickhouse/clickhouse-server:25.3.2.398745843b17f9
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.6
1
clickhouse/clickhouse-server:24.12.6a65ca89ddbe8
krb5@1.19.2-2ubuntu0.4
1.19.2-2ubuntu0.6
1
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
krb5@1.19.2-2ubuntu0.1
1.19.2-2ubuntu0.6
1
cloudve/ttyd:latestd79c1c5881c0
krb5@1.16-2ubuntu0.1
no fix listed
1
cm2network/csgo:sourcemod93df54a2e4fb
krb5@1.18.3-6+deb11u4
1.18.3-6+deb11u6
1
cmosborn/metabase-arm64:0.50.286ec0a8878ad2
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u6
1
cockroachdb/cockroach:v22.2.91116820f4134
krb5@1.18.2-22.el8_7
0:1.18.2-31.el8_10
1
cockroachdb/cockroach-operator:v2.1.0983312754620
krb5@1.18.2-8.el8
0:1.18.2-31.el8_10
1
codercom/code-server:4.11.0-debian1e2cc688008e
krb5@1.18.3-6+deb11u3
1.18.3-6+deb11u6
1
coderenvs/coder-service:1.44.61deffc4670e6
krb5@1.18.2-26.el8_9
0:1.18.2-31.el8_10
1
coderenvs/timescale:1.44.676fd37fe6830
krb5@1.18.2-26.el8_9
0:1.18.2-31.el8_10
1
codetogether/codetogether:latest4348c8a38752
krb5@1.21.1-1.el9
0:1.21.1-6.el9
1
collabora/code:24.04.13.2.101dc4ab83977
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
1
collabora/code:23.05.10.1.105299b452f7f
krb5@1.20.1-2+deb12u1
1.20.1-2+deb12u3
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
krb5@1.18.2-5.el8
0:1.18.2-31.el8_10
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
krb5@1.18.2-5.el8
0:1.18.2-31.el8_10
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
krb5@1.18.2-14.el8
0:1.18.2-31.el8_10
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
krb5@1.18.2-30.el8_10
0:1.18.2-31.el8_10
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
krb5@1.18.2-26.el8_9
0:1.18.2-31.el8_10
1
confluentinc/cp-kafka:7.5.1dc9b972db002
krb5@1.18.2-25.el8_8
0:1.18.2-31.el8_10
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
krb5@1.18.2-5.el8
0:1.18.2-31.el8_10
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
krb5@1.18.2-5.el8
0:1.18.2-31.el8_10
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
krb5@1.18.2-26.el8_9
0:1.18.2-31.el8_10
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
krb5@1.18.2-5.el8
0:1.18.2-31.el8_10
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
krb5@1.18.2-5.el8
0:1.18.2-31.el8_10
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
krb5@1.18.2-25.el8_8
0:1.18.2-31.el8_10
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
krb5@1.18.2-30.el8_10
0:1.18.2-31.el8_10
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
krb5@1.18.2-5.el8
0:1.18.2-31.el8_10
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
krb5@1.20.1-2+deb12u2
1.20.1-2+deb12u3
1
cortezaproject/corteza:2024.9.08eb7a26605c9
krb5@1.17-6ubuntu4.7
1.17-6ubuntu4.9
1
countly/api:25.05.4f4cc7447c4f5
krb5@1.18.3-6+deb11u5
1.18.3-6+deb11u6
1
countly/countly-server:25.05.4e3c238248f99
krb5@1.17-6ubuntu4.4
1.17-6ubuntu4.9
1
countly/frontend:25.05.42acbc11499b6
krb5@1.18.3-6+deb11u5
1.18.3-6+deb11u6
1
craftypath/sops-operator:v0.8.0402a0024c732
krb5@1.18.2-8.el8
0:1.18.2-31.el8_10
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.