StackRadar

CVE-2025-26465

Medium

Advisory

Published 18 Feb 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.077
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
307
of 17,781 indexed, latest versions
Container images
306
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: openssh security update

Carried by container images the latest versions of 307 of 17,781 indexed charts deploy, on 306 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4, 1:7.2p2-4ubuntu2.6, 1:7.2p2-4ubuntu2.7+34 more1:7.2p2-4ubuntu2.10+esm7, 1:7.6p1-4ubuntu0.7+esm4, 1:8.2p1-4ubuntu0.12, 1:8.2p1-4ubuntu0.fips.0.12+5 more265
opensshapk9.3_p1-r3, 9.3_p2-r0, 9.3_p2-r1, 9.3_p2-r2+5 more9.3_p2-r3, 9.6_p1-r2, 9.7_p1-r5, 9.9_p2-r028
opensshrpm8.0p1-4.el8_1, 8.0p1-6.el8_4.2, 8.0p1-9.el8, 8.0p1-15.el8_6.3+5 more0:8.0p1-26.el8_10, 0:8.7p1-38.el9_4.5, 0:8.7p1-45.el913
OSV records
ALPINE-CVE-2025-26465DEBIAN-CVE-2025-26465RHSA-2025:16823RHSA-2025:3837RHSA-2025:6993UBUNTU-CVE-2025-26465DLA-4057-1
Also known as
DSA-5868-1, USN-7270-1, USN-7270-2

Charts affected

307 by stars
ChartLatestAffected imagesRadar Score
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5

Open the chart page →

14,358
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4

Open the chart page →

3,392
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4

Open the chart page →

9,397
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.11

Open the chart page →

14,100
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4

Open the chart page →

1,838

Container images carrying it

306 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
azhar008/flaskapplication:latesta1e827b0adea
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
openssh@1:9.2p1-2+deb12u4
1:9.2p1-2+deb12u5
1
bnjbvr/kresus:0.22.137e216b182c8
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
buntha/mlflow:2.1.1154542cc3083
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
calltelemetry/web:0.8.1-rc7205d13269e350
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
calltelemetry/web:0.6.7457a7e353542
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
castopod/castopod:1.12.101fd37280cbb2
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
openssh@1:8.9p1-3ubuntu0.15
no fix listed
1
chetangautamm/repo:sipp.v3e7f7049e1544
openssh@1:8.2p1-4ubuntu0.1
1:8.2p1-4ubuntu0.12
1
cheveo/azp-agent:1.0.282240f890884
openssh@1:8.9p1-3ubuntu0.11
no fix listed
1
chubaofs/cfs-client:3.2.015ff74209ce7
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
chubaofs/cfs-server:3.2.0205030e045f2
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
codercom/code-server:4.11.0-debian1e2cc688008e
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
countly/api:25.05.4f4cc7447c4f5
openssh@1:8.4p1-5+deb11u3
1:8.4p1-5+deb11u4
1
countly/countly-server:25.05.4e3c238248f99
openssh@1:8.2p1-4ubuntu0.4
1:8.2p1-4ubuntu0.12
1
cribl/cribl:3.0.2762747cb6796
openssh@1:7.6p1-4ubuntu0.3
1:7.6p1-4ubuntu0.7+esm4
1
danuk/k8s-sftp-gcs:latestdd0e6585c44f
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
danuk/telegram-sender:0.0.1026560388070
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
darkobas/ethexporter:latest62e6464491ba
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
darkobas/tokenexporter:latesta0349a0eedf0
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
datamate/seafile-professional:11.0.202dd66b722464
openssh@1:8.9p1-3ubuntu0.13
no fix listed
1
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.11
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
openssh@1:8.2p1-4ubuntu0.13
1:8.2p1-4ubuntu0.fips.0.12
1
douz/helpdesk:latest4384103d0219
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
duck1123/me.untethr.nostr-relay:0.2.1119fc5d4cbfb
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
elyra/kernel-image-puller:3.2.2c922f1f1646a
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
emberstack/sftp:5.1.711d81a5df909b
openssh@1:8.4p1-5+deb11u3
1:8.4p1-5+deb11u4
1
epamedp/jenkins-operator:2.15.328ef56bc0ca3
openssh@9.3_p2-r0
9.3_p2-r3
1
erlangsolutions/wombatoam:4.1.284680c990147a
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
errbotio/errbot:6.1.900ee4e0953ab
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
esphome/esphome:2024.3.09ab8cc88b28c
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
esphome/esphome:2024.12.2b2c6322700ac
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
openssh@1:7.2p2-4ubuntu2.2
1:7.2p2-4ubuntu2.10+esm7
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
fanzynoodle/smeejas:0.0.15f9916c1a287
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
openssh@1:8.2p1-4ubuntu0.13
1:8.2p1-4ubuntu0.fips.0.12
1
gethue/hue:4.11.011b649636e68
openssh@1:8.2p1-4ubuntu0.5
1:8.2p1-4ubuntu0.12
1
gethue/hue:4.10.05702b2c37ff9
openssh@1:7.6p1-4ubuntu0.3
1:7.6p1-4ubuntu0.7+esm4
1
gethue/hue:latest7d5c1b9f8a79
openssh@1:8.9p1-3ubuntu0.13
no fix listed
1
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
openssh@9.7_p1-r4
9.7_p1-r5
1
gitea/gitea:1.22.376f516a1a8c2
openssh@9.7_p1-r4
9.7_p1-r5
1
gitea/gitea:1.21.6ac73e0da341f
openssh@9.3_p2-r1
9.3_p2-r3
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
openssh@1:8.2p1-4ubuntu0.5
1:8.2p1-4ubuntu0.12
1
golenski/db-init:1.0.086ca17cd3063
openssh@1:8.4p1-5+deb11u3
1:8.4p1-5+deb11u4
1
ha33ona/python:test6affdfc644d0
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
hashicorp/terraform:1.44dcb45513699
openssh@9.3_p2-r0
9.3_p2-r3
1
hashicorp/terraform:1.9.7b77efab1a448
openssh@9.7_p1-r4
9.7_p1-r5
1
haugene/transmission-openvpn:4.0059216cfae4b
openssh@1:8.2p1-4ubuntu0.3
1:8.2p1-4ubuntu0.12
1
haveagitgat/tdarr:2.00.181256348872ce
openssh@1:8.2p1-4ubuntu0.4
1:8.2p1-4ubuntu0.12
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.