StackRadar

CVE-2025-26465

Medium

Advisory

Published 18 Feb 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.077
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
307
of 17,781 indexed, latest versions
Container images
306
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: openssh security update

Carried by container images the latest versions of 307 of 17,781 indexed charts deploy, on 306 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4, 1:7.2p2-4ubuntu2.6, 1:7.2p2-4ubuntu2.7+34 more1:7.2p2-4ubuntu2.10+esm7, 1:7.6p1-4ubuntu0.7+esm4, 1:8.2p1-4ubuntu0.12, 1:8.2p1-4ubuntu0.fips.0.12+5 more265
opensshapk9.3_p1-r3, 9.3_p2-r0, 9.3_p2-r1, 9.3_p2-r2+5 more9.3_p2-r3, 9.6_p1-r2, 9.7_p1-r5, 9.9_p2-r028
opensshrpm8.0p1-4.el8_1, 8.0p1-6.el8_4.2, 8.0p1-9.el8, 8.0p1-15.el8_6.3+5 more0:8.0p1-26.el8_10, 0:8.7p1-38.el9_4.5, 0:8.7p1-45.el913
OSV records
ALPINE-CVE-2025-26465DEBIAN-CVE-2025-26465RHSA-2025:16823RHSA-2025:3837RHSA-2025:6993UBUNTU-CVE-2025-26465DLA-4057-1
Also known as
DSA-5868-1, USN-7270-1, USN-7270-2

Charts affected

307 by stars
ChartLatestAffected imagesRadar Score
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5

Open the chart page →

14,358
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4

Open the chart page →

3,392
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4

Open the chart page →

9,397
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.11

Open the chart page →

14,100
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4

Open the chart page →

1,838

Container images carrying it

306 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
novumrgi/glowroot-central:0.14.0-beta.38c54790675b1
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
ntakashi/gitana:1.4.04171ec641120
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
openssh@9.7_p1-r4
9.7_p1-r5
1
omecproject/onos-progran:1.0.05715e5648aa0
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm7
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
openssh@1:7.2p2-4ubuntu2.7
1:7.2p2-4ubuntu2.10+esm7
1
opea/codegen-ui:1.02bee4eb66f3e
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
opea/codetrans-ui:1.03ef121f34610
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
opea/docsum-ui:1.07f854e9bffaf
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
openssh@1:7.6p1-4ubuntu0.3
1:7.6p1-4ubuntu0.7+esm4
1
phntom/email-manager:0.1.22d8e2a9f2f085
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
phntom/external-dns-host-network:0.0.123adadbac8443
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
psorab/elibrary:latest53b68896c4ce
openssh@1:8.2p1-4ubuntu0.7
1:8.2p1-4ubuntu0.12
1
robmarkcole/deepstack-ui:latest410275726459
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
robotshop/rs-dispatch:latestde81f1d07b02
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
robotshop/rs-payment:latest774b52c6180d
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
robotshop/rs-shipping:latest89753ab48919
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
rundeck/rundeck:3.2.74d64fe56f767
openssh@1:7.2p2-4ubuntu2.8
1:7.2p2-4ubuntu2.10+esm7
1
rundeck/rundeck:3.0.16b13e8059ad72
openssh@1:7.2p2-4ubuntu2.6
1:7.2p2-4ubuntu2.10+esm7
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
openssh@1:8.9p1-3ubuntu0.11
no fix listed
1
salehmir/jesse:1.10.101afa95f979e9
openssh@1:8.4p1-5+deb11u3
1:8.4p1-5+deb11u4
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.11
1
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.11
1
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.11
1
seafileltd/seafile-mc:9.0.106693911bcc40
openssh@1:8.2p1-4ubuntu0.2
1:8.2p1-4ubuntu0.12
1
seafileltd/seafile-mc:10.0.170628f29c663
openssh@1:8.2p1-4ubuntu0.7
1:8.2p1-4ubuntu0.12
1
seafileltd/seafile-mc:9.0.97ac833196f60
openssh@1:8.2p1-4ubuntu0.2
1:8.2p1-4ubuntu0.12
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.11
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
openssh@1:8.2p1-4ubuntu0.2
1:8.2p1-4ubuntu0.12
1
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
openssh@9.3_p2-r0
9.3_p2-r3
1
seataio/seata-server:latest703b5de7f1a6
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
seldonio/locust-core:0.81d0da98a2d76
openssh@1:7.2p2-4ubuntu2.8
1:7.2p2-4ubuntu2.10+esm7
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
openssh@8.0p1-6.el8_4.2
0:8.0p1-26.el8_10
1
semaphoreui/semaphore:v2.9.645b50bc11833f
openssh@9.3_p2-r1
9.3_p2-r3
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
openssh@1:8.2p1-4ubuntu0.9
1:8.2p1-4ubuntu0.12
1
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
socialmediamacroscope/classification_train:0.1.207477060bba8
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
socialmediamacroscope/clowder_create_dataset:0.1.09b4211832429
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
socialmediamacroscope/clowder_create_space:0.1.0999f2ff2c128
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
socialmediamacroscope/clowder_list:0.1.051cb17626519
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.