CVE-2025-24976
UnscoredAdvisory
Published 3 Mar 2025In the index since 5 Sept 2026
- Severity
- Unscored
- worst across findings
- CVSS
- —
- base score, highest
- EPSS
- 0.004
- 27th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 17
- of 17,957 indexed, latest versions
- Container images
- 27
- deployed by those charts
- Fix available
- None
- affected package
Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT in github.com/distribution/distribution
Carried by container images the latest versions of 17 of 17,957 indexed charts deploy, on 27 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v2.7.1+incompatible, v2.8.0+incompatible, v2.8.1+incompatible, v2.8.2+incompatible+1 more | no fix listed | 27 |
- OSV records
- GO-2025-3460
- Also known as
- GHSA-phw4-mc57-4hwc
Charts affected
17 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| harborharborOfficialVerified publisher | 1.19.2 | 3 of 8See more | 1,802 |
| kubescape-operatorkubescape | 1.40.4 | 1 of 6See more | 1,060 |
| coreinstill-aiOfficialVerified publisher | 0.1.75 | 1 of 15See more | 32,513 |
| harborwener | 1.19.2 | 3 of 8See more | 1,802 |
| cp4d-deployercloud-native-toolkit | 1.0.0 | 1 of 1See more | 25,449 |
| kyvernodevopstalesVerified publisher | 2.5.1 | 2 of 2See more | 4,733 |
| harborgpg-dev | 1.18.3 | 3 of 8See more | 3,492 |
| harborhelm-harborVerified publisher | 2.3.5 | 3 of 8See more | 1,802 |
| holmesholmes | 0.1.0 | 1 of 1See more | 1,949 |
| harborkubesphereVerified publisher | 1.9.3 | 3 of 11See more | 17,895 |
| pixie-operator-chartpixie | 0.1.7 | 1 of 3See more | 1,923 |
| pixie-operator-helm2-chartpixie | 0.1.2 | 1 of 2See more | 1,778 |
| harborquench-harborVerified publisher | 0.0.31 | 3 of 9See more | 577 |
| harborsb-helm-charts | 0.3.0 | 1 of 2See more | 1,700 |
| sikalabs-harbor-master-snapshotsikalabs | 2023.6.20 | 3 of 8See more | 1,724 |
| harborsoftonic | 1.13.0 | 3 of 8See more | 7,747 |
| harborwenerme | 1.19.2 | 3 of 8See more | 1,802 |
Container images carrying it
27 by charts deploying them
A fixed version is listed for 0 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| goharbor/ | d7b780d23721 | github.com/ | no fix listed | 4 |
| goharbor/ | f71a4452a095 | github.com/ | no fix listed | 4 |
| goharbor/ | 223d5cb49d5d | github.com/ | no fix listed | 4 |
| goharbor/ | 3dc58ddedce5 | github.com/ | no fix listed | 1 |
| goharbor/ | 6412d679fdc3 | github.com/ | no fix listed | 1 |
| goharbor/ | 86bf3031f4a7 | github.com/ | no fix listed | 1 |
| goharbor/ | a30e5a8be3d9 | github.com/ | no fix listed | 1 |
| goharbor/ | c017dd84ee96 | github.com/ | no fix listed | 1 |
| goharbor/ | 39435daedd0c | github.com/ | no fix listed | 1 |
| goharbor/ | 563eb6cfd199 | github.com/ | no fix listed | 1 |
| goharbor/ | 8d5339ff2d74 | github.com/ | no fix listed | 1 |
| goharbor/ | e2b0298e894d | github.com/ | no fix listed | 1 |
| goharbor/ | 7f82ed1e2635 | github.com/ | no fix listed | 1 |
| goharbor/ | b8fa35c3d36e | github.com/ | no fix listed | 1 |
| goharbor/ | cce272836449 | github.com/ | no fix listed | 1 |
| goharbor/ | ddf6bb429eb6 | github.com/ | no fix listed | 1 |
| instill/ | b53eaa51c523 | github.com/ | no fix listed | 1 |
| ghcr.io/ | 9c73f1841ebc | github.com/ | no fix listed | 1 |
| ghcr.io/ | 185d2eebc60c | github.com/ | no fix listed | 1 |
| ghcr.io/ | fdd355a617e2 | github.com/ | no fix listed | 1 |
| ghcr.io/ | aef039822244 | github.com/ | no fix listed | 1 |
| ghcr.io/ | 8773e7e1d412 | github.com/ | no fix listed | 1 |
| quay.io/ | 13aaae779248 | github.com/ | no fix listed | 1 |
| quay.io/ | 2044ed750f5e | github.com/ | no fix listed | 1 |
| quay.io/ | 1b6002156f56 | github.com/ | no fix listed | 1 |
| quay.io/ | 39081bf0c4a9 | github.com/ | no fix listed | 1 |
| quay.io/ | f9ea8cef95ac | github.com/ | no fix listed | 1 |