StackRadar

CVE-2025-25196

Medium

Advisory

Published 19 Feb 2025In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
5.8
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
1 of 1
affected package

OpenFGA Authorization Bypass

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
github.com/openfga/openfgagolangv1.5.4, v1.6.21.8.57
OSV records
GHSA-g4v5-6f5p-m38j
Also known as
GO-2025-3470

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
dbrepodbrepo1.13.31 of 25See more

dbrepo dbrepo 1.13.3

1 of the 25 container images this version deploys carry CVE-2025-25196.

Container imageDigestPackageFixed in
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
github.com/openfga/openfga@v1.5.4
1.8.5

Open the chart page →

52,635
grafanabook-k8sinfra-v28.8.21 of 1See more

grafana book-k8sinfra-v2 8.8.2

1 of the 1 container images this version deploys carry CVE-2025-25196.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
github.com/openfga/openfga@v1.5.4
1.8.5

Open the chart page →

1,800
kube-prometheus-stackbook-k8sinfra-v265.5.11 of 6See more

kube-prometheus-stack book-k8sinfra-v2 65.5.1

1 of the 6 container images this version deploys carry CVE-2025-25196.

Container imageDigestPackageFixed in
grafana/grafana:11.2.2-security-01464eac539793
github.com/openfga/openfga@v1.5.4
1.8.5

Open the chart page →

6,036
monitoringgaloymoney0.12.211 of 6See more

monitoring galoymoney 0.12.21

1 of the 6 container images this version deploys carry CVE-2025-25196.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
github.com/openfga/openfga@v1.5.4
1.8.5

Open the chart page →

5,295
monitoringgaloymoney20.12.211 of 6See more

monitoring galoymoney2 0.12.21

1 of the 6 container images this version deploys carry CVE-2025-25196.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
github.com/openfga/openfga@v1.5.4
1.8.5

Open the chart page →

5,295
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2025-25196.

Container imageDigestPackageFixed in
grafana/grafana:11.3.1fa801ab6e1ae
github.com/openfga/openfga@v1.5.4
1.8.5

Open the chart page →

49,025
monitoring-stackhelm-charts-alexis-carbillet0.1.01 of 11See more

monitoring-stack helm-charts-alexis-carbillet 0.1.0

1 of the 11 container images this version deploys carry CVE-2025-25196.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
github.com/openfga/openfga@v1.5.4
1.8.5

Open the chart page →

9,460
kubecostradar-baseVerified publisher1.0.01 of 7See more

kubecost radar-base 1.0.0

1 of the 7 container images this version deploys carry CVE-2025-25196.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
github.com/openfga/openfga@v1.5.4
1.8.5

Open the chart page →

9,355
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2025-25196.

Container imageDigestPackageFixed in
grafana/grafana:11.5.28b37a2f028f1
github.com/openfga/openfga@v1.6.2
1.8.5

Open the chart page →

7,901
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-25196.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
github.com/openfga/openfga@v1.6.2
1.8.5

Open the chart page →

9,381

Container images carrying it

7 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
grafana/grafana:11.3.0a0f881232a6f
github.com/openfga/openfga@v1.5.4
1.8.5
3
grafana/grafana:11.4.0d8ea37798ccc
github.com/openfga/openfga@v1.5.4
1.8.5
2
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
github.com/openfga/openfga@v1.5.4
1.8.5
1
grafana/grafana:11.2.2-security-01464eac539793
github.com/openfga/openfga@v1.5.4
1.8.5
1
grafana/grafana:11.5.15781759b3d27
github.com/openfga/openfga@v1.6.2
1.8.5
1
grafana/grafana:11.5.28b37a2f028f1
github.com/openfga/openfga@v1.6.2
1.8.5
1
grafana/grafana:11.3.1fa801ab6e1ae
github.com/openfga/openfga@v1.5.4
1.8.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.