StackRadar

CVE-2025-26465

Medium

Advisory

Published 18 Feb 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.077
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
307
of 17,781 indexed, latest versions
Container images
306
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: openssh security update

Carried by container images the latest versions of 307 of 17,781 indexed charts deploy, on 306 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4, 1:7.2p2-4ubuntu2.6, 1:7.2p2-4ubuntu2.7+34 more1:7.2p2-4ubuntu2.10+esm7, 1:7.6p1-4ubuntu0.7+esm4, 1:8.2p1-4ubuntu0.12, 1:8.2p1-4ubuntu0.fips.0.12+5 more265
opensshapk9.3_p1-r3, 9.3_p2-r0, 9.3_p2-r1, 9.3_p2-r2+5 more9.3_p2-r3, 9.6_p1-r2, 9.7_p1-r5, 9.9_p2-r028
opensshrpm8.0p1-4.el8_1, 8.0p1-6.el8_4.2, 8.0p1-9.el8, 8.0p1-15.el8_6.3+5 more0:8.0p1-26.el8_10, 0:8.7p1-38.el9_4.5, 0:8.7p1-45.el913
OSV records
ALPINE-CVE-2025-26465DEBIAN-CVE-2025-26465RHSA-2025:16823RHSA-2025:3837RHSA-2025:6993UBUNTU-CVE-2025-26465DLA-4057-1
Also known as
DSA-5868-1, USN-7270-1, USN-7270-2

Charts affected

307 by stars
ChartLatestAffected imagesRadar Score
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5

Open the chart page →

14,358
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4

Open the chart page →

3,392
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4

Open the chart page →

9,397
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.11

Open the chart page →

14,100
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4

Open the chart page →

1,838

Container images carrying it

306 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
socialmediamacroscope/screen_name_prompt:0.1.2724f3f5702e0
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5
1
stackstorm/st2actionrunner:3.888235ba70cad
openssh@1:8.2p1-4ubuntu0.9
1:8.2p1-4ubuntu0.12
1
stackstorm/st2api:3.86f56d239d280
openssh@1:8.2p1-4ubuntu0.9
1:8.2p1-4ubuntu0.12
1
stackstorm/st2auth:3.833ecfda16608
openssh@1:8.2p1-4ubuntu0.9
1:8.2p1-4ubuntu0.12
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
openssh@1:8.2p1-4ubuntu0.9
1:8.2p1-4ubuntu0.12
1
stackstorm/st2notifier:3.8f190a6212195
openssh@1:8.2p1-4ubuntu0.9
1:8.2p1-4ubuntu0.12
1
stackstorm/st2rulesengine:3.8259503496ff9
openssh@1:8.2p1-4ubuntu0.9
1:8.2p1-4ubuntu0.12
1
stackstorm/st2scheduler:3.8b1de2055c362
openssh@1:8.2p1-4ubuntu0.9
1:8.2p1-4ubuntu0.12
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
openssh@1:8.2p1-4ubuntu0.9
1:8.2p1-4ubuntu0.12
1
stackstorm/st2stream:3.81c8904a3bf67
openssh@1:8.2p1-4ubuntu0.9
1:8.2p1-4ubuntu0.12
1
stackstorm/st2timersengine:3.81bf35bfaf00c
openssh@1:8.2p1-4ubuntu0.9
1:8.2p1-4ubuntu0.12
1
stackstorm/st2workflowengine:3.819fdfffdbba8
openssh@1:8.2p1-4ubuntu0.9
1:8.2p1-4ubuntu0.12
1
statcan/ckan:2.93921305425b8
openssh@1:8.2p1-4ubuntu0.2
1:8.2p1-4ubuntu0.12
1
stratospire/activityrelay:0.2.3a4c34cb01117
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
substratusai/verba:v0.4.0-baseURL261695be635eb
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
openssh@1:8.9p1-3ubuntu0.7
1:8.9p1-3ubuntu0.11
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
openssh@1:8.2p1-4ubuntu0.7
1:8.2p1-4ubuntu0.12
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
teknas09/bird-pod:latest12a1fa85c4aa
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
th0th/node-red:4.0.3-debiand06fa39f7406
openssh@1:8.4p1-5+deb11u3
1:8.4p1-5+deb11u4
1
theradius/loggia:0.463ba348546ec
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
thongngo3301/stakefish:latesta341af5976e3
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5
1
tksky1/cubeuniverse:0.1alphaec7b889f380f
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
ubcctlt/barman:v2.19cbbbbc8ae16b
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
openssh@8.0p1-19.el8_8
0:8.0p1-26.el8_10
1
vlebediantsev/config-server-another:lateste7f20450d2ae
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
vlebediantsev/file-system-ms-final:latest10393a89b4a8
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
vlebediantsev/logic-ms:latestdf8bf38c535b
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
vlebediantsev/notes-admin-front:latest007c6670ff48
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5
1
vlebediantsev/notes-project-front:latest945675fd2636
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5
1
vlebediantsev/registration-ms-final:latest427af418b75e
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
voltha/voltha-cli:1.6.0c4e41e92f046
openssh@1:7.2p2-4ubuntu2.6
1:7.2p2-4ubuntu2.10+esm7
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.11
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
youssef11gaber10/deployment-ui-react:latestba6853e35c60
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
zbalogh/reservation-api-server:1.0.97c247e399a1f
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
openssh@1:7.6p1-4ubuntu0.3
1:7.6p1-4ubuntu0.7+esm4
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
gcr.io/ml-pipeline/metadata-writer:2.0.0-alpha.5ec3ae9f6df47
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
ghcr.io/0xemma/reddark:main2a115e991894
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
openssh@9.7_p1-r3
9.7_p1-r5
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
openssh@9.9_p1-r2
9.9_p2-r0
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
openssh@1:8.2p1-4ubuntu0.5
1:8.2p1-4ubuntu0.12
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
ghcr.io/codingducksrl/wordpress:6.0.23113c0960507
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.