StackRadar

CVE-2025-24855

High

Advisory

Published 14 Mar 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
252
of 17,781 indexed, latest versions
Container images
245
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libxslt security update

Carried by container images the latest versions of 252 of 17,781 indexed charts deploy, on 245 images.

Affected packageAffected versionsFixed inImages
libxsltdeb1.1.28-2.1ubuntu0.3, 1.1.28-2ubuntu0.1, 1.1.29-5ubuntu0.2, 1.1.34-4+5 more1.1.28-2.1ubuntu0.3+esm3, 1.1.28-2ubuntu0.2+esm4, 1.1.29-5ubuntu0.3+esm2, 1.1.34-4ubuntu0.20.04.3+3 more173
libxsltapk1.1.38-r0, 1.1.39-r0, 1.1.39-r1, 1.1.42-r11.1.38-r1, 1.1.39-r1, 1.1.39-r2, 1.1.42-r269
libxsltrpm1.1.34-9.el90:1.1.34-9.el9_5.13
OSV records
ALPINE-CVE-2025-24855DEBIAN-CVE-2025-24855RHSA-2025:3107UBUNTU-CVE-2025-24855
Also known as
RHSA-2025:3389, USN-7361-1, USN-7787-1

Charts affected

252 by stars
ChartLatestAffected imagesRadar Score
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-24855.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
libxslt@1.1.38-r0
1.1.38-r1

Open the chart page →

448
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-24855.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
libxslt@1.1.38-r0
1.1.38-r1

Open the chart page →

1,589

Container images carrying it

245 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
knspar/phronetis-operator:0.1.60c4f0543ee58
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
kubeshop/testkube-dashboard:1.16.748958b4126a4
libxslt@1.1.38-r0
1.1.38-r1
1
kubevirtmanager/kubevirt-manager:1.3.3df3ea27d4a9e
libxslt@1.1.38-r0
1.1.38-r1
1
library/nginx:1.25.4-alpine31bad00311cb
libxslt@1.1.38-r0
1.1.38-r1
1
library/nginx:1.25.167f9a4f10d14
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
library/nginx:1.25.49ff236ed47fe
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
library/nginx:1.27.3fb197595ebe7
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
library/postgres:16.6557fea37a744
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
library/postgres:16.4-alpine5660c2cbfea5
libxslt@1.1.39-r1
1.1.39-r2
1
library/postgres:17.4-alpine7062a2109c4b
libxslt@1.1.42-r1
1.1.42-r2
1
library/postgres:12.15-alpine73ea9cdd4a9d
libxslt@1.1.38-r0
1.1.38-r1
1
library/postgres:12-alpine7c8f48705831
libxslt@1.1.42-r1
1.1.42-r2
1
library/postgres:17.2-alpine7e5df973a748
libxslt@1.1.42-r1
1.1.42-r2
1
library/postgres:15.38775adb39f0d
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
library/postgres:16.2-alpine951bfda46030
libxslt@1.1.39-r0
1.1.39-r1
1
library/postgres:13.12ced3ba927f4c
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
library/python:3.8d41127070014
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.3
1
livekit/ingress:v1.2.21ab01641b366
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.3
1
mediagis/nominatim:3.7c15e941485ef
libxslt@1.1.34-4ubuntu0.20.04.1
1.1.34-4ubuntu0.20.04.3
1
mediagis/nominatim:4.2d0eae7b51374
libxslt@1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.3
1
moreillon/user-manager-front:v5.1.06597e6b98d21
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
muhammedgamal/fp23:latest74b4cd69b6fa
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
nginxinc/nginx-unprivileged:1.25-alpine8265b1df5a89
libxslt@1.1.39-r0
1.1.39-r1
1
nginxinc/nginx-unprivileged8f14986c54fa
libxslt@1.1.39-r0
1.1.39-r1
1
nirmalnaveen/supermario:latest8541a39162f3
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
opea/chatqna-conversation-ui:v0.9bdb9ec215872
libxslt@1.1.39-r1
1.1.39-r2
1
opea/codegen-ui:1.02bee4eb66f3e
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
opea/codetrans-ui:1.03ef121f34610
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
opea/docsum-ui:1.07f854e9bffaf
libxslt@1.1.35-1
1.1.35-1+deb12u1
1
openelevation/open-elevation:latest82fb21612e86
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.3
1
openkm/openkm-ce:6.3.113bc465a7461b
libxslt@1.1.34-4ubuntu0.20.04.1
1.1.34-4ubuntu0.20.04.3
1
owncloud/server:10.15.051d9b74fc2a8
libxslt@1.1.34-4ubuntu0.20.04.1
1.1.34-4ubuntu0.20.04.3
1
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
libxslt@1.1.34-4
1.1.34-4ubuntu0.20.04.3
1
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
libxslt@1.1.28-2.1ubuntu0.3
1.1.28-2.1ubuntu0.3+esm3
1
pnnlmiscscripts/k8s-node-image:1.22.17-nginx-362b3ae9b5ec25
libxslt@1.1.39-r0
1.1.39-r1
1
pnnlmiscscripts/k8s-node-image:1.24.17-nginx-23952d87cca3d2
libxslt@1.1.39-r0
1.1.39-r1
1
pnnlmiscscripts/k8s-node-image:1.23.17-nginx-36a5ee1dea30e4
libxslt@1.1.39-r0
1.1.39-r1
1
pnnlmiscscripts/k8s-node-image:1.21.14-nginx-36c19a40d7435d
libxslt@1.1.39-r0
1.1.39-r1
1
pnnlmiscscripts/k8s-node-image9:1.28.15-nginx-72b91d6a46e06
libxslt@1.1.39-r1
1.1.39-r2
1
pnnlmiscscripts/k8s-node-image9:1.25.16-nginx-772c202c43c0aa
libxslt@1.1.39-r1
1.1.39-r2
1
pnnlmiscscripts/k8s-node-image9:1.24.17-nginx-882c8dc938b2f9
libxslt@1.1.39-r1
1.1.39-r2
1
pnnlmiscscripts/k8s-node-image9:1.27.16-nginx-306e1a36d646a3
libxslt@1.1.39-r1
1.1.39-r2
1
pnnlmiscscripts/k8s-node-image9:1.26.15-nginx-579785e5b82334
libxslt@1.1.39-r1
1.1.39-r2
1
pnnlmiscscripts/k8s-node-image9:1.31.7-nginx-7e3e189d9d519
libxslt@1.1.39-r1
1.1.39-r2
1
pnnlmiscscripts/k8s-node-image9:1.30.11-nginx-7f9297eea817d
libxslt@1.1.39-r1
1.1.39-r2
1
pnnlmiscscripts/k8s-node-image9:1.29.10-nginx-7fcd82530bc8b
libxslt@1.1.39-r1
1.1.39-r2
1
postgis/postgis:15-3.3-alpine4738bee21eb6
libxslt@1.1.38-r0
1.1.38-r1
1
postgis/postgis:17-3.4-alpine5a1dbedac34e
libxslt@1.1.39-r1
1.1.39-r2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.